Donor Information Security and Privacy Disclosure Policy
The Open Lunch Project Effective Date: 07/06/2026 | Last Updated: 07/06/2026
1. Introduction
The Open Lunch Project ("we," "us," "our," or the "Organization") is deeply grateful for the trust our donors place in us. Protecting the privacy and security of donor information is a responsibility we take seriously, and it is fundamental to the relationship between our donors and our mission.
This Donor Information Security and Privacy Disclosure Policy ("Policy") explains what information we collect from our donors and website visitors, how we use it, how we protect it, and the choices donors have regarding their information. This Policy applies to all donations made through our website, www.openlunchproject.org, as well as donations made by mail, phone, or in person.
By donating to or interacting with The Open Lunch Project, you can trust that your personal and financial information will be handled with the highest standards of care, confidentiality, and integrity.
2. Information We Collect
To process donations and maintain accurate donor records, we collect the following categories of information:
a. Contact Information
Full name
Mailing address
Email address
Phone number (if provided)
b. Transaction and Payment Information
Donation amount and date
Payment method (e.g., credit card, debit card, ACH/bank transfer)
Billing address
Transaction confirmation and receipt data
Please note: Full payment card numbers, bank account numbers, and other sensitive financial credentials are collected and processed directly by our secure third-party payment processors (see Section 4). The Open Lunch Project does not store complete payment card numbers on our own servers.
c. Optional Information
We may also collect information you voluntarily provide, such as:
Comments or messages submitted with a donation (e.g., "in honor of" or "in memory of" designations)
Communication preferences
Employer information (for matching gift purposes)
3. How We Use Your Information
We use the information collected solely for legitimate organizational and donor-relations purposes, including to:
Process donations securely and accurately, including verifying and completing transactions.
Issue tax receipts and acknowledgment letters for your charitable contributions, as required by IRS regulations for 501(c)(3) organizations.
Communicate with you about our mission, programs, impact updates, newsletters, and fundraising campaigns (you may opt out at any time — see Section 6).
Maintain accurate financial and donor records for internal accounting, auditing, and reporting purposes.
Comply with legal, tax, and regulatory requirements, including responding to lawful requests from regulators or law enforcement.
Improve our donor experience, such as by understanding giving trends to better steward donor relationships.
We do not use donor information for any purpose beyond what is described in this Policy without first obtaining consent.
4. Data Security Measures
The Open Lunch Project employs industry-standard administrative, technical, and physical safeguards to protect donor information from unauthorized access, disclosure, alteration, or destruction. These measures include:
Encryption: All data transmitted through our website, including donation forms, is encrypted using industry-standard TLS/SSL protocols.
Secure Third-Party Payment Processors: All online donations are processed through Stripe, PayPal, and Zeffy, each of which is a PCI-DSS compliant payment processor. These providers maintain their own rigorous security standards for handling and storing sensitive payment card data. The Open Lunch Project never has direct access to a donor's full credit card number.
Firewalls and Network Security: Our systems are protected by firewalls, intrusion detection tools, and regular security monitoring to guard against unauthorized network access.
Restricted Access Protocols: Access to donor information is limited to authorized staff and volunteers who require it to perform their job functions, based on a strict need-to-know basis. Access is protected by unique credentials and, where applicable, multi-factor authentication.
Regular Audits and Reviews: We periodically review our data handling practices, vendor security certifications, and internal access controls to ensure ongoing compliance with this Policy.
Staff Training: Employees and volunteers with access to donor data receive training on data privacy and security best practices.
While we take extensive precautions to protect donor information, no method of electronic storage or transmission is 100% secure. We encourage donors to also take steps to protect their own information, such as using secure networks when donating online.
5. Third-Party Sharing
The Open Lunch Project does not sell, trade, rent, or otherwise share donor information with outside organizations for their marketing or commercial purposes.
We may share limited information with trusted third parties only in the following limited circumstances:
Payment Processing: With Stripe, PayPal, and Zeffy, solely to complete and process donation transactions.
Service Providers: With vendors who perform services on our behalf (e.g., email delivery, database hosting, mailing services), who are contractually bound to protect your data and use it only for the specific service provided.
Legal Requirements: When required to do so by law, subpoena, or other legal process, or to protect the rights, property, or safety of The Open Lunch Project, our donors, or the public.
With Your Consent: In any other circumstance, only with your explicit permission.
Any third party with access to donor data is required to maintain confidentiality and security standards consistent with this Policy.
6. Data Retention & Donor Choice
We retain donor information for as long as necessary to fulfill the purposes outlined in this Policy, including tax and legal record-keeping requirements (typically a minimum of 7 years for financial records, in accordance with IRS guidelines).
Donors have the right to control how their information is used and displayed:
Request Anonymity: Donors may request that their name be withheld from any public donor listing, annual report, or public acknowledgment. We will honor all anonymity requests made at the time of donation or afterward.
Opt Out of Communications: Donors may unsubscribe from email newsletters at any time by clicking the "unsubscribe" link included in every email, or by contacting us directly.
Request Removal from Mailing Lists: Donors may request to be removed from physical mailing lists at any time.
Access, Correct, or Delete Information: Donors may request to review, correct, or delete their personal information from our records, subject to our legal obligation to retain certain financial and tax records.
To make any of these requests, please contact us at:
contact@openlunchproject.orgP.O. Box 103, Richmond, VA 23218
We will respond to and process all such requests within a reasonable timeframe, typically within 30 days.
7. Updates to This Policy
The Open Lunch Project may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational needs. Any changes will be posted on this page at www.openlunchproject.org, along with a revised "Last Updated" date at the top of this Policy.
We encourage donors to review this Policy periodically to stay informed about how we are protecting your information. Continued use of our website or continued giving following any changes constitutes your acceptance of the updated Policy.
Contact Us
If you have any questions, concerns, or requests regarding this Policy or how your information is handled, please contact us:
The Open Lunch Project
P.O. Box 103, Richmond, VA 23218
This Policy is intended to provide transparency to our donor community and reflects our ongoing commitment to responsible data stewardship. It does not constitute a legal contract or guarantee, and organizations should have this document reviewed by qualified legal counsel to ensure compliance with all applicable federal, state, and local laws (including but not limited to state data privacy laws such as the CCPA/CPRA, where applicable).

