Policy version 2026-09-21-v1UK GDPR / Data Protection Act design
Data we use
Account details, charity relationships, saved causes, volunteering bookings and attendance, donation and ticket records, accessibility preferences, security events, and information you choose to publish or send to United Cause. Payment card or wallet credentials are handled by the payment provider and are not stored by United Cause.
Why we use it
To provide accounts and requested services, prevent fraud, run charity verification, deliver events and tickets, maintain volunteering rotas, record donations and impact, protect the service, and meet legal/accounting obligations where they apply. The production operator must document the lawful basis for each processing purpose in the included ROPA and DPIA templates.
Sharing and external services
Information is shared only where necessary to provide a feature you choose, such as payment processing or loading Google Maps. Embedded external content is consent-controlled. Charities receive information needed to manage their own event tickets or volunteer bookings; they should not receive unrelated account data.
Your rights and controls
The account workspace includes machine-readable export, preference controls, giving-plan management and account deletion. Other rights requests can be handled by the production operator through the contact details published in the final Privacy Notice.
Retention
United Cause is designed to remove or anonymise member profile data when an account is deleted while preserving transaction or audit records only where the operator has a documented legal need to retain them. Exact live retention periods must be configured and documented before launch.