Skip to content
All legal documents

Privacy Policy

What personal data we collect, why we process it and how you can exercise your rights.

Last updated on August 15, 2026

Love Changes processes personal data to run its donation programme, answer messages and keep the website secure. This notice explains what we collect, on what legal basis, for how long we keep it and how you stay in control.

It is written to satisfy the Brazilian General Data Protection Law (LGPD), the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

Controller and data protection contact

Love Changes is the controller of the personal data described here and decides why and how it is processed.

Data protection requests and questions go through the contact form on our website, choosing the "Privacy or my data" topic. Every request that arrives there is answered, including access, correction and deletion.

Data we collect

We only collect what a specific purpose requires:

  • Donation data: name, e-mail address, optional phone number, amount, currency, frequency, donation status and reference code.
  • Payment data: handled directly by Stripe. We never see or store full card numbers — we only keep the identifiers Stripe returns.
  • Contact data: the name, e-mail address and message you type into the contact form.
  • Technical data: IP address, browser and device information, pages requested, and error and security logs generated automatically by our servers.
  • Consent records: the version of this notice you accepted, along with the date and time of the acceptance.

How we use your data

Each category is used for a declared purpose:

  • to process donations, issue receipts and manage recurring contributions;
  • to send transactional e-mail such as donation confirmations, reference codes and payment failure notices;
  • to answer the messages you send us;
  • to keep the service secure: fraud prevention, rate limiting, abuse investigation and incident response;
  • to comply with accounting, tax and nonprofit reporting obligations;
  • to produce aggregate statistics about our work, which never identify an individual donor.

Who we share data with

We do not sell, rent or trade personal data, and we do not share it for cross-context behavioural advertising. We share the minimum necessary with processors bound by contract:

  • Stripe, Inc. — payment processing and card data handling (PCI DSS certified).
  • Resend — delivery of transactional e-mail.
  • Our hosting provider — running the application and the PostgreSQL database, including encrypted backups.
  • Error monitoring — diagnostic reports about application failures, with personal identifiers removed before transmission.

International transfers

Our providers operate servers outside Brazil and outside the European Economic Area, mainly in the United States and in the European Union. Transfers are covered by standard contractual clauses and by the equivalent safeguards required by art. 33 of the LGPD.

How long we keep data

We delete or anonymize data once its purpose ends:

  • Donation and receipt records: kept for the period required by tax and nonprofit accounting rules, currently seven years after the donation.
  • Contact messages: up to 24 months after the conversation ends.
  • Security, access and error logs: up to 12 months.
  • Consent records: for as long as the related processing lasts, plus the applicable limitation period.

Security

Traffic is encrypted with TLS; administrative credentials are stored as scrypt hashes; administrative sessions expire and are logged; API endpoints are rate limited; database backups are taken daily and stored with restricted access.

No system is completely immune. If a breach is likely to create a risk to your rights, we will notify you and the competent authority within the deadlines set by the applicable law.

Your rights

Depending on where you live, you may exercise the following rights free of charge:

  • confirmation that we process your data and access to a copy of it;
  • correction of incomplete, inaccurate or outdated data;
  • deletion of data processed on the basis of consent, or that is no longer necessary;
  • anonymization or blocking of unnecessary or excessive data;
  • portability of your data to another provider in a machine-readable format;
  • objection to processing based on legitimate interests, and withdrawal of consent;
  • information about the public and private entities with which we share data;
  • for California residents: the right to know, to delete, to correct and to opt out of sale or sharing — which we do not practise — without being discriminated against for exercising them.

How to exercise your rights

Send your request through the contact form on our website, choosing the "Privacy or my data" topic, using the e-mail address linked to your data. We may ask for extra information to confirm your identity before acting on it.

We reply within 15 days for requests under the LGPD and within 30 days for requests under the GDPR and the CCPA. If a request is complex we may extend the deadline once, telling you why.

Children and adolescents

The website is not directed at children. We do not knowingly collect data from people under 18 without the consent of a parent or legal guardian. If you believe a child has sent us personal data, write to us and we will delete it.

Cookies

We use the smallest possible set of cookies, and non-essential cookies are only set after you accept them. The Cookie Policy lists each cookie, its purpose and its lifetime.

Complaints

If you are not satisfied with our answer, you may complain to the Brazilian data protection authority (ANPD), to the supervisory authority of your European member state, or to the competent authority in your country of residence.

Changes to this notice

When this notice changes we update the revision date shown at the top of the page and, for material changes, announce it on the website before the new version takes effect.