Privacy
What we collect, what we refuse to collect, and who can see it.
Last updated August 29, 2026
What we never collect
Your Social Security number or any other taxpayer identification number. There is no field for one anywhere in the product, and text matching that pattern is rejected rather than stored.
Your card number, security code, or bank details. Payment information goes to Stripe and never reaches our servers.
What we do collect
- Your account. Name, email, postal address, and an optional phone number. The address is on your receipts, which is why we ask for it.
- Your contributions. Amount, date, tax year, which organization received it, payment status, and the Stripe identifiers for the transaction.
- Your receipts and every version of them.
- Security and audit records. Sign-ins, failed sign-ins, and actions taken on compliance-sensitive records, with timestamps and IP addresses.
Who can see it
- You, for everything of yours.
- Administrators at an organization you have contributed to, limited to your contributions to that organization and the contact details they need to acknowledge them. They cannot see gifts you made elsewhere.
- SGO Direct staff, for support, compliance, and fraud review.
- Stripe, which processes payments and holds the payment details we deliberately do not.
Other donors never see anything of yours. We do not sell personal information, and we do not share it for advertising.
How long we keep it
Contribution and receipt records are retained for at least seven years, matching ordinary tax record-retention practice. These are financial records tied to a credit you may claim, so we do not delete them on request.
You can close your account. When you do, we pseudonymize the identity on your profile and keep the financial ledger, which is the part we are obliged to retain. Receipts already issued stay issued.
Your choices
You can view and correct your profile from your account at any time. You can request a copy of your data or ask us to close your account by writing to us. If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, those rights apply to you and we honour them regardless of where you live.
Security
Traffic is encrypted in transit and data is encrypted at rest. Passwords are hashed with Argon2id and never stored in a readable form. Access is scoped by role and re-checked on every request rather than trusted from a session token. Sign-in and contribution endpoints are rate limited.
Cookies
We set a session cookie when you sign in. That is the only cookie the product requires, and we do not run advertising or cross-site tracking cookies.
Contact
Write to privacy@sgodirect.com. See also our disclosures.
SGO Direct is an independent technology platform and is not affiliated with the IRS, U.S. Treasury, or any state government.
Tax treatment depends on applicable law and individual circumstances. Consult a qualified tax professional.