Privacy Policy

Last updated: August 1, 2026

HypeRaise LLC ("HypeRaise") is committed to protecting the privacy and security of students, families, schools, teams, clubs, and other organizations participating in fundraisers through the HypeRaise platform. This policy describes how the platform operates today. Where a protection is not yet built, this policy says so rather than describing an intended future state; those items are listed in Section 14.

Definitions

  • "Student" or "Participant" means a minor enrolled in or affiliated with a school, team, club, or organization who takes part in a fundraiser, whether or not they place an order themselves.

  • "Customer" or "Supporter" means an individual who places an order or makes a purchase or donation in support of a fundraiser, and who may or may not also be a Participant.

  • "Contact" or "Helper" means a person whose name and email address or phone number a Participant or School Official adds to a fundraiser so that fundraiser messages may be sent to them.

  • "School Official" means an authorized administrator, coach, teacher, or organization representative responsible for a given fundraiser.

  • "School-Administered Mode" means a fundraiser operated entirely by a School Official, in which no Participant creates an account and no Participant-specific features are used. See Section 4.

  • The commitments in this policy regarding student and Participant information apply to any individual meeting either definition above, regardless of which role they are acting in at a given moment.

1. Applicability and Compliance Framework

This policy addresses HypeRaise's obligations under the Children's Online Privacy Protection Act (COPPA) and the amended COPPA Rule, 16 C.F.R. Part 312; FERPA and the Protection of Pupil Rights Amendment, where a school designates HypeRaise a school official or discloses directory information; the Telephone Consumer Protection Act and the CAN-SPAM Act; state student-data-privacy statutes governing vendors, including California SOPIPA, Illinois SOPPA, New York Education Law § 2-d and 8 NYCRR Part 121, Connecticut, Colorado, and Texas; state comprehensive privacy laws and their heightened protections for the data of known minors; and Nevada Revised Statutes Chapter 603A. HypeRaise operates only in the United States.

Where a school, district, or state requires additional or different terms, including a signed Student Data Privacy Agreement or an NDPA-style state exhibit, those terms control for that engagement to the extent they are stricter than this policy. Where a required term describes a capability HypeRaise does not yet have, HypeRaise will identify it before signing rather than accept it.

2. Student Information and Non-Solicitation

HypeRaise does not solicit, collect, or use student information for advertising, data brokerage, lead generation, or resale purposes. HypeRaise will not:

  • Sell, rent, trade, or otherwise monetize student names or personal information.

  • Sell parent, guardian, customer, donor, or supporter information.

  • Provide student information to advertisers, advertising networks, data brokers, or third-party marketers. No advertising pixel, ad-network tag, or advertising SDK is present in the platform, and ads personalization is not enabled in the analytics tools HypeRaise uses.

  • Use student information to advertise unrelated products or services. Every message the platform sends is transactional or related to the specific fundraiser the recipient is associated with, and contact records are scoped to a single fundraiser.

  • Create advertising, behavioral, or marketing profiles based on a student's participation in a fundraiser. The platform contains no profiling or automated-decisioning capability.

  • Contact students for unrelated sales or marketing purposes.

  • Request academic records, grades, attendance records, disciplinary records, health or immunization records, special education or IEP records, eligibility or lunch status, or other confidential educational records. No field for any of these exists in the platform.

  • Collect biometric identifiers, precise geolocation, government-issued identifiers, or Social Security numbers from Participants. No such field exists, uploads are limited to a fixed set of image types, and image metadata including GPS coordinates is discarded.

  • Use student or Participant information to train or develop artificial-intelligence or machine-learning models. No artificial-intelligence component exists in the platform.

3. Collection of Participant Information

For some fundraisers, HypeRaise collects limited Participant information: name, email address, phone number, and an optional profile picture that a Participant may add on their own settings page. A Participant or School Official may also add Contacts to a fundraiser, consisting of a name and an email address or phone number.

HypeRaise does not collect or store a Participant's date of birth, home address, or student identification number, and does not store grade, class, or homeroom; no field for any of these exists. Participants are associated only with a fundraiser and a role.

Public display of names. A Participant's name as entered is displayed publicly on the fundraiser page that supporters visit. The platform does not yet offer a first-name-and-last-initial display option (Section 14). A school that does not want full names shown publicly should direct Participants to enter a first name and last initial, or should run the fundraiser in School-Administered Mode, and should treat the public fundraiser page as a public disclosure when applying its own FERPA directory-information policy.

Participant information may be used to create or administer fundraiser accounts; associate Participants with the correct team, group, or campaign; attribute fundraising activity and sales to the appropriate Participant or organization; send authorized fundraiser updates and transactional communications; provide account support; and protect the security and integrity of the platform. HypeRaise does not use Participant information for unrelated marketing and does not sell it.

4. Consent and Authorization

Schools, organizations, and fundraiser administrators are responsible for confirming that they have the appropriate authority and consent before submitting student or Participant information to HypeRaise, including any parental consent required by law or district policy.

Participants under 13. The platform does not yet include an age gate, a per-Participant parental-consent record, or a mechanism that holds Participant features closed until a consent is recorded. Until those capabilities are delivered, a fundraiser involving Participants under 13 must be run in School-Administered Mode: the School Official operates the fundraiser, and no Participant under 13 creates an account, receives an individual fundraising page or login, generates invitation links, or adds Contacts. The platform fully supports this; a fundraiser can be activated and run with no Participant accounts at all, and Participant contact information is optional throughout. In this mode HypeRaise collects no personal information online from a child; supporters who purchase or donate are adults transacting on their own behalf.

A school or organization must not enable Participant accounts, or distribute a fundraiser join code or invitation link, to Participants under 13 until HypeRaise notifies the school that the consent capability described in Section 14 is available. HypeRaise will close Participant features for any account it learns belongs to a Participant under 13, and will delete the associated information on request under Section 12.

When that capability is delivered, HypeRaise will not open Participant features for a Participant under 13 until it has recorded a School Official certification that a signed parental consent form is on file, including the identity and title of the person certifying, the method, the date, and the scope. HypeRaise treats such a certification as evidence that a parent has consented rather than as a substitute for parental consent, since FTC guidance permits a school to stand in for a parent only where information is used for a school-authorized education purpose and no other commercial purpose.

HypeRaise may request written confirmation that the appropriate authorization or consent has been obtained before activating any Participant feature.

5. Customer and Order Information

Customers and supporters provide their name, email address, phone number, delivery address, order details, and an optional message to the team when placing an order. Corporate sponsors provide a business name and company email address. This information is used only as reasonably necessary to process purchases and payments, fulfill and deliver orders, send receipts and confirmations, provide customer service, process refunds, prevent fraud, maintain transaction and accounting records, and comply with legal obligations. Customer and supporter information is not sold.

To disburse fundraising proceeds, HypeRaise collects payee name, address, email, phone, and bank routing and account numbers, which are encrypted at rest and used only for payment and accounting purposes.

6. Payment Processing Through Stripe Checkout

HypeRaise uses Stripe Checkout as its payment-processing solution. Customers enter payment information directly through Stripe's hosted checkout, and Stripe processes card data through its own PCI DSS-validated infrastructure. HypeRaise does not collect, transmit, or store full payment card numbers, card verification values, or magnetic-stripe data.

Stripe supports payment authorization, fraud detection, transaction records, refunds, payment-related support, and payment security and compliance functions. HypeRaise accesses only payment status, order amount, customer name and contact information, and transaction identifiers, as needed to administer orders, refunds, proceeds, and support.

Because card data is captured entirely by the hosted checkout, HypeRaise's payment channel is eligible for the PCI DSS self-assessment applicable to merchants using a hosted payment page; documenting that self-assessment is listed in Section 14. Payment information is not sold or used for advertising or unrelated marketing.

7. Text Message and Email Communications

The platform sends two kinds of messages. Transactional messages go to the person who took the action - receipts, account notices, fundraiser and partner reports, and disbursement notices. Fundraiser messages go to Contacts a Participant or School Official has added, and consist of an invitation to support that specific fundraiser and a small number of follow-up messages during the campaign. Messages relate only to the fundraiser the Contact was added to. HypeRaise does not send promotional or marketing messages to Participants.

Consent for fundraiser messages is currently obtained by the Participant or School Official who adds the Contact, rather than through an opt-in the Contact gives to HypeRaise directly, and the platform does not yet capture an affirmative opt-in record at the moment a Contact is added (Section 14). A school or organization must therefore instruct Participants to add only Contacts who have agreed to be contacted about the fundraiser. HypeRaise will suppress a Contact on request from the Contact, the Participant, or the school.

Messages identify the fundraiser and include instructions for obtaining help and opting out, such as "Reply STOP to cancel, HELP for help. Msg & data rates may apply." Email includes a working unsubscribe mechanism and a valid physical postal address. A recipient may revoke consent by any reasonable means, including replying STOP, QUIT, END, CANCEL, REVOKE, OPT OUT, or UNSUBSCRIBE, or by contacting HypeRaise. Text opt-outs are recorded automatically in a suppression record and honored on receipt; email unsubscribes are recorded with a timestamp. HypeRaise honors a revocation as soon as practicable and no later than ten business days, and sends at most one confirmation message. Message and data rates may apply depending on the recipient's carrier and plan.

HypeRaise does not sell phone numbers or email addresses, share them with third-party marketers, or use them to send third-party advertising.

8. Service Providers

HypeRaise uses established technology and operational service providers to support hosting, database and authentication, payments, email and text delivery, error monitoring, analytics, and platform operations. Providers that receive information covered by this policy are: Supabase (database, authentication, file storage), Microsoft Azure (application hosting, logging, backups), Stripe (payments and payouts), Twilio (text messages), SendGrid (email, including fulfillment reports containing delivery addresses), Sentry (error monitoring, which currently may receive IP address and other personal information), Google Analytics 4 (web analytics), and AppsFlyer (mobile invitation-link attribution). All operate in United States regions. This list is current as of the effective date. HypeRaise will provide an updated list on request and will notify any school or organization with an active fundraiser if a provider receiving covered information is added or replaced.

These providers receive only the information reasonably necessary to perform their services. HypeRaise does not authorize any provider to sell student or Participant information, use it for its own independent advertising, build independent marketing profiles, or contact Participants for unrelated marketing. HypeRaise is confirming and filing a written data processing agreement with each provider that receives covered information, and will make the results of that review available on request. The use of a service provider does not transfer ownership of student, Participant, school, customer, or fundraiser information to that provider.

For product fundraisers, fulfillment partners receive the information needed to ship an order, including customer name, delivery address, and order contents, and are not permitted to use it for any other purpose.

9. Data Security

HypeRaise uses reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, misuse, or loss. These safeguards include:

  • Encryption of personal information in transit and at rest, including encryption at rest of the bank account details used for disbursements.

  • A Stripe-hosted payment checkout, so that card data never enters HypeRaise systems, with fraud detection and transaction monitoring through the payment processor.

  • Role-based access control, with access to production data limited to personnel who require it, and session records that store only a hashed token rather than a reusable credential.

  • Uploads restricted to a fixed set of image types, re-encoded on receipt with metadata discarded.

  • Infrastructure and data stored only in United States regions, with database backups retained seven days.

  • Limiting collection to information reasonably necessary to operate the fundraiser.

HypeRaise does not currently hold a third-party security certification or attestation, and does not maintain these controls as a formally documented security program with a designated owner; both are addressed in Section 14. On request and subject to confidentiality, HypeRaise will complete a school's security questionnaire and answer specific questions about its architecture and controls. No electronic system can guarantee absolute security. HypeRaise takes reasonable steps to protect information and works with established providers that maintain substantial security and compliance programs.

10. Data Breach Notification

If HypeRaise determines that a breach involving student or Participant personal information has occurred, HypeRaise will notify the affected school or organization without unreasonable delay and no later than 72 hours after determining that the breach occurred, and sooner where law or contract requires - notice to a New York educational agency, for example, is required within seven calendar days of discovery. The notice will describe, to the extent known, the nature and date of the incident, the categories and approximate number of individuals and records affected, the data elements involved, the status of the investigation, and the steps taken to contain and remediate it. HypeRaise will reasonably cooperate with the school's or organization's own notification obligations under applicable law and will provide a written post-incident report on request.

11. Data Retention

HypeRaise retains personal information only for as long as reasonably necessary to operate and complete a fundraiser, administer accounts, process and fulfill transactions, distribute proceeds, provide support, maintain financial and accounting records, prevent fraud, resolve disputes, and comply with legal obligations. Current retention periods are:

  • Participant account records and Contacts: retained while the fundraiser and account remain in place. HypeRaise does not yet apply an automated deletion schedule to these records; they are deleted on request under Section 12, and a defined maximum retention period is listed in Section 14.

  • Customer order and transaction records, including name, email, phone, delivery address, and any message: retained seven years for tax, accounting, refund, and dispute purposes.

  • Disbursement and payee records, including bank details: retained seven years, encrypted at rest.

  • Messaging opt-out and suppression records: retained as long as needed to keep honoring the opt-out.

  • Database backups: retained seven days, so a deleted record may persist in a backup for up to seven days.

  • Application, error, and infrastructure logs held by the providers in Section 8: retained 90 days.

HypeRaise does not currently have a de-identification capability, and this policy makes no claim that Participant information is anonymized. Information retained for legal, accounting, security, or compliance purposes is not used for any other purpose.

12. Access, Correction, and Deletion Rights

A parent, legal guardian, Participant, Customer, Contact, or School Official may request access to, a copy of, correction of, or deletion of personal information, or withdraw consent, by contacting privacy@hyperaise.com or writing to HypeRaise LLC, 10161 W Park Run Dr Ste 150, Las Vegas, NV 89145.

HypeRaise acknowledges requests within 10 business days and responds substantively within 30 days, extendable by 15 days where reasonably necessary with notice to the requester. There is no fee. HypeRaise verifies the identity and authority of the requester before disclosing or deleting information, and may direct a request to the school or organization where that entity controls the record. Deletion requests are executed manually across HypeRaise's systems and its providers, and HypeRaise confirms in writing when a deletion is complete, identifying any records retained for tax, accounting, or legal reasons. On written request, HypeRaise will also provide a school or organization with the records it holds relating to that entity's fundraisers in a usable electronic format at no charge.

13. Ownership and Allocation of Responsibility

The school or organization retains ownership of and control over student and Participant information relating to its fundraisers. HypeRaise acts as a service provider and acquires no ownership interest in that information.

The school, organization, or fundraiser administrator submitting student or Participant information to HypeRaise is responsible for obtaining any required consent prior to submission, for running fundraisers involving Participants under 13 in School-Administered Mode as required by Section 4, and for instructing Participants not to add a Contact without that person's permission. HypeRaise is responsible for handling information it receives in accordance with this policy.

Allocation of liability between the parties is governed by the applicable services agreement, consistent with the terms of the HypeRaise Fundraising Platform Agreement.

14. Capabilities in Development

HypeRaise publishes this list so that a school or organization can evaluate the platform accurately. Each item will be reflected in a revised version of this policy when delivered.

  • Age identification and an under-13 parental-consent workflow, with Participant features held closed until a School Official certification of parental consent is recorded (Section 4).

  • An automated retention and deletion schedule, including a defined maximum retention period for Participant records after a fundraiser closes, deletion within 30 days of a request or of contract termination, and certification of deletion on request.

  • Affirmative opt-in capture at the moment a Contact is added, with a record of the disclosure shown, the method, and the date (Section 7).

  • A first-name-and-last-initial display option and a per-fundraiser setting controlling what appears publicly (Section 3).

  • A documented information security program with a named owner, annual review and risk assessment, documented staff training, and scheduled vulnerability testing (Section 9).

  • Reduced personal information in error monitoring, and a confirmed written data processing agreement on file for every provider receiving covered information (Sections 8 and 9).

  • A documented PCI DSS self-assessment for the hosted-payment-page channel (Section 6), and published policy and subprocessor pages, after which the Section 8 list will be maintained online and referenced here.

HypeRaise expects to deliver these by the end of the first quarter of 2027. A school or organization for which any of these is a condition of contracting should raise it with HypeRaise before a fundraiser begins.

15. Certification

HypeRaise certifies that, as of the effective date of this policy:

  1. It does not solicit or collect student information for advertising, resale, data brokerage, or lead-generation purposes, does not sell student names or personal information, and does not sell parent, guardian, customer, donor, or supporter information.

  2. No advertising pixel, ad-network tag, or advertising SDK is present in the platform, and no targeted-advertising, profiling, automated-decisioning, or artificial-intelligence capability exists in it.

  3. Every message the platform sends is transactional or related to the specific fundraiser the recipient is associated with, and no cross-fundraiser or post-campaign marketing list exists.

  4. It requests and stores no confidential academic or educational records, collects no biometric identifier, precise geolocation, government identifier, or Social Security number from Participants, and stores no Participant date of birth, home address, or student identification number. No field for any of these exists in the platform.

  5. It collects Participant name, email address, and phone number only when reasonably necessary to operate a fundraiser, and requires School-Administered Mode for fundraisers involving Participants under 13 until the consent capability in Section 14 is delivered.

  6. It uses Participant information only for legitimate fundraising, transactional, communication, support, security, accounting, and compliance purposes.

  7. It uses Stripe Checkout for hosted payment processing and never stores payment card numbers, and encrypts at rest the bank details used for disbursements.

  8. Personal information is encrypted in transit and at rest, access to production data is role-based and limited, and all covered information is stored and processed in the United States.

  9. It includes opt-out instructions in messages, records text opt-outs automatically, and honors opt-out requests no later than ten business days.

  10. It limits service-provider access to what is reasonably necessary, and is confirming and filing a written data processing agreement with each provider receiving covered information.

  11. It will notify an affected school or organization of a breach involving student or Participant information no later than 72 hours after determining that it occurred.

  12. It honors access, correction, and deletion requests at no charge within the timelines in Section 12, and confirms completed deletions in writing.

  13. The school or organization retains ownership and control of student and Participant information, which HypeRaise will provide or delete on request.

HypeRaise does not certify that it holds a SOC 2 report or independent penetration test, that it maintains a documented information security program with a designated owner, that it applies an automated retention and deletion schedule to Participant records, that it de-identifies Participant information, that it captures an affirmative messaging opt-in from each Contact, or that it operates an age gate or parental-consent workflow for Participants under 13. Section 14 lists each of these with its planned remedy.

16. Governing Law and Updates

This policy is governed by the laws of the State of Nevada, without regard to conflict-of-law principles, except that any mandatory provision of the law of the state in which a school or organization is located applies to the extent it governs the handling of that entity's student data. HypeRaise reviews this policy at least annually and may update it from time to time; material changes affecting student or Participant information will be communicated to schools and organizations with an active fundraiser at least 30 days before taking effect. Each version carries a version number and effective date, and prior versions are available on request.

This policy applies to fundraisers conducted through the HypeRaise platform unless a separate written agreement establishes additional or more protective privacy or security requirements, in which case those requirements control.

Issued by HypeRaise LLC, effective July 31, 2026. Adopted by HypeRaise LLC and applicable to all fundraisers conducted through the HypeRaise platform as of that date. A copy countersigned by an authorized representative of HypeRaise, or execution of a school's or district's own student data privacy agreement or vendor attestation, is available on request to privacy@hyperaise.com.