Privacy Policy

Last updated: 24 August 2026

This Privacy Policy describes how your personal information is collected, used, and shared when you visit suredonation.com and when you use the SureDonation plugin on a site we operate.

When you run the SureDonation plugin on your own website, you decide what your donation forms collect and you are responsible for the privacy policy shown to your donors. Most of what the plugin does stays on your own server. This policy covers our own site, and it covers the points where our own services sit in the path on a site you run, which are license activation, update checks, and optional usage tracking, each described below.

Who We Are

We are Brainstorm Force US LLC. You can find more about us, including our full address, on our company website.

Contact for all privacy matters: [email protected]

What Personal Information We Collect

When you visit our site, we automatically collect basic information about your device, including your browser type, IP address, and time zone. As you browse, we collect information about the pages you view, what referred you to the site, and how you interact with it.

We also collect the information you choose to give us, such as your name and email when you download the plugin, subscribe to updates, contact support, or buy a Pro license.

Cookies and Similar Technologies

Cookies are small data files placed on your device, often with an anonymous identifier. We use cookies and similar technologies across four categories:

  • Essential. Needed for the site to work, including security and core functionality.
  • Functional. Remember your preferences and settings.
  • Analytics. Help us understand how visitors use the site.
  • Marketing. Used for advertising measurement and remarketing.

Our consent system is configured to prevent non-essential analytics and marketing technologies from running until the required consent has been given. Functional technologies are handled according to their purpose and the applicable consent requirements. You can change your choice any time using Cookie Preferences in the footer.

We honor the Global Privacy Control (GPC) signal where the law requires it. If your browser sends a GPC signal, we treat it as a request to opt out of the sale or sharing of your personal information.

A list of the cookies and tracking technologies our scanner detects on this site is kept on our SureCookie Cookie Policy page, linked from the cookie banner. It updates when the scanner detects a change. A scanner sees what loads on the pages it visits, so a technology that appears only on a page it has not yet scanned may not be listed straight away.

We keep records of your cookie consent choices for up to 365 days, so we can honor your prior preferences and show we met consent requirements.

Donations and Donor Information

SureDonation is a self-hosted WordPress plugin. When the plugin runs on a site, donor records, donation amounts, payment method, and recurring subscription details are stored in that site’s own WordPress database.

On sites our customers run, that donation data stays in their database and is not sent to us by the plugin. Payments run directly between that site and the payment provider the site owner has connected. What does reach us from a customer’s site is limited to license activation, update checks, and optional usage tracking, described under License Keys and Information About Your Website and Server Configuration below, and anything a site owner chooses to send us in a support ticket. If we add a hosted feature in future that changes this, we will update this policy before releasing it.

If you make a donation or a purchase through a form on our own site:

  • We collect the details you enter, such as your name, email address, donation or order amount, and campaign.
  • Card payments are handled by Stripe or PayPal. Card details are collected directly by the payment provider and are not stored by us.
  • If recurring giving is used, the subscription is managed through Stripe, which handles renewals.
  • A donor or customer account may be created for you so you can view your history and receipts.
  • Offline contributions, such as a bank transfer, are recorded manually if you tell us you intend to give that way.

Contact Forms

Information you submit through a contact form on our site is sent to our self-hosted support desk. This can include your first and last name, email address, and your message. We use it to reply to you and to manage the request, and it is stored in our self-hosted CRM for that purpose. Submitting a contact form does not add you to our marketing list. We only send you marketing email if you separately opt in, as described under Newsletter Emails below.

Support

To help with our products, we may ask for temporary access to your website, either your live site or a staging copy, such as an admin login or FTP or database credentials. We may also ask for a license key, name, or email address.

Troubleshooting usually happens directly on your own site, and in that case we do not transfer, export, or store your site’s data on our servers. Where practical we recommend a staging copy.

For more complex issues we may copy your site to our own servers to investigate. We delete that copy once the issue is resolved.

A few points about access you share with support:

  • We use any access only to debug your specific issue, on your site.
  • We do not copy site data to our own systems, except where you authorize us to create a temporary troubleshooting copy as described above, which we delete once the issue is resolved.
  • We do not share your access or your data with anyone outside the company, other than the service providers listed in this policy that host and operate our support systems.
  • We recommend keeping a working backup of anything you share with us.

Once your issue is resolved, rotate or revoke any login, FTP, or database credentials you shared with us. We have no further use for them after the ticket closes.

We keep support ticket records, including screenshots and logs shared in a ticket, for 3 years from the date the ticket is closed. We keep them to refer back to how an issue was resolved and to spot recurring problems.

If your site holds your own donors’ or visitors’ personal data that we see while troubleshooting, we access it only as needed to fix your issue and do not keep or reuse it. You remain responsible for your own obligations toward your site’s visitors.

Purchase

If you buy from us, our payment provider may need your card and billing details to process the payment. We do not store card details on any database we can access.

We use payment providers that state they maintain applicable PCI DSS compliance for their payment services. PCI DSS is administered by the PCI Security Standards Council.

When you make or attempt a purchase, we verify your card through the gateway and collect details such as your name, billing address, payment information, email address, and phone number.

We keep billing and transaction records for as long as your account or license is active, including for renewals. Because we have tax, accounting, and audit obligations, we keep financial records for the period the law requires even after an account is closed or a deletion request is made. This is a standard legal exception to deletion and applies only to financial and transaction records.

Information About Your Website and Server Configuration

When you use our WordPress products, and only if you have opted in to usage tracking, we may receive website and technical usage information about your site. This can include whether SSL is installed, Curl, PHP, and MySQL versions, PHP settings, server software, WordPress version and language, time zone, whether it is a Multisite install, debug settings, site URL, active plugins and theme, and updater version.

Most of this describes software and server configuration rather than a person. Some of it, such as your site URL, can be connected to you or to your account, so we do not treat it as categorically non-personal and we handle it under this policy.

This is off unless you turn it on, and you can turn it off again any time. We use it to build more compatible software.

License Keys

A license key validates your purchase and unlocks benefits like automatic updates and support. When you activate a key, we receive your website URL, name, and email address, and we keep a record of every site URL where the key is activated.

We keep license activation records while the license is active, and afterwards for the period reasonably necessary for account history, support, fraud prevention, tax and accounting obligations, and dispute handling.

Third-Party Services Loaded On Our Pages

Some features load files from other companies. When your browser fetches one of those files, that company receives your IP address and basic browser details:

  • Google Fonts (Google LLC). Supplies the typefaces used on our pages. It loads with the page as part of presenting the page, and is not used for advertising or analytics. We do not claim that loading fonts from an external provider is legally necessary, and we are able to serve the same typefaces from our own servers instead, as we already do for the consent banner itself.
  • Cloudflare Web Analytics (static.cloudflareinsights.com). Measures how quickly our pages load. It loads with the page and sets no advertising or analytics cookie.
  • Powerful Docs (app.powerfuldocs.com). Runs our help chat and documentation search, and loads when that feature is used. It is blocked until you give consent.

Information We Send To Third Parties From Our Servers

Separately from what your browser loads, our servers send some information to other companies while handling your visit or your purchase. Your browser settings and the cookie banner cannot control these:

  • Payments. When you pay, your payment details are sent to Stripe or PayPal to take the payment.
  • Email delivery. When we send you a receipt, a license email, or a newsletter, your email address is passed to our email delivery provider to send the message.

Who We Share Your Data With

We do not sell or trade your personal information for money.

Some analytics and advertising tools involve sharing personal information for cross-context behavioral advertising, as defined under California law. That sharing only happens for the rows marked below, and only after you give consent through our cookie banner, or is subject to your California opt-out rights described further down.

The table below is built from the SureCookie scan of this site. The domain is shown so each row traces back to the scan.

CategoryService (domain detected)What they receivePurposeSale / Share / Service Provider
Tag managementGoogle Tag Manager (www.googletagmanager.com)IP address, browser and device information, page URLLoads and manages our other scripts and reads your consent status to decide which may run. It loads with the page, running in Google Consent Mode, because it is the component that reads your choiceService provider, not sold or shared
Website analyticsGoogle Analytics (www.google-analytics.com, region1.google-analytics.com)Page views, device and browser identifiers, and cookies once you have consentedHelps us understand site usage. GA4 data may also build Google Ads audiences through Ads linking. It runs in Google Consent Mode: before you answer the banner it may send a page-view measurement without setting an analytics cookie and with consent signalled as denied, and it only sets cookies and builds audiences after you consentShared for cross-context behavioral advertising, once you have consented
Performance analyticsCloudflare Web Analytics (static.cloudflareinsights.com)IP address, request metadata, page URL, and page timing informationMeasure how quickly our pages load. It sets no advertising or analytics cookie and is not linked to advertising audiencesService provider, not sold or shared. Loads with the page
AI chat and documentation supportPowerful Docs (app.powerfuldocs.com)Chat messages, and your name and email if you give them in the chatProvides help chat and documentation search. Held back until you give consentService provider, not sold or shared
Typeface deliveryGoogle Fonts (fonts.googleapis.com)IP address, browser informationServes the typefaces used on our pages. Loads with the page as part of presenting it, and is not used for advertising or analyticsService provider, not sold or shared
Consent managementSureCookie (our own plugin)Your consent choices, the categories you accepted or declined, and your IP address are recorded in this site’s own WordPress database. Where the banner loads an image or a font from surecookie.com in order to display itself, that request carries no consent recordRuns our cookie consent banner and records your consent locallyNot a sale or share. Processed on this site
WordPress core servicesWordPress.org (s.w.org)Basic request metadataCore WordPress functions such as emoji support and update checks. Set to Essential on this siteService provider, not sold or shared

How we classify these recipients: the last column reflects the written agreement and data-processing terms we have in place with each provider, and the way we have configured the service. It is our assessment rather than a guarantee about a provider’s own practices, and we review it when we add a provider or change a configuration.

Recipients A Client-Side Scan Cannot See

These handle data on our servers, so they do not appear in the SureCookie scan. They are listed here for completeness:

  • Payment processing (Stripe and PayPal). Payment and billing details, IP address. Takes and processes payments. Service provider.
  • Email delivery. Email address. Sends transactional and marketing email. Service provider.

Cross-BSF-Product Tracking

Brainstorm Force runs several separately branded product sites, including Astra, Spectra, and CartFlows. Each site runs its own cookie consent tool. Your choice on one site does not carry to another. To opt out across sites, you need to do it on each one.

How Long We Keep Your Data

We keep personal information only as long as we need it, or as long as the law requires:

  • Cookie consent records: up to 365 days.
  • Support ticket records: 3 years from the date the ticket is closed.
  • Donation and order records made on our own site: for as long as needed to service the donation or order, and afterwards for the period our tax and accounting duties require.
  • Purchase and license records: for as long as you hold a license, then for the period our tax and accounting duties require.
  • Newsletter and marketing contact details: until you unsubscribe or ask us to delete them.
  • Analytics data held by Google: for the retention period set in our Google Analytics configuration.

You can ask us to delete your data sooner. See What Rights You Have Over Your Data below.

Where Your Data Is Processed

We are based in the United States, and several providers listed above process data in the United States and other countries. Where personal information leaves the European Economic Area, the United Kingdom, or India, the safeguard we rely on depends on the destination and on the region the data came from:

  • From the EEA: an adequacy decision where one covers the destination, the European Commission’s Standard Contractual Clauses, or the EU-US Data Privacy Framework where the recipient is certified under it.
  • From the United Kingdom: the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it. EU Standard Contractual Clauses on their own do not cover a UK restricted transfer, which is why the Addendum or the IDTA is used.
  • From India: contractual safeguards with the recipient, and transfers are made consistent with the restrictions applying under the Digital Personal Data Protection Act, 2023 and the rules made under it.

Ask us at [email protected] for details of a particular transfer.

California Privacy Rights

If you are a California resident, you have these rights under the CCPA, as amended by the CPRA:

  • Right to know what personal information we collect, use, disclose, and if applicable sell or share, and to get a copy.
  • Right to delete personal information we collected from you, subject to some exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of your personal information. Based on the table above, this means opting out of the analytics and conversion-measurement tools that involve cross-context behavioral advertising, currently Google Analytics. We do not treat the other recipients listed above as sales or shares of personal information: each is engaged under a written agreement that limits their use of personal information to providing their service to us.
  • Right to limit the use of sensitive personal information, where it applies.
  • Right not to be discriminated against for using any of these rights.

To opt out, use Do Not Sell or Share My Personal Information or Cookie Preferences in the footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out. We action opt-out requests as soon as feasible, and no later than 15 business days from receipt.

To use your other rights, contact [email protected]. We verify your request and respond within 45 days, with a possible 45-day extension for complex requests, in which case we tell you the reason.

You can also name an authorized agent to make a request for you, subject to us verifying their authority.

Your Rights Under India’s Digital Personal Data Protection Act (DPDP)

If you are in India, you have these rights as a Data Principal under the Digital Personal Data Protection Act, 2023:

  • Right to a summary of the personal data we hold about you and how we process it.
  • Right to correction and erasure of your personal data.
  • Right to grievance redressal, described below.
  • Right to nominate someone to exercise your rights if you die or cannot act.
  • Right to withdraw consent any time, without affecting processing done before you withdrew.

We do not knowingly collect personal data from anyone under 18 without verifiable parental consent, in line with the DPDP Act.

Grievance Officer: Mohit Sharma, [email protected]

If you have a grievance about how we handle your data, contact the Grievance Officer above, or write to [email protected] and ask for it to be passed on. Either route starts the same process.

As our own service commitment, we aim to acknowledge your grievance within 72 hours with a reference number and an expected timeline, and to resolve most grievances within 30 days and in any event within 90 days. These are timelines we set for ourselves rather than statutory deadlines. The Digital Personal Data Protection Rules, 2025 come into force in phases, with several provisions taking effect later than the date of this policy, and we will update this section as those provisions apply to us.

How Secure Is My Information

We maintain technical and organizational measures appropriate to the risk, in order to protect your personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Card information, when provided, is encrypted in transit using TLS (also known as SSL).

What Rights You Have Over Your Data

To exercise the privacy rights available to you, including access, correction, deletion, objection, restriction, or withdrawal of consent, contact [email protected]. Some requests are subject to legal exceptions, and some processing must continue for legal, security, accounting, contractual, or other permitted purposes.

If you donated on a website that runs SureDonation, and your request concerns that donation, contact that website’s owner. Those records are held by them, not by us.

You can also ask about the source of your data if you did not give it to us directly, or how long we keep it. You can ask us to delete data no longer needed for its original purpose. Some records, such as financial and transaction records, may be kept even after a deletion request where tax, accounting, or audit law requires it. You can ask us to stop using your data for direct marketing, and withdraw consent any time using the unsubscribe link in our emails.

Legal basis for processing (EEA and UK visitors): depending on the purpose, we process your data based on your consent (for example non-essential cookies and marketing email), on the need to perform our contract with you (for example completing a purchase), on our legitimate interests (for example improving our products and preventing fraud), or on a legal obligation.

If you believe we have not met data protection law, you can complain to your local data protection authority. Within technical limits, we will provide your data to you or your authority on request.

Children’s Online Privacy Protection Act Compliance

We do not knowingly collect personal information from children under 13. If we find we have, we will take reasonable steps to remove it. If you are under 13, please do not submit personal information through the site.

Third-Party Links

We may link to third-party products or services. Those sites have their own privacy policies, and we are not responsible for their content or practices.

Affiliate Disclosure

Some links in our store may be affiliate links. We earn a referral fee when you buy from a company we recommend. We only recommend products we believe add value. Affiliate tracking cookies follow the same consent preferences described in the Cookies section above.

Remarketing and Targeted Advertising

We use Google Analytics, which can measure conversions and, through Google Ads linking, help build advertising audiences. This may involve cross-context behavioral advertising as defined under California law. Our scanner did not detect advertising pixels from other networks on this site when this policy was last updated.

You can opt out through Google directly, or by using Cookie Preferences in the footer, which applies to the advertising-related tools listed in this policy.

Newsletter Emails

We send product announcements, updates, and offers by email. You get these only if you ask for them, by subscribing or by ticking the marketing option on a form. You can stop them any time using the unsubscribe link in every email.

Downloading, installing, or buying one of our products does not by itself sign you up for marketing email.

Marketing email is separate from the service email we send about a purchase, a license, a security notice, or a support ticket. Unsubscribing from marketing does not stop those.

If you are in the EEA or the UK, we only send marketing email with your consent, and we never make that consent a condition of buying or using our products.

Will This Privacy Policy Ever Change

We may update this Policy to keep pace with changes to our site, software, business, and the law. When we do, we will post the updated Policy here and change the date at the top. Where a change is significant, we will take reasonable steps to tell you about it. Where a change means we need your consent for something new, we will ask for that consent rather than treat your continued use of our products as agreement.

Contact Us

For questions about our privacy practices or to make a complaint, email [email protected] or write to:

Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States

If you are in India and want to raise a grievance under the DPDP Act, write to our Grievance Officer, Mohit Sharma, at [email protected], or use [email protected] and we will route it.

Trusted by Thousands of Businesses
Collect Donations. Stress Free.
24/7 World Class Support Team
Scroll to Top