1.3 Information from Third Parties
At RaiseIt, transparency is foundational to our platform. While we collect much of the information you provide directly, we also receive and process certain data from trusted third-party service providers, partners, and public sources to ensure secure, compliant, and efficient crowdfunding operations.
This section outlines what third-party information we receive, why we receive it, how we process it, and your rights regarding this data.
2.1 Categories of Third-Party Information We Receive
We only receive third-party data when it is necessary for platform functionality, security, compliance, or service improvement. The types of information include:
| Category | Examples | Providers | Purpose |
|---|---|---|---|
| Payment & Financial Data | Transaction status, currency, fraud flags | Stripe, Adyen, PayPal | Process pledges, prevent fraud, reconcile payouts |
| Identity & Verification | Name, government ID status, address verification | Persona, Onfido, Jumio | KYC/AML compliance, creator verification, age gating |
| Security & Fraud Signals | Device fingerprints, IP reputation, risk scores | Sift, Kount, Cloudflare | Block malicious accounts, protect backers & creators |
| Analytics & Usage | Page views, session duration, feature interaction | Google Analytics, Mixpanel, PostHog | Improve UX, optimize campaign tools, measure performance |
| Advertising & Retargeting | Ad interactions, conversion events, interest categories | Meta, Google Ads, TikTok, LinkedIn | Show relevant campaigns, measure marketing ROI |
| Social & SSO Providers | Profile name, email, avatar (if permitted) | Google, Apple, Meta, X | Simplify sign-up/login, sync social sharing |
🔒 Note on Data Minimization
We configure all third-party integrations to request only the minimum data necessary for the stated purpose. We never request sensitive data (e.g., full credit card numbers, health information, or government document copies) directly from providers unless legally required for verification.
2.2 Legal Basis for Processing Third-Party Data
Our processing of third-party information relies on one or more of the following lawful bases under applicable privacy regulations (GDPR, CCPA/CPRA, LGPD, etc.):
- Contractual Necessity: Required to fulfill payment processing, campaign fulfillment, and account verification obligations.
- Legitimate Interest: Platform security, fraud prevention, system optimization, and fraud risk modeling.
- Legal Compliance: AML/KYC regulations, tax reporting (e.g., IRS Form 1099, HMRC requirements), and consumer protection laws.
- Consent: Used where required for analytics, advertising personalization, or non-essential cookies. You may withdraw consent at any time.
2.3 How We Handle & Secure Third-Party Data
When data reaches our systems from third parties, it is subject to the same security standards, retention policies, and access controls as data you provide directly:
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Access Controls: Role-based access, multi-factor authentication, audit logging
- Retention: Financial records retained per legal requirements (typically 5–7 years); analytics & advertising data anonymized or deleted within 24 months unless otherwise required
- Audits: Annual SOC 2 Type II & ISO 27001 certifications; third-party processors undergo strict DPAs & security questionnaires
2.4 Your Rights & Controls
Even when information originates from third parties, you retain control over how it is used where permitted by law:
- Access & Portability: Request a copy of all third-party data we hold about you via Privacy Dashboard
- Correction: Inaccurate verification or profile data can be updated in your account settings or via support
- Opt-Out: Disable personalized advertising through your cookie preferences or industry opt-out tools (NA-Ada, DAA, TCF)
- Deletion: Request removal of non-essential third-party data, subject to legal & financial recordkeeping obligations
2.5 Changes to Third-Party Data Practices
As our ecosystem evolves, we may integrate new service providers or modify existing data flows. Material changes to this section will be communicated via:
- Platform notifications for consent-dependent changes
- Email updates for high-impact policy revisions
- Updated "Last Updated" date and changelog in our Privacy Center
2.6 Questions or Concerns?
Our Data Protection Officer (DPO) team is available to address questions about third-party data flows, processor relationships, or your privacy rights.