Legal

Privacy Policy

Your privacy is important to us. This policy explains how The Chahal Foundation collects, uses, and protects your personal information.

Last updated: May 28, 2026

Introduction

The Chahal Foundation ("we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at chahalfoundation.org or make a donation to our organization.

The Chahal Foundation is a 501(c)(3) public charity (EIN: 39-5160137).

Information We Collect

Donation Information

  • Name and contact information (email, phone, address)
  • Payment details (processed securely by Stripe)
  • Donation amount, frequency, and designation
  • Employer matching information

Form Submissions

  • Contact form inquiries
  • Volunteer and event registration
  • Newsletter subscriptions
  • Fundraiser creation details

Analytics & Usage Data

  • Pages visited and time spent
  • Device type, browser, and operating system
  • IP address and approximate location
  • Referral source and search terms

How We Use Your Information

We use the information we collect for the following purposes:

Process and acknowledge your donations
Send tax receipts and donation confirmations
Communicate about our programs and impact
Send newsletters (with your consent)
Respond to inquiries and support requests
Improve our website and user experience
Analyze donation trends and campaign performance
Comply with legal and regulatory requirements
Prevent fraud and ensure security
Fulfill employer matching requests

AI Education & Training and Student Data

When we run AI literacy, coding, mentorship, career-navigation, or student support programs, we may collect information needed to operate those programs, such as participant registration details, school or partner affiliation, mentor matching preferences, attendance, session notes, skills interests, project progress, and outcomes voluntarily reported by participants.

We use this information to provide program access, match students with appropriate mentors, improve curriculum, report aggregate impact, protect participants, and satisfy donor or grant reporting requirements. We do not sell participant data.

If a program involves minors, we use age-appropriate safeguards and collect only the information necessary for participation, safety, communication, and impact reporting. Program partners may have additional consent, school, parent, or guardian processes.

Third-Party Processors for Program Delivery

To deliver labs, interactive learning tools, and program infrastructure, we may engage third-party AI, API, and cloud service providers. We minimize the student data shared with any processor to only what is required for the specific service, and we work with providers whose data practices meet our standards. The categories of processors we may use include:

AI model providersmay include Anthropic (Claude), OpenAI
Cloud & infrastructuremay include Amazon Web Services, Google Cloud, Microsoft Azure
Coding, IDE & developer toolingmay include GitHub
Analytics & communicationscovered in the Third-Party Services section above (e.g., Google Analytics, Brevo)

The specific providers used may change as our programs evolve. We will update this section when we add a materially new category of processor for student data.

Data Retention — Student Program Records

Student program participation data (registration details, attendance, session notes, and progress records) is retained only as long as needed to run the program and meet any applicable legal or grant-reporting obligations. As a default, routine participation records are deleted or anonymized within 24 months of a participant's last activity in a program, unless a longer period is required by law, a funder's reporting terms, or a participant's own request for continued access.

Your Choices — Access, Correction, Deletion & Opt-Out

Any participant — or a parent or guardian acting on behalf of a minor — may request access to, correction of, or deletion of their program data. You may also opt out of having your data processed by any specific AI or cloud tool used in a program. To make any of these requests, please contact us. We will respond within 30 days. Exercising these rights will not affect your ability to participate in the program where operationally feasible.

Minors & data minimization: We apply heightened care when programs serve participants under 18. We collect only the minimum data necessary, do not share minors' personally identifiable information beyond what is needed for program operation and safety, and do not use student data for advertising or unrelated profiling. These commitments apply regardless of where a participant is located.

Third-Party Services

We use trusted third-party services to help operate our website and process donations. These services may collect data as described below:

Google Analytics 4

Website analytics and traffic analysis

Data collected: Page views, session data, device information, anonymized IP address

Privacy Policy

Microsoft Clarity

User experience analysis through heatmaps and session recordings

Data collected: Mouse movements, clicks, scrolling behavior (personal data is masked)

Privacy Policy

Stripe

Secure payment processing for donations

Data collected: Payment card information (we never see your full card number)

Privacy Policy

Brevo (Sendinblue)

Email communications and newsletters

Data collected: Email address, name, communication preferences, email engagement

Privacy Policy

Google reCAPTCHA

Bot prevention and form security

Data collected: Device and browser information for security verification

Privacy Policy

Cookies

We use cookies and similar technologies to enhance your experience, analyze site traffic, and for marketing purposes. Cookies are small text files stored on your device that help us provide and improve our services.

You can control cookie preferences through your browser settings. Note that disabling certain cookies may affect website functionality.

View our full Cookie Policy

Your Privacy Rights

European Union (GDPR)

If you are a resident of the European Economic Area, you have the following rights:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

California (CCPA/CPRA)

California residents have additional rights under the CCPA and CPRA:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to say no to the sale of personal information
  • Right to delete personal information
  • Right to non-discrimination for exercising rights
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information

Note: The Chahal Foundation does not sell your personal information. We only share data with third-party service providers as necessary to operate our organization and fulfill our mission.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention Periods:

  • Donation records: 7 years (as required by IRS regulations)
  • Contact form submissions: 3 years or until resolved
  • Newsletter subscriptions: Until you unsubscribe
  • Analytics data: 26 months (Google Analytics default)

Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • SSL/TLS encryption for all data transmission
  • PCI-DSS compliant payment processing through Stripe
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Secure data storage with encryption at rest
  • Employee training on data protection

Children's Privacy

Our website is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly. If you believe we may have collected information from a child under 13, please contact us.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.

Contact Us About Privacy

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your data, please contact us.

Organization

The Chahal Foundation
EIN: 39-5160137