Privacy Policy

Last updated: 15 March 2026


1. Introduction


TheLocalFund (operated by TheLocalFund.co.uk) is committed to protecting your privacy. This policy explains when and why we collect personal information, how we use it, and how we keep it secure. It applies to information we collect when you donate, sign up for newsletters, or interact with our services, including those provided in partnership with Donation Rewards.

2. Information we collect


We may collect the following types of information:

  • Identity data: name, title, date of birth (if you choose to enter a prize draw).
  • Contact data: email address, postal address, phone number.
  • Donation data: amount donated, cause supported, payment method (but never full payment card details – those are handled by our PCI‑compliant payment partners).
  • Marketing preferences: whether you opt in to receive updates from us or our sponsors.
  • Technical data: IP address, browser type, device information, and how you use our website (via cookies).

3. How we collect your information


We collect information directly from you when you:

  • Make a donation through our website or via a donation page.
  • Sign up for our newsletter or create an account.
  • Contact us by email, phone, or post.
  • Enter a prize draw or competition (including free entry methods).
  • Respond to a survey or feedback request.

We may also receive information from trusted third parties, such as Donation Rewards, when you participate in their reward schemes, or from fraud prevention agencies.

4. How we use your information


We use your information for the following purposes:

  • To process your donation and issue any prize draw tickets, rewards, or receipts.
  • To communicate with you about the cause you supported, and to send administrative updates.
  • To comply with legal obligations (e.g., Gift Aid, fraud checks, charity reporting).
  • To improve our website and services – we analyse usage patterns to enhance user experience.
  • To send you marketing communications – only if you have given us your consent (you can opt out at any time).

Our lawful bases for processing are: (a) performance of a contract (your donation), (b) compliance with a legal obligation, (c) our legitimate interests (improving our service, fraud prevention), and (d) consent (for marketing).

5. Sharing your information


We do not sell your personal data. We may share your information with:

  • Donation Rewards – to enable the prize draw element of your donation and to administer free entries. Their use of your data is governed by their privacy policy.
  • Payment processors (SquareUp) – to securely handle your donation. We only share the minimum necessary to complete the transaction.
  • Local causes – aggregated donation totals (no personally identifiable information) unless you specifically consent to share your name for public recognition.
  • IT service providers who host our website and manage our email communications – they act under our instructions and are contractually bound to keep data secure.
  • Law enforcement or regulators if required by law.

6. Cookies and similar technologies


Our website uses cookies to enhance your experience and analyse traffic. Analytics cookies are only enabled after you provide consent via our cookie banner. You can control cookies through your browser settings. For more details, see our Cookie Policy (linked in footer).

7. International transfers


Your information is stored securely in the UK / European Economic Area. Some of our service providers may operate outside the UK; in such cases we ensure appropriate safeguards (such as Standard Contractual Clauses) are in place.

8. Data retention


We keep your personal information only as long as necessary for the purposes it was collected, or to satisfy legal, accounting, or reporting requirements. Donation and payment records are kept for 7 years for HMRC purposes (Gift Aid). Audit logs are retained for 12 months, webhook payloads for 90 days, failed webhook records for 180 days, and stale pending donations for 7 days before removal.

9. Your rights


Under UK data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Request erasure of your data (in certain circumstances).
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time (where we rely on consent).

To exercise any of these rights, please contact us at privacy@thelocalfund.co.uk. We will respond within one month. If you are not satisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

10. Security


We take data security seriously. We use encryption (HTTPS), access controls, and regular security reviews to protect your information. However, no online transmission is 100% secure – you provide information at your own risk.

11. Changes to this policy


We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review it periodically.

12. Contact us


If you have any questions about this policy or our data practices, please contact our Data Protection Officer:
Email: privacy@thelocalfund.co.uk

Last Updated: March 15, 2026