TECHNOLOGIES
PRIVACY POLICY
Effective Date: January 1, 2026
Last Updated: May 6, 2026
Website: letselev8.com
Privacy contact: privacy@letselev8.com
This summary is provided for convenience only. It does not replace the full Privacy Policy that follows and is not a substitute for reading the detailed sections below.
| Topic | Summary |
|---|---|
| Who we are | ForGood Technologies, LLC (d/b/a Elev8 Technologies), a Wyoming limited liability company. Elev8 is a technology provider operating a fintech Fund Capturing Platform; Elev8 does not itself perform regulated financial services |
| What we do | We provide Card-Linking, Round-Up, Rewards & Loyalty, Sponsor Contribution, and Enterprise Engagement technology. All fund movement is initiated, executed, and controlled by licensed third-party financial institutions, not Elev8. We are not a bank, payment processor, payment facilitator, money transmitter, money services business, fundraising platform, charitable organization, or donation processor, and we do not hold, custody, or transmit funds. |
| What we collect | Identity, contact, account, device, tokenized transaction metadata, and engagement signals. We do not store raw primary account numbers (PANs), CVV codes, or full bank account numbers. Optional categories include geolocation (if enabled) and identity-verification signals, plus data we receive from sponsors, organizations, and partners. |
| How we use it | To operate the Platform, enable features like card-linking and round-ups, deliver rewards, prevent fraud, comply with law, and, where permitted, improve and personalize our services. |
| Selling / sharing | We do not sell Personal Information as defined under applicable law. To the extent certain datasharing practices may be classified as a “sale” or “sharing” (including for cross-context behavioral advertising) under state privacy laws, you have the right to opt out. |
| Your rights | Access, correct, delete, port, limit, opt out of sale/share and targeted ads, appeal denials, and withdraw consent, subject to your jurisdiction and verification. |
| Security | Encryption in transit and at rest, tokenization, MFA, least-privilege access, monitoring, and formal vendor risk management. |
| Contact | privacy@letselev8.com • 1621 Central Avenue, Cheyenne, WY 82001 |
ForGood Technologies, LLC, a Wyoming limited liability company doing business as Elev8 Technologies (“Elev8,” “Company,” “we,” “us,” or “our”), respects your privacy and is committed to protecting it through our compliance with this Privacy Policy (“Policy”).
Elev8 operates a financial-technology (“fintech”) platform purpose-built as a Fund Capturing Platform that enables organizations, sponsors, merchants, financial institutions, and individuals to capture, direct, and amplify program-related funds through modern payment, engagement, and loyalty technologies. For the avoidance of doubt, Elev8 is a technology provider, it is not a fundraising platform, charitable organization, professional fundraiser, charitable solicitor, or donation processor, as further described in Sections 42 and 43.
This Policy describes the types of information we collect, how we use and disclose it, the choices available to you, and the protections we apply. By accessing or using the Platform, you acknowledge that you have read and understand this Policy.
This Policy applies to information we collect, process, use, disclose, retain, or otherwise handle through:
Certain Elev8 services may be offered through a sponsoring organization, enterprise client, financial institution, or merchant partner. When that partner acts as the data controller or has its own privacy notice, that partner’s notice governs data it collects directly; this Policy governs the data that Elev8 itself processes.
This Policy applies to:
This Policy does not apply to:
Elev8 is a technology platform. Elev8 is not a bank, credit union, money transmitter, money services business, issuer, acquirer, payment processor, broker-dealer, investment adviser, or charitable organization. Elev8 does not hold, custody, or transmit funds, and Elev8 does not issue payment credentials.
Elev8 provides software, APIs, and dashboards that coordinate data between users, sponsoring organizations, merchants, financial institutions, and payment processors. Key modules include:
Elev8 enables users to link eligible payment cards so that qualifying merchant transactions can trigger benefits, contributions, or rewards. Elev8 receives transaction metadata from card networks and processors through secure, tokenized channels. Elev8 does not receive full primary account numbers (PANs) or CVV codes.
Elev8 calculates micro-contribution amounts, for example, rounding up a transaction to the nearest whole dollar, based on transaction metadata. The calculation is a software output; the actual movement of funds is performed by a third-party bank, payment processor, or gateway under agreements with the sponsoring organization or user.
Elev8 records, issues, tracks, and redeems points, credits, offers, and sponsor-funded incentives. Reward balances are ledger entries maintained in Elev8 systems; fulfillment of cash-equivalent rewards is performed by partners.
Elev8 allows sponsors (brands, enterprises, financial institutions, and other funders) to configure and measure sponsor-funded program mechanics tied to user engagement, transactions, or campaign participation. Sponsor-funded payouts are performed by the sponsor, the sponsor’s bank, or an applicable payment partner, not by Elev8, and are not solicitations of charitable contributions by Elev8. The term “contribution” as used in this Policy refers to program mechanics configured by the sponsor or organization, not to charitable gifts, donations, or tax-deductible payments made to Elev8.
Elev8 provides organizations with administrative consoles that surface aggregate performance metrics, campaign analytics, and, where permitted, individual engagement records.
Elev8 offers APIs, webhooks, and SDKs that allow authorized partners, financial institutions, and payment providers to integrate with the Platform under written agreements that include data-protection obligations.
All financial transactions are processed by third-party financial institutions, card networks, and payment processors, not by Elev8.
For clarity, the following terms have the meanings given below when used in this Policy:
| Term | Meaning |
|---|---|
| Personal Information / Personal Data | Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. |
| Sensitive Personal Information | A subset of Personal Information subject to heightened protection, such as government identifiers, precise geolocation, financial account information, biometric identifiers, and certain health information. |
| Processing | Any operation performed on Personal Information, whether automated or not, including collection, recording, organization, storage, use, disclosure, transfer, and destruction. |
| Controller / Business | The entity that determines the purposes and means of processing Personal Information. |
| Processor / Service Provider | An entity that processes Personal Information on behalf of a Controller. |
| Sub-processor | A third party engaged by a Processor to process Personal Information on behalf of the Controller. |
| De-identified Data | Information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual. |
| Aggregated Data | Information relating to a group or category of individuals from which identities have been removed. |
The categories and specific elements of information we collect depend on how you interact with the Platform and on the configuration of the program, organization, or sponsor you engage with.
Sensitive financial data (such as raw Primary Account Numbers “PANs”, full bank account numbers, or CVV codes) is handled by regulated third-party processors and is not stored by Elev8. Elev8’s systems are designed to receive and store only tokenized or masked values consistent with PCI DSS scope-reduction guidance.
Where applicable and legally permitted, we may process the following sensitive categories, subject to heightened controls and, where required, explicit consent or a recognized legal basis:
The Platform is not directed to, and we do not knowingly collect Personal Information from, children under 13 years of age (or under 16 where applicable law imposes a higher threshold). See Section 23 for more on children’s privacy.
We collect information through the following channels:
When you register for an account, link a payment method, configure contribution or rewards preferences, contact support, respond to a survey, or otherwise interact with the Platform.
Through secure integrations with card networks, issuers, acquirers, payment processors, and open-banking aggregators. These integrations typically exchange tokenized identifiers and transaction metadata rather than raw financial credentials.
Organizations, sponsors, and merchants may provide us with information about their users, members, participants, employees, campaigns, and programs in connection with the services Elev8 provides to them. Where a customer organization independently characterizes a program as charitable or fundraising in nature, it does so under its own terms, disclosures, and regulatory obligations, not Elev8’s.
When required, we use regulated identity verification and fraud-prevention providers that return pass/fail indicators, risk scores, and, in limited cases, verification artifacts.
Through cookies, pixels, SDKs, APIs, server logs, tag-management systems, analytics SDKs, and other tracking technologies that collect device, network, and usage information.
Including publicly available business registries, government records, social-media business profiles, and commercial data providers, for purposes such as KYB, sanctions screening, and enrichment of organizational records.
When a referrer or partner tells us about you, or when you are enrolled in a program by an entity authorized to do so.
We use Personal Information for the purposes described below. A single data element may support more than one purpose.
Where applicable law (such as the EU/UK GDPR, LGPD, or similar frameworks) requires us to identify a legal basis for processing, we rely on one or more of the following:
We do not sell Personal Information in exchange for monetary consideration. Depending on your jurisdiction, certain data-sharing may nevertheless be considered a “sale” or “sharing” under law, and you have rights to opt out as described in Section 17.
We disclose Personal Information in the following circumstances:
We share information with vendors that perform services for us under written contracts, including:
For card-linking, offer fulfillment, contribution settlement, and reconciliation, we exchange tokenized identifiers and transaction metadata with participating financial institutions and payment providers.
In connection with a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or similar transaction, Personal Information may be transferred as a business asset, subject to appropriate confidentiality and data-protection commitments.
When you explicitly direct or authorize us to share information, including via connected-account permissions.
We may disclose aggregated, anonymized, or de-identified data that does not reasonably identify you, for any lawful purpose, including benchmarking, research, marketing, and industry reporting.
We engage sub-processors to help us deliver the Platform. Each sub-processor is contractually obligated to:
A current list of key sub-processors is maintained and available upon request to enterprise customers under a Data Processing Addendum (DPA). We perform risk assessments before onboarding sub-processors and on a periodic basis thereafter.
Elev8 is not itself a financial institution within the meaning of the Gramm-Leach-Bliley Act (GLBA) or the Federal Trade Commission’s Safeguards Rule. Elev8 does not establish customer relationships under GLBA, does not solicit financial products or services, and does not issue GLBA privacy notices in its own name.
Elev8 may, however, act as a service provider to GLBA-regulated institutions. In that capacity, Elev8 processes nonpublic personal information (“NPI”) only as a service provider, strictly under written contract and pursuant to the documented instructions of the regulated institution. The regulated institution remains the controller of its customers’ NPI and remains responsible for its GLBA Privacy Rule obligations to its customers, including providing initial and annual privacy notices and any applicable opt-out rights. Customers of any such institution should refer to that institution’s privacy notice for information about how their NPI is collected, used, and shared.
In support of GLBA-regulated institutions and other partners, Elev8 maintains administrative, technical, and physical safeguards consistent with the principles of the FTC Safeguards Rule and applicable financial-institution vendor-management expectations, including:
Nothing in this Section is intended to characterize Elev8 as a “financial institution” for purposes of GLBA or to subject Elev8 to obligations beyond those that apply to a service provider under contract with a covered institution.
Elev8 aligns its information-security practices with the requirements of the Payment Card Industry Data Security Standard (PCI-DSS) applicable to our role. To support that alignment, we generally:
PCI-DSS responsibilities are typically shared among Elev8, our payment service providers, card networks, and our Business Customers, and the specific allocation depends on the integration model and use case.
Our card-linking and transaction-triggered features depend on participation in card-network programs (e.g., Visa, Mastercard, American Express, Discover) and issuer agreements. We handle transaction data in accordance with applicable network rules and program requirements, which may restrict retention, further disclosure, or use of transaction data for unrelated purposes.
Where you choose to connect a bank account or other financial account, you may authorize an open-banking aggregator (such as a data-access provider or screen-scraping or API-based aggregator) to share specific financial data with Elev8. We honor authorization revocations you initiate through our Platform or through the aggregator. We align with industry frameworks such as the Financial Data Exchange (FDX) principles, including consumer consent, data minimization, traceability, and security.
We maintain a written information-security program designed to protect Personal Information against unauthorized access, acquisition, alteration, disclosure, or destruction. Measures include:
No method of transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee its absolute security.
We retain Personal Information only as long as necessary to fulfill the purposes for which it was collected, including for:
Retention periods may vary depending on the type of data involved, the specific purpose for which it was collected, the legal or contractual obligations that apply, and any active legal holds. We use the following criteria to determine how long to keep each category of information: the duration of our relationship with you; the nature, sensitivity, and volume of the information; the potential risk of harm from unauthorized use or disclosure; the purposes for which we process the information and whether we can achieve those purposes through other means; and applicable legal, regulatory, tax, accounting, audit, and reporting requirements.
By way of illustration only, the table below shows representative retention ranges. Actual retention for any given record may be shorter or longer based on the specific legal basis or operational need that applies.
| Category | Illustrative Retention Range |
|---|---|
| Active account records | For the life of the account, plus a reasonable period thereafter to meet legal, tax, audit, dispute, and recordkeeping obligations. |
| Transaction & program-activity metadata | Retained for as long as required by applicable financial, tax, AML, and recordkeeping laws, which can typically range from several years to longer where required. |
| Rewards ledger entries | For the life of the program plus any wind-down, reconciliation, or audit period required by the program operator or applicable law. |
| Support communications | Retained for a reasonable period after the last interaction to support service quality, dispute resolution, and legal defense. |
| Marketing preferences & suppression lists | Retained for as long as needed to honor your opt-out and meet related legal obligations. |
| Security & access logs | Retained for a period appropriate to security, fraud-prevention, and legal-defense needs, subject to legal holds. |
| De-identified and aggregated data | May be retained for so long as it remains de-identified or aggregated and cannot reasonably be linked to an individual. |
After an applicable retention period ends, we delete, destroy, or irreversibly de-identify the Personal Information, subject to legal holds, backup cycles, and technical limitations of our systems. The table above is illustrative and not exhaustive; it does not establish a fixed retention period for any specific record.
Depending on where you live and the law that applies, you may have some or all of the rights described below. We respond to verifiable requests within the timelines required by applicable law.
California residents have the rights listed above, and we provide the following additional disclosures:
California “Shine the Light” (Cal. Civ. Code § 1798.83): California residents may request information about our disclosure of Personal Information to third parties for their direct marketing purposes.
Residents of Virginia, Colorado, Connecticut, and Utah have rights to access, correct (where applicable), delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. Colorado and Connecticut residents may also use recognized universal opt-out mechanisms such as the Global Privacy Control (GPC).
Residents of these states have substantially similar rights under their respective comprehensive privacy laws. We honor verifiable requests in accordance with those laws, including rights to access, correct, delete, port, opt out of sales and targeted advertising, and, where applicable, opt out of certain profiling and of processing of Sensitive Data without consent.
Submit a request by:
We will verify your request using information we already have about you. An authorized agent may submit a request on your behalf with a signed, written authorization (and, where required, proof of identity). If we deny your request, you may appeal by replying to our decision; we will respond to appeals within the timeframe required by applicable law.
If you are in the EEA, United Kingdom, or Switzerland, you have additional rights under the EU GDPR, UK GDPR, or Swiss FADP, including rights to:
If you are in the EEA, UK, or Switzerland, you may contact us at privacy@letselev8.com. Where required, we will appoint a representative for purposes of Article 27 GDPR or UK GDPR.
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws (e.g., Quebec Law 25, BC PIPA, Alberta PIPA) may apply. You have rights to access and correct your Personal Information, to withdraw consent (subject to legal or contractual restrictions), and to file a complaint with the Office of the Privacy Commissioner of Canada or provincial counterpart.
Where applicable, we comply with additional data-protection frameworks such as Brazil’s LGPD, Australia’s Privacy Act (APPs), and other relevant national or regional laws. Users in those jurisdictions may contact us to exercise rights granted under their local laws.
We and our authorized partners use cookies and similar technologies (pixels, tags, beacons, SDKs, local storage) for the purposes described below:
| Category | Purpose |
|---|---|
| Strictly Necessary | Required for the Platform to function (authentication, security, session management). These cannot be disabled through our controls. |
| Performance & Analytics | Help us understand how users interact with the Platform to improve performance and user experience. |
| Functional | Remember preferences, settings, and personalization choices. |
| Advertising & Measurement | Measure campaign performance; where enabled, support targeted advertising. |
You can manage cookie preferences through our cookie-preferences tool (where available), browser settings, device-level opt-outs, and industry tools such as the Digital Advertising Alliance’s YourAdChoices, the Network Advertising Initiative’s opt-out, and the European Interactive Digital Advertising Alliance (EDAA). On mobile devices, you may reset or limit advertising identifiers through your device settings.
We also recognize the Global Privacy Control (GPC) and similar universal opt-out signals where required by law.
The Platform integrates with third parties, including financial institutions, card networks, payment processors, sponsors, merchants, identity verification providers, and analytics providers. These third parties operate under their own privacy policies. We are not responsible for the privacy practices of third parties we do not control. Before linking an account, installing an integration, or transmitting data to a third party, we encourage you to review that party’s privacy notice.
The Platform is not directed to or designed for children under 13, and Elev8 does not knowingly collect Personal Information directly from children under 13 (or under 16 where a higher threshold applies under applicable law). Elev8 does not target advertising to children and does not knowingly enable other parties to do so through the Platform.
Elev8 may provide its technology to schools, youth-sports organizations, after-school programs, parent to teacher associations, faith communities, and similar organizations whose participants may include minors. Where such an organization enrolls minors on or through the Platform:
Despite our practices, information about a minor could be inadvertently provided to the Platform, for example, through an organization, a sponsor, or a user. If Elev8 becomes aware that it has inadvertently collected Personal Information from a child in a manner that requires verifiable parental consent under applicable law and such consent has not been obtained, Elev8 will take reasonable steps to delete or restrict the information.
If you are a parent or legal guardian and believe that information about your child has been provided to the Platform without appropriate consent, please contact privacy@letselev8.com so we can promptly investigate and, where appropriate, delete the information.
Elev8 is based in the United States, and our service providers may be located in the United States, Canada, the European Economic Area, the United Kingdom, and other jurisdictions. Where we transfer Personal Information across borders, we rely on legally recognized transfer mechanisms, including:
We do not collect or store biometric templates (such as fingerprint, face, voiceprint, or iris templates). When you choose to use device-based biometric authentication (for example, Face ID or Touch ID) to access the Platform, the biometric processing occurs on your device, and your device returns only a success/failure signal to us. Where state laws such as the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, or Washington HB 1493 would otherwise apply, we confirm that Elev8 does not collect, capture, or purchase biometric identifiers from you.
Elev8 is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). The Platform is not designed to handle protected health information (PHI), and you should not submit PHI to Elev8. Where we operate with healthcare-adjacent organizations, we do so under appropriate contracts that restrict the categories of data shared.
Elev8 applies privacy-by-design principles throughout product development and operations:
We may use automated processing and profiling for purposes such as:
We do not use solely automated processing to make decisions that produce legal or similarly significant effects on you without appropriate safeguards (such as meaningful human review, the ability to contest a decision, or the ability to request reconsideration). Where required by law, you may object to such processing or request human review by contacting privacy@letselev8.com.
Elev8 may use machine-learning, artificial-intelligence, and similar analytics techniques to operate, secure, monitor, support, and improve the Platform, for example, for fraud detection, anomaly detection, transaction-pattern analysis, engagement analytics, and product personalization.
Where we train, fine-tune, or evaluate models using information that may include Personal Information, we apply technical and organizational safeguards designed to reduce risk, including de-identification or aggregation where feasible, access controls, logging, vendor due diligence, and contractual restrictions on our service providers’ permitted use of data.
We do not knowingly use Personal Information to train, fine-tune, or improve generative-AI or foundation models in ways that are materially incompatible with the purposes for which the information was collected, and we do not knowingly sell Personal Information to third parties for model-training purposes. We do not knowingly permit our service providers to use Elev8 customer data to train their own publicly available models, except as expressly permitted in our written agreements with them.
Enterprise and Business Customers may have additional contractual commitments regarding model training, prompt and output retention, model isolation, and acceptable use of customer data in their separate agreements with Elev8, which will control over this Section to the extent of any conflict.
The AI and data-protection landscape is evolving rapidly. Our specific practices, vendors, and safeguards may change over time, and we will update this Policy or related notices as needed to reflect material changes in our use of AI or machine learning.
Because there is no industry consensus on how to interpret browser “Do Not Track” (DNT) signals, we do not currently respond to DNT signals. Where required by law, we recognize Global Privacy Control (GPC) and other universal opt-out mechanisms as a valid request to opt out of sale and sharing of Personal Information.
We maintain a formal incident-response program. In the event of a security incident involving Personal Information, we will:
We strive to make our Platform and our privacy notices accessible. If you need this Policy or any privacy tool in an alternative format, please contact privacy@letselev8.com.
If you submit comments, reviews, feedback, testimonials, referrals, or other content through the Platform, that content, along with any information you choose to include, may be stored, processed, and, where appropriate, displayed by Elev8 or shared with the applicable organization or sponsor. Do not submit information you do not wish to be collected and processed in this way.
We may contact you about products, offers, campaigns, and program updates by email, SMS, push notification, phone, or mail, as permitted by law and subject to your preferences.
Even if you opt out of marketing, we may still send service and transactional messages necessary to operate the Platform.
When an organization or sponsor uses Elev8 to operate a campaign, program, or initiative:
We create and use aggregated, anonymized, and de-identified data that cannot reasonably be linked back to you. Where applicable law requires, we maintain technical and organizational controls to prevent re-identification and contractually restrict recipients from attempting re-identification. Aggregated and de-identified data are not considered Personal Information for purposes of this Policy.
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make a material change, we will provide reasonable notice, such as by posting the updated Policy with a new “Last Updated” date, sending an email, or displaying an in-Platform notice. Your continued use of the Platform after the revised Policy becomes effective constitutes acceptance of the changes.
Any disputes regarding this Policy or the Platform are subject to the dispute-resolution, governing-law, and venue provisions set forth in our Terms of Service and, where applicable, in any master agreement between Elev8 and a business customer. Nothing in this Policy limits rights that cannot be waived under applicable law.
This Policy is governed by the laws of the State of Wyoming, USA, without regard to its conflict-of-laws principles, except where mandatory consumer or data-protection laws of your jurisdiction require otherwise.
Elev8 has designated a Privacy Office responsible for overseeing our privacy program. The Privacy Office coordinates our privacy-by-design, vendor-management, training, and incident-response activities, and serves as the principal point of contact for privacy inquiries. Where we are required to designate a Data Protection Officer (DPO), an EU representative under Article 27 of the EU GDPR, or a UK representative under the UK GDPR, we will do so and update this Policy accordingly.
As part of our accountability program, and where required by applicable law (including the EU/UK GDPR, the Swiss FADP, the LGPD, and analogous frameworks):
Privacy contacts:
General privacy: privacy@letselev8.com
Security: security@letselev8.com
Legal notices: legal@letselev8.com
For questions, concerns, or requests related to this Policy or our privacy practices:
ForGood Technologies, LLC (d/b/a Elev8 Technologies)
Attn: Privacy Office
1621 Central Avenue, Suite 9191
Cheyenne, WY 82001, USA
Email: privacy@letselev8.com
Website: letselev8.com
Elev8 is a technology provider. For clarity:
Elev8 is a technology and software provider. Elev8 is not, and does not operate as, any of the following:
Elev8 does not solicit, request, accept, hold, process, transmit, disburse, acknowledge, or receipt charitable contributions, donations, gifts, or pledges, and does not make any representation that any payment, round-up, reward, transfer, or other transaction on the Platform is a charitable contribution, a tax-deductible payment, or otherwise has any charitable, gift-tax, or income-tax character.
The term “Fund Capturing Platform” refers to Elev8’s technology-enabled mechanics, including card-linking, round-ups, rewards, loyalty, and sponsor-funded program payouts, and is not a description of fundraising, charitable solicitation, or gift processing. Elev8 provides software; it does not raise, collect, or administer charitable funds.
Organizations, sponsors, enterprise customers, financial institutions, and other third parties that deploy the Platform are solely responsible, as applicable, for:
Elev8 does not verify, endorse, audit, or assume responsibility for any customer’s charitable status, solicitation registrations, tax-exempt determinations, or donor-facing representations, and is not liable for any customer’s failure to comply with charitable or fundraising laws.
Elev8 does not provide tax advice. Nothing on the Platform constitutes an opinion or representation that any amount is deductible as a charitable contribution or has any particular tax treatment. Users should consult their own qualified tax advisors regarding the tax consequences of any payment, round-up, reward, or other transaction.
The legal relationship between a user and any program, offer, campaign, benefit, reward, or sponsor-funded payout is governed by the terms of the applicable organization, sponsor, merchant, or financial institution, not by Elev8. Elev8 is not a party to any gift, pledge, donation, subscription, purchase, or similar transaction, and Elev8’s role is limited to providing the technology under which such programs operate.
Nothing in this Policy or in Elev8’s provision of the Platform creates any fiduciary, trust, agency, escrow, or similar relationship between Elev8 and any user, organization, sponsor, or other person.
The table below summarizes the categories of Personal Information we process, the purposes of processing, and the categories of recipients. This appendix is provided to support transparency obligations under laws such as the CCPA/CPRA and GDPR.
| Category | Primary Purposes | Categories of Recipients |
|---|---|---|
| Identity & Contact | Account creation, authentication, communications, identity verification. | Service providers, identity verification vendors, organizations, sponsors. |
| Financial & Transaction Metadata | Card-linking, round-up, rewards, contribution coordination, fraud prevention. | Card networks, payment processors, banking partners, fraud vendors. |
| Device & Technical Data | Security, diagnostics, analytics. | Cloud providers, analytics providers, security vendors. |
| Behavioral & Engagement | Personalization, reporting, program analytics. | Analytics vendors, organizations, sponsors (aggregated). |
| Enterprise & Organizational | Administration, reporting, billing. | Cloud providers, support vendors, auditors. |
| Sensitive (limited use) | KYC/identity verification, security, fraud prevention, optional geolocation features. | KYC/identity verification vendors, fraud vendors, with consent. |
Real humans, fast replies. Tell us a little and we'll take it from there.