Privacy Policy

Privacy Policy

Last updated: May 18, 2026

This policy describes what personal information we collect when you donate or interact with this site, how we use it, who we share it with, and the choices you have.

Who we are

This website is operated by Acts Ministries International ("AMI", also referred to as "we", "us", or "our"), a 501(c)(3) nonprofit organization based in Anaheim, California, United States, in partnership with Panti Asuhan Insan Permata, a children's home in Pekanbaru, Indonesia. All donations are received and processed by AMI, and AMI is the controller of the personal information described in this policy. AMI raises and grants funds in support of the home. You can reach us by email at info@insanpermata.org for any privacy-related question or request described in this policy.

Information we collect

Information you provide directly

  • Donation form: your email address, full legal name, donation amount (USD), and donation type (one-time or monthly).
  • Stripe Checkout: your payment card details, cardholder name, and (when the card brand requires it) billing postal address are collected directly by Stripe on its hosted checkout page. We do not see or store your card information.
  • Account setup: a password you choose, which is hashed by Supabase Auth and never stored in readable form.

Information we receive from Stripe

After a successful donation, Stripe sends AMI a confirmation that includes: your donation amount, currency, paid status, a Stripe customer identifier, a session identifier, and (for monthly donations) a subscription identifier. We store these alongside your email and donor name to issue receipts and prepare your year-end contribution statement.

Information collected automatically

  • Server and access logs: our hosting provider (Vercel) and database provider (Supabase) automatically log standard request metadata such as IP address, browser type, request path, response code, and timestamp. These logs are kept for short retention windows per the providers' defaults.
  • Authentication cookies: if you create a donor account, a session cookie (set by Supabase) keeps you signed in. It is strictly necessary for the site to function and is not used for tracking or advertising.

What we do NOT collect

  • No analytics or advertising tracking. We do not run Google Analytics, Meta Pixel, or any third-party tracker.
  • No phone numbers, government IDs, or tax IDs are collected on our donation form.
  • We do not knowingly collect any information from children. The profiles of children featured on our website are published by us with the consent of their guardians, not collected from visitors.

How we use your information

  • To process your donation and send you a payment receipt.
  • To create an optional donor account so you can view your donation history and download a year-end contribution statement.
  • To send you transactional emails related to your account (such as your initial invitation or a password reset).
  • To prepare aggregate financial and operational reports about our work — these reports do not identify you personally.
  • To comply with our legal and tax record-keeping obligations.

We do not sell or rent your personal information to anyone. We do not share your information with any party for that party's own marketing purposes.

Third-party processors

The vendors below process your data on our behalf to keep the site and donations running:

  • Stripe, Inc. (USA) — payment processing. Stripe receives your email, donor name, card details, billing ZIP/address (when applicable), and your IP for fraud screening. See Stripe's privacy policy.
  • Supabase Inc. (USA) — database, authentication, file storage, and transactional invitation/password-reset emails. See Supabase's privacy policy.
  • Vercel Inc. (USA) — web hosting and image delivery. See Vercel's privacy policy.
  • Cloudflare, Inc. (USA) — bot-protection challenge on our donation form (Turnstile). See Cloudflare's privacy policy.

Where your data is stored

Our processors are based in the United States and your information is stored on infrastructure they operate. If you donate from outside the U.S., your data will be transferred to and processed in the U.S. and other jurisdictions where our processors operate.

How long we keep your data

  • Donation records and contribution statements: retained for at least seven years to support tax record-keeping recommendations.
  • Donor account: retained while your account is active. You can request deletion at any time (see your rights below).
  • Server and authentication logs: retained per our providers' defaults — typically days to weeks for access logs.
  • Stripe records: retained according to Stripe's own policies, which we do not control.

Your rights

Depending on where you live (including residents of California, Virginia, Colorado, Connecticut, Utah, and Texas under their respective state privacy laws), you may have the right to:

  • Access the personal information we hold about you.
  • Request that we correct inaccurate information.
  • Request that we delete your personal information, subject to our legal record-keeping obligations.
  • Receive a copy of your information in a portable format.

We do not "sell" or "share" your personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).

To exercise any of these rights, email info@insanpermata.org from the address associated with your donation. We'll respond within 30 days.

Donors in the EU, EEA, and UK

If you donate from the European Union, the European Economic Area, or the United Kingdom, the EU/UK General Data Protection Regulation (GDPR) applies to our processing of your personal information, in addition to the rights described above.

Lawful bases. We process your personal information on the following bases:

  • Performance of a contract (Art. 6(1)(b)) — to process your donation, issue your receipt, and operate your optional donor account.
  • Legal obligation (Art. 6(1)(c)) — to keep donation and tax records as required by applicable law.
  • Legitimate interests (Art. 6(1)(f)) — to secure the site, prevent fraud and abuse, and report on our work in aggregate, balanced against your rights and freedoms.

International transfers. Our processors are located in the United States, so your personal information is transferred to and processed in the U.S. Where we transfer your data to provide the services you request, we rely on the transfer derogation for performance of a contract with you (Art. 49(1)(b)). Our processors additionally apply their own transfer safeguards, including the EU Standard Contractual Clauses where they offer them.

Your GDPR rights. In addition to the rights listed above, you have the right to access, rectify, erase, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent where processing is based on consent (without affecting prior processing). To exercise these rights, email info@insanpermata.org.

Supervisory authority. You have the right to lodge a complaint with your local data protection supervisory authority — in the UK, the Information Commissioner's Office (ICO); in the EU/EEA, the authority in your country of residence — if you believe our processing of your personal information infringes applicable law.

Cookies

We use a single strictly-necessary cookie set by Supabase to keep you signed in to your donor account. We do not use analytics, advertising, or third-party tracking cookies. Because this cookie is required for the site to function, no consent banner is shown.

Children's privacy

Our donation site is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with information, please contact us so we can delete it.

Profiles of the children we care for that appear on this site are published by Insan Permata, with the consent of their guardians, to communicate the work of the home to supporters. Those profiles are shown only on pages that require a donor sign-in. See our Child Protection Policy for the safeguards we apply when telling their stories.

Security

We use industry-standard safeguards: HTTPS for all traffic, password hashing via Supabase Auth, server-side validation on file uploads, signed Stripe webhooks, and least-privilege server access to the database. No system is perfectly secure, but if we ever learn of unauthorized access to personal information we'll notify affected donors as required by law.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the latest revision. Your continued use of the site after a revised policy is posted constitutes your acceptance of the revised policy.

Contact

Email: info@insanpermata.org
Postal: Acts Ministries International, 1380 S. Sanderson Ave, Anaheim, CA 92806, United States