Privacy Policy

Effective date: 2026-08-28

This Privacy Policy explains what information Serve Source ("Serve Source," "we," "us," or "our") collects, how we use it, and the choices you have. It applies to servesource.org, app.servesource.org, and related services (the "Site"), and it supplements our Terms of Service.

1. The Short Version

We collect information you give us directly (like when you create an account, submit a testimonial, or donate), information organizations give us about their locations and contacts, and some automatic technical data (like which pages get viewed — page-view records carry no IP address and no identifier that follows you between visits). We use it to run the Site, connect people and organizations relationally, and — with your consent — reach out through email, text, or phone.

We do not sell your contact information or data, and we do not use it to build mailing lists for anyone outside Serve Source. We may use personal contact information to help make meaningful, relationally-driven introductions between people and partner organizations, and to share publicly available disaster response opportunities (prayer, financial partnership, volunteering) on social media, from our own Serve Source accounts.

The rest of this policy explains all of this in more detail, section by section, with the plain-language summary first and the fuller legal language underneath.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account, donate, submit a testimonial, sign up for an event, or fill out a form on the Site, you may provide: your name, email address, phone number, mailing address, organization affiliation and role, and the content of whatever you're submitting (a testimonial, a community report, an indication that you're praying for a response, etc.).

We also collect a few things specific to how the Site works:

  • Prayer submissions — an optional message, and an optional postal code so your prayer can appear on the map near where you are. Here is exactly what happens to that postal code: we send it to our geocoding provider (LocationIQ — see Section 7) to get the approximate center point of that postal area, and then we shift that point in a random direction by a random distance of roughly half a mile to two miles. Only the shifted point is stored on your prayer. We never ask for or store a street address, and we never read your device's GPS location. The shift is re-rolled on every submission, so repeat prayers don't stack onto an identical pin. If you're signed in, we also save the postal code and its postal-area center point to your profile, so you don't have to type it again. If you're not signed in, the postal code isn't retained at all — only the shifted point. If you check the box asking to be contacted, we'll also store the email you provide for that purpose.
  • Testimonials — your name, role/title, and organization (if any), plus an email we use only to follow up about your submission — never displayed publicly.
  • Donations — processed through Overflow or Stripe; we receive your name, donation amount, and a payment processor's own customer reference, but never your full card number.
  • Agreements you sign on the Site — if you electronically sign an agreement here (for example, the volunteer and intern confidentiality agreement), we keep a record of what you signed: your name as typed, the exact version of the document you saw, the date and time, and — as the audit trail any electronic signature depends on — the IP address and browser the signature came from. If the signer is under 18, that record also includes the name, email address, and relationship of the parent or guardian who signed with them. We ask whether a signer is 18 or older; we don't ask for a birth date and we don't store an age.
  • Volunteer interest — if you indicate interest in volunteering with a particular organization or in a particular area, we store that so we (or the relevant organization) can follow up.
  • Forms — we use online forms, both on our own platform and through established third-party form and survey tools, to collect information you choose to submit. For example, our "Submit Community Report" form lets you tell our team about an area impacted by a disaster, so partner organizations and churches know where to respond; other forms let you register for an event. Whatever you submit through these forms is used consistent with this Privacy Policy, and while it sits in the form provider's system it's also subject to that provider's own privacy policy. If you'd like to know which provider is behind a particular form before you fill it out, ask us at info@servesource.org and we'll tell you.

Legal language: Personal Data collected under this section 2.1 is collected when you voluntarily provide it, and by providing it you consent to its use as described in this Policy.

2.2 Information Organizations Provide About Their Contacts

Some of our partner organizations provide us with information about their own contacts — for example, a list of churches an organization wants to help us engage around disaster response and relationship-building, before and after a disaster. We keep a record of where each contact record came from (for example: a form, a manual entry, an import, or a partner-provided list), and we track, per contact and per communication channel (email, text, call, or postal mail), whether that person has opted in or out of hearing from us — so we can honor their preferences regardless of how the record originated. Anyone included this way can ask us at info@servesource.org to be corrected or removed from our records at any time.

2.3 Communication Platforms

Serve Source uses communication platform(s) — such as email, text, and messaging tools — to coordinate with partner organizations. When a partner organization discloses information to us this way, that information may become part of the disaster-response data we publish on the Site.

Some of these platforms are also shared spaces that partner staff can join directly to communicate with Serve Source and with each other. If you join one, your name and the email address on your account there are visible to other participating partner organizations, and you may choose to add a phone number to your own profile within that platform — that's entirely your own choice, not something Serve Source populates or requires.

Legal language: Serve Source may use one or more third-party communication platforms to receive information from partner organizations, coordinate disaster-response activities, and facilitate connections within Serve Source's partner network. Information a partner organization discloses to Serve Source through such a platform may be used to create or update Site content, consistent with our Terms of Service. Where such a platform is a shared space that partner staff may join directly, the individual's name and account email are visible to other participants, and the individual may voluntarily add a phone number to their own profile there. Visibility and use of information within a shared communication platform is also subject to that platform's own terms and the conduct of other participants, which Serve Source does not fully control.

2.4 Organization and Location Information

Organizations that join Serve Source, or that we list because we're connected with them or believe they're mission-aligned (see our Terms of Service), provide or have associated with them information such as their name, logo, description, services, location(s), and contact details. Some of this information — such as an organization's name, logo, service area, and general contact information — is displayed publicly, so the public and other partner organizations can find and coordinate with them. Organization logos and branding remain the property of the organization, as described in our Terms of Service.

An organization may request an export of its own disaster-response data from us at any time — see Section 11.

2.5 Automatically Collected Information

When you view a page on the Site, we record which page you viewed, the page that referred you there, and your browser's user-agent string — the line your browser sends describing itself, typically its name, version, and operating system. We do not store your IP address alongside page views, and we don't set an identifier that follows you from one visit to the next, so these records aren't linked to you or assembled into a profile of your browsing. We describe the user-agent string here rather than calling this data anonymous, because a detailed user-agent string is the kind of thing that can contribute to identifying a device.

We use this first-party data to understand which disasters, organizations, and resources people are actually finding, and to improve the Site. We do not currently use Google Analytics or any other third-party analytics or advertising tracker — see Section 7 for our forward-looking plans on that front.

2.6 Session Recording

Serve Source uses the session-recording feature built into the web-application platform our Site runs on — Base44, Inc., a Wix company (see Section 7). It records how visitors move through the Site: pages viewed, clicks, and form submissions, along with signals like repeatedly clicking something that isn't responding. We use it to find the places where the Site is confusing or broken, and for nothing else.

What we can tell you about how it works: recordings are held by the platform for 30 days and then deleted automatically, and only the 500 most recent sessions are kept at any one time. They're viewable by the small number of Serve Source administrators who have access to our application dashboard. We don't use recordings to build a profile of you, we don't link them to your account for marketing, and we don't share them.

What we won't overstate: payment details are entered directly into secure fields hosted by Stripe, in a separate frame the recorder cannot reach, so card and bank numbers are never captured. For other form fields, the platform's documentation doesn't specify what masking it applies. We're getting a definite answer from the platform and will update this section with it — until then, please treat anything you type into a form on the Site as something a Serve Source administrator could see.

2.7 Resource Downloads

When you download a resource from our Resources section, we record which resource was downloaded and your browser's user-agent string. If you're signed in, that record is associated with your account and email address. If you're not signed in, we store a one-way salted hash of your IP address — a scrambled, irreversible value that lets us tell one download apart from another without keeping the address itself.

2.8 Outbound Link Tracking

Links on the Site to a partner organization's own website may include tracking parameters (for example, utm_source, utm_medium, utm_campaign) so that the organization can see, in their own website analytics, that a visitor was referred by Serve Source and roughly why (for example, a specific disaster response listing). These parameters are visible in the resulting URL; they don't carry any of your personal information — they identify Serve Source as the referrer, not you.

2.9 Information We Don't Yet Collect, But May in the Future

We're planning a feature that would let disaster survivors submit assistance requests directly through the Site. That isn't built yet. When it is, we'll add a dedicated section to this Privacy Policy (and to our Terms of Service) describing exactly what's collected and how it's used, before that feature goes live.

3. How We Use Your Information

We use the information described above to: operate and maintain the Site; create and manage accounts; process donations; respond to your questions and submissions; send administrative communications (confirmations, updates to our policies, security alerts); and, where you've opted in, send you other communications like newsletters or updates about opportunities to get involved.

Because creating an account means we'll be working together, we'll also send you account-related and organizational updates from Serve Source; you can opt out of non-essential communications at any time (see Section 11).

Legal language: We use Personal Data in a manner consistent with the purpose for which it was provided. If we ever intend to use your Personal Data in a way materially inconsistent with this Policy, we will inform you before or at the time of collection.

4. Using Contact Information to Build Relationships

Part of Serve Source's mission is helping people and organizations make meaningful, relationally-driven connections — a church learning about a response organization working nearby, a volunteer connecting with the right opportunity, a donor learning about a specific need. We may use contact information for this purpose, consistent with each person's channel-level consent status described in Section 2.2 — we don't add someone to an email or text communication channel without their opt-in for that channel. This may include inviting you to join a shared communication platform with other partner organizations, as described in Section 2.3.

You can choose exactly which updates you'd like to receive — such as disaster alerts, prayer opportunities, or partner news — using the preference link included in our emails, which lets you opt in or out topic by topic.

5. Public Disaster Response Data and Social Media

Serve Source publishes publicly available disaster response information — either submitted through the Site or shared with us in other communications — and shares it to help magnify the efforts of partner organizations, including opportunities to pray, give financially, or serve with a partner organization. This sharing happens through Serve Source's own social media accounts, not through your personal accounts or on your behalf. We may use software tools, including AI-assisted tools, to help draft this kind of content or match a need to a resource; any public-facing content is reviewed by our team before it's published.

6. What We Don't Do: No Selling of Contact Lists or Information

Serve Source does not sell, rent, or trade your contact information or other personal data. If Serve Source is ever involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy (or a successor policy you're notified of).

7. Who We Share Information With

We work with a small number of service providers to run the Site, and we only give each one the information it needs to do its job:

  • Stripe — processes donations. Stripe receives your payment details directly; we never see or store your full card number.
  • Overflow — processes some donations, embedded directly on our website. Overflow receives your payment details directly; we receive your name, donation amount, and a payment processor's own customer reference, but never your full card number.
  • LocationIQ — used to convert addresses into map coordinates (geocoding) and back.
  • Esri / ArcGIS — used for custom mapping. Today, Esri holds a separate, manually-maintained copy of some organization data — including some individual contact information (names, emails, phone numbers) tied to organization locations — that is not automatically synced with our platform. As our mapping tools evolve, we intend to limit what's shared with Esri to organization-level display information (name, location, category) wherever possible, rather than individual contact details.
  • Form and survey tools — used for the specific forms described in Section 2.1. We'll name the provider behind any particular form on request.
  • Communication platform(s) — such as email, text, and messaging tools, used to coordinate with partner organizations; see Section 2.3 for what's visible to other participants if you join a shared one.
  • Our web-application platform — hosts our data and application infrastructure, and the Site itself is built on it.
  • Domain and security monitoring tools — see Section 8.

Advertising and analytics — forward-looking. We may in the future use advertising platforms (such as Google Ads or Meta/Facebook Ads) to promote Serve Source, and analytics tools (such as Google Analytics) to understand Site usage. If we do, we will update this Policy and our cookie consent mechanism accordingly before those tools go live.

We may also disclose information if required by law, to protect our legal rights, to protect the safety of Site users or the public, or in connection with a business transfer as described in Section 6.

8. Monitoring of Partner Organizations

Serve Source uses automated tools to monitor publicly available information about our partner organizations — their websites, social media accounts, and domain/security records — to help us identify organizations that may have stopped operating, changed ownership, or begun sharing malicious or inappropriate content, and to flag potential domain security vulnerabilities so we can notify the organization. This monitoring is about organizations' public-facing presence; it is not used to compile information about their individual staff members.

9. Cookies and Similar Technologies

The Site may use cookies and similar technologies to keep it running properly (for example, keeping you signed in) and to understand how the Site is used, including the session-recording feature described in Section 2.6. We do not currently use third-party advertising cookies. If that changes — for example, if we adopt Google Analytics or an advertising platform as described in Section 7 — we'll update this section and our cookie consent mechanism at that time.

10. Data Retention

We keep information for as long as it's genuinely useful for the purposes described in this Policy — and because Serve Source is a relational organization, useful is often measured in years. Knowing that a particular church showed up for a response in 2019 matters when disaster strikes that same community years later. We'd rather hold the history of a relationship than lose it. In practice:

  • Account and organization records — kept while the account or organization profile is active, and for 7 years after it's closed or goes inactive.
  • Contact records and communication history, including per-channel opt-in and opt-out status — kept for 10 years after our last meaningful interaction with you. Opt-out records we keep indefinitely, because remembering "don't contact me" is the only way to reliably honor it.
  • Donation and financial records — kept for 7 years, as our tax, audit, and nonprofit reporting obligations require.
  • Electronic signature records — kept for the life of the agreement signed and for 7 years afterward, including the audit trail described in Section 2.1 (name as typed, document version, timestamp, IP address, and browser). We keep these for as long as the agreement could still matter; a signature record that outlives its agreement by a few years is rather the point of having one.
  • Disaster response, event, and community report records — kept indefinitely, as part of the historical record of who responded to what, and when.
  • Prayer submissions — kept indefinitely; they carry no identity, and only a shifted location.
  • Testimonials — kept while published, and for 3 years after they come down.
  • Website technical records (page views, resource downloads) — kept for 25 months, then deleted or rolled up into counts that aren't tied to any individual record.
  • Session recordings — kept by our platform for 30 days, then deleted automatically.

These are the periods we aim for, and we may keep something longer where the law requires it or where it's needed to resolve a dispute or enforce our agreements. We take reasonable steps to keep information accurate and to honor correction and deletion requests — see Section 11.

11. Your Choices and Rights

You can ask us to correct, update, or delete your personal information, or to stop receiving communications from us, at any time by contacting info@servesource.org. You can unsubscribe from most email communications using the link included in the email itself; we may still send you transactional or administrative emails (like account or donation confirmations) even after you unsubscribe from promotional messages. For your own security, please avoid sending sensitive information to us by email. If you'd rather not use email — or you need to send us something sensitive, such as a document verifying your identity — write to us instead at Serve Source, 400 West Main St, Suite 3, Round Rock, TX 78641.

We'll acknowledge a privacy request within 10 days of receiving it, and give you a substantive response within 45 days. If a request turns out to be complicated and we need longer, we'll tell you so within those 45 days rather than leaving you wondering. In some cases, we may need to retain certain information (for example, to comply with the law or maintain accurate financial records), in which case it will be kept separately and not used for other purposes.

Organizations: a partner organization may request an export of its own disaster-response data on the Site at any time by contacting info@servesource.org — we're happy to provide it.

State privacy rights — offered voluntarily. Most U.S. state privacy laws, including the California Consumer Privacy Act and the Texas Data Privacy and Security Act, apply to businesses operating for profit and exempt 501(c)(3) nonprofits like Serve Source. So strictly speaking, they don't require us to do any of this. We're offering these rights anyway, to residents of every state, because we think you should have them regardless of how we happen to be incorporated: you may ask what personal information we hold about you, ask us to correct anything inaccurate, and ask us to delete it. As stated in Section 6, we do not sell personal information, and we do not share it for cross-context behavioral advertising. To exercise any of these rights, contact info@servesource.org.

Users outside the United States. Serve Source is based in the United States. Our team, our systems, and our data are here, and the information we collect is processed and stored here. By using the Site, you understand that your information is transferred to and processed in the U.S., which may not provide the same data-protection protections as the country you live in.

We do publish information about disasters and response efforts outside the United States. That coverage is written for people in the U.S. who want to pray for, give to, or serve in those responses — it isn't aimed at survivors abroad looking for local help, and it isn't an attempt to recruit users outside the U.S. We don't market the Site outside the United States, we don't offer it in other languages, and we don't track, profile, or target visitors based on being in another country. We're saying this plainly because it's an honest description of who the Site is built for.

If you're outside the U.S. and use the Site anyway — including if you're staff at an international partner organization — you're welcome here, and we will honor requests to access, correct, or delete your personal information exactly as we would for anyone else. Contact info@servesource.org. If the law where you live gives you additional rights, tell us what you're asking for and we'll do our best to accommodate it consistent with our practices and our obligations in the U.S.

12. How We Protect Your Information

We take reasonable technical and organizational measures to protect personal information from unauthorized access, disclosure, alteration, or destruction, including access controls limiting who on our team can view personal information and encryption in transit. No system is completely secure, and we can't guarantee absolute security of information transmitted to us.

If we discover a security breach that affects your personal information, we'll notify you — and any regulator we're required to notify — without unreasonable delay, and as applicable law requires. We'll tell you what happened, what information was involved, what we've done about it, and what we'd suggest you do.

13. Children's Privacy, and Age

Our services are not directed to children, and creating an account requires you to be at least 18. We do not knowingly collect personal information from anyone under 13. If we learn we've collected personal information from a child under 13 without appropriate consent, we will delete it. If you believe we have such information, contact us at info@servesource.org.

We don't ask your age, and we don't collect it. That's deliberate. Serve Source doesn't recruit, screen, place, train, or supervise volunteers — we point people toward opportunities, and the organization running an opportunity sets its own age requirements. Those requirements differ from one organization to the next, differ by the kind of work involved, and differ from state to state. If you're a young person who wants to serve, or a parent or youth leader bringing minors along, ask that organization directly what its minimum age, parental-consent, and supervision rules are before you go.

The parts of the Site that don't require an account — submitting a prayer, sending in a community report — can be used without telling us who you are, and we don't ask. If a parent or guardian registers a minor for an event, whatever they provide about that minor is handled under this Policy and shared with the organization hosting the event.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, we'll update the effective date at the top of this page. Your continued use of the Site after a change takes effect means you accept the revised Policy.

15. Contact Us

Questions about this Privacy Policy? Contact us at:

Serve Source 400 West Main St, Suite 3 Round Rock, TX 78641 info@servesource.org