We respect your privacy and are committed to protecting your personal information. This Privacy Policy outlines the types of personal information we receive and collect when you use [Your Website/App Name], as well as some of the steps we take to safeguard your information.
Your Privacy, Protected by Design
The Pappr API helps nonprofits process donations without ever storing raw personal data. We achieve this by using a tokenisation layer that replaces sensitive donor details with secure, pseudonymous tokens — ensuring privacy is preserved from the first transaction to the final report.
What We Collect (and Tokenise)
The Pappr API processes a small set of fields strictly necessary to generate and store a unique donor token:
name_first
(optional)email_address
(optional)Donation metadata (e.g.
amount_gross
,created_at
,donor_token
)
These are converted into secure tokens and saved in a protected Supabase database. We never store payment card details or unencrypted personal identifiers.
Data Security
We implement a variety of security measures to ensure the safety of your personal information when you enter, submit, or access your personal information. However, please note that no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
How We Use This Data
We only use the tokenised data to:
Log donation activity tied to a donor token
Provide nonprofits with donation analytics and insights
Route recurring payments via secure Payfast integrations
Support future enhancements like donor trend analysis or token-linked loyalty
Data is processed in a way that removes the need to identify users directly, protecting both nonprofit platforms and their donors
Sharing 3rd Party Tools
Pappr does not sell or share data with any third parties.
We use:
Supabase (secure backend and data storage)
Payfast (for processing actual payments; no card data is passed to Pappr)
Optional third-party tools (like EmailJS, Mailchimp, or Typeform) only if you choose to integrate them
In these cases, you control what is shared, and we provide the webhook endpoint to receive the results — not the original tools
Policy Updates
This privacy policy may evolve with the platform. We'll publish changes on pappr.org and notify active developers via email if significant updates affect how your data is processed.