Privacy notice
Last updated: 19 August 2026.
Raise: A Celebration of Giving uses this service to administer chapter money, reimburse expenses, maintain its accounting records, prevent duplicate or unauthorised payments, and meet its charity governance duties. Questions or data-rights requests can be sent to treasurer@joinraise.org.
Information we use
We may use your name, email address, chapter, payment-request details, payee and bank details, uploaded receipts, training completion, Google sign-in identity, approval history and related audit records. Do not upload special-category information or unrelated personal information; redact it first where possible.
Why and on what basis
We use the information only to process and evidence legitimate Raise expenses and financial decisions. Depending on the record, this is necessary to perform the reimbursement arrangement, comply with accounting and charity-law obligations, and pursue Raise's legitimate interests in sound financial administration, fraud prevention and continuity. We do not use receipt data for advertising or model training by Raise.
Processors and storage
The service is hosted on Railway. Receipt images or PDFs are sent to OpenAI to extract merchant, date, amount, currency and short visible evidence. OpenAI's output cannot approve a payment: deterministic checks and an authorised Raise officer make the decision. Google provides sign-in; Resend processes transactional email over HTTPS. Complete backups are encrypted before being written to separate Railway Object Storage; the recovery key is kept outside Railway.
Retention and access
National access is limited to allowlisted Treasury staff. Chapter members use their own Google identity and see only their chapter and their own private payment profile; legacy bearer submission links are read-only. Accounting records, including receipts and approval evidence, are normally retained for six years after the end of the relevant financial year. Complete bank details are encrypted, revealed only through an audited recent-authentication action, and purged 90 days after access ends or a request completes unless an open request or legal hold requires them. Failed training attempts and operational logs are reviewed and removed when no longer needed.
Your rights
You may ask for access, correction, restriction, objection or deletion where the law permits. Some financial records cannot be deleted while Raise must retain them. You may also complain to the UK Information Commissioner's Office.