Privacy Policy

This Privacy Policy explains what information we collect, how we use it, and the choices and rights you have — across both gracepoint-solutions.com and the GracePoint Platform.

Version: 1.0  ·  Effective Date: August 1, 2026  ·  Last Updated: August 1, 2026

1. Introduction

GracePoint Solutions, Inc. (“GracePoint,” “we,” “us,” or “our”) provides a charitable technology platform (the “Platform”) used by nonprofit, faith-based, humanitarian, and other charitable organizations to manage Gifts-in-Kind (“GIK”) inventory, coordinate distribution, engage donors, and — where those organizations choose to do so — accept charitable monetary donations.

This Privacy Policy explains what information we collect, how we use it, when we share it, how long we keep it, and the choices and rights you have. It applies to both of our sites and to everything you do on them:

  • Our public website at www.gracepoint-solutions.com — our marketing and informational pages, including contact and demo request forms;
  • The Platform at my.gracepoint-solutions.com — where our client organizations and their authorized users sign in and work;
  • The Donor Portal, accessed through the Platform by organizational donors of our clients;
  • Volunteer Scanning, made available to individuals who scan a QR code to help identify and place inventory in a warehouse or Point of Distribution — see Section 4A; and
  • Recipient Impact Submissions, made voluntarily by individuals who receive donated goods. If you scanned a QR code on a donated item, you are on the Platform at my.gracepoint-solutions.com — see Section 4.

The two sites do different things and collect different information. Our public website is informational; the Platform is where charitable operations actually happen, and it handles more — and more sensitive — information.

Different parts of this Policy apply to different people. Use the guide below to find the parts that apply to you.

Which Parts Apply to You

If you are… Start here
A visitor to our website — browsing, or submitting a contact or demo request §3.1, §9 (Cookies), §11 (Your Rights)
Someone who received donated items and scanned a QR code §4 (Recipient Impact Submissions) — please read this section
A volunteer who scanned a QR code to identify or place inventory §4A (Volunteer Scanning) — please read this section
A staff member, volunteer, or contractor at an organization that uses the Platform through a provisioned account §3.2, §5 (Network Features), §11 (Your Rights)
An organizational donor with a Donor Portal account §3.3, §11 (Your Rights)
An organization using Network features — the POD Marketplace or POD Circle §5 (Network Features and Peer Coordination)

If your information is on the Platform because of your relationship with one of our client organizations, that organization’s own privacy policy also applies to you, and you may wish to review it alongside this one.


2. An Important Point About Our Role

GracePoint provides technology. We are not a charity, a donor, a recipient, a warehouse operator, a carrier, a broker, a fundraiser, an appraiser, or a tax adviser, and we are not a party to transactions between the organizations and individuals who use the Platform.

For most of the information on our Platform, our client organizations decide what is collected and why — we process that information on their behalf and on their instructions. In privacy terms, our clients are generally the “controller” (or “business”) and GracePoint is generally the “processor” (or “service provider”).

There are limited exceptions where GracePoint acts on its own behalf — for example, when we manage account security and authentication, when we log Volunteer Scanning activity (see Section 4A), and when we retain Network records after a client organization leaves (see Section 8). We identify those exceptions in this Policy.

Other Privacy Policies That May Apply to You

Other privacy policies may apply to you alongside this one:

  • Our client organizations. If your information is on the Platform because you interact with one of our client organizations, that organization’s own privacy policy governs that organization’s own practices, and you may wish to review it.
  • Stripe. If you make a monetary donation to one of our client organizations, Stripe’s own privacy policy governs Stripe’s handling of payment information.

3. Information We Collect

3.1 Website Visitors

When you visit our website, we may collect:

  • Information you give us — such as your name, email address, organization, telephone number, and any message you submit through a contact, demo request, or support form. A telephone number is optional. If you give us one, we may use it to contact you about your inquiry and — with your permission for those specific channels — to send you marketing text messages or place marketing calls. See Section 6 (Marketing communications).
  • Information collected automatically — such as IP address, browser type, device type, pages viewed, referring page, and time spent. This is collected through cookies and similar technologies and through analytics tools. See Section 9 (Cookies and Analytics).

3.2 Authorized Users of Our Client Organizations

When a client organization gives someone access to the Platform through a provisioned account, we process that person’s:

  • Name (first and last), business email address, organization name, and role or permission designation;
  • Telephone number — optional, and only on the Enterprise Warehouse Platform. A telephone number is never required to create an account or to use the Platform. The POD Platform does not collect telephone numbers at all;
  • Login credentials and authentication data; and
  • Records of Platform activity necessary for security, support, and account administration.

We use this information to provide the Platform — including account access, authentication, password resets, two-factor authentication, support requests, and service communications such as planned-maintenance and system notifications.

This is different from Volunteer Scanning, described in Section 4A, which does not involve a provisioned account and collects a different, more limited set of information that varies by scanning location.

3.3 Donor Information

Our client organizations may submit information about their donors to the Platform, including donor names, contact information, and donation history, to support the organization’s own fundraising, receipting, and donor communications.

Donor Portal. Where a client organization creates a Donor Portal account for an organizational donor, we process the primary contact’s name, business email address, and organization name, together with that account’s authentication codes, session data, login history, and password credentials (if set), to operate and secure the account. We act on our own behalf for these account-security purposes. The GIK journey information, valuation references, and approved impact content displayed inside the Donor Portal are processed on our client’s behalf.

Donor Portal accounts are for corporate and organizational donors only.

Payments. If a client organization chooses to accept monetary donations, those donations are processed through the organization’s own Stripe Connected Account. GracePoint does not receive, hold, custody, pool, control, transfer, or disburse donated funds, and GracePoint does not collect or process payment card data. Stripe’s handling of payment information is governed by Stripe’s own terms and privacy policy.

3.4 Recipient Information

We do not collect names, email addresses, or telephone numbers from the people who receive donated goods. The Platform provides no field for entering them, and someone who scans a QR code on a donated item is never asked for them.

What we do process is records of distribution events and confirmations that items were received — submitted by, and processed on behalf of, the client organization. Personal information about a recipient could still end up in a free-text field that a client organization types into, and we address that in Section 3.5.

Recipient Impact Submissions are addressed separately in Section 4, because they involve information provided directly by recipients to GracePoint and are handled differently.

3.5 Information We Do Not Seek

We do not seek to collect special categories of sensitive personal information beyond what is described in this Policy, and our client organizations are responsible for not submitting such information to the Platform unless they have met all applicable legal requirements for doing so.

Information typed into free-text fields. Some parts of the Platform accept free-text — item descriptions, condition notes, and messages between organizations. A client organization could type personal information into one of these fields even though we do not ask for it and the field is not designed to hold it. We do not monitor or scan what organizations type. Client organizations are responsible for what they submit, and our Acceptable Use Policy prohibits putting recipient personal information into features not designed to receive it.


4. Recipient Impact Submissions — Please Read This Section

If you received donated items and scanned a QR code on those items, this section is about you. Scanning that QR code brings you to a page on my.gracepoint-solutions.com, which is GracePoint’s Platform.

4.1 It Is Voluntary

Sharing a story or photo is entirely optional. You may confirm the items you received and skip the story and photo. You may also skip the process altogether. Nothing you receive depends on whether you share anything.

4.2 What We Collect

If you choose to participate, we may collect:

  • Confirmation of the items you received;
  • A written story about how the donation helped you, if you choose to provide one; and
  • A photo, if you choose to provide one.

4.3 What We Do With It

  1. We apply privacy protection immediately — and we do not keep the original. When you submit a photo or story, our privacy-protection processing runs right away: it blurs identifiable faces and physical features in photographs and removes personally identifiable information from written stories. We do not store your original photo or your original written story. Only the privacy-protected version is kept.
  2. The organization that gave you the items reviews it. Only that organization decides whether your privacy-protected story is shared further. They may decline it.
  3. If approved, the donor may see it. The organizational donor who contributed your items may then see the privacy-protected version.

No one ever receives your original photo or story — not organizations, not donors, and not us.

To be precise about how this works: your original passes through our system only for the moment it takes to apply the privacy protection. It is not written to storage, and it does not persist afterward. What remains is the protected version.

4.4 A Statement About Our Privacy Technology

Our privacy-protection processing is designed to blur faces and remove personal details, and we use commercially reasonable efforts to do so. We cannot and do not guarantee that it identifies and removes every piece of identifying information in every case under all conditions. Please keep this in mind when deciding whether to share a story or photo, and consider whether your story includes details that could identify you even after personal details are removed.

Because we do not keep the original, this processing is applied once, at submission — the protected version is what exists going forward.

4.5 How Long We Keep It

Your original photo and story are not stored. Privacy protection is applied the moment you submit, and the original does not persist afterward — so there is no original for us to keep, share, or delete.

The privacy-protected version — with faces blurred and personal details removed — is retained indefinitely as part of the receiving organization’s impact records. If you want it removed, email support@gracepoint-solutions.com. We apply GDPR-standard deletion practices to every request. See Section 11.

4.6 Your Name

Your name and contact information are not shared with donors as part of this process.


4A. Volunteer Scanning — Please Read This Section

If you scanned a QR code to help identify or place donated inventory in a warehouse or Point of Distribution, this section is about you. Scanning that QR code brings you to a page on my.gracepoint-solutions.com, which is GracePoint’s Platform. This section is separate from Section 4 (Recipient Impact Submissions), which covers a different kind of QR code scan — by someone receiving aid, not by a volunteer helping to process it.

4A.1 What We Collect — This Depends on Where You Are Scanning

If you are scanning at a warehouse, we collect your first name, last name, and mobile telephone number. We also ask whether you are currently a student — answering that question is optional, and you may leave it blank and continue.

If you are scanning at a Point of Distribution, we collect only your name or email address — whichever you provide.

In both cases, we collect nothing else from you as a Volunteer — not your physical address, not your date of birth, and no government identification.

4A.2 What We Do With It

We use this information only to log your scanning activity for our own audit and recordkeeping purposes.

Where we collect your telephone number, we do not use it to contact you, and GracePoint does not send text messages to Volunteers. The organization you are volunteering with may contact you at that number.

We provide this information to the organization you are volunteering with. That organization receives your name and, where collected, your telephone number, together with your scanning activity, so it can track volunteer hours and contact you about serving again. What that organization does with it is governed by its own privacy practices, not by this Policy. We do not sell it, we do not share it for advertising, and we do not give it to anyone else other than the service providers that operate the Platform for us.

4A.3 Whose Terms Apply

Before you begin Volunteer Scanning, you are shown, and must agree to, the Volunteer Scanner Click-Through Agreement, which links to this Privacy Policy. That Agreement covers your access to the scanning function; this Policy covers what we do with the information described in Section 4A.1.

4A.4 The Organization You’re Volunteering With Manages Its Own Volunteer Program

We provide the scanning tool. The organization you’re volunteering with is responsible for its own volunteer recruitment, screening, training, supervision, and any age or safety requirements it applies — GracePoint does not monitor or supervise volunteers or volunteer activity, and has no capability to do so.

Age. We do not verify the age of any volunteer, and we have no way to do so. We do not ask for your date of birth and we do not restrict access to the scanning function based on age. The Volunteer Scanner Agreement asks you to confirm that you are at least eighteen, or that you have your parent’s or guardian’s permission. The organization you are volunteering with is responsible for its own age requirements and for obtaining any parental or guardian permission it requires.

4A.5 How Long We Keep It

The information described in Section 4A.1, and the associated scan log, are retained as part of our audit records. If you want it removed, email support@gracepoint-solutions.com. We apply GDPR-standard deletion practices to every request. See Section 11. Please note: removing it from our records does not remove the copy held by the organization you volunteered with. To have that copy removed, contact that organization directly.


5. Network Features and Peer Coordination

The Platform includes features that let client organizations coordinate directly with each other across the GracePoint Network. If your organization uses these features, this section explains what other participants can see.

5.1 POD Marketplace

The POD Marketplace lets participating organizations post requests for needed Gifts-in-Kind and post excess inventory they wish to share.

What other participants can see. When your organization posts a request or an inventory listing, the following is visible to other Network PODs: your organization’s identity, the content of your posting, and — if your organization has completed Stripe’s optional verification — a verification indicator. Participants who respond to your posting may coordinate with your organization through the Marketplace messaging tool (see Section 5.2) or through contact information you exchange with them.

An important visibility boundary. POD Marketplace postings are visible to other Network PODs only. They are not visible to the general public, and they are not visible to the Enterprise Warehouse customer that a posting organization is connected to.

What we don’t control. If participants exchange contact information and coordinate outside the Platform, GracePoint does not control what they do with the information they exchange. Each participant is responsible for its own handling of information it receives from another participant, and for its own due diligence before transacting. Coordination that happens inside the Marketplace messaging tool is described in Section 5.2.

5.2 Marketplace Messaging

The Marketplace includes a messaging tool that lets two organizations communicate to coordinate the delivery of posted goods. Unlike coordination that happens off the Platform, these messages are hosted and stored by GracePoint. This section explains exactly how we handle them.

What we collect. The text of your messages, the organizations and Authorized Users who sent and received them, and timestamps. Messaging is text-only — the tool does not support sending files or images. Conversations are one-to-one between two organizations.

How long we keep it. Messages are stored for ninety (90) days from when they are sent, after which they are automatically and permanently deleted.

Whether we read it. GracePoint does not monitor, scan, or proactively review messages. We do not review message content in the ordinary course. GracePoint personnel can access message content, and will do so only where necessary to: (a) investigate a report of abuse or misuse; (b) respond to a support request; (c) address a security incident; or (d) comply with a legal obligation.

Reporting abuse. If you receive a message that is abusive, harassing, fraudulent, or otherwise violates your agreement with us, report it to support@gracepoint-solutions.com. Because we do not monitor messages, reporting is how we learn about problems. We do not guarantee any particular investigation outcome or timeframe.

Please don’t put Recipient information in messages. Messages are intended for coordinating the delivery of posted goods. They are not an appropriate place for information about the individuals who receive aid. Your organization is responsible for what it sends.

About deleting messages. A message is a shared record of a conversation between two organizations, so neither organization can delete messages, and we cannot delete individual messages on request — deleting your side would destroy the other organization’s record of its own coordination. All messages are permanently deleted automatically ninety (90) days after they are sent. This is a narrow exception: it applies to messages only, and does not affect deletion of your other personal information. See Section 11.

Our role. We process message content on behalf of the participating organizations. We act on our own behalf with respect to storing and securing messages, responding to abuse reports, and meeting our legal obligations.

5.3 POD Circle

POD Circle lets an organization (“Circle Host”) create a private coordination circle with up to five other Network organizations (“Circle Members”).

What Circle Members can see. Circle Members can view the Circle Host’s Gifts-in-Kind inventory within the Platform and submit requests for those items. If your organization participates as a Circle Member in another organization’s Circle, that Circle Host can see your requests. Visibility is limited to the Circle — it is not public and is not shared with other Network participants outside the Circle.

When it ends. If a Circle is cancelled or terminated, Circle Members’ access to the Circle Host’s inventory visibility ends.

5.4 Verification Indicators

Where an organization has completed Stripe’s optional verification for accepting charitable monetary donations, we may display a “Verified for Stripe Donations” indicator next to that organization’s name. This indicator reflects status reported to us by Stripe — we do not independently verify it. It applies only to Stripe-processed monetary donations, not to Gifts-in-Kind, and it is not a GracePoint endorsement. Participation in Stripe verification is optional, so the absence of an indicator does not mean an organization is not legitimate.

5.5 What GracePoint Does Not Do

GracePoint does not vet, screen, certify, verify, or approve any organization on the Network, and we make no representation about any participant. We do not guarantee that any request will be fulfilled, that any listing is accurate, or that any coordination will succeed. Each participant is responsible for its own due diligence before transacting with any other participant.


6. How We Use Information

We use the information described above to:

  • Provide, operate, maintain, secure, and improve the Platform and our website;
  • Authenticate users and protect against fraud, abuse, and unauthorized access;
  • Generate item identification and valuation references, reports, exports, and summaries for our client organizations’ operational use;
  • Apply privacy-protection processing to Recipient Impact Submissions;
  • Log Volunteer Scanning activity for audit and recordkeeping purposes;
  • Respond to inquiries and provide customer and technical support;
  • Send administrative, security, and service-related communications;
  • Send marketing communications, as described below;
  • Generate anonymized and aggregated statistics that do not identify any individual; and
  • Comply with law and enforce our agreements.

Marketing communications

We separate two kinds of messages, and the difference matters because only one of them is optional.

Service communications keep the Platform working — planned-maintenance and outage notices, security and system notifications, support responses, authentication and password-reset messages, and billing and account notices. These are not marketing and you cannot opt out of them, because you cannot use the Platform without them.

Marketing communications are optional. They include newsletters, announcements about new or existing features, and educational content to help your organization get more out of the Platform. Every marketing message we send includes a way to unsubscribe, and we honor those requests promptly. Opting out of marketing does not stop your service communications.

Platform Users and Donor Portal Users may opt in to more. If you have an account on the Platform because your organization gave you one, or you are a Donor Portal user, you may separately choose — as an optional, standalone action, never a condition of using the Platform or Portal — to receive product updates, GracePoint news, marketing communications, and the text-message (SMS) version of urgent notices, by email, by text message, or both. This is different from, and does not replace, the Service Communications described above, which continue regardless. We do not enable text messages for anyone who has not affirmatively opted in through this specific opt-in, and a phone number you provide for your Platform or Portal account for other purposes is not, by itself, treated as consent.

We do not market to Volunteers or Recipients. GracePoint never uses the information described in Section 4A.1 to send marketing or any other communication. Where we collect a Volunteer’s mobile telephone number, we do not use it to contact the Volunteer and we do not send text messages to Volunteers. As described in Section 4A.2, the organization a Volunteer serves receives that information and may contact the Volunteer about future service; those are the organization’s own communications, not ours. We do not send marketing communications, SMS messages, or Platform-generated email of any kind to Recipients.

Text messages and phone calls — two separate programs. We operate two SMS programs, each with its own opt-in: (1) messages to people who contacted us through a form on our marketing website at www.gracepoint-solutions.com, after obtaining permission for that specific channel — that form presents two consent checkboxes, and one of them also covers marketing telephone calls, which may be automated, pre-recorded, or use an AI voice; and (2) messages to Platform users and Donor Portal users who separately opted in through their account preferences, as described above. We do not move a number between these programs, and we do not use a phone number collected through one program to text someone under the other.

When your organization leaves. If your organization stops being a GracePoint client, we stop sending marketing and optional communications to its users and remove them from our marketing lists. We keep only the minimal record needed to honor a past unsubscribe request.

This section covers both SMS programs described above: phone numbers collected through a form on our marketing website, and phone numbers Platform users and Donor Portal users provide when they separately opt in through account preferences. It does not apply to a phone number used only for account or security purposes, which we never use for marketing or any other optional communication absent a separate opt-in.

We text only people who opted in. We do not send marketing text messages to anyone who has not expressly agreed to receive them, and agreeing is never a condition of getting any product, service, or information from us.

We keep records of consent. When you opt in or opt out, we record the action and the time it happened. We keep these records to honor your choices and to document that consent was given.

Stopping messages. Reply STOP to any message and we will stop. You will get one confirmation message and nothing further unless you opt in again. Reply HELP for assistance, or email support@gracepoint-solutions.com. Message and data rates may apply — those are set by your carrier, not by us.

Your mobile information is not shared for marketing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We share it with service providers that help us operate — for example, our customer relationship management system and the service that delivers the messages — and only so they can perform that work for us. All other categories of use exclude text messaging opt-in data and consent records, and that information is not shared with any third party.

Phone calls. If you agreed to receive marketing calls — which may be automated, pre-recorded, or use an AI voice, and which are consented to together with marketing text messages in one of our marketing-website consent checkboxes — you can withdraw that agreement at any time by emailing support@gracepoint-solutions.com or telling the caller. We maintain an internal do-not-call list and honor withdrawal requests promptly.

Full terms for our marketing-website SMS program are in our Website Terms of Use at https://gracepoint-solutions.com/terms-of-use. Full terms for the Platform and Donor Portal opt-in are in the POD Agreement, the Enterprise Warehouse agreement, and the Donor Portal Terms of Use, as applicable.

We send text messages only to people who ask for them. On our marketing website, you can opt in by checking the text-message box on our contact form. As a Platform user or Donor Portal user, you can opt in through your account preferences. In every case, the box is never checked for you, and agreeing is never a condition of getting any product, service, or information from us. We do not send text messages to phone numbers obtained from any other source. The marketing-website program sends up to 4 messages per month; the Platform/Donor Portal program’s frequency depends on the notices and updates that occur. Reply STOP at any time to stop, or HELP for help. Message and data rates may apply.

About our technology. Some Platform features generate outputs automatically — for example, item identification and valuation references. These outputs are tools only. They are estimates and references, they are not guaranteed to be accurate or complete, they do not constitute an appraisal or tax, legal, or accounting advice, and the client organization remains responsible for reviewing them and making all final determinations. We do not disclose the particular methods underlying these features.

We do not use individually identifiable information from our client organizations to train our models or tools without that organization’s consent.


7. When We Share Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

We share information only as follows:

With our client organizations. Information we process on a client’s behalf is available to that client — subject to the Recipient Impact Submission protections described in Section 4. Volunteer information described in Section 4A is provided to the organization at whose location you scanned, for volunteer-hour tracking and volunteer communication.

With third-party service providers. We use third-party providers to operate and support the Platform, in functional categories including cloud hosting and infrastructure, analytics, customer relationship management, payment processing, and automated processing tools. These providers process information only as necessary to provide their services to us and are bound by appropriate obligations. Stripe, Inc. is identified specifically because our client organizations contract with Stripe directly for payment processing. We do not otherwise publish the identity of specific providers; client organizations may request a current list of the providers that process personal data on their behalf under their Data Processing Addendum.

For legal reasons. We may disclose information if required by law, subpoena, court order, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, protect safety, investigate fraud, or respond to a government request.

In a business transaction. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.


8. How Long We Keep Information

Category Retention
Original Recipient photos and stories Not stored — processed momentarily to apply privacy protection; does not persist afterward
Privacy-protected (redacted) Recipient content Retained indefinitely; deleted on valid request
Volunteer name, telephone number where collected, and scan log Retained as part of our audit records and provided to the organization at whose location the scan occurred; deleted from our records on valid request
Authorized User accounts, after a client organization leaves Deleted after the 30-day export window
Transaction, GIK, Donor, and Recipient records Retained — see “About records that involve more than one organization” below. Deleted on valid request.
Encrypted backup copies Up to 7 days — normal backup rotation, after which they are overwritten
Marketplace messages Ninety (90) days from sending, then automatically and permanently deleted
Public website analytics (www.gracepoint-solutions.com) Up to 2 months (event data) and up to 14 months (user-identifier data)
Platform usage information (my.gracepoint-solutions.com) As long as reasonably necessary to operate, secure, and improve the Platform

We retain information only as long as reasonably necessary and proportionate for the purposes described in this Policy, subject to any legal obligation to retain it.

About records that involve more than one organization

Some records on the Platform don’t belong to only one organization. A record of donated goods moving from a warehouse to a POD is simultaneously that POD’s record of its own operations — and that POD may still be a GracePoint customer.

So when a client organization leaves GracePoint:

  • We delete their user accounts — the names, emails, and login information of their staff.
  • We keep the transaction, inventory, Donor, and Recipient records submitted through their account, because deleting them would destroy other organizations’ records of their own work, and would break the history of the Network those organizations still rely on.

When we keep those records, we become responsible for them. The organization that left is no longer directing what happens to that data — we are. That means we are the “controller” of it, we rely on our legitimate interest in keeping Network records accurate and intact for the organizations still using them, and your privacy rights run directly against us. We don’t use retained records to market to you, solicit you, or build profiles.

You can still ask us to delete it. We apply GDPR-standard deletion practices to every request, regardless of where you live, because that standard is generally at least as protective as California’s and other state laws. Email support@gracepoint-solutions.com. See Section 11.

About backups. When we delete something, we remove it from our live systems right away. A copy may remain in our encrypted backups for up to 7 days, until the normal backup cycle overwrites it. During that window we don’t access or restore it, and if a backup ever is restored, we re-apply the deletion. After 7 days it’s gone.

Recipient stories and photos. We never store the original — only the privacy-protected version. That does not change when an organization leaves, and you can request deletion of the protected version at any time.


9. Cookies and Analytics

The two sites are treated differently. Our public marketing website and the Platform serve different purposes and are subject to different cookie and analytics treatment.

Public marketing website — www.gracepoint-solutions.com

The marketing site uses cookies and similar technologies to operate the site, remember preferences, and understand how the site is used. We use a third-party analytics provider to collect information such as pages viewed, time on page, and referring source. We use this information to understand how visitors find and use the site, to improve it, and to identify and follow up on inquiries from organizations interested in our services.

These analytics cookies are not necessary to operate the site. Where required by applicable law, we obtain your consent before setting them, and you may decline without losing access to the site.

Public website analytics event data is retained for up to 2 months, and user-identifier data for up to 14 months, after which it is automatically deleted.

The Platform — my.gracepoint-solutions.com

The Platform uses cookies and similar technologies that are necessary to operate the service — for example, to keep you signed in, maintain your session, and protect against unauthorized access. Because these are required for the Platform to function, they cannot be disabled while using it.

We do not track page visits or browsing behavior on the Platform. The Platform does not use analytics cookies, and no third-party analytics provider operates on it.

We maintain audit logs. The Platform creates and retains standard audit records — for example, sign-in events, Volunteer Scanning activity, and records of actions taken on data — which we use to operate and secure the service, to investigate suspected misuse, and to support our customers’ own recordkeeping. Audit records themselves are not used for advertising and are not sold or shared. Aggregated statistics derived from Platform activity are used for GracePoint’s own marketing and advertising as described below, but the underlying audit records and individual-level or organization-level usage data are not.

We use aggregate Platform statistics in our marketing and advertising. We compile anonymized, aggregated statistics about overall Platform activity across our full Network of Warehouse and POD clients — for example, total Gifts-in-Kind donations processed, total item valuations generated, total funds raised, and total people served — and may use these statistics in our marketing and advertising, including on our website, in email communications, and in printed materials. These statistics are aggregated across the Network and do not identify or attribute figures to any individual organization, Warehouse, POD, donor, or recipient. We do not publish a list of our clients, or attribute any statistic to a specific client, without that client’s express written permission.

Platform information stays with us. We do not make Platform usage or activity information available to any third-party analytics provider or other third party for any purpose. The Platform is not a public website: it is available only to organizations that have entered into an agreement with us and to the users those organizations authorize, and to Volunteers who access the scanning function via QR code.

Your choices

You can control cookies through your browser settings. Blocking some cookies may affect how the marketing site works; cookies necessary to operate the Platform cannot be disabled while using it.

We do not use cookies to sell personal information or for cross-context behavioral advertising.


10. Security

We implement and maintain commercially reasonable technical and organizational measures designed to protect information against unauthorized access, use, disclosure, alteration, and destruction, consistent with the sensitivity of the information involved. All data we store is encrypted at rest and in transit and is subject to restricted access.

No system is perfectly secure. We cannot guarantee absolute security, and we do not claim to. If you believe your account or information has been compromised, contact us immediately at support@gracepoint-solutions.com.

We do not hold a security certification. We do not claim SOC 2, ISO 27001, HIPAA, or any other security certification, accreditation, or third-party attestation. If that changes, we will update this policy.


11. Your Privacy Rights

The rights available to you depend on where you live and on whether GracePoint or one of our client organizations controls your information.

If your information is on the Platform because of your relationship with one of our client organizations, that organization generally controls it. Please direct your request to that organization. If you send your request to us instead, we will forward it to the appropriate organization or assist them in responding, as our agreement with them requires.

If GracePoint controls your information — for example, website inquiries, Donor Portal account security data, Volunteer name or email address collected for scanning-activity logs, or privacy-protected Recipient Impact Submission content we retain — you may exercise your rights with us directly.

11.1 California (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and share, and to access it;
  • Delete personal information we collected from you, subject to exceptions — see the narrow Marketplace messages exception below;
  • Correct inaccurate personal information;
  • Opt out of sale or sharing for cross-context behavioral advertising — we do not sell or share personal information for these purposes;
  • Limit the use and disclosure of sensitive personal information;
  • Non-discrimination — we will not discriminate against you for exercising your rights; and
  • Portability — receive your information in a portable format where applicable.

One narrow exception — Marketplace messages. We can honor deletion requests for personal information generally. Marketplace messages are the exception. A message is a shared record of a conversation between two organizations, and deleting one organization’s messages would also destroy the other organization’s record of its own coordination. For that reason, neither organization can delete messages, and we are not able to delete individual messages on request.

All messages are automatically and permanently deleted ninety (90) days after they are sent, so the information does not persist. We state this plainly rather than imply a capability we do not have. This exception applies only to Marketplace messages — it does not affect your deletion rights as to any other personal information, and it does not affect your other rights (access, correction, portability, or opt-out) as to messages.

Privacy-protected Recipient content. We apply privacy protection to Recipient photos and written stories at submission and do not retain the original, as described in Section 4. We do not claim that privacy-protected content is anonymized or de-identified under any legal standard. Where privacy-protected content remains capable of being associated with you, we treat it as personal information and honor your rights as to it.

We do not use Recipient content to infer characteristics about you. We do not use it for profiling, for advertising, or for any purpose other than those described in Section 4, and we do not sell or share it.

Volunteer information. We honor access, correction, and deletion requests for the information we hold from you as a Volunteer, and for the associated scan log, in the same manner as described in this Section. This reaches our records only — see Section 4A.5 regarding the copy held by the organization you volunteered with.

11.2 Virginia, Colorado, Connecticut, and Texas

If you are a resident of Virginia, Colorado, Connecticut, or Texas, you have rights that may include:

  • Access — confirm whether we process your personal data and access it;
  • Correction — correct inaccuracies;
  • Deletion — delete personal data you provided or that we obtained, subject to the narrow Marketplace messages exception described above;
  • Portability — obtain a copy in a portable format;
  • Opt out of targeted advertising, sale of personal data, and certain profiling — we do not engage in these activities; and
  • Appeal — appeal a denial of your request. If we deny your appeal, you may contact your state Attorney General.

Colorado, Connecticut, and Virginia require consent before processing sensitive data. Texas requires notice and an opportunity to opt out.

11.3 Other Jurisdictions

If you are located outside the United States, additional rights may apply to you. Contact us and we will respond consistent with applicable law.

Our services are directed to organizations located in the United States. We do not offer the Platform to individuals in the European Economic Area or the United Kingdom, and we do not intend to process their personal information.

11.4 How to Exercise Your Rights

Email support@gracepoint-solutions.com or write to us at the address in Section 16. We will verify your identity before responding, and we will respond within the time required by applicable law. An authorized agent may submit a request on your behalf with proof of authorization.


12. Security Incidents

If we experience a security incident that compromises your personal information in a way that requires notice under applicable law, we will notify you as required by that law.

If your information is on the Platform through your relationship with one of our client organizations, we will notify that organization, which is responsible for determining whether and how to notify you, consistent with our agreement with them.

Where GracePoint controls your information directly — for example, website inquiries, Donor Portal account security data, or your name or email address as a Volunteer — we will notify you directly using the contact information we have on file.


13. Children’s Privacy

The Platform and our website are not directed to children, and we do not knowingly collect personal information from children.

If you believe a child has provided us personal information, contact us at support@gracepoint-solutions.com and we will take appropriate steps.


14. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last Updated” date above. If we make material changes, we will provide additional notice as required by applicable law. Your continued use of our website or the Platform after an update means you accept the revised Policy.


15. Accessibility

GracePoint Solutions, Inc. is committed to making our website usable by the widest possible audience, including people with disabilities. We are working to ensure our website conforms to the Web Content Accessibility Guidelines (WCAG) 2.1, Level AA, to the extent reasonably practicable.

If you encounter any part of our website that is difficult to access or use, please contact us at support@gracepoint-solutions.com, including the page and the issue you experienced, and we will work to address it.

This statement does not constitute a warranty or guarantee of accessibility and does not create any legal right or remedy.


16. Contact Us

GracePoint Solutions, Inc. P.O. Box 8 Pleasanton, CA 94566 Email: support@gracepoint-solutions.com

For privacy questions, requests, or concerns, email us at the address above.