Privacy Policy
This document contains the privacy practices for the Wishbone.org web site and Wishbone.org’s other web sites (collectively, the "Sites"). These Sites are owned and operated by or on behalf of Wishbone.org ("Wishbone"). We at Wishbone take your privacy seriously. The purpose of this Privacy Policy is to inform you about the information that is collected about you on the Sites, how Wishbone may use and disclose the information that is collected, how information can be corrected or changed, and your obligations regarding information about others you may encounter in using the Sites. Please note that this Privacy Policy only governs information gathered from you online through these Sites.
1. How Does Wishbone Collect Information?
Our web server automatically recognizes and collects the domain name and IP address of visitors to our Sites. In addition, we collect information volunteered by the visitor to participate in activities on the Sites, such as making a donation, responding to surveys, registering to create an account, requesting email newsletters and/or contacting us through one or more of our contact email addresses. Wishbone also collects personal information when you create an account. When you create an account we ask for information such as your name, email address, postal address, and phone number. If a visitor has enabled cookies in their browser, we also will send a cookie file that will only store a unique, random session ID that is maintained throughout the session to track the pages visited, allowing us to provide visitors to our Sites with certain conveniences, such as delivering unique content. We also use cookies to track the path of users through our Sites, and to keep track of where they came from (for example, if they arrive via a search engine). We also collect aggregate tracking information derived mainly from tallying page views throughout our Sites.
2. How Does Wishbone Protect Information?
Wishbone exerts reasonable efforts to protect personal information received from users of our Sites from unauthorized use or disclosure. We do not allow unauthorized access via the Internet to the portion of our server that contains personally identifiable user information. All credit card information provided as requested on the Sites for donations is encrypted using the SSL.
Wishbone utilizes Stripe (www.stripe.com), a state-of-the-art online credit card processor to process credit card donations on Wishbone.org. Wishbone does not store credit card information for any donor. Specifically:
PCI
Our credit card processor has been audited by a PCI-certified auditor, and is certified to PCI Service Provider Level 1. This is the most stringent level of certification available
SSL and HSTS
Our credit card processor mandates HTTPS for all services, including our public website. They regularly audit the details of their implementation: the certificates they serve, the certificate authorities they use, and the ciphers they support. They use HSTS to ensure browsers interact only over HTTPS.
Encryption
All card numbers are encrypted on disk with AES-256. Decryption keys are stored on separate machines. None of our processor's internal servers and daemons are able to obtain plaintext card numbers; instead, they can just request that cards be sent to a service provider on a static whitelist. Infrastructure for storing, decrypting, and transmitting card numbers runs in a separate datacenter, and doesn't share any credentials with Stripe's primary services (API, website, etc.).
3. How Does Wishbone Use Information?
3.1 General
Wishbone uses information for the following general purposes: to evaluate proposals to fund students’ scholarships, provide information regarding approved proposals to the Sites' visitors and potential donors, to customize the content and/or layout of the Sites for each individual user, to improve the content of our Sites, our services or programs, and to contact you.
3.2 Contacting You
By creating an account on a Site, you agree to receive emails based on transactional activity, which may include confirmation emails, receipts, acknowledgment messages, or updates on students you've funded. You can unsubscribe from Email Updates and News at any time by contacting Wishbone or logging into your Site account and adjusting your "Email Preferences" settings or by using the link found on the email message to unsubscribe.
Email addresses provided by users of the Sites will only be used to send email from or related to Wishbone and its programs. Wishbone strictly enforces email privacy, and email addresses are not sold, leased or bartered to or with any third parties.
Postal addresses collected online may be used for various mailings from Wishbone and its affiliates. Postal addresses are not sold, leased or bartered to or with any third parties.
3.3 Donations, Registries and Other Services
By voluntarily providing us with your name, credit card information, email address, postal address, telephone number, billing address, and any other personally identifiable information, you consent to our use of such information for the purpose(s) for which it was collected, such as processing your donations and/or for providing any other service or product you request.
3.4 Aggregate Data
Wishbone may collect information about the use of the Sites, such as the types of services used and how many users we receive daily. This information is collected in aggregate form, without identifying any user individually. Wishbone may use this aggregate, nonidentifying statistical data for statistical analysis, marketing or similar promotional purposes. This may include disclosure of this information to a third party market analysis firm.
4. How Does Wishbone Disclose Information?
We do not sell, trade, or rent your personal information to others without your consent. We disclose your personal information only to process your credit card donations, or in the following circumstances:
4.1 Governmental Order
Wishbone may provide your personal information if necessary, in Wishbone's good faith judgment, to comply with laws or regulations of a governmental or regulatory body or in response to a valid subpoena, warrant or order or to protect the rights of Wishbone or others.
4.2 Business Transition
If Wishbone goes through a business transition, such as a merger, we reserve the right to transfer your personal information, which will likely be among the assets transferred.
4.3 Contractors and Other Third Party Service Providers
Wishbone may employ contractors or other third parties. These contractors or other third parties may have access to your personal information if necessary to perform services for us; however, they may only use such personal information for the purpose of performing that function and may not use it for any other purpose.
4.4 Donation
When a visitor to a Site makes a donation, the person’s name, location, and photo may, by choice, be displayed to various users of the Sites; however, no other personal information about the named person will be disclosed on the Sites. By choosing to provide your name, location, and/ or photo, you have provided and granted Wishbone the right to publicly disclose such information.
4.5 Matching Contributions
We may disclose your contact information (name, postal address, email address and telephone number) and donation information (donation amount and supported program scholarships) to your employer if you have notified us that your employer will match your donation for the purposes of enabling your employer to make a matching donation. Wishbone is not responsible for the privacy practices of your employer. For more information regarding the handling of your information by your employer, please refer to your employer's privacy policies.
4.6 Third Party Websites
Wishbone is not responsible for the contents, services or the privacy polices or practices of websites to which we may provide hyperlinks from these Sites, or of the websites of its affiliates, program partners, school partners, organization partners, sponsors or corporate partners. The program providers listed on our database are separate entities and their presence on the Sites does not indicate that Wishbone is responsible for their practices of websites.
5. Teacher Advocates and Participating Schools
5.1 General Rule
In the ordinary course, Wishbone discloses a teacher’s title, name, school name and city, teacher’s recommendation comments, student’s name, and student’s program scholarship information.
5.2 Verification of Affiliation
The name and postal address of teacher advocates and schools who have indicated an affiliation with a teacher organization may be provided to teachers who have indicated the same affiliation so as to enable authentication of a teacher's affiliation.
5.3 Teacher Recommendations for Student Wishes
Wishbone may provide visitors to the Sites and potential donors with information regarding the teacher’s submitted recommendation for his or her student’s proposed scholarship. For fulfillment purposes, we may provide the teacher’s title, name, recommendation, school name and address, and selected enrollment information to the program partner, selected by students. Wishbone is not responsible for the privacy practices of these organizations or companies. For more information regarding the handling of your information by these organizations or companies, please refer to the privacy policies of these organizations or companies.
5.4 School Officials and Teacher Colleagues
Wishbone may provide information about a teacher (including but not restricted to name, school, school’s postal address, and student’s proposal information), to principals, teacher colleagues at the same school, superintendents, or other employees of local, state, or federal school systems.
5.5 Donors
Wishbone may provide donors and Site visitors with information about a teacher advocate and school, namely the teacher's title, name, school name, school city and proposals submitted by relevant students.
6. Students and Parents
A Note to Parents
Use of the Sites by children (defined as persons under the age of 18) is permitted under the User Agreement with parental consent and supervision.
Wishbone has no plan to disclose personally identifiable data of any child provided to Wishbone through use of the Sites. All participating students have provided Wishbone with an official parental consent form agreeing to participate as a user. Wishbone’s policy is that Donors do not interact with students directly.
The following additional terms apply to those who sign up to be Wishbone students, as permitted by parental consent.
6.1 General Rule
In the ordinary course, Wishbone discloses a student’s name, school name and city, filmed video or photograph, program selection information and students’ updates compiled for funded scholarships, including provided photos. Recipients of such information include donors, school officials, teacher colleagues, Site visitors, third party contractors, and other teachers.
6.2 Verification of Affiliation
The contact information (name, postal address, email address and telephone number) of students who have indicated an affiliation with an organization (e.g., Achievement First, Uncommon Schools, KIPP, Young Women’s Leadership Network, College Track, College Bound Initiative) may be shared with the associated organization for purposes of verification that the student belongs to the organization. However, our agreements with the affiliated organizations only permit them to use such personal information for the purpose of performing that function and prohibit them from using it for any other purpose.
6.3 Student Wishes
Wishbone will provide visitors to the Sites and potential donors with information regarding student scholarships available for funding. For fulfillment purposes, we will provide the student’s name, address and selected enrollment information to program partners, selected by students. Wishbone is not responsible for the privacy practices of these organizations or companies. For more information regarding the handling of your information by these organizations or companies, please refer to the privacy policies of these organizations or companies.
6.4 School Officials and Teacher Colleagues
Wishbone may provide information about a participating student or teacher advocate (including but not limited to name, postal address, and student’s wish information and wish updates), to principals, teacher colleagues at the student’s school, superintendents, or other employees of local, state, or federal school systems.
6.5 Donors
Wishbone may provide donors and Site visitors with information about a student, namely the student’s name, video or photograph, scholarship proposal and scholarship updates submitted by him/her. Wishbone’s policy is that Donors do not contact a student directly and are not given students’ contact information.
7. Your Personal Information
If you wish for us to delete your personal information please submit a request in writing to:
Wishbone.org
Attn: Financial Operations
41 Grant Avenue, Suite 200, San Francisco, CA 94108
Or via email at: [email protected]
The request should include your name, address and telephone number. Upon receipt of your request, we will use reasonable efforts to delete your information from our files.
8. Contact Wishbone.org
If you have any questions about our Privacy Policy or practices, you may contact us at [email protected] or at:
Wishbone.org
Attn: Financial Operations
41 Grant Avenue, Suite 200, San Francisco, CA 94108
We are always happy to hear your questions or comments.
9. Changes to this Privacy Policy
This Privacy Policy may be changed or updated by us from time to time by posting such changes on the Sites. When we post changes to this Privacy Policy, we will revise the "last updated" date at the bottom of this Privacy Policy. We encourage you to periodically review this Privacy Policy to be informed of how Wishbone is protecting your information.
This Privacy Policy was last updated on 10/12/13