Mission Delafé · Legal
Privacy Policy
Effective July 30, 2026
This policy explains how Mission Delafé collects, uses, discloses, retains, and protects personal information across our websites, ministry activities, fundraising services, and internal Delafé CRM application.
Mission Delafé, Inc. (“Mission Delafé,” “we,” “us,” or “our”) is a nonprofit ministry that shares testimonies of Jesus and supports the relationships, communications, fundraising, and operations that make that mission possible. This Privacy Policy applies to:
missiondelafe.organd other websites or forms that link to this policy;- our fundraising, newsletter, volunteer, event, testimony, and contact activities;
- Delafé CRM, our restricted internal relationship-stewardship application; and
- beta distribution of Delafé CRM through Apple TestFlight.
This policy does not replace a privacy notice presented by a third-party service when you interact directly with that service.
Information we collect
Information you provide
Depending on how you interact with Mission Delafé, you may provide:
- your name, email address, telephone number, mailing address, organization, and communication preferences;
- messages, questions, volunteer or event information, testimony submissions, ministry interests, and other information you choose to share;
- newsletter subscription information;
- donation information, such as the amount and date of a gift, campaign, recurring-gift status, donation status, payment-method category, public or anonymous display preference, and related transaction information; and
- requests concerning access to, correction of, deletion of, or restriction of your personal information.
Donations are processed through Givebutter and its payment providers. Mission Delafé does not receive or store your complete payment-card number in Delafé CRM.
Information in Delafé CRM
Delafé CRM is available only to authorized Mission Delafé personnel. It may contain:
- supporter and relationship records received from Givebutter or entered by authorized personnel;
- donation, recurring-plan, campaign, engagement, and communication history;
- staff-created notes, tasks, relationship fields, journeys, email drafts, templates, reports, and audit records;
- Microsoft Entra account information for authorized users, including name, work email address, account identifier, and assigned application role; and
- limited application and update information, including a randomly generated installation identifier, application version and build, operating-system version, device architecture, update preferences and status, failure category, and check-in time.
Delafé CRM does not request a device’s contacts, precise location, health data, or complete payment-card information.
AI-assisted features
When an authorized user deliberately uses an AI-assisted drafting, reporting, or analysis feature, Mission Delafé may process the user’s instruction, draft, or conversation through OpenAI’s API. The application is designed to minimize this information before transmission:
- known names and contact details are removed or replaced where the feature permits;
- common email addresses, telephone numbers, street addresses, and government identifiers are redacted;
- donor analysis uses bounded, categorical facts and aggregates rather than contact details or free-form ministry-interest text; and
-
requests use
store: false, and API inputs and outputs are not used by OpenAI to train its models by default.
Automated redaction cannot guarantee that every identifying or sensitive detail will be removed from arbitrary prose. Authorized users are instructed not to include unnecessary personal information. AI output is advisory: a person must review donor-facing communications, suggested actions, and relationship decisions. AI does not independently send communications, change donor records, merge identities, or make decisions that produce legal or similarly significant effects.
Website, embedded-service, and device information
Our websites and service providers may automatically receive limited technical information, such as IP address, browser and device type, operating system, referring page, pages or links used, and approximate location inferred from an IP address. Webflow hosts our main website, and Microsoft Azure hosts this privacy page and related application services. Embedded Givebutter and beehiiv features may use cookies or similar technologies when you donate or subscribe.
Apple automatically collects certain TestFlight beta information and shares some of it with Mission Delafé, including invitation status, name and email address for email invitations, app and build version, device model, operating system, sessions, crashes, and crash logs. If you submit TestFlight feedback, Apple may also share your comments, screenshots, and related technical information. Mission Delafé uses this TestFlight information only to improve the application and related products and does not disclose it to another third party except as Apple permits.
How we use information
We use personal information to:
- respond to questions, messages, applications, and testimony submissions;
- process and acknowledge donations and maintain accurate fundraising records;
- provide requested newsletters and ministry communications;
- understand and steward Mission Delafé’s relationships with supporters, volunteers, partners, and other contacts;
- plan campaigns, tasks, events, journeys, and follow-up;
- authenticate authorized users and enforce role-based access;
- provide, secure, audit, troubleshoot, and improve our websites and internal applications;
- provide human-reviewed drafts, summaries, reports, and recommendations;
- prevent fraud, abuse, unauthorized access, and other security incidents;
- maintain tax, accounting, legal, and organizational records; and
- comply with applicable law and protect our rights and the rights of others.
Information that may reveal religious beliefs, ministry interests, testimony content, health circumstances, or other sensitive experiences is used only for the purpose for which it was provided and for closely related ministry, relationship, safety, or legal needs. Mission Delafé does not sell personal information or donor data, and we do not use Delafé CRM information for targeted advertising.
How we disclose information
We disclose personal information only as reasonably necessary for the purposes described above:
- Webflow hosts our main website and may process website and form information.
- Givebutter and its payment providers process donations and provide fundraising records to Mission Delafé.
- beehiiv processes newsletter subscriptions and email-delivery activity.
- Microsoft provides Entra authentication, Azure website and application hosting, storage, databases, operational monitoring, and authorized organizational email services.
- OpenAI processes minimized content when an authorized user invokes an enabled AI-assisted feature.
- Apple distributes beta versions through TestFlight and processes beta installation, usage, crash, and feedback information.
- Professional advisers and public authorities may receive information when reasonably necessary to comply with law, respond to lawful process, investigate security or fraud, protect safety, or establish or defend legal rights.
- A successor organization may receive relevant information as part of a merger, reorganization, or transfer of Mission Delafé’s operations, subject to appropriate safeguards and notice where required.
These providers process information under their own agreements and privacy terms. We require service providers handling information on our behalf to protect it consistently with their responsibilities and applicable law.
Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including ministry stewardship, donor history, security, dispute resolution, tax and accounting obligations, legal requirements, and the exercise or defense of legal rights. Different records therefore have different retention periods.
Specific Delafé CRM controls include:
- When live Givebutter ingestion is enabled, raw provider payload content is scheduled for deletion after 30 days. Raw webhook bodies are scheduled for lifecycle deletion after 30 days and may remain recoverable to a limited group of privileged operators for an additional 14-day disaster-recovery period.
- The current frozen pilot database used for product evaluation does not retain raw Givebutter provider bodies. It contains the accepted relationship and donation records needed to display the pilot.
- When application-owned AI conversation persistence is enabled, protected message text is limited to the most recent 20 messages in a conversation and is scheduled for deletion after 30 days. Limited conversation metadata may remain for ownership, security, and audit purposes.
- Operational cloud logs are generally retained for 30 days. Security, access, audit, tax, accounting, and donor-history records may be retained longer where their purpose or applicable law requires it.
- Apple states that it generally retains TestFlight feedback for one year and may retain crash and usage information until related bugs are resolved.
Deletion from an active system does not always remove information immediately from restricted backups or disaster-recovery copies. Such copies are isolated from normal use and expire according to their recovery schedules. We may also retain information that is necessary to complete a transaction, comply with law, preserve an individual’s opt-out or restriction, prevent fraud, or establish or defend legal claims.
Your choices and privacy requests
You may:
- unsubscribe from newsletters by using the link in the message;
- ask us to stop optional communications;
- request access to, correction of, deletion of, or restriction of personal information associated with you; and
- ask questions about how your information is used or disclosed.
Send a request to info@missiondelafe.org with the subject Privacy Request. You may also write to the postal address below. To protect personal information, we may need to verify your identity and authority before fulfilling a request. We may coordinate a request with Givebutter or another service that is authoritative for the relevant record. We may deny or limit a request where permitted or required by law, and we will explain the applicable reason.
Depending on where you live and whether a privacy law applies to the relevant processing, you may have additional rights. Maryland residents may have rights under the Maryland Online Data Privacy Act when that law applies, including rights to confirm processing, access, correct, delete, obtain a portable copy, and opt out of certain sale, targeted-advertising, or profiling activities. Mission Delafé does not sell personal information or use personal information for targeted advertising.
If you disagree with our response, email info@missiondelafe.org with the subject Privacy Appeal and explain the decision you want reconsidered. Maryland residents may also contact the Maryland Office of the Attorney General.
Children’s privacy
Our website and Delafé CRM are not directed to children under 13, and we do not knowingly collect personal information online from children under 13 without appropriate authorization. If you believe a child under 13 has provided personal information to us, contact us so we can review and, where appropriate, delete it.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include authenticated and role-limited access, encryption in transit, managed cloud identities, restricted secret storage, audit records, data minimization, and review gates for sensitive operations. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Authorized Delafé CRM users are responsible for protecting their account and device, using the application only for approved Mission Delafé work, and avoiding unnecessary sensitive information in free-text fields.
International processing
Mission Delafé is based in the United States. Our service providers may process information in the United States and other countries, which may have different data-protection laws than your location. Where required, we use contractual or other recognized safeguards for cross-border processing.
Changes to this policy
We may update this policy as our services, vendors, or legal obligations change. We will post the updated policy with a revised effective date. If a change materially affects how we use personal information, we will provide additional notice when reasonably appropriate or legally required.
Contact us
Mission Delafé, Inc.325 Ellington Blvd., Unit 425
Gaithersburg, MD 20878
United States
Email:
info@missiondelafe.org
Telephone: (240) 883-3026
Back to missiondelafe.org