For charities using Cheerful Give
Compliance starter pack
Everything to add to your website and put in place so you can take donations with Cheerful the right way - data protection, consent and tax records, wherever you and your donors are based.
1Which rules apply to you
Two things decide your obligations: where your charity is based, and where your donors are. A UK charity taking a gift from California may need to consider Californian rules; a US charity taking EU donations may fall under the GDPR - so check both.
The reassuring part: Cheerful's defaults - an unticked mailing-list opt-in, donor data kept on your own site, card details held only by Stripe, and built-in export / delete tools - already meet the strictest of these regimes, so following this pack puts you in good shape almost everywhere.
| Where | Main privacy law | Regulator | Marketing email | Breach report |
|---|---|---|---|---|
| UK | UK GDPR + DPA 2018 | ICO | Opt-in (PECR) | ICO, within 72h |
| EU / EEA | GDPR | Your national authority | Opt-in (ePrivacy) | Authority, within 72h |
| USA | State laws - California (CCPA/CPRA), Virginia, Colorado & more | State Attorneys General; CPPA in California | Opt-out allowed (CAN-SPAM); opt-in safest | Varies by state |
| Canada | PIPEDA (+ Quebec Law 25) | OPC / provincial | Express opt-in (CASL - strict) | OPC, as soon as feasible |
| Australia | Privacy Act 1988 (APPs) | OAIC | Opt-in (Spam Act) | OAIC, notifiable breaches |
| Elsewhere | Your local data-protection law | Local regulator | Ask for consent to be safe | Check locally |
2Who's responsible for what
You (the charity) are the data controller - it's your donors' data and your responsibility. Cheerful is a data processor acting on your instructions, and it uses a few sub-processors on your behalf: Stripe (payments), Cloudflare (the secure infrastructure that forwards donations to your site) and Resend (system emails). Ask Cheerful for its Data Processing Agreement to keep on file.
3What data is handled, and where it lives
| Data | Where it's stored |
|---|---|
| Donor name, email, donation history | Your own website |
| Card details | Stripe only - never your website |
| Gift Aid declaration (name + address) | Your website (kept for HMRC) |
| Mailing-list opt-in | Your website (+ Mailchimp / MailerLite if you connect it) |
| Fraud / bot checks, IP address | Stripe & hCaptcha |
Good news for you: donor data stays on your own site, and card details only ever touch Stripe - so you're never handling card numbers.
4Add this to your Privacy Policy
Adapt the [bracketed] parts. This tells donors what happens to their data - a legal must-have.
Donations & payments. When you donate through our website we collect your name, email and donation details, stored on our site. Card payments are handled by Stripe - we never see or store your card details. If you claim Gift Aid, we keep your name and address to make the claim to HMRC, as required by law. If you tick the box, we add you to our mailing list; you can unsubscribe at any time. Our donation form uses hCaptcha to prevent fraud, which may process your IP address. Your data may be handled by our providers (Stripe, Cloudflare, Cheerful[, Mailchimp/MailerLite]), including outside the UK under appropriate safeguards. You can ask to see, correct or delete your data at [your contact email]. We keep donation and Gift Aid records for [7] years for accounting and HMRC, and marketing consent until you unsubscribe.
5Add this to your Cookie notice
Our donation form loads Stripe and hCaptcha to take payments securely and block fraud. These may set cookies and read your IP address for security purposes.
6Handling donor requests (see / delete their data)
Donors have the right to ask what you hold and to have it deleted. In WordPress, go to Cheerful → Privacy tools, search by email, then Export or Anonymise.
7Set a retention schedule
Decide how long you keep each type of data, then stick to it (Cheerful can auto-anonymise old donations for you under Privacy tools).
| Data | Keep for |
|---|---|
| Donation & Gift Aid records | Current year + 6 years (HMRC / accounting) |
| Mailing-list consent | Until they unsubscribe (review ~every 2 years) |
| Failed / abandoned donations | Short - e.g. 90 days, then anonymise |
In the UK, set the retention period to at least 7 years so Gift Aid records survive. Elsewhere, match your own tax authority's record-keeping period.
8Get consent right
- Marketing (mailing list): the checkbox is opt-in and unticked by default - never pre-tick it. The EU/UK and Canada (CASL) require this; the US technically allows opt-out, but opt-in is safest everywhere.
- Fee cover & tips: start switched off so the donor actively chooses to add them.
- Keep the record: Cheerful stamps the donor's privacy/terms agreement onto each donation, so you have an audit trail.
9If something goes wrong (data breach)
If donor data is ever exposed - a hack, an email sent to the wrong person, a lost laptop - most regimes require you to report it to your regulator if people could be harmed, and to tell affected people if the risk is high. In the UK/EU that's within 72 hours (the UK's is the ICO); elsewhere the timeframe and regulator differ - see the table up top.
Have a one-pager ready: who to call, how you'll assess the risk, and the ICO reporting link - so you're not scrambling on the day.
10Keep a simple Record of Processing (ROPA)
A one-page table of what personal data you hold. Small charities have a lighter duty, but this is cheap insurance:
| What | Why | Shared with | Kept |
|---|---|---|---|
| Donor details | Process the gift | Stripe, Cheerful | 7 years |
| Gift Aid declaration | HMRC claim | HMRC | 7 years |
| Mailing list | Marketing (consent) | [Mailchimp / none] | Until unsubscribe |
11Do you need a Data Protection Officer?
Usually no for a small charity - a formal DPO is only required for large-scale monitoring or large-scale special-category processing. But you should name one person who's responsible for data protection so it doesn't fall through the cracks.
12Quick checklist
- Checked which country's rules apply to you and your donors
- Privacy Policy updated (section 4) and linked on your donation form
- Cookie notice updated (section 5)
- Cheerful's Data Processing Agreement on file
- Retention period set to 7+ years in Privacy tools
- You know how to Export / Anonymise a donor on request
- A breach one-pager written
- One person named as responsible for data protection
A starting point, not legal advice - check with your own adviser.