Privacy Policy

Last updated: October 2026

1. Controller

[Firmenname], [Adresse], represented by [Vertretungsberechtigt]. Email: [E-Mail]. This policy follows the EU General Data Protection Regulation (GDPR).

2. Visiting the website

When you visit GrantPeers, our server processes your IP address, the page requested, date and time, and your browser's user agent to deliver the site and protect it against abuse (Art. 6(1)(f) GDPR). Server logs are deleted after 14 days. To measure interest in result pages we count visits to "/for/…" pages on the server, storing only the page, the time and a daily-changing one-way hash of the IP address (no cookie, no pixel). We use no analytics tools, no advertising, no tracking pixels and no third-party fonts or scripts.

3. Cookies

We only use strictly necessary cookies: a session cookie to keep you logged in and a security cookie (CSRF protection). That is why there is no cookie banner.

4. Your account

For an account we store your email address, a securely hashed password, your organization profile, your saved list, notes and update emails (Art. 6(1)(b) GDPR, contract). We keep this data until you delete your account; billing records are kept as required by tax law (up to 10 years).

5. Emails

We send service emails (welcome, end of trial) and – unless you opt out – a weekly update. Every update email has an unsubscribe link. Our emails contain no tracking.

6. Payments

Payments are processed by Stripe (Stripe Payments Europe Ltd., Ireland). Stripe receives the data needed for the payment. We do not see or store full card details. See stripe.com/privacy.

7. Hosting

The service is hosted on servers of Hetzner Online GmbH in Germany under a data processing agreement.

8. Data from public tax returns

The foundation and grant data comes from tax returns that organizations must file with the U.S. IRS and that the IRS publishes. These returns can include names of board members, officers and contact persons. We process these names to help nonprofits find the right contact (Art. 6(1)(f) GDPR, legitimate interest in transparency about grantmaking; Art. 14 GDPR information is given here). Names are only shown to logged-in users and never on public pages. Grants to individuals are never shown by name.

Objection and erasure: If your name appears and you want it hidden, email [E-Mail] with your name and the foundation. We will hide it promptly, usually within a few days.

9. Emails to nonprofits

We send a small number of business emails to U.S. nonprofit organizations about our service. We take contact addresses only from the organization's own public website (we prefer general addresses such as info@ and staff whose role relates to fundraising), store the address, the page where we found it and the date, and use it for at most three messages (Art. 6(1)(f) GDPR, legitimate interest in business communication). Every email names the sender and includes an unsubscribe link; a reply "no" also works. After an unsubscribe we keep only the address on a block list so we never contact it again.

10. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority.