Privacy Policy

The purpose of this policy is to detail how we collect, use, and protect donors’ personal information.

Publication date: January 2020

Plan International USA (Plan) is committed to respecting your privacy. This privacy policy describes the types of information we collect and how we use that information. Regardless of how you provide us with your personal information, we strive to honor your privacy preferences.

By using this website or providing any information to Plan International USA, you agree: (1) to abide by the practices described in this statement, as well as in our Website Terms of UseSafeguarding Children and Young People PolicyPlan International USA Linking Agreement and other policies that we may post on the website; and (2) that Plan may use your information in accordance with this policy.

The information we collect

Information we collect directly

Through you: You may choose to provide personal information by phone, mail or on our website when you participate in activities such as setting up an account in MyPlan, sponsoring a child, making a donation, submitting a form or joining an email list. The personal information we collect may include your name, postal address, zip code, telephone number, organization name, email address, credit card number, bank information or billing information.

Information we collect automatically

Through cookies: Our website uses cookies to distinguish you from other individuals entering the site. A “cookie” is a small piece of data that is sent to your browser from Plan’s web server and is stored on your computer’s hard drive. Cookies are used to collect non-identifying information about the user, such as web-surfing behavior or user preferences for a specific website. Plan uses two different types of cookies: session-based and persistent cookies. Session-based cookies expire at the end of a browser session so that once you close your browser the cookie simply terminates. Persistent cookies remain on your computer until you remove them and are used to provide internal website analytics. In addition, Plan also uses “pixels,” or transparent GIF files, to help manage online advertising. These pixels do not collect identifying information, and are used by third-party service providers for aggregate reporting and campaign functionality.

When you enter the Plan International USA website, a notice pops up which allows you to enable or disable cookies on the Plan website. By disabling cookies, you are disabling the storage of your personally identifiable information. However, we will still use some cookies for essential web functions, such as running the Plan website. You may also opt out of the use of cookies by disabling cookies on your browser. You can manually delete all cookies, including persistent ones, using your browser’s privacy settings. However, please note that some website functions will not work without the use of cookies.

Through Google Analytics: Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. It uses cookies to “remember” what you have done while on the Plan website, and then uses that information to advertise to you online. Plan is currently using the following Google Analytics Advertising Features: Remarketing, Display Network Impression Reporting, DoubleClick Platform integrations and Demographics and Interest Reporting. You may opt out of Google Analytics and other third-party use of cookies by clicking here or by visiting Google’s ad settings.

Though social media sites: When you access a social media site where Plan has a presence, we may obtain your personal data depending on your settings or the privacy policies of those sites. To change your settings on these services, please refer to their privacy notices which will tell you how to do this.

Information from children: Plan does not knowingly solicit data from children under the age of 13 and does not knowingly market to children under the age of 13 without parental consent. You can find more information about our Child Protection Standards here.

How we use your personal information

We will never:

  • Share your information with a third party to use for their own marketing purposes.
  • Rent or sell personal information to any other business or organization.
  • Send out donor mailings on anyone else’s behalf.

Administrative purposes: The information you provide us is shared with staff and service providers that process transactions and provide services on our behalf — for example, vendors who process your credit card information, send communications or perform site optimization services. These service providers are not authorized by us to use or disclose the information except as necessary to perform services on our behalf or to comply with legal requirements.

Facebook Lookalikes: If you live in the United States, we may participate in Facebook’s Custom Audience Lookalike program, which enables us to display personalized ads to persons not on our email lists when they visit Facebook; these individuals have browsing behavior similar to you. Facebook does not share this information in any way, and deletes the information as soon as the match process is complete. If you would like to opt out of this program, send an email from the email address you are opting out of to the email address provided in our contact information below. Place the following text in the subject line of the email: “Opting Out of Website Custom Audience Ads,” and include your name and email address in the body of the email.

Analysis & market research: We may analyze information we’ve received to improve the content offered on Plan’s website and create a more user-friendly experience. Your information may also be used in the aggregate (pooled and anonymized) for marketing and strategic development purposes.

Legal purposes: We may disclose information about you (i) if we are required to do so by law or (ii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity. We reserve the right to transfer any information we have about you in the event we sell or transfer all or a portion of our business or assets. Should such a sale or transfer occur, we will use reasonable efforts to try to direct the transferee to use personal information you have provided in a manner that is consistent with this privacy notice.

How we contact you

The personal information you provide will be used to contact you with information directly related to your donation. For example, you will receive a payment confirmation email, end-of-year tax receipt and be notified about any account issues.

If you have opted into our email/mailing list, we will also contact you — by mail, electronically or by telephone — with information about our work, ways that you can help, updates about your sponsored child or about how your support is helping children in need. Even if you opted in, you can always opt-out of our email/mailing list at any time by sending an email to [email protected] or by updating your user preferences within MyPlan.

If you opt in to receiving text messages from Plan via your mobile phone, we will occasionally contact you. For full terms and conditions from our text messaging vendor, click here.

How we protect your personal and payment information

Plan takes information security seriously. We regularly review our information security procedures to ensure that your information is transferred, used and stored responsibly. We securely store donor information in our internal donor database. Our security measures include, but are not limited to: annual staff training on data handling; limiting the number of staff with access to your personal information; and electronic and physical security measures, including protection against malicious web activity, 24/7 security software monitoring of staff computers and SIEM monitoring of all network activity.

We accept donations for sponsorship, projects and other activities via phone, mail and online through a secure site. When you donate to Plan online, your credit card information is processed by a third-party payment processor and secured by a third-party security company. Your ACH and credit card contributions are processed in compliance with laws and rigorous prevailing industry standards (i.e., PCIDSS, NACHA). To ensure PCIDSS compliance, Plan utilizes a secure VLAN subnet and specialized monitoring hardware and software. Your payment information is not stored electronically at Plan and therefore cannot be released by Plan for any purpose. Plan’s website utilizes 2048-bit SHA-256 RSA encryption to protect all data in transit.

Your rights as a legal resident of the European Union

Under European data protection law, in certain circumstances, you have the right to:

Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be relayed to you, if applicable, at the time of your request.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground, as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent

If you wish to exercise any of the rights set out above, please contact us at [email protected].

Protection against fraud

Plan will never ask you to:

  • Supply bank details via email;
  • Send money to support an individual child;
  • Enter into direct personal correspondence with a child without oversight by Plan.

Links to other websites:

The Plan website contains links to other websites. We do our best to carefully choose those sites with which we link but cannot take responsibility for the practices or content of these sites. We encourage you to review the privacy policies posted on any sites you may visit before providing personal information.

Contacting us about your privacy preferences:

If you have any questions or concerns about this policy, or would like to review and/or update the information we have collected about you, please contact us:

Plan International USA
275 Promenade Street Suite 225
Providence, RI 02908

Telephone: 800.556.7918
Email: [email protected]