Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(PrivacyPolicy): Update & GDPR compliance #11056

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

Betree
Copy link
Member

@Betree Betree commented Feb 26, 2025

No description provided.

Copy link

vercel bot commented Feb 26, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
opencollective-frontend ✅ Ready (Inspect) Visit Preview 💬 Add feedback Feb 26, 2025 11:45am

@Betree Betree force-pushed the chore/privacy-policy-update branch 3 times, most recently from 7a88afb to 58a8f0c Compare February 26, 2025 11:33
Copy link
Contributor

@BenJam BenJam left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Couple of mods needed in here. But mostly I'm interested in the consideration given to OFITech acting as a data controller over being a data processor. I believe it's more usual for us to be the data processor (a la Shopify) but there are cases where the platform acts as the controller, like Patreon.


- **Sentry**: An error monitoring service that helps us identify and fix bugs in our applications. It may collect technical data related to errors encountered while using our Services.

- **Metabase**: An analytics platform we use to analyze data.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Might be worth being more specific here.


<p class="lead">This Privacy Policy explains how information about you is collected, used, and disclosed by Open Collective, Inc. ("Open Collective" or “we”). This Privacy Policy applies to information we collect when you use our websites and online services (collectively, the Services) or when you otherwise interact with us.</p>
<p class="lead">This Privacy Policy explains how information about you is collected, used, and disclosed by OFi Technologies LLC ("OFi Technologies", "we", "us", or "our"), a company 100% owned and controlled by Open Finance Consortium, a C3 non-profit. The opencollective.com website is operated by OFi Technologies LLC. This Privacy Policy applies to information we collect when you use our websites and online services (collectively, the "Services") or when you otherwise interact with us.</p>
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Policy then goes on to talk about Open Collective but Open Collective is not defined.


We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of the policy and, in some cases, we may provide you with additional notice (such as adding a statement to our homepage or sending you a notification). We encourage you to review the Privacy Policy whenever you access the Services or otherwise interact with us to stay informed about our information practices and the ways you can help protect your privacy.

## Data Controller

OFi Technologies LLC is the data controller of your personal information. We are responsible for, and determine how your personal data is processed. If you have any questions about this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer at [email protected].
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe it's normal for a platform to operate as a data processor, not controller. I think it's worth looking at what the implications of this are.


- **Performance of Contract**: Processing your information is necessary to provide the Services to you, such as creating an account, processing contributions, or handling expense reimbursements.
- **Legitimate Interest**: We process your information for our legitimate business interests, such as improving our Services, understanding how our Services are used, preventing fraud, and marketing our Services.
- **Consent**: In some cases, we process your information based on your consent, such as for certain types of marketing communications.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Worth looking at but you have this basis covered in service provision and legitimate interest. Not sure this needs to be stated here as a result. Note that of course we have to gain explicit informed and free consent at the point that we register users to be able to send marketing and other non-service-provision based messaging.


## Transfer of Information to the U.S. and Other Countries
Open Collective is based in the United States and the information we collect is governed by U.S. law. When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States or other countries which have not been determined by the European Commission to have laws that provide an adequate level of data protection, we use legal mechanisms designed to help ensure your rights and protections, including:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the big 1️⃣


### Compliance
## Children's Privacy
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants