Privacy
Privacy notice
Version 2.0 · Effective
This notice explains how YWAM Endless Summer collects, uses, shares, and retains personal information across the public site, student and staff portal, DTS applications, payments, fundraising, and support. Applicable laws and legal bases can vary by your location and relationship with us.
1. Organization responsible
YWAM Endless Summer is a ministry of Diversified Christian Ministries INC, a 501(c)(3) nonprofit. For matters involving this portal and your information, contact us at:
YWAM Endless Summer1205 Magnolia Ave
Carlsbad, CA 92008, USA
dts@ywamendlesssummer.org
+1 (760) 208-8154
2. Information we process
- Identity, account, and contact details: name, date of birth, email, phone, general location, language, credentials, and role.
- Application and participation data: program/year, personal responses, family background, education, references, and admissions status.
- Sensitive information: physical and mental health, disability, medication, allergies, religious/spiritual life, and criminal history when requested to assess support, safety, or suitability.
- Guardian and minor-consent data, including the consent response, time, network address, browser details, and invitation evidence.
- Finance and fundraising data: amounts, payment status, invoice/link identifiers, goals, and donations. Hosted providers receive payment-card details; the portal does not store full card numbers.
- Communications: email, support and privacy requests, and, when chat is escalated, an AI-generated, format-validated summary and provided contact details.
- Technical and security data: IP address, user agent, cookies/session data, authentication events, audit records, errors, and aggregate usage.
We receive data directly from you or a guardian, from authorized staff, and from providers you use for payments, donations, authentication, or communications. Do not submit another person's information without permission.
3. Purposes and legal bases
We use information to operate accounts; receive and assess applications; plan support, safety, and participation; communicate; manage payments, fundraising, and accounting; respond to privacy rights; prevent abuse; maintain audit evidence; and meet obligations.
Where GDPR or a similar law applies, we may rely—depending on context—on steps before or performance of a relationship, legal obligations, legitimate interests in administration and security, consent for specific optional uses, and vital interests in an emergency. Health, religious, and other special-category data also require a condition permitted by law, such as explicit consent or another condition applicable to a religious/nonprofit organization. The exact basis depends on the facts and jurisdiction; acknowledging this notice does not turn all processing into consent.
If required information is not provided, we may be unable to assess an application, offer safe support, create an invoice, or complete the requested service. Optional fields are identified where appropriate.
4. Minors
The online portal does not create accounts for applicants under 13; contact admissions for an assisted process. A minor age 13 or older may create an account, but the portal blocks the application from starting until a parent or legal guardian provides consent directly through a private, expiring, one-time link. The invitation email includes the minor's full name so the guardian can identify the request. We retain evidence of the consent. We do not rely on the minor checking a box for the guardian. Contact us if you received an invitation in error or believe consent is missing.
5. Recipients and providers
Internal access is limited to authorized staff or volunteers who need information for admissions, support, finance, safety, administration, or compliance. We do not sell personal information. Depending on the feature used, providers may process data for us or as independent controllers:
- Supabase — authentication, database, and storage.
- Vercel — hosting, delivery, and cookieless web analytics.
- Google Workspace / Gmail — email and communications, including chat escalations.
- Google Calendar — appointment scheduling through an external Google page.
- Anthropic — processing AI-chat messages to generate responses.
- Upstash — request rate-limiting and abuse prevention.
- Stripe, Donorbox y QuickBooks — hosted payments, donations, invoicing, and accounting, depending on the transaction.
We may also disclose information when legally required, to protect a person or service security, or in a legitimate organizational change with appropriate safeguards. This list can change; we will update this notice for material changes.
6. International transfers
We operate in the United States and use global providers, so information about people in other countries may be transferred to and processed in the United States or elsewhere. Where law requires added protection, we assess an appropriate mechanism (for example, contractual clauses or another recognized mechanism) and provider safeguards. You may ask about safeguards relevant to your situation.
7. Artificial-intelligence chat
The public-chat message and up to 12 recent context messages are sent to Anthropic to generate a response. The chat cannot look up your account or application. The conversation normally exists in browser memory for that visit and is not stored as a regular record in the portal database. If chat escalates to a person, only an AI-generated, format-validated summary and the name/email you share are emailed to the team; the transcript is omitted. Format validation does not confirm that the summary is accurate. Do not put health details, passwords, card numbers, identity documents, or other confidential information in chat. An AI response may be wrong and is not medical, legal, or immigration advice.
8. Retention
The following are retention targets, subject to tax, legal, safeguarding, dispute, investigation, or valid preservation needs. The portal does not enforce these periods automatically; authorized staff must review records and delete or restrict them when appropriate.
| Record | Period/target |
|---|---|
| Incomplete applications | Target: 12 months after the last activity. |
| Unsuccessful or withdrawn applications | Target: 2 years after the decision or withdrawal. |
| Accepted participant records | Target: 7 years after the relationship ends, unless an obligation requires longer. |
| Medical and sensitive application data | Limited to admissions, safety, and participation needs; target: deletion or access-restriction review within 3 years after the program. |
| Payments, invoices, and accounting | Usually 7 years or the applicable tax/legal period. |
| Consent, audit, and privacy-request evidence | Up to 7 years after the account or case closes when needed to demonstrate compliance. |
| AI chat | Normally not stored in the portal database. If escalated to a person, the emailed AI-generated, format-validated summary and contact details follow the correspondence target: 3 years after the last contact. |
| Storage-notice acknowledgment | In your browser until you clear site data. |
9. Your choices and rights
Depending on applicable law, you may have rights to know/access, correct, receive a portable copy, delete, restrict or object to certain processing, and withdraw consent for the future. Withdrawal does not invalidate earlier processing, and some records may be retained under another basis or obligation. You may also appeal or complain to the data-protection authority where you live, work, or believe an infringement occurred.
Submit a request through the portal or email us. We verify identity and authority before disclosing or changing data. Filing a deletion request does not automatically delete an account or guarantee every record can be erased.
10. Security and changes
We use HTTPS, role-based access controls, MFA for sensitive administrative access, audit logging, and application-layer encryption for designated medical, spiritual, and other fields. No safeguard eliminates all risk. Contact us immediately if you believe your account or information is at risk.
We will publish a new version and date when this notice changes materially. Browser cookies and local storage are described in the cookie policy.