Privacy Policy
Last Updated: August 13, 2026
This Privacy Policy explains how IT HUB Service Inc., doing business as 501c3.help (“501c3.help,” “Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information.
This Policy applies to the website located at 501c3.help, related pages and tools, client-access features, communications, consultations, and services that link to this Policy (collectively, the “Services”).
1. Privacy Summary
We collect information that you provide, information generated when you use the Services, and information received from service providers or third-party platforms when you authorize access.
We use personal information to:
- respond to inquiries;
- provide nonprofit consulting, document-preparation, technical, advertising, and operational services;
- operate client accounts and portals;
- process payments;
- maintain security;
- analyze and improve the Services;
- communicate about services and updates;
- comply with law.
We do not sell personal information for money.
We use analytics and advertising technologies, including technologies provided by Google, Meta, and Yandex. Those technologies may disclose identifiers and internet activity to third parties and may be treated as “sharing,” targeted advertising, or similar processing under certain privacy laws.
You may contact us at team@501c3.help to exercise applicable privacy rights.
2. Personal Information We Collect
The information we collect depends on how you interact with us.
2.1 Contact and identity information
We may collect:
- name;
- email address;
- telephone or WhatsApp number;
- mailing or business address;
- job title;
- organization name;
- professional role;
- preferred language and communication channel.
2.2 Organization and project information
When you request services, we may collect information about:
- nonprofit or proposed nonprofit name;
- mission, programs, beneficiaries, and geographic scope;
- founders, directors, officers, employees, contractors, and authorized representatives;
- governance, compensation, related-party, fundraising, and business relationships;
- state and federal filing history;
- tax-exempt status;
- budgets, projected revenue, grants, donations, and program fees;
- domains, websites, advertising, software, and technical infrastructure;
- government or third-party correspondence;
- documents and information needed to prepare filings, policies, websites, campaigns, or compliance materials.
Some of this information may relate to individuals associated with an organization.
2.3 Account and authentication information
Client-access features may collect:
- username or login identifier;
- encrypted or hashed password;
- access permissions;
- authentication records;
- login history;
- security and account-recovery information.
When you authorize us to access an external platform, we may receive delegated access, temporary credentials, authentication tokens, account identifiers, or related permission data.
2.4 Communications and consultation information
We may collect:
- emails;
- WhatsApp messages;
- form submissions;
- consultation notes;
- meeting details;
- support requests;
- feedback;
- files and attachments;
- records of consent and communication preferences.
We may record a call or meeting only after giving notice or obtaining consent when required.
2.5 Transaction and payment information
We may collect:
- services purchased;
- invoice and payment status;
- transaction date and amount;
- billing address;
- refund, dispute, or chargeback information;
- limited payment-method information received from the processor, such as card brand and last four digits.
Payment providers such as Stripe process complete payment-card information. We do not ordinarily store complete card numbers or security codes.
2.6 Device, internet, and usage information
We and our technology providers may automatically collect:
- IP address;
- browser type and version;
- device and operating-system information;
- language and time zone;
- approximate location derived from IP address;
- referring and exit pages;
- pages viewed;
- links clicked;
- dates and times of visits;
- session duration;
- cookie and advertising identifiers;
- conversion and campaign information;
- diagnostic, security, and error logs.
2.7 Third-party platform information
At your direction, we may receive or process information from platforms and agencies such as:
- state filing agencies;
- the Internal Revenue Service;
- Google for Nonprofits and Google Ads;
- TechSoup;
- domain registrars and hosting providers;
- analytics providers;
- email and productivity providers;
- CRM systems;
- donation and payment platforms;
- social networks;
- nonprofit-benefit providers.
The information received depends on the permissions you authorize and the services requested.
2.8 Sensitive personal information
Depending on the service, we may process information that certain laws classify as sensitive, including:
- account credentials;
- financial or payment information;
- government-issued identifiers contained in filing documents;
- precise organizational ownership, governance, or compensation information;
- personal information contained in government correspondence;
- authentication tokens.
Do not provide Social Security numbers, full payment-card details, health information, biometric information, or other highly sensitive information unless we specifically request it through an appropriate secure process.
We do not use sensitive personal information to infer characteristics about individuals or for purposes that require a separate right to limit use under California law.
3. Sources of Personal Information
We may collect personal information:
- directly from you;
- from another person authorized to act for your organization;
- automatically through the Site;
- from payment, analytics, advertising, hosting, security, CRM, messaging, and communication providers;
- from government records and public sources;
- from a referral source;
- from third-party platforms when you authorize access;
- from contractors or professional advisors assisting with your project.
If you provide information about another person, you represent that you are authorized to do so and that you have provided any notice or obtained any consent required by law.
4. How We Use Personal Information
We may use personal information to:
4.1 Provide requested services
- respond to inquiries;
- conduct consultations;
- evaluate project fit and readiness;
- prepare mission, program, governance, and operational materials;
- draft documents for review;
- create websites and digital infrastructure;
- provide filing and administrative assistance;
- support nonprofit-benefit enrollment;
- configure analytics, advertising, CRM, email, donation, and technical systems;
- manage Google Ad Grants and other campaigns;
- provide ongoing nonprofit operations support;
- deliver educational content and client access.
4.2 Operate and secure the Services
- create and manage accounts;
- authenticate users;
- provide customer support;
- prevent fraud, abuse, and unauthorized access;
- monitor system performance;
- troubleshoot errors;
- maintain backups;
- protect users, clients, the public, and our systems.
4.3 Process transactions
- issue invoices;
- process and confirm payments;
- administer refunds and disputes;
- maintain accounting, tax, and transaction records;
- prevent payment fraud.
4.4 Communicate
- respond to messages;
- send project and account notices;
- deliver requested educational materials;
- send compliance or service updates;
- request information or approvals;
- provide marketing communications where permitted;
- manage communication preferences.
4.5 Analyze and improve
- understand Site usage;
- measure advertising and campaign performance;
- evaluate content and tools;
- improve accessibility, design, security, and functionality;
- develop new services;
- conduct internal reporting and quality control.
4.6 Comply with law and protect rights
- comply with legal, tax, accounting, regulatory, and recordkeeping obligations;
- respond to lawful requests and legal process;
- establish, exercise, or defend legal claims;
- enforce agreements;
- investigate suspected misconduct;
- protect the rights and safety of users, clients, third parties, and the Company.
5. Cookies and Similar Technologies
We use cookies, pixels, tags, local storage, server logs, and similar technologies.
5.1 Types of technologies
Essential and security technologies support core functions, fraud prevention, load balancing, account access, and security.
Preference technologies remember settings and choices.
Analytics technologies help us understand Site use and performance. Current implementations may include Google Analytics and Yandex Metrica.
Advertising and measurement technologies help measure campaigns, referrals, and conversions. Current implementations may include Meta Pixel and Google advertising or conversion technologies.
5.2 Information collected by these technologies
These providers may receive:
- IP address;
- device and browser identifiers;
- cookie identifiers;
- page and link activity;
- referring pages;
- approximate location;
- conversion events;
- campaign information.
Some providers may combine this information with information they receive from other websites or services according to their own policies.
5.3 Your choices
You may control cookies through:
- the cookie or privacy-preference control provided on the Site;
- browser settings;
- device settings;
- provider-specific opt-out tools;
- a legally recognized opt-out preference signal, where applicable.
Blocking some technologies may affect Site functionality.
5.4 Do Not Track and Global Privacy Control
Because there is no universally accepted standard for browser “Do Not Track” signals, the Site does not respond to ordinary Do Not Track signals.
Where required by applicable law, we treat a qualifying Global Privacy Control (GPC) or other legally recognized opt-out preference signal as a request to opt out of sale or sharing for the browser or device that sends the signal.
Other parties, including analytics and advertising providers, may collect information about your online activities over time and across different websites when you use the Site.
6. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients.
6.1 Service providers and contractors
We may use providers supporting:
- hosting, content delivery, and security;
- analytics and advertising measurement;
- payment processing;
- email, messaging, and video communications;
- client portals and CRM systems;
- document storage and collaboration;
- website development and maintenance;
- accounting and professional services;
- customer support;
- data backup and recovery.
These providers receive information needed to perform services for us and are subject to contractual or legal restrictions where required.
6.2 Government agencies and nonprofit platforms
At your direction or as needed to perform purchased services, we may disclose information to:
- Secretaries of State and other formation agencies;
- the Internal Revenue Service;
- state tax and charity regulators;
- local government agencies;
- Google for Nonprofits, Google Ads, TechSoup, and other nonprofit-benefit platforms;
- other agencies or platforms identified in your project.
Government filings may become public records.
6.3 Professional advisors
We may disclose information to attorneys, CPAs, tax professionals, filing specialists, consultants, and other advisors when reasonably necessary for review, compliance, or service delivery.
No attorney-client relationship with a third-party professional is created unless that professional separately agrees to represent you.
6.4 Analytics and advertising partners
We may disclose identifiers, device information, internet activity, approximate location, and conversion data to analytics and advertising providers, including Google, Meta, and Yandex.
Depending on applicable law, some of these disclosures may be considered “sharing” for cross-context behavioral advertising or targeted advertising.
6.5 Business transactions
We may disclose information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections where practicable.
6.6 Legal and safety disclosures
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with law, legal process, or a lawful government request;
- enforce agreements;
- investigate fraud, abuse, or security incidents;
- protect rights, property, safety, or systems;
- establish, exercise, or defend legal claims.
6.7 With your direction or consent
We may disclose information when you request, direct, authorize, or consent to the disclosure.
7. Sale and Sharing of Personal Information
We do not sell personal information for monetary consideration.
We may use analytics, advertising, and conversion technologies that disclose personal identifiers and internet activity to third parties. Under some privacy laws, these activities may be considered:
- “sharing” for cross-context behavioral advertising;
- targeted advertising;
- a sale or disclosure requiring an opt-out right.
You may opt out through the Site’s Your Privacy Choices control, by using a qualifying GPC signal where applicable, or by emailing team@501c3.help.
We do not knowingly sell or share personal information of individuals under 16 years of age.
8. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, security, dispute resolution, and legal, tax, accounting, and regulatory obligations.
Our general retention approach is:
| Category | General retention approach |
|---|---|
| Inquiries and consultation communications | Generally up to 3 years after the last meaningful interaction |
| Client, project, filing, and service records | During the relationship and generally up to 7 years afterward |
| Payment, invoice, tax, and accounting records | Generally 7 years or longer when required by law |
| Account, authentication, and security logs | Generally up to 2 years, subject to security needs |
| Analytics, cookie, and advertising data | According to provider settings and business needs, generally no longer than 26 months in identifiable form where configurable |
| Marketing preferences | Until you opt out; suppression records may be retained to honor the opt-out |
| Legal claims and investigations | For the applicable limitation period and any related proceedings |
We may retain information longer when required by law, an agency, litigation hold, contract, fraud-prevention need, or legitimate security need. We may delete or deidentify information earlier when it is no longer needed.
Public government records may remain available from the government agency even after we delete our copy.
9. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information.
Measures may include:
- access controls;
- authentication;
- encryption in transit;
- secure hosting;
- backups;
- monitoring;
- limited permissions;
- vendor management;
- staff and contractor confidentiality obligations.
No system is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.
You are responsible for protecting your passwords, devices, accounts, and copies of documents.
10. Your Privacy Rights
Depending on your residence and applicable law, you may have the right to:
- confirm whether we process your personal information;
- access or know the personal information we maintain;
- request correction;
- request deletion;
- receive a portable copy;
- opt out of sale, sharing, or targeted advertising;
- limit certain uses of sensitive personal information;
- withdraw consent where processing is based on consent;
- appeal a denied request;
- receive equal service and not be discriminated against for exercising a privacy right.
These rights are subject to exceptions. For example, we may retain information needed to complete a transaction, provide a requested service, comply with law, maintain security, protect legal rights, or preserve records required by an agency or contract.
10.1 How to submit a request
Send a request to:
team@501c3.help
Use the subject line:
Privacy Request
Describe:
- your name;
- the email address or telephone number associated with your interaction;
- the organization involved, if applicable;
- the right you want to exercise;
- the information or service involved.
10.2 Verification
We may need to verify your identity and authority before completing a request. Verification may require matching information you provide with information already maintained by us.
We will not request more information than reasonably necessary.
10.3 Authorized agents
Where permitted by law, you may use an authorized agent. We may require evidence of the agent’s authority and may ask you to verify your identity directly.
10.4 Appeals
Where applicable law provides an appeal right, you may appeal a denial by replying to our decision or emailing team@501c3.help with the subject line Privacy Appeal.
11. California Privacy Notice
This section supplements the rest of this Policy for California residents.
11.1 Categories collected
During the preceding 12 months, we may have collected the following categories of personal information:
| California category | Examples | Sources | Business or commercial purposes |
|---|---|---|---|
| Identifiers | Name, email, phone, WhatsApp number, postal address, IP address, account ID, cookie ID | You, authorized representatives, devices, providers | Service delivery, communication, accounts, security, analytics, advertising |
| Customer-record information | Contact details, billing details, organization and service records | You, representatives, payment and service providers | Service delivery, billing, support, compliance |
| Commercial information | Services considered or purchased, payment and transaction history | You, payment processors | Transactions, service administration, analytics |
| Internet or electronic activity | Pages viewed, clicks, referring pages, device and browser data, interaction records | Devices, cookies, analytics and advertising providers | Security, analytics, advertising measurement, improvement |
| Approximate geolocation | Approximate location inferred from IP address | Devices and providers | Security, localization, analytics |
| Professional or employment information | Role, organization, board or officer position, professional background | You, representatives, public sources | Project evaluation and service delivery |
| Inferences | Service interests, readiness, likely project needs | Derived from interactions | Personalizing communications and services |
| Sensitive personal information | Credentials, financial details, government identifiers in documents, authentication tokens | You, processors, authorized platforms | Transactions, account access, filing and service delivery, security |
We do not intentionally collect every example listed above from every person.
11.2 Categories disclosed for business purposes
We may disclose the categories listed above to:
- service providers and contractors;
- payment processors;
- hosting and security providers;
- analytics and advertising providers;
- communication and CRM providers;
- government agencies and nonprofit platforms at your direction;
- attorneys, CPAs, and professional advisors;
- parties to a business transaction;
- law enforcement or other recipients required by law.
11.3 Categories sold or shared
We do not sell personal information for money.
Analytics and advertising technologies may disclose or “share” these categories for cross-context behavioral advertising or similar purposes:
- identifiers;
- internet or electronic activity;
- approximate geolocation;
- commercial or conversion information.
Recipients may include analytics and advertising providers such as Google, Meta, and Yandex.
You may opt out through Your Privacy Choices, a qualifying GPC signal, or by contacting us.
11.4 California rights
Subject to applicable law, California residents may request:
- categories and specific pieces of personal information collected;
- sources and purposes;
- categories of recipients;
- correction;
- deletion;
- opt-out of sale or sharing;
- information about financial incentives, if any;
- nondiscriminatory treatment.
We do not offer a financial incentive program in exchange for personal information.
11.5 Applicability
Some California privacy rights apply only when a business meets statutory thresholds or when a particular processing activity is covered. We may honor a request voluntarily even when a specific law does not require it.
12. Communications Choices
You may opt out of marketing emails by using the unsubscribe link or contacting us.
You may ask us to stop marketing communications through WhatsApp or another messaging channel.
Opting out of marketing does not prevent us from sending:
- account notices;
- transaction confirmations;
- project communications;
- security alerts;
- legal notices;
- messages required to complete a requested service.
Text messages have their own terms, set out in section 13.
13. Text Messages
We send a text message to a phone number only when you gave us that number yourself, and only for the purpose you gave it for.
A number you leave on a form on the Site. We use it to reach you about the request you made. That may be a text message, a WhatsApp message, or a call.
A number you leave on a page that offers to connect you with a specific person. We use it only to tell you when that person is available, and to connect that call.
We do not sell or rent phone numbers. We do not share a phone number, or your consent to be messaged, with anyone for their own marketing or promotional use, and that includes the person you asked to be connected with. The only third parties that receive a number are the service providers that carry the message or place the call on our behalf, described in section 6.1, and they may use it only for that purpose.
Message frequency varies with what you asked for. Message and data rates may apply. Those rates are set by your mobile carrier, not by us.
Reply STOP to any message and we stop texting that number. Reply HELP for help, or email team@501c3.help.
Stopping text messages does not cancel your request, your account, or a service you purchased. We may still reach you by email about a service you asked for.
14. Children’s Privacy
The Services are intended for adults and nonprofit founders, directors, officers, professionals, and authorized organizational representatives.
They are not directed to children under 13.
We do not knowingly collect personal information online from children under 13. If we learn that we collected such information without legally sufficient authorization, we will take reasonable steps to delete it.
A parent or guardian who believes a child provided personal information may contact team@501c3.help.
15. International Visitors
We are based in the United States.
If you access the Services from another country, your information may be transferred to, stored in, and processed in the United States and other countries where our providers operate.
Those countries may have privacy laws different from the laws where you live.
Where required, we use an appropriate legal basis and transfer mechanism.
16. Third-Party Websites and Services
The Services link to third-party websites and platforms.
Their privacy practices are governed by their own policies. We are not responsible for third-party privacy, security, or data practices.
Review the relevant policy before providing information to a third party.
17. Changes to This Policy
We may update this Policy to reflect changes in our Services, technology, vendors, or legal obligations.
The “Last Updated” date identifies the current version.
Material changes may be communicated through:
- a prominent Site notice;
- email;
- a client portal;
- another reasonable method.
We encourage you to review this Policy periodically.
18. Contact Us
For privacy questions, requests, complaints, or concerns, contact:
IT HUB Service Inc.
Doing business as 501c3.help
5750 Sunrise Blvd 130
Citrus Heights, CA 95610
United States
Email: team@501c3.help
Use the subject line “Privacy Request” for requests concerning personal information.
Privacy correspondence sent by post reaches us at the address above. Email is faster, and we may verify your identity and authority before acting on a request either way.