Security Overview
At GiveWheel, protecting the personal data entrusted to us by charities, fundraisers and donors is a fundamental part of operating our platform.
We are committed to maintaining a secure, reliable and resilient service through appropriate technical and organisational measures, industry-standard security practices, careful operational controls and trusted technology providers.
This page provides an overview of the measures we take to protect the GiveWheel platform and the information processed through it.
Policy Sections
Infrastructure
GiveWheel is hosted on Heroku, a cloud platform operated by Salesforce. Our hosting environment is designed to provide a secure, resilient and scalable foundation for our services.
Communications between users and GiveWheel are protected using Transport Layer Security (TLS). This helps protect information transmitted between a user's browser and our platform from interception or unauthorised access.
We regularly maintain and update our application and infrastructure, including applying relevant security updates and patches, to help address vulnerabilities and maintain the reliability of our services.
Payment Security
Online card payments made through GiveWheel are securely processed by Stripe.
GiveWheel does not store or directly process customers' full payment card details. Payment information is entered into Stripe's secure payment infrastructure and is handled by Stripe in accordance with its security and compliance requirements.
Stripe is a PCI DSS Level 1 Service Provider, the highest level of certification available under the Payment Card Industry Data Security Standard.
By using Stripe for payment processing, GiveWheel is able to minimise the amount of sensitive payment information handled directly by our own systems.
Data Protection
We take appropriate technical and organisational measures to protect personal information against unauthorised access, accidental loss, disclosure, alteration or destruction.
Depending on the nature of the information and the system involved, these measures include:
- Encryption of data in transit using HTTPS/TLS.
- Secure storage of user passwords using industry-standard password hashing.
- Role-based access controls designed to restrict access to authorised personnel.
- Authentication and access controls protecting administrative systems.
- Logging and monitoring of relevant platform activity to help identify and investigate potential security issues.
- Appropriate controls over access to systems and personal information.
Our handling of personal data is described in our Privacy Policy and is subject to applicable UK data protection legislation, including the UK GDPR.
Application Security
Security is considered throughout the development and operation of the GiveWheel platform.
Our application security practices include:
- Keeping application software and dependencies appropriately updated.
- Applying security patches where relevant.
- Reviewing third-party software dependencies for security and maintenance considerations.
- Testing and reviewing the application for common web application security risks, including risks identified by the OWASP Top 10.
- Following secure software development practices.
- Conducting code review as part of the development process.
We continually review and improve our security practices as the platform and the threat landscape evolve.
Availability and Resilience
We recognise the importance of maintaining a reliable fundraising platform for charities, fundraisers and event organisers.
To support service continuity and recovery, we:
- Monitor the health and availability of our platform.
- Maintain regular backups of critical application data.
- Maintain processes for responding to operational and security incidents.
- Investigate and resolve service issues as promptly as reasonably practicable.
- Continually review opportunities to improve the resilience and reliability of our systems.
While no online service can guarantee uninterrupted availability, we take reasonable steps to minimise disruption and restore services as quickly as reasonably practicable when incidents occur.
Third-Party Service Providers
GiveWheel relies on carefully selected technology and service providers to operate parts of its platform.
Key providers include:
- Heroku (Salesforce): cloud hosting and application infrastructure.
- Stripe: secure payment processing.
- Amazon Web Services (AWS): infrastructure used within the hosting environment where applicable.
We assess the security and suitability of third-party providers as appropriate to the services they provide. These providers operate their own security and compliance programmes and are responsible for the security of the infrastructure and services they provide to us.
Where appropriate, our use of third-party providers is governed by contractual and technical controls designed to protect information processed on our behalf.
Responsible Disclosure
We take security vulnerabilities seriously and encourage responsible disclosure.
If you believe you have identified a security vulnerability affecting GiveWheel, please contact us at [email protected] with sufficient information for us to understand and reproduce the issue.
We will acknowledge legitimate reports promptly, investigate reported vulnerabilities appropriately and work to address confirmed security issues as quickly as reasonably practicable.
When reporting a vulnerability, we ask security researchers to:
- Avoid accessing, modifying or deleting personal or other user data.
- Avoid disrupting or degrading our services.
- Test only against accounts and systems they are authorised to access.
- Provide sufficient information to reproduce and investigate the issue.
- Allow us a reasonable opportunity to investigate and remediate a confirmed vulnerability before publicly disclosing it.
Security Limitations
We recognise that no internet-connected system can be guaranteed to be completely secure.
Our security measures are designed to reduce risk and protect the confidentiality, integrity and availability of information, but they cannot eliminate every possible security threat or guarantee that a security incident will never occur.
We continually review our systems and processes and seek to improve our security posture as new technologies, vulnerabilities and threats emerge.
Governing Law
GiveWheel's Terms and Policies are governed by the laws of England and Wales.
Any dispute arising from or relating to these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales, unless applicable consumer protection laws provide otherwise.
These Terms constitute the entire agreement relating to your use of the Platform.
If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions will continue to apply.
A delay or failure by either party to enforce any provision of these Terms does not waive the right to enforce it later.
Contact Us
If you have any questions regarding these terms or the GiveWheel Services, please contact us:
Email: [email protected]
Website: www.givewheel.com
Last reviewed: 01/08/2026