Single Homeless Project - Privacy Policy

  1. Introduction

1.1    We are committed to safeguarding the privacy of our website visitors in accordance with relevant statutory guidance. 

1.2    We will ask you to consent to our use of cookies in accordance with the terms of this policy when you first visit our website. 

1.3    This policy will apply where we are acting as a data controller, whereby we can control the purposes and means of processing personal data obtained through the website. 

1.4    In this policy, “we”, “us” and “our” refer to Single Homeless Project. 

  1. How we use your personal data 

2.1    We have a responsibility to define; 

       a. The general categories of personal data that we can process said data;

       b. The purpose for which we may process said personal data; and

       c. The legal bases for processing. 

2.2    Your use of our website may lead to us processing your data (“usage data”) for which the legal basis is consent. 

2.2.1   The usage data may include, but is not limited to, your IP address, browser type and version, referral source, length of visit, website navigation paths, page views, operating system and geographical location.

2.2.2   The usage data may also include, in limited capacity, information about the timing, frequency and pattern of your use and/or any information stored via online accounts, such as name, profile picture, gender and date of birth. 

2.2.3   The source of the usage data are our analytic tracking system/s and the purpose is to analyse use of the website for a variety of reasons, including, but not limited to, developing our services, advertising to supporters and offering a better experience to website visitors.

2.3    We may process information inputted in any enquiry you have submitted to us regarding services or any other reason for contact (“enquiry data”) for which the legal basis is consent. 

2.3.1   This enquiry data may be processed to answer queries, understand recurring enquiries and/or how to improve our website in presenting useful information. 

2.4    We may process information provided via our newsletter subscription module/s (“newsletter data”) for which the legal basis is consent. 

2.4.1   This newsletter data may be processed for sending you relevant emails as per your request

2.5    We may process your information in any communication you send or share with us (“correspondence data”) for which the legal basis is legitimate interests (expectation of response or correspondence). 

2.5.1   This correspondence data may be processed to communicate with you, taking in to account the balance of your data rights. 

2.6    We may process your information to fulfil a purchase or transaction made through our website (“transaction data”), for which the basis is legitimate interests (financial processing at your request). 

2.6.1   This may include collaboration with a third party or joint data processor, whom shall have their own privacy policy you must review. 

2.6.2    This includes GoCardless and Stripe, for which you can review the providers’ privacy policies at https://gocardless.com/legal/privacyandhttps://stripe.com/gb/privacy. 

2.7    We may process personal data through a software that’s purpose is to assist and/or streamline the organisations processes, for which the basis is legitimate interests (maximising charity funds and resource).  

2.7.1    This includes, but is not limited to, FundraiseUP, JustGiving, Zapier, Wordpress, Google, Hotjar and Mailchimp. 

2.7.1.1   Where caching is available, it will likely be employed. 

2.7.1.2   For most intents and purposes these will be considered joint data processors. 

2.7.1.3   You are encouraged to view their privacy policy/ies should you have concerns. 

2.8    We may process personal data for marketing purposes (“marketing data”), for which the basis can be either legitimate interests or consent. 

2.8.1    This includes, but is not limited to, sending you marketing communications, using data to create custom audiences, using pixels to retarget and/or sending requested notifications or updates. 

2.9    We may process any publicly available data to assess potential and existing audiences in order to optimise strategy (“public data”), for which the basis is legitimate interests (maximising charitable advertising budget and appearing to more interested parties). 

2.10    And where necessary for the establishing, defence, or exercise of legal claims, whether in court proceedings, or in an administrative or out-of-court procedure, we may process any of your personal data identified in this policy, for which the legal basis is the law and legitimate interest (protection of legal rights). 

2.11    Where necessary for maintaining or obtaining insurance, obtaining professional advice, or managing risks, we may process any of your personal data identified in this policy, for which the legal basis is legitimate interest (proper protecting of our organisation against risks). 

2.12    We may process non-personally identifiable information for a variety of reasons, including to share with a third party. The assurance that this will not infringe on your data rights is reinforced. 

2.12.1   We will not, without your express consent, supply your personal information to any third party for the purpose of their or any other third party's direct marketing. 

2.13    In addition to clauses 2.2 to 2.7, we may process your data if necessary to comply with legal obligation or to protect vital interests of a natural person or our organisations virtual and non-virtual assets, for instance, against fraud. 

2.14    In every circumstance, before you disclose to us the personal information of another person, you must obtain that person's consent to both the disclosure and the processing of that personal information in accordance with this policy. 

2.15    Your privacy settings can be used to limit the publication of your information on our website, and can be adjusted using privacy controls on the website. 

  1. Disclosing personal information

3.1    We may disclose your personal information to any of our employees, officers, insurers, professional advisers, agents, suppliers or subcontractors insofar as reasonably necessary for the purposes set out in this policy.  

3.1.1   This list is non-exhaustive but does make assurances that except provided in the clauses of this policy, we will not share your data with unnecessary third parties. 

3.2    We may disclose your personal information; 

3.2.1   To clauses outlined in Section 2;

3.2.2   To the extent that we are required to do so by law; 

3.2.3   In connection with any ongoing or prospective legal proceedings; 

3.2.4   In order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk); 

3.2.5   To the purchaser (or prospective purchaser) of any business or asset that we are (or are contemplating) selling; and 

3.2.6   To any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order disclosure of that personal information. 

  1. Retaining personal information

4.1    Our data retention policies and procedure are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal information. 

4.2    Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. 

4.3    Notwithstanding the other provisions of this Section 4, we will retain documents (including electronic documents) containing personal data; 

4.3.1   To the extent that we are required to do so by law; 

4.3.2   If we believe that the documents may be relevant to any ongoing or prospective legal proceedings; and

4.3.3   In order to establish, exercise or defend our legal rights.

4.4    We will retain your personal data as follows: personal data shall be retained for a minimum period of 3 years unless requested otherwise.

  1. Security of personal information

5.1    We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. 

5.2    We will store all the personal information you provide on our secure (password- and firewall-protected) servers. 

5.3    Data relating to your enquiries that is sent from your web browser to web server, or from our web server to your web browser, will likely be protected using encryption technology.  

5.3.1   All electronic financial transactions entered into through our website will be protected by encryption technology. 

5.4    You acknowledge that the transmission of information over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet. 

5.5    You are responsible for keeping the password you use for accessing our website confidential; we will not ask you for your password (except when you log in to relevant sections in our website, such as Single Homeless Project's Knowledge Hub). 

  1. Amendments

6.1    We retain the right to update this policy when necessary by publishing a new version on our website. You may not be informed of this change. 

6.1.1   Therefore, you should check this page occasionally to ensure you are happy with any changes to this policy. We encourage you to also regularly clear your cookies and reassert consent. 

6.2    We may notify you of changes to this policy by email, should we feel it is necessary.  

6.3    If you are unhappy with a new privacy policy and wish to revoke your consent, please change your preferences and cookie settings. 

  1. Your rights

7.1    You may instruct us to provide you with any personal information we hold about you; provision of such information will be subject to: 

7.1.1   The supply of appropriate evidence of your identity.

7.2    We may withhold personal information that you request to the extent permitted by law. 

7.3    You may instruct us at any time not to process your personal information for marketing purposes. We will then withdraw your personal data insofar as what we have reasonable control over. 

  1. Personal data of children

8.1    Our website and shop is almost exclusively targeted at persons over the age of 18.  

8.1.1   The services we provide include support for Young People which may provide information for people over the age of 16.   

8.2    If we have reason to believe that we hold personal data under the age of 16 in our databases, we will delete that personal data. 

  1. Third party websites

9.1    Our website includes hyperlinks to, and details of, third party websites, such as the UK Government to corroborate our Registered Charity Number.

9.2    We have no control over, and are not responsible for, the privacy policies and practices of third parties. 

9.3    We will reasonably review our partnerships with third parties, and ensure they are compliant with our standard of data protection. 

  1. Updating information

10.1  Please let us know if the personal information that we hold about you needs to be corrected or updated by contacting complaints@shp.org.uk 

  1. Cookies

11.1    Our website uses cookies. 

11.2    A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server. 

11.3    Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed. 

11.4    Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies. 

11.5    We use both session and persistent cookies on our website. 

11.6    The names of the cookies that we use on our website, and the purposes for which they are used, are set out below; 

11.6.1   _cookie_accept to recognise whether the user has accepted the cookie message or not 

11.6.2   ToggleStatus  to show whether the user has hidden or shown the contacts filter search 

11.6.3   ASP.NET_SessionId to authenticate a user's session after logging in. This Closes when you exit the browser 

11.6.4   ARRAffinity which tells our infrastructure which server to handle the request 

11.6.5   MemberLoggedIn which is a binary flag which stores whether a user is logged in or not 

11.6.6   ai_session and ai_user to track users as they navigate the website predominately for infrastructure performance insights 

11.6.7   DisplayName which keeps track of a donors preference to show their name during a Direct Debit 

11.6.8   __unam (used by ShareThis) which is set as part of the ShareThis service and monitors "click-stream" activity, e.g. web pages viewed, navigation from page to page, time spent on each page etc. The ShareThis service only identifies a user if they have separately signed up with ShareThis for a ShareThis account and given them consent. Checks how long you stay on a site: when a visit starts, and ends. It does not contain any personal information and is used only for analytical purposes. 

11.7     We primarily use Google Analytics to analyse the use of this website.  

11.7.1    Google Analytics generates statistical and other information about website use by means of cookies, which are stored on users' computers.   

11.7.2    The information generated relating to our website is used to create reports about the use of the website. Google will store this information.   

11.7.3    Google's privacy policy is available at: http://www.google.com/privacypolicy.html.  

11.7.4    The Google Analytics Cookies used on this website are: __utma; __utmz; _ga; _gid; _gat_UA-17460106-1 

11.8     Most browsers allow you to refuse to accept cookies; for example; 

11.8.1    In Internet Explorer (version 11) you can block cookies using the cookie handling override settings available by clicking "Tools", "Internet Options", "Privacy" and then "Advanced"; 

11.8.2    In Firefox (version 47) you can block all cookies by clicking "Tools", "Options", "Privacy", selecting "Use custom settings for history" from the drop-down menu, and unticking "Accept cookies from sites"; and

11.8.3    In Chrome (version 52), you can block all cookies by accessing the "Customise and control" menu, and clicking "Settings", "Show advanced settings" and "Content settings", and then selecting "Block sites from setting any data" under the "Cookies" heading. 

11.8.3    More information can be found at; https://support.google.com/chrome/answer/95647?hl=en (Chrome); https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-(Firefox); http://www.opera.com/help/tutorials/security/cookies/ (Opera); https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer (Internet Explorer); https://support.apple.com/kb/PH21411 (Safari); and  https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy (Edge/Bing) 

11.10     You have a right to be informed that blocking all cookies will likely have a negative impact upon the usability of many websites. 

11.11     If you block cookies, you will not be able to use all the features on our website. 

11.12     You can delete cookies already stored on your computer; for example: 

11.12.1    In Internet Explorer (version 11), you must manually delete cookie files (you can find instructions for doing so at http://windows.microsoft.com/en-gb/internet-explorer/delete-manage-cookies#ie=ie-11); 

11.12.2    In Firefox (version 47), you can delete cookies by clicking "Tools", "Options" and "Privacy", then selecting "Use custom settings for history" from the drop-down menu, clicking "Show Cookies", and then clicking "Remove All Cookies"; and

11.12.3     In Chrome (version 52), you can delete all cookies by accessing the "Customise and control" menu, and clicking "Settings", "Show advanced settings" and "Clear browsing data", and then selecting "Cookies and other site and plug-in data" before clicking "Clear browsing data". 

  1. Data protection registration

12.1    We are registered as a data controller with the UK Information Commissioner's Office. 

12.1    Our data protection registration number is:  Z8447316. 

  1. Data protection officer

13.1    Our data protection officers contact details are: Doug Becker at dbecker@shp.org.uk 

  1. Our details

14.1    This website is owned and operated by Single Homeless Project. 

14.2    We are registered in England and Wales under Registered Charity Number 287779, and our registered office is at 245 Gray's Inn Road, London WC1X 8QY. 

14.3    Our principal place of business is at 245 Gray's Inn Road, London WC1X 8QY. 

14.4    You can contact us;  

       a. By the address given above;

       b. By using our website contact form;

       c. By telephone, on the contact number published on our website; or

       d. By email, using the email address published on our website.

       e. By the contact form below

    Any further questions?