Privacy Policy
Last updated: Jul 9, 2026
Who we are
This system (app.ywamsj.org) is operated by YWAM San José for the day-to-day management of housing, schools, teams, and related programs. It is used on behalf of two affiliated organizations:
- Youth With a Mission Costa Rica, a U.S. 501(c)(3) nonprofit corporation. Donations and certain U.S.-dollar payments (school fees, team payments, sponsorships) are processed through this entity.
- CIMEC, a Costa Rican legal entity operating locally under the name YWAM San José.
This policy describes how we collect, use, and protect personal information across the app, regardless of which entity a given transaction is processed through.
Who this applies to
The app serves several groups of people, and we collect different information depending on your relationship to us:
- Staff — name, work email, department, assigned roles, and (optionally) a profile photo.
- School applicants — application details, contact information, and information you submit for program enrollment.
- Visiting team leaders and team members — registration details and, where required for trip logistics (for example, group flights or official paperwork with local authorities), passport information.
- Donors and payers — name, email address, and payment amount. We never see or store your card number — all card payments are processed directly by Stripe on Stripe-hosted payment pages.
- Anyone submitting a facilities, IT, or transportation report — name, email or phone, and the details of the report.
- Photos you or staff upload (for example, Homes of Hope family photos, staff avatars, incident reports) for the purpose they were uploaded for.
How we use this information
We use the information above to:
- Operate the housing, schools, teams, transportation, facilities, kitchen, and IT modules of the app.
- Process payments and donations, and issue receipts.
- Communicate with you about your application, registration, trip, or report (by email).
- Maintain accurate financial and program records, including for our own accounting.
We do not sell personal information, and we do not use it for advertising.
Who we share data with
We use a small number of service providers ("subprocessors") to run the app. Each only receives the data it needs to perform its function:
- Stripe — processes card payments. Card details are entered directly into Stripe's own hosted payment forms and never pass through our servers.
- Microsoft Azure — hosts the application, our database, file storage (uploaded photos and documents), and outbound email (Azure Communication Services).
- Intuit QuickBooks Online — completed transactions are recorded in our own accounting system for bookkeeping; this is a one-way record of completed payments, not a marketing or communications tool.
- GitHub — when staff report a bug through the in-app feedback tool, an internal bug report may be created in our private GitHub repository so developers can track and fix it; this report may include your name and the details you submit.
Cookies
The app uses two purpose-limited cookies:
- A session cookie that keeps you signed in.
- A language preference cookie that remembers whether you last used English or Spanish.
We do not use advertising or third-party tracking cookies, and we do not sell data to anyone.
How long we keep information
- Financial records (payments, donations, receipts) are retained as required by U.S. and Costa Rican legal, tax, and audit requirements.
- The app uses a "soft delete" model for most records: deactivated accounts and records are hidden from normal use but retained rather than immediately and irreversibly erased, so that historical reports and financial reconciliation stay accurate.
- If you would like a record permanently removed sooner (subject to the legal retention requirements above), contact us using the details below.
How we protect your information
- All traffic to the app is encrypted in transit (HTTPS).
- Passwords are never stored in plain text — they are hashed before being saved.
- Access to different parts of the system is restricted by role — staff can only see and do what their role permits.
- Administrative actions are recorded in an internal audit log.
We do not claim any specific industry security certification (such as SOC 2, ISO 27001, or PCI-DSS) — our security practices are described honestly above, and we do not store card numbers ourselves.
Your rights
You can ask us to:
- Tell you what personal information we hold about you.
- Correct inaccurate information.
- Delete your information, subject to the legal/financial retention requirements described above.
To exercise any of these rights, or if you have any question about this policy, contact us at privacy@ywamsj.org.
Changes to this policy
We may update this policy from time to time as the app changes. The "last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to staff by email where appropriate.
See also our Terms of Service.
