Givebutter: What a Board Should Ask (2026 Evaluation)

Givebutter holds and moves your donation revenue under terms that cap its total liability at $100. Its trust centre exists but is unlinked and gated. Its public safety page is about donor fraud, not your data. Here is what a board should ask.


The short answer

Givebutter is a well-run, widely liked fundraising platform, and none of what follows contradicts that. It is also, increasingly, a company that holds your money rather than merely processing it, and the contract governing that relationship is written the way consumer platform contracts are written rather than the way vendor agreements are. That mismatch is the whole evaluation.

We read every page reachable from Givebutter’s own navigation and footer on 11 September 2026, then checked three things their navigation does not reach.

Question a board asks What we found
What is their liability if something goes wrong? Capped at $100.00 in the aggregate by the Terms of Use
Can we sue? No. Binding arbitration, class action waiver, one year to bring any claim
Is there a SOC 2 report? A trust centre exists but is gated and unlinked. Nothing is publicly verifiable
Who actually holds our donations? Stripe, with funds at Fifth Third Bank N.A., Member FDIC
Is donor data sold? No. But partners match visitors against outside data and hand it back
Can they close our account? Yes, at sole discretion, with or without cause and without notice
Can we tell donors not to tip? Doing so can count as abuse under the fee-coverage programme

This is a company evaluation. Whether the product is good is a different question, answered in our Givebutter review, and how the fees actually work belongs in our Givebutter pricing breakdown, which is where the numbers live and where they are deliberately left. If you are weighing one specific alternative, our Givebutter versus Fundraise Up comparison covers that head to head.


The liability cap is the single most important sentence in the contract

The contrast between the ten billion dollars Givebutter states has been donated through its platform and the one hundred dollar aggregate liability cap in its terms of use

Section 22 of the Terms of Use ends with this: in no event shall the total liability of the company to you for all damages, losses, and causes of action, whether in contract or tort, exceed, in the aggregate, $100.00.

One hundred dollars. Total. For everything. That is a standard clause on a free consumer website, and it is the clause Givebutter’s terms carry while the platform states it has moved more than ten billion dollars in donations.

We are not suggesting this is a trap, and a cap like this is common across platforms in this category. What matters is what it means operationally. Most nonprofit vendor policies assume that a failure by a critical supplier is recoverable in some proportion to the harm. Here it is not, contractually, and that has three consequences a board should actually act on.

Consequence What to do about it
Your recovery is your own insurance, not the vendor’s Check that your cyber and crime cover contemplates a third-party platform holding receipts
Data loss is your operational risk alone Export donor records on a schedule rather than treating the CRM as the record of truth
Disputes go to arbitration, not court Know before you sign, because this is the clause finance directors most often assume is negotiable

The dispute terms are worth reading alongside it. Claims go to American Arbitration Association arbitration rather than a court, class actions are waived, all claims must be brought within one year, and if the arbitration clause were struck down the fallback venue is Wilmington, Delaware. Hearings happen in the county of your billing address, which is the one genuinely accommodating term in the section.

Faz says: Read section 22 of any platform contract before you read the feature list. It takes ninety seconds and it tells you what the vendor thinks the relationship is worth. Everything else on the site is written by marketing. That paragraph is written by a lawyer who was being careful.


The trust centre exists. You cannot read it

This is the finding we nearly got wrong, and the way we got it right is worth stating because it applies to every vendor in this category.

Following Givebutter’s own navigation and footer, there is no security page. There is a Trust and Safety page, which we cover below and which is about something else entirely. On that evidence alone the honest write-up would have been “no published security disclosure”, and it would have been wrong.

A separate probe of the usual trust-centre hostnames found trust.givebutter.com returning a live page whose own title is simply “Trust Center”. It is linked from nowhere in their own navigation or footer that we could find. And its entire public content is a form: first name, last name, email, company name, and a reason chosen from existing customer, prospective customer, or other. Nothing else is visible. No control list, no certification summary, no document index.

So the correct statement about Givebutter and SOC 2 is not that there is no report. It is that Givebutter maintains a trust centre, does not link to it, and requires you to identify yourself before you can learn anything at all from it. Whether it holds a SOC 2 report is something we cannot confirm or deny, and neither can any other public source.

Saru says: Put the trust centre access request in the same email as the demo request. Gated trust centres take days to approve, and an approval that lands after your board meeting is the same as no approval. The request itself is also a test: how fast it is granted tells you something about how the security function is resourced.

What is publicly assertable about Givebutter’s security posture is thin. The privacy policy states that encryption is used and that payment data is handled by PCI-compliant third parties rather than stored on Givebutter’s servers. That is the whole of it. No penetration testing statement, no uptime commitment, no sub-processor list, no breach notification window, no named framework.


The Trust and Safety page answers a different question than you think

Givebutter’s public Trust and Safety page is genuinely useful, and it is aimed at donors. It describes a specialist team that approves accounts and verifies the identity of individuals and nonprofit organisations, a review of every payout for fraudulent activity, fraud signals escalated by support and engineering, and Stripe Radar assessing fraud and blocking carding attempts.

Every one of those is a control against a bad actor using the platform to defraud donors. None is a control protecting your organisation’s data. The page contains one compliance assertion, and it is that Stripe is a PCI-compliant payment processor. That is Stripe’s certification, not Givebutter’s, and it covers card data specifically rather than your donor database.

A small thing that says something larger

While probing for a security page we requested givebutter.com/security. It returns a live page, titled “Emergency Security Upgrade”, which turns out to be a donation campaign run by a registered charity raising money for its own security work. Campaign slugs on Givebutter occupy the root path namespace, so a fundraiser can claim a word like “security” at the top level of the domain.

It is harmless in itself and mildly charming. It is also a reminder that on this platform your campaign URL is a first-come claim on a shared namespace, which is worth knowing if your campaign name matters to you, and worth knowing for anyone who assumes a path on a vendor’s domain is a vendor page.


Where your money actually sits

This is the part of Givebutter that has changed most, and the part most likely to surprise a treasurer. The platform now offers a wallet product that holds settled funds, advertises a yield on balances, and issues spend cards so an organisation can pay for purchases directly rather than transferring to its bank first.

The four parties behind one wallet balance

The disclosure sits in small type in the footer, and it is specific. Givebutter partners with Stripe Payments Company for money transmission services and account services, with funds held at Fifth Third Bank N.A., Member FDIC. The wallet Visa commercial cards are powered by Stripe and issued by Celtic Bank. Givebutter’s own terms state plainly that the company remains solely a platform provider and is not a payment processor, a money transmitter, or a financial institution.

Role Who actually performs it
Money transmission and account services Stripe Payments Company
Where settled funds are held Fifth Third Bank N.A., Member FDIC
Card issuing for the spend cards Celtic Bank
The platform itself Givebutter, Inc., a Delaware corporation

For a finance committee this changes the question from “is the software reliable” to “are we comfortable holding operating cash outside our own bank, in an arrangement between three companies, one of which disclaims being a financial institution”. That is a legitimate thing to be comfortable with. It is not a thing to be accidentally comfortable with because the wallet was enabled by default in a product update.


The privacy policy says two things that both need reading

The summary at the top of Givebutter’s privacy policy says, in plain English, that the company does not sell your data, shares it with trusted partners to provide services, and never trades it for cash or ads. Later in the same document there is a passage about advertising partners that deserves to be read carefully.

What the advertising section actually describes

It states that online data partners or vendors may set cookies, pixels and similar technologies that connect personal information collected from the site with personal information about the same person collected elsewhere, based on their activity on unrelated websites. It states that this may include matching or linking a person’s personal information with their email or home address. It states that these partners then provide the combined information back to Givebutter, which may use it to send marketing to those email or home addresses. The opt-out is hosted at an identity resolution provider’s domain.

Both statements are true at once, and the distinction is real rather than a dodge. Givebutter is not selling data outward. It is receiving enriched records inward. But a nonprofit whose donors land on a Givebutter-hosted donation page should understand that the arrangement described is identity resolution, that it can reach a postal address, and that the plain-English summary would not lead a reader to expect it.

Two smaller clauses belong in the same review. Personal information is listed as a transferable asset in the event that substantially all of the company’s assets are acquired, which is standard and still worth your board knowing. And California and Nevada privacy requests are handled by emailing a general inbox with a specific subject line rather than through a form, which works but leaves you without a receipt.


The fee-coverage programme has a clause about what you may tell your donors

Givebutter’s commercial model rests on optional donor tips, and the company operates a credit programme that covers the payment processing fee on eligible transactions where tips are enabled and the donor chose not to cover fees. It is a real benefit and it is why the platform can describe itself as free.

The terms around it are where the evaluation sits. Participation can be suspended or terminated at the company’s sole discretion. Credits are subject to caps that may be monthly or aggregate, may vary by plan or customer segment, and are published in account materials rather than on the pricing page, so the ceiling is not knowable before you sign. The programme is explicitly described as not insurance, not surety, not escrow, and not a fiduciary undertaking. Offline payments, taxes, penalties, refunds, chargebacks and network assessments are excluded.

And the definition of abuse includes, in the terms’ own words, encouraging donors not to cover fees.

The sentence to put in front of your board

Read literally, a nonprofit that tells its supporters the tip is optional and they need not add it is doing something the terms characterise as misuse of the programme. We are not aware of that being enforced, and we are not suggesting it routinely is. But a charity’s duty to be straight with its donors about where their money goes is not a preference it can contract away comfortably, and a board that reads this clause should decide deliberately how it will talk to donors about tips rather than discovering the tension later.

Faz says: This is the clause to take to your board, not the liability cap. The cap is standard across the category. A term that shapes what you are allowed to say to your own donors about your own fees is not standard, and it is the kind of thing a trustee will want to have decided on rather than inherited.


Company viability, in the company’s own figures

Givebutter publishes more about itself than most of this category, on its about page and in its careers material. These are the company’s own numbers, marked as accurate to April 2026: founded in 2016, more than 170 team members, more than ten million people described as changemakers on the platform, and more than ten billion dollars donated through it. The team is fully remote across roughly 25 states and eight countries, organised around ten hubs. The company is Givebutter, Inc., incorporated in Delaware.

No funding history, ownership structure or investor list is published anywhere we could reach, so the usual viability questions cannot be answered from the site. For an organisation planning to run its receipting through this platform for several years, ownership and runway are fair questions to ask directly, and the absence of an answer on the website is not itself a concern.

One small freshness note, offered as an observation rather than a finding: the site footer carried a 2025 copyright line when we read it in September 2026. It signals nothing about the company’s health. It does mean a reader checking whether a page is current cannot use the footer to do it.


What we would settle before signing

None of this makes Givebutter a bad choice, and for a small organisation the economics are genuinely hard to beat. These are the specific gaps between what is published and what a nonprofit board needs on the record.

Ask for Why it matters
Trust centre access, requested on day one It is gated and unlinked, and approval is on your critical path
The current fee-credit caps, in writing They are published only inside your account, so you cannot see them before signing
A sub-processor list with change notification Neither is published anywhere public
Clarity on what you may tell donors about tips The terms treat discouraging tips as abuse of the credit programme
A written data export and offboarding procedure The liability cap means recovery of lost records is your problem alone
A decision on whether to enable the wallet It moves operating cash outside your own bank, through a three-party arrangement
Your insurer’s view of the $100.00 cap Your cover, not the vendor’s contract, is what actually stands behind a failure

How we did this and what we did not do

We have not run a campaign on Givebutter. This is a company evaluation built from published material and contract text, not a product test. Everything above was read from Givebutter’s own pages on 11 September 2026 by following their navigation and footer, plus a probe of trust-centre hostnames, a search of their public help centre, and a direct request to the paths their navigation does not list.

We did not request access to the trust centre, so we make no claim about what it contains in either direction. Where we could not establish something we have said we could not find it, which is a different claim from saying it does not exist, and only one of those two is supported by what we did.

Faz - founder of AIToolsBakery

Written by

Faz

Faz is the founder of AIToolsBakery. Some tools here are tested hands on. Others are assessed from vendor documentation and pricing verified on the live page, and every review says which one it is. Sponsors can buy a position in a guide. They cannot buy the score, the criticism, or silence about a better option.

How we test and how we make money →

Frequently Asked Questions

What is Givebutter’s liability if something goes wrong?
Does Givebutter have a SOC 2 report?
Is the Givebutter Trust and Safety page a security page?
Who actually holds the money donated through Givebutter?
Does Givebutter sell donor data?
Can a nonprofit tell donors not to leave a tip?
What are the fee-coverage caps?
Is Givebutter a stable company to build on?
ShareLinkedIn
Faz
Faz
The Baker
Faz is the editor and founder of AI Tools Bakery, where every AI tool review is built on verified vendor pricing, documented user reports, and published product records. 10+ years in digital marketing, now covering AI software across 19 industries with honest verdicts and no pay-to-win rankings.
Scroll to Top