Introduction
Youth Save A Smile Foundation is a non-profit youth organization registered in Bangladesh, dedicated to education, community development, health awareness, and youth empowerment. Our website and member administration portal are operated solely for organizational purposes.
By using our website or admin panel, you agree to the collection and use of information as described in this policy. If you do not agree with any part of this policy, please discontinue use of our services.
Information We Collect
We collect information in the following ways:
Information you provide directly:
- Full name, Bengali name, date of birth, blood group
- Email address and mobile phone numbers
- Residential address (district, upazila, union, village)
- School/institution name, batch year, joining date
- Profile photo and signature image
- Social media profile links (Facebook, LinkedIn, Instagram)
- Parent/guardian names and their professions
- Skills, hobbies, and organizational affiliations
- Donation details including amounts and payment methods
- Messages submitted through our contact form
Information collected automatically:
- IP address and browser user agent (for security and spam prevention)
- Pages visited and timestamps (visitor logs)
- Session data during your logged-in activity
Information from third-party services:
- If you connect your Facebook account, we receive your Facebook User ID, display name, and profile picture URL via the Facebook Graph API
How We Use Your Information
We use the information we collect strictly for the following purposes:
- Managing member registration, profiles, and membership status
- Tracking monthly fee payments and generating receipts
- Organizing and managing events and volunteer participation
- Issuing certificates of participation and service
- Communicating important organizational updates via email
- Responding to contact form inquiries and support requests
- Maintaining blood donor records for community health initiatives
- Generating anonymized statistical reports for internal planning
- Improving our website and services based on usage patterns
- Preventing fraud and unauthorized access to our systems
Facebook Login & OAuth Integration
Our member portal offers an optional Facebook account connection feature. This integration is provided solely to allow members to use their Facebook profile picture as their member photo. It is entirely optional and not required to use the portal.
What we access when you connect Facebook:
- public_profile — your Facebook name and profile picture only
- We do not access your friends list, posts, messages, email, or any other Facebook data
What we store:
- Your Facebook User ID (to identify the connection)
- A short-lived Facebook access token (to retrieve your profile picture on demand)
- The date and time you connected your account
- If you choose "Use as Profile Photo", the image is downloaded and saved locally to our server — the Facebook URL itself is not permanently stored
This integration uses the Facebook Graph API v23.0. Facebook's own data practices are governed by Meta's Privacy Policy.
Data Sharing & Disclosure
We do not share your personal data with external parties except in the following limited circumstances:
- With your consent: We may display your name, photo, and committee position on our public website as part of the committee directory, if you or an authorized admin has enabled this
- Legal obligations: If required by applicable Bangladeshi law, court order, or government authority
- Service providers: We use PHPMailer with our SMTP provider to send you emails. Email content may pass through their servers but is not stored or used by them for other purposes
- Cloudflare Turnstile: Used on our contact form for bot prevention. Cloudflare processes a minimal fingerprint to verify human visitors. See Cloudflare's Privacy Policy
Internal access to member data is role-restricted. Only authorized roles (Master Admin, Central Office Secretary, batch-level officers) can view specific member records based on their access level.
Data Storage & Security
Your data is stored on secured servers. We implement the following technical measures to protect your information:
- Sensitive fields (email, mobile number, address, date of birth, and family details) are encrypted at rest using AES-256 encryption before being stored in our database
- Searchable fields use a separate one-way hash (SHA-256) to enable lookup without exposing raw values
- Passwords are hashed using PHP's
password_hash()with bcrypt — never stored in plain text - Session-based authentication with "remember me" tokens stored securely
- Role-based access control (RBAC) ensures members only access data they are authorized to see
- OTP-based password reset with rate limiting and immediate token invalidation after use
Cookies & Tracking
Our website uses cookies and similar technologies for the following purposes:
- Session cookies: Required for login sessions and maintaining your authenticated state in the member portal. These expire when you close your browser or log out
- Remember-me cookies: If you enable "Remember Me" on login, a secure token is stored in your browser for extended sessions. You can clear this by logging out
- Visitor analytics: We log IP addresses and page visits in our own database for basic traffic analysis. We do not use Google Analytics or any third-party analytics platform
We do not use advertising cookies, tracking pixels, or cross-site tracking technologies.
Your Rights
As a member or user of our services, you have the following rights regarding your personal data:
- Access: You can view your own profile information at any time through the member portal
- Correction: You can update your personal details (email, phone, address, social links, blood donation status, profile photo) directly from your profile settings
- Disconnection: You can disconnect your Facebook account at any time from your settings page
- Deletion: You may request deletion of your account and personal data by contacting us. Note that some records (event participation, fee history) may be retained for organizational record-keeping as permitted by law
- Objection: You may object to certain uses of your data by contacting us in writing
To exercise any of these rights, please contact us at saveasmile.fd@gmail.com.
Children's Privacy
Youth Save A Smile Foundation serves youth members. Our member portal is designed for use by individuals who are members of our organization. We collect member data as necessary for organizational management.
For members under 18, we encourage parental awareness of their participation. We do not knowingly collect data from children for commercial purposes, and we do not display minor members' personal contact details publicly.
The Facebook connection feature is only accessible to logged-in members through the internal portal and is not promoted to or accessible by the general public.
Third-Party Services
Our platform integrates with the following third-party services. Each has its own privacy policy which governs their data handling:
- Meta (Facebook Graph API) — Optional member profile picture connection. Meta Privacy Policy →
- Cloudflare Turnstile — Bot prevention on public contact form. Cloudflare Privacy Policy →
- PHPMailer / SMTP — Email delivery for notifications, OTP, and receipts. Emails are transmitted securely via TLS
- Google Maps — Embedded map on our contact page for location display only. No personal data is shared with Google through this embed
- Font Awesome — Icon library loaded from CDN. No personal data is collected or transmitted
Data Retention
We retain your personal data for as long as your membership is active and for a reasonable period afterward for record-keeping purposes:
- Active members: Data is retained for the duration of active membership
- Inactive / left members: Core profile data is retained indefinitely for organizational history and alumni records, unless a deletion request is made
- Contact form submissions: Retained for up to 2 years for follow-up and correspondence purposes
- Visitor logs: IP and page visit logs are retained for up to 90 days for security analysis
- Facebook tokens: Stored until you disconnect your Facebook account or your membership is deleted
- Fee and donation records: Retained indefinitely for financial accountability and audit purposes
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will update the "Last Updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of our website or member portal after changes are posted constitutes your acceptance of the updated policy.
For significant changes that affect how we process your data, we will notify active members via email.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:
- Email: saveasmile.fd@gmail.com
- Email: adminpanel@saveasmilefd.org
- Phone: +880 1853 808713
- Address: Milonpur, Khagrachari Sadar, Khagrachari, Chittagong Hill Tracts, Bangladesh
We aim to respond to all privacy-related inquiries within 7 business days.
Have a privacy question?
Our team is happy to help clarify how we handle your personal information.