Pagoda Blog

Are Crowdfunding Sites Safe? How to Protect Your Data When Donating Online

September 7, 2023

Crowdfunding has become one of the most popular ways to raise money for a cause, from funding an individual’s healthcare costs to helping a nonprofit launch a new community program. In 2022 alone, there were 6,455,080 worldwide crowdfunding campaigns and in North America, crowdfunding sites raise an average of $17.2 billion every year. Crowdfunding is especially popular during times of crises, like in the aftermath of a natural disaster


While the percentage of fraudulent crowdfunding campaigns (referred to as ‘crowd-thieving’) remains small, it’s always important to provide payment information online with caution. There are a few simple tips you can follow when deciding whether to donate to a crowdfunding campaign: 


1. Only give to organizations and individuals that you know 

This goes for any form of online-giving. When you receive an email in your inbox asking you to donate to a charity, make sure you recognize the sender. Did you sign up for this organization’s email list? 


If you see an ad on a website asking for donations, first research the organization and the fundraising campaign by opening a new tab and conducting an independent online search. If you can find information about the fundraising campaign on the organization’s website or social media outlets, then you can pretty safely assume it’s a legitimate cause. 


If you don’t recognize the organization, however, you should do a little more digging to verify that the nonprofit is listed on either Charity Watch, Charity Navigator, or BBB Wise Giving Alliance. It’s important to note that mostly larger organizations are listed on these sites, but if it’s a smaller organization asking you for donations, then odds are it’s based in your community and you or someone you know is familiar with its work.   


2. Check to see how the funds will be used 

Crowdfunding campaigns should clearly state where raised funds will be directed (either to an organization or an individual) and how exactly the funds will be used. The more transparent they are, the better. 


3. Don’t click on graphic images or sensationalized pleas

Scammers will often create highly dramatized pleas for help, including graphic images of violence and destruction to tug at our heartstrings. Often, however, these images aren’t real and are actually AI-generated.  


4. Be wary when handing over sensitive information 

Before you enter sensitive information like your credit card number, name, email, and home address, verify that the website can be trusted. First, check to see that the domain is in fact associated with an organization that you know and trust. Second, look to see that the domain has HTTPS in the address, ensuring at least a basic level of encryption. Third, look for a privacy policy that states how your information will be stored and used.  


5. Only donate on crowdfunding sites you can trust

Not all crowdfunding sites have the same rules and regulations or privacy policies and cybersecurity practices. Consider only donating to well-established crowdfunding sites that have a reputation for protecting their users from fraudulent campaigns and with transparent, comprehensive privacy policies in place. 


Let’s take a look at 4 of the most popular crowdfunding sites and how their security policies stack up: 


Security policies of 4 popular crowdfunding sites



Indiegogo’s Trust & Safety Policy boasts around-the-clock monitoring of their network to protect your payment information and prevent unauthorized access. They verify the identity information of each campaign creator to help prevent fraud. They closely monitor campaigns, using both automated systems and manual reviews. They also provide helpful tips for reviewing campaigns before you donate. You can find a more detailed outline of how they protect both the ‘backers’ and the ‘entrepreneurs’ under their Terms of Use



GoFundMe has been in the crowdfunding game since 2010, helping people and organizations raise billions of dollars worldwide. This level of experience helps to ensure the safety of your information - GoFundMe is a well-established company and is a leader in the crowdfunding space. 


According to GoFundMe, fraudulent fundraisers make up less than one-tenth of 1% of all fundraisers on the platform. Fraudulent fundraisers most often take the form of a ‘copycat’ campaign that basically copy and pastes word-for-word the language used in a successful GoFundMe campaign. The platform, however, is constantly monitoring for these copycats and uses tools to compare images and text that allow them to quickly spot and remove these campaigns before any money has been collected. 


They also put their Trust & Safety policy front and center on their homepage, encouraging users to see how they prioritize your privacy. This is a great example of how to leverage cybersecurity as a competitive edge for your business



Mightycause is exclusively for nonprofits who are launching fundraising campaigns. They state up front on their Terms and Privacy page what information they ask users to provide and how they use that information. They go to great lengths to clarify exactly what is expected of registered charities and personal causes and how payments are processed. They include multiple ways to contact their ‘privacy coordinator’ should you have any questions.  



Patreon has a very comprehensive privacy policy page that details what information they collect, how it’s used and shared, and how they comply with state, federal, and global regulations. They also make it easy to contact a data protection officer should you have any questions or concerns regarding data privacy. 


Is crowdfunding a safe way to donate? 

Overall, crowdfunding is a safe way to donate to causes you care about but you should always stay vigilant when providing payment information online. The above crowdfunding sites are all well-established, reputable, trustworthy sites. If it’s a platform you don’t recognize, take the time to look for transparency and accessibility. You should easily be able to understand how your data is stored, shared, and protected and find a direct contact to someone who handles data privacy should you have any questions.    

Feature photo by Katt Yukawa on Unsplash

Related reading: 

How to Avoid Online Scams for Disaster Aid 

What to Do If You Receive Blackmail in Your Inbox
LinkedIn Scams and How to Spot Them 


Want to get more posts like these once a month in your inbox? Sign up for the Pagoda newsletter and sharpen your technical skills, from cybersecurity to digital marketing



Want IT to serve you better?







About Pagoda Technologies IT services

Based in Santa Cruz, California, Pagoda Technologies provides trusted IT support to businesses and IT departments throughout Silicon Valley, the San Francisco Bay Area and across the globe. To learn how Pagoda Technologies can help your business, email us at to schedule a complimentary IT consultation.

Return to Pagoda Blog Main Page

As your trusted IT service partner, Pagoda Technologies is here to help you achieve your near and long-term business goals through reliable and affordable IT support. 

Pagoda Technologies

101 Cooper Street

Santa Cruz, CA 95060


Contact us for a free IT consultation



Get in touch 

Join our newsletter

Want IT to serve you better? 




Follow Us

Facebook LinkedIn LinkedIn