Who this covers
Operation Surprise Attack is a registered 501(c)(3) nonprofit organization, EIN 87-3484307, based in Perrysburg, OH. This policy covers https://operationsurpriseattack.org and the forms on it. It does not cover other companies' websites we link to, including our social media pages and the services that process donations.
Last updated September 17, 2026.
What we collect
We only collect what you type into a form. There is no account to create and nothing is collected in the background.
The contact, volunteer and partner forms ask for your name, email address, an optional phone number, and whatever you write in the message box.
The newsletter signup asks for your email address only.
The donation form asks for your name, email address, an optional phone number, an amount, and an optional note. It does not ask for card or bank details.
The recipient application asks about the child: their full name, birthdate, grade, school, interests, diagnosis and treatment, a short bio, and photos. It asks four questions about how often the family has worried about affording groceries, bills, housing and transportation. It asks for the parent or guardian's name, phone number, email and address. If you are referring a child who is not your own, it also asks for your name, email, phone number and how you know the child.
Information about children
This is the most sensitive information we hold, and we treat it that way.
A parent or guardian, or an adult referring the child, submits it, not the child. We do not knowingly collect anything directly from a child under 13.
We use a child's first name, age, diagnosis and favorite things to build the campaign flyer that goes to schools, because that is what lets a classroom make a card meant for that specific child. When a parent or guardian applies, the application asks for their explicit permission before we do this. When someone else refers a child, we get that permission from the parent or guardian before we share anything. That permission is the only basis on which we share it.
We do not publish a child's last name, street address, hospital room, or any other detail that would let a stranger find them.
You can withdraw permission at any time by emailing us. We will stop using the information, and we will ask the schools involved to do the same, though we cannot pull back cards that are already in the mail.
What we do with it
We use what you send to answer you, to run the card campaign you applied for, to arrange a delivery, to schedule volunteers, to thank donors and issue donation receipts, and to send campaign news to people who asked for it.
We do not sell your information. We do not rent it, trade it, or hand it to advertisers. We do not use it to build a profile of you.
Who sees it
Our board members and the volunteers working on a campaign see what they need to do their part. Everyone on the team is expected to keep it confidential.
What you send through a form on this site is stored in the contact system we use to reply and keep track of conversations, GoHighLevel (also known as LeadConnector). It holds that information on our behalf under its own privacy policy and security standards, and the replies we send you go out through it.
A recipient application, including its photos, may also be emailed to our own inbox through the email service Resend, which handles it under its own privacy policy and security standards.
Schools and youth organizations taking part in a campaign receive the flyer described above, and nothing else.
We will hand information to law enforcement or a court only if the law requires it, or if we believe a child is in immediate danger.
Donations and payment details
We never see or store your card or bank details. Donations are processed by PayPal, Venmo, Cash App, or Zeffy, and each of those handles your payment information under its own privacy policy and security standards.
What reaches us is the record of the gift itself: who gave, how much, and when. We keep that because a nonprofit has to account for its income.
Cookies and tracking
This site sets no cookies of its own. It counts page views with Vercel Web Analytics, which records the page visited, the site you came from, and a rough country and device type. It uses no cookies and keeps nothing that identifies you or follows you between visits.
There is no Google Analytics, no advertising pixel, and no social media tracking script. There is no consent banner because nothing here needs your consent.
Our web host keeps standard server logs, which include the requesting IP address, for security and troubleshooting.
How long we keep it
We keep a campaign application while we are running or following up on that child's campaign, and afterwards in our own records, because families often come back to us and because a nonprofit has to be able to show what it did.
We keep donation records for as long as our accounting and tax obligations require.
Newsletter signups stay until you unsubscribe. Every email we send has an unsubscribe link.
If you want your family's information removed from our records, email us and we will remove what we are not legally required to keep.
Your choices
You can ask us what we hold about you, ask us to correct it, ask us to delete it, or withdraw permission you gave earlier. Email us and we will handle it ourselves. We will not charge you for it and we will not make you jump through hoops.
Changes to this policy
If we change how we handle information, we will update this page and change the date at the top. If the change is significant and affects families already in a campaign, we will contact them directly.
Contact us
Questions about this policy, or about information we hold, come straight to us.
Email support@operationsurpriseattack.org or call (567) 331-2162. You can also write to Operation Surprise Attack, 27072 Carronade Drive, Suite A #307, Perrysburg, OH 43551.

