JITPOMI · Impact Reports
Privacy — Impact Reports
Effective date: October 3, 2026 · Provider: JITPOMI LLC
Impact Reports is provided by JITPOMI LLC. Samson Ssali handles privacy concerns sent to dev@jitpomi.com. Contact dev@jitpomi.com with privacy questions.
What the app handles
Site owners provide organization information, report titles, summaries, public document links, cover images, reviewed report transcripts, and donation links. These are intended for public display. Do not add confidential documents or personal information that you do not have permission to publish.
Automatic readable text
Report Studio can extract embedded text from PDF and DOCX documents. Scanned PDF pages can be recognized using Tesseract.js in the editor’s browser. OCR language models and program resources are downloaded from their public hosts; document pixels are processed in the browser. Draft text is not published until the site owner accepts it and saves. Review names, figures and reading order against the original. The app does not automatically send document contents to an AI transcription service.
Public report pages
Site owners can enable a public HTML report library hosted by Cloudflare. It contains the organization details, summaries, public document links and any supplied report text, so browsers, search engines and automated readers can access it without running JavaScript. Disabling this option stops the app from serving that page; search engines may retain earlier copies until they revisit it. Do not enable it for private information.
Engagement reporting
When the site's analytics consent allows it, the app records report opens, successful reader loads, page views, download actions, share actions, giving-link clicks, and reader errors. Stored observations contain an event ID, action, report ID, year, format, optional page number, share method and button placement, plus Wix creation timestamps. They do not contain visitor names, email addresses, payment details, document contents or search text.
Wix access tokens identify the site installation and caller when communicating with the app backend. Caller identity is used temporarily for request validation and burst limiting; it is not added to engagement records. Wix and hosting providers may process network metadata and technical logs under their own policies.
Donation checkout attribution
If the site owner enables report checkout attribution, donors choose an amount and explicitly agree to link their donation to the report before continuing to Wix checkout. The app stores the report ID, checkout ID, campaign ID, requested amount and attribution-consent choice in a protected Wix app collection. Wix processes checkout and payment details. Authorized dashboard users can verify matched orders and payment/refund records. Wix may return donor details with those records; the app does not store or display donor names, emails or payment credentials in its attribution report. Verification currently runs when an editor requests it, rather than through automatic payment notifications. Standalone public-reader donation links are not matched to completed payments.
App permissions include Manage Orders and Manage Donation Campaigns. The app uses them to create donation checkouts and read campaign, order and payment records; it does not charge or refund payments itself. Attribution mappings follow the same owner-managed retention approach described below.
Storage and access
Report settings and engagement observations are stored in app collections on the Wix site. Public report settings are readable by site visitors. Engagement records are readable by authorized site editors and writable only through the app's validated backend. Site owners can export engagement summaries and manage collection data through Wix CMS. Records are not automatically deleted on a fixed schedule in this release; site owners should manage retention appropriate to their organization. Removing a report does not delete its earlier engagement observations.
Other services
Cloudflare hosts the public report pages and app support pages and handles authenticated reporting requests. Access tokens are used in transit to validate requests against Wix and are not stored as engagement records. Public libraries are read from the selected Wix installation using the app’s credentials, stored as an encrypted hosting secret. Engagement records are not returned by these public pages.
Documents and covers are fetched from the public URLs the site owner supplies, including Wix Media Manager. The PDF reader loads pinned PDF.js resources from jsDelivr. Downloading, sharing or opening the giving page can send the visitor to the relevant external provider. Optional Wix Analytics events require both analytics and third-party data consent. Optional Wix Donations campaign metrics are requested using the authorized dashboard user's permissions and do not contain donor-level records in this app.
Your choices
Visitors can use the site's consent controls. Reading does not require accepting analytics. Site owners are responsible for the notices and permissions required for their own published reports and visitor analytics. Contact the site owner for requests about its reports or engagement records; contact JITPOMI for app support or privacy concerns.
Changes
We will update this page when data handling changes and identify the effective date of the updated version.