Public listings, private contact
Privacy Notice
This notice explains what becomes public, what remains private, and what the Recovery Hub processes to run the Community Board and Partner Board.
1. Public listing information
Community Board listing text, topic, general area, timing, provider/cost context, and optional public business/provider profile are public. For neighbor needs and offers, the poster chooses either Contact through the Hub or a deliberately public contact route. Community Resource listings publish an official provider/resource contact route. Partner Board listings publish organizational identity and an official organizational contact route. Hub-Verified Partner profiles may also publish organization-managed service descriptions, service areas, locations, hours, operational updates, and official contact routes.
Individual listing pages are marked not to be indexed by search engines, but that is not secrecy. Public information can still be copied, cached, screenshotted, indexed indirectly, or shared elsewhere.
2. Private listing email and Contact through the Hub
A Community poster may provide a private email for listing management. It is required when the poster chooses Contact through the Hub and must be verified before private contact opens. Partner Board listings require a private organizational management email. Private management addresses are not returned by public listing or search APIs and are not displayed on public pages.
When Contact through the Hub is active, a responder provides an email address and a short first message. The Hub sends a one-time verification link to that responder. Only after the responder proves control of the address does the Hub forward the message and verified reply address to the poster. The Hub verifies control of an email address, not a person's identity, intentions, credentials, safety, or offer. If the poster replies directly, the poster's email address is then shared with that responder and further communication occurs outside the Hub.
3. Information processed privately
- Listing and verified-organization management: private management email, representative name and role where verification is requested or established, verification method/status, listing or profile status and dates, terms/consent records, email-delivery timestamps, management-token verification data, match-alert settings, and duplicate-alert suppression records.
- Private contact activation: one-way verification-token data and activation timestamps for a relay-enabled listing.
- Pending first contact: responder name if supplied, responder email, first message, one-way verification-token data, and hashed anti-abuse identifiers while verification is pending.
- Minimal contact events: listing ID, one-way responder/connection hashes, delivery status, and timestamps. Message text and responder email are not retained in the contact-event record.
- Security records: salted one-way hashes derived from connection or email information for rate limiting and abuse prevention. Raw connection addresses are not intentionally stored in the Hub database.
- Reports: listing ID, reason, explanation, optional private reporter contact, and a contact-event reference when a Hub-forwarded message is being reported.
- Provider logs and analytics: Netlify, Supabase, Cloudflare, the transactional email provider, and Umami Cloud may process limited operational, security, or analytics data under their own policies.
4. Search privacy
The Recovery Hub's natural-language search runs in the browser. Freeform search text is kept in the URL fragment where practical rather than sent as a normal query parameter to the hosting server. Legacy search links may be normalized into that format. Search receives a reduced public-safe Community listing payload that excludes public contact values as well as all private management and Hub-contact data. Users should still search with general terms and avoid names, street addresses, account numbers, medical details, or other sensitive information.
5. Why information is used
Information is used to publish and manage listings, forward verified first-contact messages when requested, suggest possible matches between active needs and offers when requested, send operational email, prevent automated abuse, enforce rate limits, investigate reports, remove unsafe or prohibited content, troubleshoot failures, and protect the site and community.
6. Service providers
The Hub uses Netlify for hosting/server functions, Supabase for database storage, Cloudflare Turnstile for bot and abuse prevention, Resend or another configured transactional email provider for listing, contact, and report messages, and Umami Cloud for privacy-focused site analytics. External sites linked from the Hub are governed by their own terms and privacy practices.
Umami is configured to exclude URL fragments from analytics page URLs. That prevents the Hub's fragment-based search text and private management or verification tokens from being sent to Umami as part of the tracked page URL. Ordinary anonymous Umami sessions do not use cookies and are identified by a generated hash based on the visitor's IP address, user agent, and website ID. The Hub also configures the tracker to respect the browser's Do Not Track setting and to run only on the Hub's production domains.
The Hub does not sell personal information, use it for targeted advertising, or operate advertising analytics.
7. Retention
- Active listings remain public until they expire, are resolved, are closed, are hidden, or are removed.
- When explicitly chosen after resolution, a sanitized outcome may appear publicly for up to 14 days without names, contact methods, original details, or the old listing page.
- Inactive Community and Partner listings and associated listing-management records are ordinarily deleted after about 30 days, subject to reasonable safety, fraud, legal, or operational preservation needs.
- Verified organization profiles and representative-authorization records may remain longer than individual listings because they provide continuing organizational ownership and access. Access may be revoked or transferred when a representative changes roles. The Hub retains only the management and verification information reasonably needed to operate that relationship, subject to safety, fraud, legal, and operational needs.
- An unverified message sent through the Hub is intended to expire after about one hour and is removed by automated cleanup after expiration. After successful forwarding, the pending responder email and message content are deleted.
- Minimal contact-event metadata is ordinarily deleted within about 30 days.
- Private match-notification history is ordinarily deleted within about 30 days or when related listing records are deleted.
- Rate-limit hashes are ordinarily deleted within 2 days.
- Reports are ordinarily retained for up to 90 days unless longer preservation is reasonably needed for safety, fraud, legal, or operational reasons.
- Service providers may retain delivery, security, or analytics records according to their own policies.
8. Private links and verification links
A management link acts like a password for a listing or verified organization profile. Its secret token is kept in the URL fragment so browsers do not send it as part of the normal page request. The database stores protected token data used to verify and, where necessary, deliver management links. Contact verification links likewise keep their one-time token in the URL fragment. Poster contact-activation links expire and may be resent from Manage; responder verification links are short-lived.
9. Children
Children should not submit listings or direct contact information. A parent or legal guardian should post on behalf of a minor without publishing the child's name, address, school, phone number, social profile, or other identifying details.
10. Security and limits
Reasonable safeguards include server-only database access, row-level security, token hashing/encryption where applicable, data minimization, rate limiting, and human verification. No website can guarantee absolute security, uninterrupted availability, email delivery, or that public information will not be copied by others.
11. Correction, removal, and questions
Use the private management link to edit, renew, change Community contact privacy, resolve, close, remove, or manage alerts for a listing. If the link is lost and a management email was provided, request a fresh link from the appropriate management page. To report exposed personal information, an abusive Hub-forwarded contact message, or another privacy concern, use the report form or email info@foxvalleyrecovery.org.