Privacy Policy
Your information, held to a higher standard.
RescueBeacon is built on trust: supporters must trust that their giving and personal information are handled with care, and rescues must trust that the sensitive documents they share for verification go nowhere else. This policy explains what we collect, why, and how you can control it.
1What we collect
From supporters: the name, email, and password (stored only as a one-way hash) you provide when creating an account, plus whatever profile information you choose to add — a display name, username, bio, location, and avatar image. We also record your activity on the Service: rescues you follow, flares you share or save, and discovery interactions, so we can show you a useful feed and earn badges for your participation.
From rescues (public): your organization's name, description, location, website, and the flares and outcomes you post. This is the public record described in the Terms of Service, and it is permanent.
From rescues (confidential): the EIN and the documents you submit during application for verification. Your EIN is encrypted at rest before it is ever stored. These materials are used only for verification and our legal compliance — they are never shown on your public profile and are never sold or shared with third parties.
From everyone: technical information needed to run the Service — your IP address (used for security and abuse prevention, and recorded with consent records), browser and device type, and basic analytics.
2How we use information
- To operate the Service: accounts, profiles, feeds, flares, and outcomes.
- To verify rescues: confirming their deductible tax status (501(c)(3) or 170(c)(1)) using the confidential materials above.
- To send account email: verification emails, and — only if you opt in — updates.
- To keep the Service safe: fraud prevention, moderation, and abuse detection.
- To fulfill legal obligations, including donation and payment record-keeping.
We do not sell your personal information. We do not use it for advertising, and we do not share it with third parties except the service providers who help us operate (hosting, email delivery, payment processing), who are bound by contract to use it only for those purposes.
3Consent records
When you agree to the Terms of Service — at signup, or when applying as a rescue — we record a time-stamped consent record containing your account identifier (or, for applications without an account, your email address), the version of the Terms you agreed to, the surface where you agreed, and your IP address. We keep these records so that both you and we can always establish what was agreed and when.
4The public record and its 3-year retention
As described in Terms of Service Section 6, a verified rescue's public profile — its name, history, flares, and outcomes — is retained for 3 years after the organization leaves the Service, then removed. This is a transparency commitment to supporters, and it also means that the public information a rescue posts is not private information under this policy.
The confidential verification materials described in Section 1 are not part of the public record and are covered by the deletion rights in Section 5.
5Your rights: access, correction, deletion
You may access and correct most of your personal information directly from your account settings. You may also contact us at any time at support@rescuebeacon.org.
Deletion. You can request deletion of your personal data — including the documents you submitted during application and the personal information tied to your supporter account — from your dashboard (“Request deletion”) or by writing to support@rescuebeacon.org. The request goes to our review queue; when it is approved, we send a confirmation email and delete the data. We will honor requests in a reasonable time, subject to legal obligations (such as donation and payment record-keeping, which we must retain). Where deletion is limited by law, we will tell you exactly what we kept and why.
What cannot be deleted: the public record of a verified organization during its 3-year retention period (Section 4), and records we are required by law to keep. Deactivating a supporter account hides it from other users without destroying it, so nothing is lost if you reactivate.
6Children
RescueBeacon is not directed at children under 13, and accounts and donations require users to be at least 18. If you believe a child has provided us personal information, contact us at support@rescuebeacon.org and we will delete it.
7Data security and retention
We use encryption in transit (HTTPS) and at rest for sensitive data such as EINs, restrict internal access to personal information to people who need it, and apply standard security practices to our hosting. No system is perfectly secure; we will notify you promptly if we discover a breach affecting your personal information.
Retention. We keep personal information only as long as needed for the purposes described here, plus any period required by law. Specifically:
- Supporter accounts are deleted on approved request; donation and payment records are retained as required by law.
- Verified rescue public records are retained for 3 years after the organization leaves the Service, then removed (Section 4).
- Consent records are kept for the life of the platform so that what was agreed — and when — can always be established.
- Email and audit logs are kept for operational and security purposes.
8Changes to this policy
We may update this policy as the Service evolves. The current version is always posted here with its effective date, and we will notify you of material changes. Your rights to access, correct, and delete your personal data are never reduced retroactively.
9Contact
Privacy questions, data requests, and deletion requests go to support@rescuebeacon.org. We aim to reply within a reasonable time, and we will never penalize you for asking.