Privacy Policy
Your trust matters to us. This policy explains what data we collect, how we use it, and how we protect it — across the CareHub platform, mobile app, and Volunteer U website.
Information We Collect
We collect information needed to provide CareHub, secure accounts, support organizations, and improve the service.
- Personal information: name, email address, phone number, role, organization, profile photo, account settings, billing contact information, support messages, and invitation details.
- Care and organization information: care requests, People directory records, assignments, availability, follow-ups, care touch notes, conversation threads, attachments, audit logs, and admin settings entered by authorized users.
- Automatic information: IP address, browser and device type, app version, operating system, log timestamps, crash or diagnostic metadata, and security event data.
- Third-party information: billing status from Stripe, authentication data from Supabase, email delivery status from Resend, push notification delivery data from Expo, and hosting logs from Vercel.
How We Use Your Information
- Provide, personalize, maintain, and secure CareHub.
- Authenticate users, enforce role-based permissions, and prevent abuse.
- Coordinate care workflows, follow-ups, team assignments, availability, reminders, and messaging.
- Process billing, manage subscriptions, deliver emails, and send push notifications.
- Respond to support requests, troubleshoot issues, audit activity, and improve product quality.
- Comply with legal, tax, security, and operational obligations.
CareHub Mobile App Data
The CareHub mobile app collects the same account and care workflow data described above when you use app features. This can include profile details, organization membership, care requests, care touch notes, follow-up tasks, availability, Connect messages, attachments, calendar preferences, and notification settings.
Download CareHub for iOS (App Store) or Android (Google Play). Sign in with the same account you use on the web portal.
Authorized users in your organization may see information based on their role and your organization's configuration. Admins and leaders may see care coordination activity, team availability, People directory records, notes, assignments, and reporting needed to manage care.
Camera and Photos
Used only when you choose to upload a profile image or attachment.
Microphone
Used only when you choose to record or attach audio in Connect.
Calendar
Used only when you choose to add follow-up reminders to your device calendar.
Notifications
Used to send care reminders, follow-up alerts, and organization updates you enable.
Biometrics
Used only for optional local unlock. Biometric data stays on your device and is not sent to CareHub.
Files and Documents
Used only when you choose files to attach to messages or care workflows.
Third-Party Services
We use trusted service providers to operate CareHub. These providers process data only as needed to deliver their services to us.
| Service | Purpose | Data Processed |
|---|---|---|
| Supabase | Authentication, database, file storage, and security controls | Account, organization, care workflow, and uploaded attachment data |
| Stripe | Subscription billing and payment processing | Billing contact details, plan details, and payment metadata |
| Resend | Transactional email delivery | Email address, name, invitation, notification, and support email content |
| Expo | Mobile app builds, updates, push notifications, and device services | Device push tokens, app version, crash/update metadata, and notification payloads |
| Vercel | Web hosting, performance, logs, and infrastructure security | IP address, browser/device metadata, server logs, and web request data |
Data Sharing & Disclosure
We may share information in limited circumstances:
- With your organization and authorized users according to roles and permissions.
- With service providers listed above who help us host, secure, bill, notify, and support the service.
- With law enforcement, regulators, or courts when required by law or needed to protect rights and safety.
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.
Data Storage & Security
CareHub stores data using cloud providers with security controls designed for modern SaaS products. We use encryption in transit, access controls, role-based permissions, logging, secure authentication, and operational safeguards. No system can guarantee perfect security, so organizations should also manage user access carefully and remove access when users leave.
Data Retention & Deletion
We retain information for as long as needed to provide CareHub to your organization, comply with legal and billing obligations, resolve disputes, enforce agreements, and maintain security. Organization admins may delete or update many records inside CareHub.
To request account deletion, email support@volunteeru.org with the subject line "Delete My CareHub Account." We will verify the request and delete or de-identify eligible account data within 30 days unless retention is required by law, security, billing, fraud prevention, or your organization's active service agreement.
Your Privacy Rights
Depending on where you live, including under GDPR or CCPA/CPRA, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have the right to opt out of sale or sharing for targeted advertising. CareHub does not sell personal information.
To exercise privacy rights, contact us at support@volunteeru.org. We may need to verify your identity and, for organization-managed data, coordinate with your organization.
Push Notifications
If you opt in, CareHub may send push notifications for follow-ups, care reminders, Connect messages, and organization updates. You can opt out at any time in the mobile app under More - Notifications or through your device settings. Disabling push notifications does not delete your account or stop essential in-app notices.
Children's Privacy
CareHub is intended for use by authorized organization staff, leaders, and volunteers. It is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child provided us personal information, contact us so we can review and delete it where required.
Changes to This Policy
We may update this Privacy Policy from time to time. When changes are material, we will update the effective date and may notify account owners or users through CareHub, email, or the website.
Contact Us
Questions, privacy requests, and account deletion requests can be sent to Volunteer U.