What we collect
- Contact-form data. When you use the contact form on this site, the form opens a draft email in your local mail client. HROC receives whatever you choose to send to admin@hrocinc.org. We do not store or process the data through a server-side form handler — the data leaves your device only when you press send in your own mail client.
- Server access logs. Our hosting provider records standard web-server access information (IP address, browser type, time of request, URL requested). This is used for spam prevention, abuse mitigation, and traffic analysis. Logs are retained for up to 90 days.
- Donor information. Online donations are processed through third-party platforms (Every.org and/or our payment processor). Those platforms collect donor name, email, and payment details under their own privacy policies. HROC receives donor name, donation amount, donation date, and donor email address only for tax-receipt and acknowledgment purposes. We do not receive payment card information.
- Mailed donations. If you mail a check, we retain donor name, mailing address, amount, and date for acknowledgment, tax-receipt, and record-keeping purposes required of 501(c)(3) organizations.
What we do not collect
- We do not collect personally identifying information from people receiving direct services in the field. Outreach is anonymous; service interactions do not require ID, identification, or registration.
- We do not knowingly collect data from children under 13. If you believe a child has provided data through the site, contact us and we will delete it.
- We do not sell, rent, or trade personal information.
- We do not deploy advertising trackers, social-media pixels, or behavioral retargeting on this site.
Cookies and analytics
This site uses only the minimum technical cookies required by the hosting provider for security and abuse prevention. We do not currently run third-party analytics on this site. If we add analytics in the future (for example, a privacy-respecting tool like Plausible or Fathom), we will update this policy and the site will display a notice.
Third-party services we rely on
- Hosting + CDN: Netlify and Cloudflare for static-site delivery; Amazon Web Services S3 and Backblaze B2 for image and document hosting.
- Email: Google Workspace for our staff email infrastructure (admin@hrocinc.org and related addresses).
- Donations: Every.org for online charitable contributions. Donor data submitted there is governed by their privacy policy at every.org/privacy.
- Fonts: Google Fonts (Inter, Fraunces) for typography.
Each of these providers has its own privacy practices. We choose vendors with strong data-protection commitments, but we cannot control their internal operations.
Your rights
If you are a Washington resident, a California resident, an EU resident, or any individual who has shared data with HROC, you have the right to:
- Request a copy of the data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data, subject to legal record-keeping requirements (donor records for 501(c)(3) tax purposes are retained as required by the IRS).
- Opt out of any future marketing communications.
To exercise any of these rights, email admin@hrocinc.org with the subject line "Privacy Request." We respond within 30 days.
Data security
We protect data at rest and in transit through standard industry practices: HTTPS for all site traffic, encrypted storage on hosting providers, access controls on staff email and donor records, and minimum-necessary data collection. No system is fully impervious to compromise; we will notify affected individuals if a breach occurs that materially affects their data.
Children
This site is not directed at children under 13 and does not knowingly collect data from children. HROC's direct services in the field may serve children indirectly (for example, harm-reduction supplies for families), but we do not collect personally identifying information about minors through this website.
Updates to this policy
We may update this policy as our practices change, as services evolve, or as required by law. The effective date at the top of this page reflects the most recent revision. Material changes will be summarized in a brief notice on the homepage for at least 14 days after the change.
Contact us
Questions about this privacy policy or about how HROC handles your data: