New Arc Collective / Draft for legal review

Privacy Policy

Draft — owner and legal review required before publication.

This draft is not legal advice or a claim of legal compliance. It describes practices identified during an application review, which must be confirmed for the production service.

Initial draft. Effective date pending review.

New Arc Collective is a nonprofit corporation registered in Nevada. Its IRS status is pending. This notice describes information handled through this website and the services available here, based on the application’s current implementation. It does not determine which privacy laws apply.

Information we receive

  • Contact messages: names, email addresses, and message text you send through the public contact form. The application sends these to New Arc Collective’s designated email recipient through Resend; the application does not save the message body in its own database. A separate abuse-prevention record contains derived email and network-address identifiers and attempt timestamps. Old attempt records are removed when a later reservation runs cleanup; records may remain longer during inactivity.

  • Member accounts: identity and account information supplied through Clerk sign-in, including verified email, name, and account/profile image where provided. Member records may also contain profile names, an optional U.S. ZIP code and its general city/state lookup, membership status, role, newsletter preference, and related timestamps. The ZIP lookup is requested from Zippopotam.us when a ZIP code is submitted or changed; coordinates and ZIP+4 are discarded by this application.

  • Newsletter preferences: email address, subscription state, and consent/verification timestamps. New verified member registrations are enrolled in email updates by default as disclosed during registration. Existing opt-outs are preserved. The separate newsletter-only subscription form requires an affirmative choice and email confirmation.

  • Reports and member content: information or files a member or administrator chooses to submit for the member service. Publicly shared reports may be visible to anyone. External report links and embedded third-party report sites are controlled by their respective publishers.

  • Team pages: administrators can publish names, roles, biographies, and uploaded portraits or external portrait URLs. Published Team details are visible to anyone. Uploading a portrait stores a file for use in a draft; it does not itself publish the Team page. No general portrait-file retention period has been approved.

  • Policy administration: private audit records of policy-editor changes contain the administrator’s internal application identity, the action, the policy revision, and a timestamp. These are used to track policy saves, publication, and draft discards; actor identities are not exposed in public policy responses.

  • Operational information: the hosting and security infrastructure may process request and diagnostic information. The application also uses rate-limiting records to protect public forms and subscription endpoints.

How information is used and shared

Information is used to provide account access, maintain membership and preferences, respond to contact requests, deliver requested community-update emails, protect the service from abuse, and operate the website. Service providers used by the application include Clerk for authentication, Resend for email delivery, and Zippopotam.us for an optional ZIP-to-city/state lookup. The web host and database provider also process information to operate the service. Their current terms, locations, subprocessors, and retention practices have not been established in this review and should be confirmed with each provider.

The Figtree typeface is hosted with this website under its Open Font License; displaying the font does not make a runtime request to Google Fonts. Signing in contacts Clerk for authentication and security, and a security challenge may be provided by Cloudflare. Clerk’s optional browser telemetry is disabled in this application. Authentication and challenge providers may still receive connection information needed to provide or protect the requested service. Member report viewers require permission for third-party report embeds before requesting the publisher’s website; that site may process the visitor’s request under its own notice. Follow external links only if you are comfortable with that site’s practices.

The application does not contain a configured advertising tracker or third-party behavioral advertising integration. Optional first-party analytics, if enabled by your browser choice, count selected events by UTC calendar day without storing a visitor identifier. They are not required for account access.

Storage and retention

Externally hosted Team portraits require the same optional external-content permission as report embeds, including in the administrator editor. A portrait host receives your IP address and browser connection information when an allowed image loads. Local and uploaded portraits do not contact an external portrait host. Withdrawing permission removes external image sources and restores local placeholders, but cannot undo requests already received by a host.

Application data is stored in the service database and by the service providers described above. A member account deletion disables the account and newsletter and requests deletion from Clerk, but the application retains a historical membership record; this flow is not a complete erasure of all application records. This review did not identify an approved general retention schedule for member, newsletter, report, administrative policy-audit, provider, backup, or log data. Do not infer that records are removed after a particular period.

An invitation-data minimization process is documented for records older than 90 days, but its production gates require separate owner approval. Its production status was not verified for this notice; it is not a promise that invitation records are currently being purged. Application cleanup does not remove copies retained by backups, logs, email providers, or recipient mailboxes.

Your choices and requests

You can manage email-update preferences through the link provided in the service and can unsubscribe from community-update email. Optional analytics and third-party report embeds can be declined or changed in cookie preferences. Account profile controls allow changes to some profile fields. For a privacy question or to request access, correction, or deletion, contact privacy@newarccollective.org. We will review requests in light of applicable requirements and records that the service retains. This draft does not promise a particular legal right, deadline, or outcome.

Children and audience

The organization has not provided a confirmed intended-audience age policy or jurisdictional scope for this draft. Obtain owner and legal review before making any age-related or geographic privacy claims.

Changes and contact

When this notice is finalized, New Arc Collective should add its effective date and update it when relevant data practices change. Questions about this draft or privacy practices may be sent to privacy@newarccollective.org.

Contact us about privacy