Effective Date: January 24, 2020
CaringBridge Inc. ("CaringBridge," "us" or "we") operates the CaringBridge.org website and mobile applications as a free online service (this "Service") to help families and friends stay in touch during a health challenge.
By submitting your personal information to us, you are consenting to the processing of your personal information in the United States. CaringBridge is located in the United States and all data related to the Service and individual Sites (as defined below) is collected and processed by CaringBridge in the United States. Your personal data will therefore be transferred to, processed and stored in the United States which may be outside of the country where you live.
If you are not located in the United States, your local privacy laws may give you certain rights to access information held about you and you may have the right to ask us not to process your personal data for marketing purposes by emailing us at email@example.com.
When you use our Service, you may be creating and maintaining a personal, individual page or website on behalf of yourself or another person (“Individual Site”) or visiting and posting to an Individual Site created by someone else. By their very nature, these Individual Sites contain a great deal of personal information about the subject of the Individual Site and other individuals. For this reason, we allow the creator of an Individual Site to control the level of privacy they apply to their Individual Site. Our goal is to balance our users' need to find each other and communicate information and support against our users' desire for a measure of privacy.
You may increase the privacy of the Individual Site by making it accessible “By Invitation Only.” This privacy setting can be changed at any time during the lifetime of the Individual Site by going to “Site Settings.”
CaringBridge also offers a public search listing feature that allows you to publish portions of your Individual Site to the public Internet. The publicly visible information may include: (1) the first and last name and the subject of the Individual Site; (2) the title of the Individual Site; (3) the profile picture of the Individual Site; (3) the date and time of the first journal post to the Individual Site; and (4) the date and time of the most recent journal post to the Individual Site. This public profile will be indexed and displayed through public search engines when someone searches for your name. You have the option to activate the public profile feature when you initially create an Individual Site or at any time during the lifetime of the Individual Site by going to “Site Settings.”
Every member of a caring community, including the creators of Individual Sites and all users are responsible for maintaining the confidentiality of the website address of an Individual Site in accordance with the subject's wishes.
The lawful basis for collection of the information described in this section is your consent, as necessary to fulfil a contract with you, our legal obligations, and our legitimate business interests.
Information You Volunteer. CaringBridge collects the personal information you and others knowingly and voluntarily provide when you use our Service on our Site or through our mobile application, for example, the personal information you provide when you create or post content on an Individual Site, complete a survey, make a donation, use our "tell a friend" feature, or contact our customer care personnel. "Personal information" means information about an identified or identifiable individual. Examples of personal information include your name, your email address and email username, social media sign-in information, address, credit card information and your photograph.
Google User Information. If you choose to register for or sign into the Site using Google, CaringBridge will access, collect, and store certain personal information associated with your Google User Account, including your first name, last name, email address, and profile picture. Upon request, CaringBridge will also access, collect, and store your contacts.
Credit Card Information. If you provide credit card information through the Service, the information you provide is never stored on our server. Instead, when you click on the "submit" button, it is forwarded immediately to a third-party service provider for processing. We use industry standard Secure Sockets Layering (SSL) software to encrypt all of your credit card information as it travels over the Internet and via wireless methods to our third-party service provider. We do not retain a copy of your credit card information. Our third-party services providers use your credit card information only to process your transaction (and for fraud prevention purposes) and are bound by contract to keep your credit card information confidential.
Information Collected From Your Mobile Device. When using our mobile application, we will collect your device type and the operating system you are using to create aggregate statistics in order to improve our mobile application.
We do not ask you for access or track any location-based information from your mobile device at any time while downloading or using our mobile application or services.
Information Sent to Us by Your Web Browser. We collect information that is sent to us automatically by your web browser and through our mobile application. This information typically includes your IP address, the identity of your Internet service provider, the name and version of your operating system, the name and version of your browser, the date and time of your visit, and the pages you visit. Please check your browser if you want to learn what information your browser sends or how to change your settings. Generally, we do not link the information provided by your browser to information that identifies you by name.
More About IP Addresses. An "IP address" is a unique number that is automatically assigned to your computer when you connect to the Internet. It is used to identify your computer's "location" in cyberspace, so that the information you request can be delivered to you. If you use a dialup connection or a connection that assigns dynamic IP addresses, your computer will be assigned a new IP address each time you connect to the Internet. If, however, your computer is permanently connected to the Internet using a static IP address, the IP address assigned to your computer will generally be the same each time you use your computer.
IP addresses do not include your name, email address or other information that identifies you personally, but in some cases, they can be used to identify you. For example, we may link your IP address to account information that identifies you personally. We may also provide your IP address to our third-party service provider who can use it to identify your state and zip code. This gives us valuable demographic information about the individuals who use the Service. The third-party service provider is bound by contract to use the IP addresses we provide only for this purpose. In addition, if, for example, we suspect fraud or a threat to the security of the Service, we may share our server logs - which contain IP addresses - with the appropriate investigative authorities, who could use that information to trace and identify individuals.
We use "cookies" and other web technologies to collect information and support certain features of the Service on our Site. For example, we may use these technologies to:
Some of these cookies are strictly necessary cookies. These cookies are required for the service to function. The service will not function properly without them. These cookies include session or persistent cookies. Other cookies are not required for the site to operate but provide information that helps us understand usage of our site to provide a better user experience.
Types of cookies we use:
Session cookies: Session cookies are stored on the user’s device temporarily and are deleted when the user ends their session. We use session cookies to pass information back and forth between pages of our application only.
Persistent Cookies: Persistent cookies are stored on the user’s device until they expire, even after the browser is closed. We use persistent cookies for authentication and remember me capability to keep a user from having to login every time they use the site.
Third Party Cookies: Third Party cookies are installed for the user by third parties that track usage and activity information to improve the user experience and provide site usage information for us.
Our third-party tracking-utility and ad network partner uses a software technology called clear gifs (a.k.a. Web Beacons/Web Bugs), that help us better manage content by informing us what content is effective on our Site or on Individual Sites. Clear gifs are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of Web users. In contrast to cookies, which are stored on a user's computer hard drive, clear gifs are embedded invisibly on certain pages on the Site and are about the size of the period at the end of this sentence. We do not tie the information gathered by clear gifs to our customers' personally identifiable information.
The information we collect using these web technologies does not identify you personally. If, however, you have created a user identity, for example by registering, we may link the information we collect using these web technologies to other information that identifies you personally.
If you do not wish to receive cookies, you may set your browser to reject cookies or to alert you when a cookie is placed on your computer. You may also deactivate our cookies as soon as you leave the Service. Although you are not required to accept our cookies when you visit the Service, if you set your browser to reject cookies, you will not be able to use all of the features and functionality of the Service.
We may also use third-party vendors, such as Google Ad Words, Bing Ads and/or Yahoo Gemini, to promote our Services online. These ad network partners may display our promotions or information regarding our Services on other websites based on your internet usage. Any information that these third parties collect via cookies will not be linked to your personally identifiable information.
If you wish to opt-out of targeted promotions based on your internet usage, you may opt-out by going to http://www.networkadvertising.org/managing/opt_out.asp. By completing this opt-out request, you will still receive online advertising, but it will not include targeted promotions based on cookies and online analytics.
Generally, CaringBridge does not use any personal information posted in content on an Individual Site, except to provide our Service to you, your friends and your family. We may use the personal information we collect through the Service:
Google User Information. If you choose to register for the Site using Google, CaringBridge will use your Google User Information to facilitate the registration process. You will have the option to modify or delete any Google User Information pulled into the Site during the registration process.
Survey Information. From time to time, we may post a survey on the Service, if we have your contact information and your consent, we may send you a questionnaire or survey. Your participation in any survey is always voluntary. We compile statistical information from the responses to our surveys. These statistics do not identify you personally. These statistics help us understand the needs and preferences of the groups we serve and improve the content and functionality of the Site as well as Individual Sites.
Email Communications from the Site. We will occasionally send you information about products, services, newsletters and promotions on our Service. You can sign up for these emails from us on our site. Out of respect for your privacy, we present the option not to receive these types of communications. If you no longer wish to receive our newsletter and promotional communications, you may opt-out of receiving them by following the instructions included in each newsletter or communication or by emailing us at firstname.lastname@example.org. We offer an opportunity to opt-out of certain communications in your account, or you may contact us at email@example.com or CaringBridge 2750 Blue Water Rd. Suite 275, Eagan, MN 55121 to opt-out.
Notifications from the Mobile Application. When using our mobile application, we will provide you with the opportunity to opt into receiving notifications from us through your device. If you no longer wish to receive these communications, you may opt out of receiving them at the device level by modifying your profile settings.
Individual Site Creators. If you engage with an Individual Site, we may share your name and email address with the creator of the site. For example, we provide your name and email address to the creator of an Individual Site on which you post content or on which you choose to receive notifications. We will also provide your name and email address to the creator of any Individual Site that requires visitors to log in. Likewise, we share your name and email address with the creator of an Individual Site to which you dedicate a donation.
Invite Others. If you choose to use our referral service to tell a friend about our Service or share an Individual Site through our Site or mobile application, we will ask you for your friend's name and email address. We will automatically send your friend a one-time email inviting him or her to visit the site. CaringBridge does not store this information and collects this information for the sole purpose of sending this one-time email.
Third-Party Vendors. CaringBridge stores personal information collected through our Service on third-party service providers systems, generally through the use of their software as a service or infrastructure products. This information, while stored on their systems is generally not available for the third-party service provider to access. Examples include Amazon Web Services infrastructure services, our Salesforce CRM/Marketing services, and our Oracle Customer Care system. CaringBridge also uses third party service providers to process and manage various functions where the service provider does have access to your personal data as part of their ability to provide the service to CaringBridge. Examples include our payment processing systems. These companies are required by contract to keep your personal information confidential and may only use it to provide services on our behalf. We periodically audit all significant third-party vendors for their security and data privacy practices including compliance with the General Data Protection Regulation (EU) 2016/679 (the “GDPR”).
Visitors to Your Site. If you choose to activate the public search listing feature for your Individual Site, people may find your Individual Site profile information. Information will be indexed and displayed through public search engines whenever someone searches for your name: This information may include: (1) the first and last name the subject of the Individual Site; (2) the title of the Individual Site; (3) the profile picture of the Individual Site; (3) the date and time of the first journal post to the Individual Site; and (4) the date and time of the most recent journal post to the Individual Site. Even if you deactivate your Individual Site, third-party search engines may not update their caches, which may contain old public profile information for your Individual Site.
Donors. If you donate to CaringBridge, online or offline, we will not sell, trade or share your personal information with other organizations, nor send donor mailings on behalf of other organizations.
Statistics. CaringBridge shares statistical information about the use of our Service with our donors, sponsors and partners. This information does not identify any individual personally.
Research. CaringBridge may share non-personally identifiable information from the Service with third parties for research purposes.
Import Contacts. You can import contacts from your email account address book to invite them to register to use our Services. We collect your username for the email account you wish to import your contacts from and will only use it for that purpose.
Single Sign-On. You can log in to our site using sign-in services such as Facebook, Google, or an Open ID provider. These services will authenticate your identity and provide you the option to share certain personal information with us such as your name and email address to pre-populate our signup form. Services like Facebook give you the option to post information about your activities on the Site to your profile page to share with others within your network.
Testimonial. We display personal testimonials of satisfied customers on our site in addition to other endorsements. With your consent we may post your testimonial along with your name. If you wish to update or deactivate your testimonial, you can contact us at firstname.lastname@example.org.
We will retain your information for as long as your account is active or as needed to provide you services. If you wish to deactivate or delete your account or request that we no longer use your information to provide you services, contact us at email@example.com. If you provide, enter, upload, or create any information on our site, it may be difficult if not impossible, to deactivate or delete this information if you later desire to remove the data. By providing this information in any form, you consent that this information loses its right for future deletion. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Sensitive Personal Data. Sensitive personal data is a subset of personal data which includes, but is not limited to, information revealing race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information that concerns health, sexual orientation, genetic, biometric data or criminal allegations (convictions or otherwise). In general, CaringBridge will not collect sensitive personal data from its users unless you voluntarily provide such information as part of your use of the Service. Providing sensitive personal data is entirely optional. By providing your sensitive personal data, you consent to our collection of such data. Our lawful basis for collection of this data is with your consent. If you provide this information, it may be difficult, if not impossible, to delete this information if you later desire to remove the data. By providing this information in any form, you consent that this information loses its right for future deletion.
Individuals or families on a health journey have CaringBridge Individual Sites. If author(s) of an Individual Site have personally identifiable information changes, you may correct, update or amend it by making the change in your account and site settings. If you no longer desire our service, you may deactivate your Individual Site in site settings or ask us to deactivate it by contacting us at firstname.lastname@example.org. There is an option for recovery when your Individual Site is deactivated.
If you would like to permanently delete your Individual Site, you may ask us to delete it by contacting us at email@example.com. There is no option for recovery when your Individual Site is deleted.
It may take up to 90 days to delete all the activity on an account or an Individual Site. While the deletion process is in progress, the account or Individual Site is deactivated and inaccessible to you or other CaringBridge users.
We maintain reasonable administrative, physical and technological measures to protect the confidentiality and security of your personal information. For example, we use industry standard Secure Sockets Layering (SSL) encryption to protect your profile information, Site creation information, donation information, and credit card information as it travels over the Internet or via wireless transmission. We restrict access to our data center and our databases, and we use a secure server dedicated to online donations to protect your personal and financial information. Specifically, your credit card information is not stored on our server; it is only stored with our third-party services provider for donation processing. We also have firewall protection in place.
Unfortunately, no website, server or database is 100% secure. Therefore, we cannot guarantee its absolute security. If information on an Individual Site is made public, we cannot safeguard or protect that information. For this reason, you should use care and discretion when you post content on a Site and never post information that can be used for identity theft purposes, such as social security numbers, bank account numbers, or credit card numbers.
CaringBridge communities may include friends and family of all ages. Special care must be taken to protect children under the age of 16. For this reason, CaringBridge does not permit children under the age of 18 to create or maintain their Sites, or children under the age of 16 to register as users.
European Union data subjects may have certain rights under the GDPR, including the following:
Right of Access. You may have the right to access data collected about you. If you would like to know what information we have collected about you and how it has been used, please contact us at firstname.lastname@example.org.
Right of Rectification. You may have a right to correct any incorrect or incomplete information we have about you. To request a correction, please contact us at email@example.com.
Right to Erasure. In certain circumstances, you may have the right to request that we delete your personal information. To request erasure, please contact us at firstname.lastname@example.org.
Right to Restrict Processing. In certain circumstances, you may have the right to restrict the processing of your personal information. To exercise your right to restrict processing, please contact us at email@example.com.
Right to Data Portability. You may have the right to receive personal data we have collected from you in an accessible format. You may also have the right to have the personal information we have collected from you transferred to another controller. To submit a request, please contact us at firstname.lastname@example.org.
Right to Object. You may have the right to object to the processing of your personal data for direct marketing purposes. To object to the processing of your personal data, please contact us at email@example.com.
Rights Related to Automated Decision-Making Including Profiling. You have the right not to be subject to a decision based solely on an automated process (no human involvement) which produces legal effects or significantly affects you in a similar way. We will not make these types of decisions by solely automated processed. If you believe that an automated decision-making process was applied to you, please contact us at firstname.lastname@example.org.
You may exercise any lawful rights you may have under the GDPR by emailing us at email@example.com.
Access and Correction Rights. California Civil Code § 1798.83 permits users that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please contact us at firstname.lastname@example.org.
Do Not Track Signals. The service does not respond to browsers' Do Not Track Signals.