At Privacy Rights Clearinghouse (PRC), we strive to have a clear privacy policy based on Fair Information Principles. Please don't hesitate to contact us with your questions.
Before you read the full policy, here are some highlights.
- We collect personal information when you provide it to us and when you use this website and our services. We always try to collect the minimum amount of personal information necessary to accomplish the purpose for which it is collected.
We use personal information only for the purpose we collect it unless you ask us to use it otherwise.
- We automatically collect analytics information when you visit this website, but allow you to opt out of collection if you choose.
- We do not sell or rent any personal information.
- We implement physical, administrative and technical security measures to protect information we collect. In addition, all communications between PRC and our site visitors will be conducted over an encrypted connection.
- If you want to stop receiving communications from us, update your information, close an account or request information be deleted, let us know.
Information PRC Collects
Generally, the personal information we collect is limited to
- name
- email address
- home address
- biographical information (for intern/volunteer/employee applicants)
- usage/engagement analytics
Why and How PRC Collects Information
Email Lists
Why
We maintain email lists to contact our subscribers.
How
When you join one of our email lists, you must provide an email address and will have the option to share your first and last name. We use the email address you provide us to send you messages associated with the particular list. We do not sell, rent or share our mailing list.
We use Campaign Monitor to send our newsletters, alerts and other email to our subscribers. Campaign Monitor allows us to track whether a subscriber has opened and/or interacted with an email through the use of tracking beacons. When you subscribe you may be asked if you agree to the use of tracking beacons. Declining will not impact your ability to receive our emails. You can also opt out of the use of tracking beacons by clicking on Preferences Center in the footer of any Campaign Monitor email you receive from us.
You may always unsubscribe from our email lists. To unsubscribe, look for a unsubscribe from this list link at the bottom of any email you receive from us. See information about Campaign Monitor and its privacy statement for more information.
Information Retention
We retain email addresses (and, when submitted, first and/or last names) until you unsubscribe or ask to be removed from a mailing list.
Donations
Why
We collect donation information to communicate with our donors and maintain financial records.
How
When you donate, we will record the name and contact information you provide us so that we can thank you, provide you with receipts for tax purposes and keep you up to date with occasional donor-related emails. You may separately choose to join one of our other email lists but will not be automatically added. Any email we send will contain information about how to unsubscribe from the applicable list.
We do not sell, rent or share our donor list.
We do not process online donation payments. We contract with Giving Fuel and its default payment gateway (WePay) to process online donation payments. Please see the Giving Fuel privacy policy and terms for more information.
Information Retention
We retain financial records for auditing and tax purposes, however we can make any gift or donation anonymous at your request. Otherwise, we retain donor contact information until you ask us to remove it.
Applications
Why
We collect applicant information to expand our team.
How
We ask prospective interns and employees (and occasionally volunteers) to submit information that may include a cover letter, a resume or CV, contact details, biographical information and references. This information is only shared internally with relevant staff and board members.
Information Retention
We will remove application data from our computer systems when applicants are no longer under consideration, though some applicant information may be retained by individual employees or in personnel files.
Services
Why
We collect information to provide services.
How
Your Stories
We use the stories you submit to raise awareness, advocate for stronger privacy protections, analyze trends and publish reports. You may choose to share your story anonymously or to provide us with additional information.
We do not share any personally identifiable information unless you give us permission or we are legally required to do so.
If you request that we share your story, we may share with appropriate federal or state government agencies and/or with journalists. When you ask us to share, we may include any information you provide us so that the recipients can contact you to follow up (if they choose to do so). When we share stories, we cannot guarantee how the recipient will use (or potentially share) your personal information.
Your Questions
If you choose to ask us a question through our website, we request your email address and state. The email address is necessary to respond to your inquiry, and providing your state helps us give you relevant resources and a better answer to your question. You can choose whether to provide us with more information. We will only share information you provide to the extent you request it.
Information Retention
We retain stories until you ask us to remove them. PRC will retain analytic and categorical information about submitted questions, but we endeavor to remove contact details from our records after the question has been answered. Additionally, upon request, we can completely remove a question from our records. If you have requested that we share your question or story with third parties and we share, your information will be subject to that the third party's privacy (and retention) policy.
Social Media
We use social media to engage with our supporters and the public and to advance our education and advocacy work. We maintain Facebook, LinkedIn, Twitter and YouTube accounts. Information shared on each of those platforms is governed by each platform’s respective privacy policy.
Information Retention
We will attempt to delete messages we receive through our social media pages when we respond to those messages or when the inquiry is resolved. However, individual employees may retain copies of any correspondence.
Website Analytics
Why
We collect analytics data to understand how people use our website.
How
Our website automatically collects some technical information about visitors, and we receive reports from our analytics provider, Matomo. The analytics data our website collects is stored in a database used by Matomo to generate reports that contain aggregate data about how people use our website. We do not receive personally identifiable information in these reports, and do not attempt to identify individuals.
Cookies
A cookie is a string of information a website stores on a visitor’s device. We may use session cookies (meaning they disappear when you close your browser) on our website with our analytics provider to learn more about how visitors use and reach our website. We do not allow third party tracking cookies on our website, and you can still use our website even if you set your browser to reject cookies.
Opting Out of Tracking Cookies
If you choose to opt out of our analytics collection, a cookie ‘matomo_ignore’ will be set. All visitors with a matomo_ignore cookie will not be tracked.
“Do Not Track” Browser Setting
Matomo also will not track visitors who have indicated they do not want to be tracked in their web browser. You may indicate this preference in most browsers’ settings.
Information Retention
We configure our analytics provider to anonymize tracking data, masking all but one byte of a visitor’s IP address (e.g. 192.xxx.xxx.xxx). We regularly delete raw individualized log information after 7 days, unless we believe we need to retain it for longer in order to investigate or report a bug or malicious attack. We maintain aggregate reports about website visitors indefinitely.
Information Others May Collect
Facebook, Linkedin and Twitter Buttons
When you click on one of these buttons your browser will open a new window linking you to these social platforms. Our privacy policy only applies to our website and activities. If you click a link on our site that takes you to a different organization or company’s website, you will be subject to its privacy policy. These platforms are not able to log the fact that you visited one of our pages merely because their branded icons are listed on our website. They will receive information about your visit to our site if you click on the icon to share through one of those services.
Tableau Dashboards
We may embed interactive dashboards created using Tableau software on our website in order to provide users with visual representations of our data. Tableau is a third-party service, and their collection and use of your information is subject to their own privacy policies. For more information about Tableau's data collection and privacy practices, please review their Privacy Policy at https://www.tableau.com/privacy.
Security
We maintain appropriate administrative, technical and physical safeguards to protect information we have, including your personal information. It is impossible to guarantee absolute security, but we exercise great care in protecting information we collect.
We also rely on third parties to take appropriate security measures for web hosting, email marketing and donation processing.
Information Sharing and Disclosure
It is our general policy to disclose personal information only when you consent to that disclosure (for example, if you request that we share your story with government agencies or journalists). However, there are some limits to what we can promise. Most of these disclosures are unlikely, but we feel it is necessary to let you know they are possible.
Legal Requirements
We disclose personal information when required by law. We cannot guarantee that your personal information will never be sought by subpoena, search warrant, court order or other lawful form of legal process. We may or may not contest a demand for data.
If we are able, we will make a reasonable attempt to notify you about any such disclosure. We cannot guarantee that we will be able or allowed to contact you.
We may disclose personal information to law enforcement if we have reason to believe that our site has been used in a way that violates the law (for example, someone uses our website for improper activities or tries to hack our website).
Our Defense
We may disclose personal information to the extent we reasonably believe it necessary
- to protect the security or integrity of our operations
- to take precautions against liability
- in the event of a security breach, or to take actions to prevent, minimize, or remedy any harm from the breach
- to the extent required by law, or to provide information to a law enforcement agency or for an investigation related to public safety
Service Providers and Contractors
We may disclose personal information we collect to contractors who provide us services and support. This may include auditors, our internet service provider, lawyers, consultants, volunteers, contractors and others. We attempt to minimize sharing personal information, and we avoid it where possible. However, we depend on third parties to support some of our services and operations. We strive to select vendors and contractors who have strong privacy and security policies.
If we ever change our structure, merge with another organization or evolve in other ways, personal information may be shared with a successor organization. We will do our best to ensure that the information is handled in accordance with this policy.
Access, Correction and Data Quality
We try to collect only information that is necessary, and to retain that information for only so long as is necessary. If we have personal information about you, we will make that information available to you upon request. If you wish to access or amend any personal information that we hold about you, or to request that we delete or transfer any information about you that we have obtained, you may contact us and we will comply unless we are otherwise required to keep it. We do not charge a fee for processing any of these requests.
Children’s Privacy/COPPA
This website is not directed at children under the age of 13. Some children may use our website to obtain information, but we do not anticipate that they will engage in activities that result in PRC obtaining any personal information. If we learn that we have information about a child under the age of 13, we will delete it.
Site Visitors Outside the U.S.
Individuals outside the U.S. are welcome to use our website, but must acknowledge that any personal information provided to us through our website is collected, stored and otherwise processed in the U.S. Privacy protections for personal data in the U.S. are different from privacy protections available by law in other countries (they are often weaker). If this is unacceptable, you should not provide us with any personal information.
Changes to PRC Policies
We may make changes to this policy on occasion. We will take reasonable efforts to announce substantial changes on this page, on our home page, and on our social media accounts.
PRC Privacy Policy Revision History
- Revised 01.02.2012: We revised our policy to add more detail, describe our complaint tool, spell out the disclosures that we make with more specificity, provide information about access and correction. We did not make any changes to our basic policy of respecting the privacy of our users, or to our policy of not giving user data to advertisers.
- Revised 05.19.2014: We revised our policy to note the switch from AWstats to the Piwik Analytics engine.
- Revised 10.06.2016: We revised our policy to reflect changes associated with our website overhaul, to make the policy more reader-friendly, and to account for the addition of Constant Contact and Network for Good as third party vendors.
- Revised 05.07.2018: We revised our policy to reflect the transfer of our analytics data processor from Piwik to Matomo, and updated opt-out and user choice options.
- Revised 10.17.2019: We restructured this policy to be more readable and easier to understand. We also updated this policy to add a new payment processor (Giving Fuel) and Newsletter service (Campaign Monitor).
- Revised 2.27.2023: We updated the privacy policy to correct a dead link and to include information about the use of Tableau dashboards.
- Revised 5.30.2024: We updated our contact address.
Contact
If you have questions or comments regarding our privacy policy, please contact us. We can also be reached at 619-298-3396 or by mail at 3245 University Ave. #1101, San Diego, CA 92104.
We instruct all staff members on our privacy, confidentiality and security policies. Our team members who have access to personal information are required to abide by these policies, and we hold them accountable for doing so.