Effective September 13, 2026

Privacy Policy

Information we receive

CVF may receive information that people voluntarily provide through public forms, including contact details, provider suggestions, correction requests, and volunteer-interest information. We use it for review, follow-up, security, duplicate prevention, and improving the directory.

Privacy commitments

CVF does not sell personal information. Public form submissions are reviewed through protected systems and are not published automatically. Please avoid submitting sensitive personal information that is not needed for the stated form.

Privacy-limited site measurement

CVF uses limited, first-party measurement to understand whether the public directory is working. This may count successful Resource Finder uses and result ranges; requests for published provider pages; browser-confirmed views of supported public and provider pages; selections of provider Website or Call controls, Share outcomes, broad browse categories, and provider results; approximate 30-minute sessions; and broad source and device classes. A session is an approximate activity grouping, not a person. Source classes are direct, internal, Google, Facebook, other search, other social, referral, or unknown. Device classes are desktop, tablet, mobile, or unknown.

The browser sends only controlled event labels, public provider identifiers where applicable, broad source and device classes on view events, a random event identifier, and an event time. Source classification happens in the browser; the referring URL is not sent. Device classification happens in the browser; the user-agent string is not sent. CVF does not send Resource Finder or Navigator text, city or county input, result contents, provider phone or email details, destination URLs, raw referrers, IP addresses, user-agent strings, names, email addresses, account identifiers, precise location, or unrelated cookies to the Analytics application.

If Global Privacy Control is enabled in the browser, these limited events may still be counted without an Analytics session or presence cookie and without a session count. Otherwise, after an accepted event, CVF may set a random first-party session cookie for up to 30 minutes and refresh that short period after later accepted events. The cookie is Secure, HTTP-only, SameSite=Lax, available only to this site, and is not stored with event details. Session counts are stored only as coarse daily totals and cannot be connected to a provider, category, search, or action. Blocking or deleting the cookie does not prevent use of the site or event delivery, but makes session totals less precise.

Longer-lived presence measurement, new-versus-returning classification, unique visitor estimates, reach estimates, precise geography, sponsor measurement, and public Analytics reports are not enabled. Analytics records are separated by retention class: short-lived event-level records expire after 35 days; daily aggregate facts are intended to be kept for up to 25 months; and any future approved monthly snapshots could be kept for up to seven years. Analytics data is not combined with form submissions, volunteer or administrator accounts, donor records, or sponsor records. These measurements are approximate and are not counts of people.

Questions and requests

For privacy questions or to request access, correction, withdrawal, or deletion where applicable, contact [email protected]. Limited legal, dispute, security, audit, and retention obligations may apply.