Privacy Policy
Last updated: June 10, 2026
1. Introduction
VolunteerOps ("we," "our," or "us") is committed to protecting the privacy of individuals who use our volunteer management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service. Please read this policy carefully.
2. Information We Collect
We collect information in the following ways:
- Account Information: Name, email address, phone number, and assigned role when an account is created.
- Volunteer Application Data: Legal first, middle, and last name; any alias; date of birth; gender; mailing address; other states previously lived in; phone and email contact information; driver's license number and state; Social Security Number; emergency contact name, phone, and relationship; organization affiliation and contact; a written description of the volunteer service you intend to provide; volunteer type (e.g., General or Limited Service); and background-related disclosures required by the facility (prior employment with the department, visiting list status, probation/parole status, felony and misdemeanor history, pending charges, and gang affiliation history).
- Identity Photos & Documents: When required by your facility, a headshot photo and identification or supporting documents may be captured or uploaded — typically during in-person identity verification or at a kiosk — and associated with your volunteer record.
- Custom Jurisdiction Fields: Additional questions defined by the facility or jurisdiction (e.g., program preferences, additional affiliations).
- PREA Acknowledgment: For Limited Service applicants, a timestamped record of the PREA (Prison Rape Elimination Act) acknowledgment.
- Returning-Volunteer Verification: Email magic-link verification tokens used to confirm identity when an existing volunteer reapplies.
- Agreement & Signature Data: Typed and/or drawn digital signatures captured during volunteer agreement acknowledgment, along with timestamp and the agreement version signed.
- Check-In/Check-Out Records: Timestamps and facility associated with each visit.
- Usage Data: Log data, IP addresses, browser type, and pages visited for security and analytics purposes.
3. How We Use Your Information
We use collected information to:
- Process and manage volunteer applications, approvals, and renewals.
- Verify volunteer identity through submitted photos and identification.
- Track PREA acknowledgment and other facility/jurisdiction-specific compliance requirements.
- Facilitate facility check-in and check-out operations through kiosks.
- Send notifications regarding application status, approval expirations, and renewal reminders.
- Maintain audit trails and compliance records required by facility administrators.
- Improve platform security, performance, and functionality.
- Respond to support requests and inquiries.
4. Data Security
We implement enterprise-grade security measures including AES-256-GCM field-level encryption for sensitive personally identifiable information (PII) such as Social Security Numbers and driver's license data. Uploaded photos and identity documents are served exclusively via short-lived signed URLs. We enforce role-based access controls so that only authorized personnel can access sensitive records, and decryption or export of sensitive PII is recorded in a tamper-evident audit trail. While we take all reasonable steps to protect your data, no method of transmission over the Internet is 100% secure.
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Within Your Organization: Authorized staff — Super-administrators, State administrators, Volunteer Service Coordinators (VSCs), Officers, and General Facility users — can access volunteer records as governed by their assigned role and facility scope. Decryption and export of sensitive PII is audit-logged.
- Service Providers: Trusted vendors who assist us in operating the platform (e.g., cloud infrastructure, email delivery) under strict confidentiality agreements.
- Legal Requirements: When required by law, court order, or government authority.
6. Data Retention
We retain volunteer application data and check-in records for as long as your facility's subscription is active and for a reasonable period thereafter, or as required by applicable law. Check-in and audit logs may be retained longer to satisfy facility compliance and reporting obligations. You may request deletion of your personal information subject to legal and contractual retention obligations.
7. No PHI / Not a HIPAA Service
VolunteerOps is not a Covered Entity or Business Associate under HIPAA. The Service is not designed to receive, store, or transmit Protected Health Information (PHI), and users agree not to submit PHI through the platform. No Business Associate Agreement (BAA) is offered or implied. If PHI is submitted in error, contact us at privacy@volunteerops.com for secure removal.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or request deletion of your personal information. To exercise these rights, contact your facility administrator or reach out to us directly at privacy@volunteerops.com.
9. Cookies and Tracking
We use essential cookies and session tokens to maintain authentication and platform functionality. We do not use third-party advertising cookies or sell browsing data.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by posting the new policy on this page with a revised date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us at privacy@volunteerops.com.