Privacy Policy

How we collect, store, protect, and respect your information.

⚠️

Legal review required. This policy is a working draft. It must be reviewed by an attorney before this site is opened to veterans. FLAG: Requires attorney review before publishing.

1. Who We Are

Patriot Haven is a 501(c)(3) nonprofit organization based in Arizona. We provide administrative case organization, general process education, and referral services to U.S. veterans at no cost. We do not provide legal advice or VA representation.

2. What We Collect

When you complete our intake process, we collect: your name, email address, phone number (optional), branch of service, service dates, self-reported document inventory, and stated goals. We also record your consent timestamp and a hashed (anonymized) version of your IP address for security logging.

3. How We Store It

Your data is stored in a secure database with role-based access controls. Staff can only access case records assigned to their role. All activity is logged in an append-only audit trail. We are in the process of executing a HIPAA Business Associate Agreement (BAA) with our cloud storage provider. No personal health information is stored until that BAA is in place.

4. How We Use It

Your information is used solely to: build and maintain your case dashboard, send you case update communications (if you opted in), and facilitate warm referrals to accredited VSO partners (only with your explicit review and approval).

5. What We Don't Do

We do not sell your data. We do not share your data with any third party without your explicit consent. We do not use your data for advertising or marketing.

6. Data Retention

Active case records are retained for 12–24 months or until you request deletion. Document files are retained for 24 months from upload, then automatically flagged for deletion review.

7. Your Right to Deletion

You may request deletion of your data at any time by contacting us at [contact email — Travis to add before publishing]. Upon request, your record is flagged for deletion and removed from active use within 30 days. Audit log entries are retained for legal compliance.

8. Contact

For privacy inquiries, contact: [Travis to add email before publishing]

Last updated: June 2026