Skip to main content

Your privacy

Privacy Policy

How we collect, use, and protect the information you share with us.

This Privacy Policy explains how the Palisades Long-Term Recovery Group (“Pali LTRG,” “we,” “us”) handles personal information when you use thepalihub.org or contact us about PaliHub. PaliHub is a project of Pali LTRG, which is fiscally sponsored by the CCF Community Initiative Fund, a 501(c)(3) organization.

This policy covers information handled through PaliHub. It does not cover the practices of other organizations or websites that you choose to visit from PaliHub.

Information we collect

  • Newsletter and contact information. If you subscribe, we collect your email address. If you contact us, we collect your name, email address, subject, and message.
  • Account and profile information. If an account is created for you, we keep your name, email address, role, account status, and related timestamps. Staff-created invitation records include the invited email address, intended role, status, expiration, inviter details, and timestamps. If you connect Google, we also receive a Google account identifier, basic profile details, and authentication tokens, and may receive your Google profile photo. You may choose to add your previous and current ZIP codes.
  • Your PaliHub activity. If you are signed in, we keep your saved resources and events and your recovery-checklist progress so those choices are available when you return.
  • Organization information. An organization claim can include your role, work email, and verification note. Organization managers and staff may submit organization descriptions, public contact details, logos, photos, and files. Organization profile fields become public when saved. Uploaded files are stored at public URLs as soon as the upload completes, even before you save the profile, and anyone with the URL may access them. Do not upload private or sensitive information or media you are not authorized to publish. Removing a file from a profile does not delete the stored file; contact us to request deletion.
  • Technical and security information. When you use the site, we and our hosting providers may process your IP address and user agent, browser or device information, requested pages, time of access, session and security identifiers, and error or diagnostic information. Search and filter terms are included in request URLs, so they can appear in your browser history and hosting or operational logs. Our hosting provider may derive an approximate location from an IP address. Contact- and newsletter-form rate-limit records use coded identifiers instead of storing the underlying IP address or newsletter email in those counter rows. Authentication sessions and sign-in security records may store IP addresses as described above.

Please do not send passwords, Social Security numbers, financial account details, or medical records through the contact form or organization-claim note.

How we use information

  • To operate, maintain, troubleshoot, and protect PaliHub.
  • To authenticate accounts, send one-time sign-in codes, and provide saved-item, checklist, profile, and organization-management features.
  • To send a newsletter you requested and manage confirmation, unsubscribe, delivery, and related subscription records.
  • To respond to messages, review organization claims, publish approved organization information, and communicate with organization managers.
  • To comply with law, investigate misuse, and protect PaliHub, its visitors, and others.

How information is disclosed

We disclose information only for the purposes described above:

  • Vercel provides website hosting, delivery, security, and operational logs. See Vercel’s Privacy Notice.
  • Our database host stores application records needed to operate accounts, saved items, organization features, and site content.
  • Postmark delivers contact messages, one-time sign-in codes, invitations, and operational email. See Postmark’s Privacy Policy.
  • Mailchimp manages newsletter subscriptions and campaigns. Depending on campaign settings, Mailchimp may process delivery, open, click, browser, device, and approximate-location information. See the Intuit Global Privacy Statement that covers Mailchimp.
  • Google provides optional sign-in and provides YouTube videos when you choose to play one. See Google’s Privacy Policy.
  • Cloudflare stores and delivers public site assets and may store private content-only snapshots. See Cloudflare’s Privacy Policy.
  • Authorized people. Pali LTRG staff can access information needed to administer PaliHub. Authorized organization managers can access and edit only the organizations they manage; PaliHub does not give them visitors’ ZIP codes, saved items, checklist progress, newsletter records, or contact messages.
  • Legal and safety reasons. We may disclose information if reasonably necessary to comply with law, respond to valid legal process, investigate abuse, or protect rights, safety, and security.

We do not sell or rent personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.

Cookies and online tracking

When needed for sign-in, security, or an account session, PaliHub uses essential cookies. We do not currently use third-party web analytics or advertising trackers. Because PaliHub does not track visitors across other websites or sell or share personal information for targeted advertising, browser Do Not Track and Global Privacy Control signals do not change how the site operates.

YouTube’s privacy-enhanced player is not loaded until you choose to play a video. Once it loads, Google and YouTube may receive your IP address, device information, and interactions with the player under Google’s privacy policy.

If a page displays media hosted by another provider, your browser sends that provider ordinary request information such as your IP address, user agent, and the PaliHub site origin in order to load the media.

Other websites

Donation and disaster-registration links open separate systems, including the CCF Community Initiative Fund donation platform and the California Long-Term Recovery registration system. This website does not transmit or store the information you enter there. The destination service—and Pali LTRG or its fiscal sponsor where described in that service’s notice—may receive it. The destination’s privacy policy applies. Other resource-directory and event links may also lead to independent websites.

How long we keep information

  • Account, profile, saved-item, checklist, membership, and organization-claim records are generally kept while an account is active or while needed to administer the related feature. Closing an account removes its live account record and linked personal saved-item, checklist, membership, and claim records. It does not automatically erase invitation records, email copies, provider records, approved public content, cached files, or staff attribution labels.
  • Unsubscribing stops future newsletters but does not by itself delete the Mailchimp contact or campaign history. You may separately ask us to delete your newsletter data. Mailchimp may retain limited suppression, security, or legal records.
  • Contact messages may remain in Postmark and the receiving mailbox according to their configured retention and as needed to respond, keep appropriate operational records, or resolve a dispute.
  • Session and verification records include expiration times, but expired records may remain until routine cleanup. Authentication security counters and infrastructure logs follow their system and provider-account settings. Invitation records and private content snapshots do not currently have automatic deletion schedules and remain until manually removed.
  • Public organization content remains until it is removed or replaced. Public files may be cached for up to one year and may remain in browser or content-delivery caches for a period after removal.

Deletion from active systems may not immediately remove copies from backups, caches, or records that we must retain for legal, security, or fraud-prevention reasons. Backup retention varies by system and provider, and some private content snapshots require manual deletion by an administrator. These copies are access-restricted where applicable and may remain until they are deleted or overwritten.

Your choices and requests

  • Use the unsubscribe link in a newsletter to stop marketing email.
  • Use your profile to clear optional ZIP codes, remove saved resources or events, and update checklist progress.
  • Contact us to request access to, correction of, or deletion of personal information, or to close an account. We may need to verify your identity and may retain information where law, security, or another legitimate obligation requires it.
  • Manage or revoke PaliHub’s connection in your Google account if you used Google sign-in. Revoking Google access does not close your PaliHub account or delete its stored record; contact us separately for that.

Security

We use safeguards designed to protect personal information, including HTTPS between your browser and PaliHub, role-based access controls, restricted administrative access, and hashed one-time sign-in codes and invitation tokens. No website or storage system can guarantee absolute security.

Children’s privacy

PaliHub is not directed to children under 13, and we do not knowingly collect personal information from them. A parent or guardian who believes a child has provided personal information should contact us so we can review and delete it.

Changes to this policy

We may update this policy as PaliHub changes. We will post the revised policy and its updated date here. If a change materially expands how we use or disclose personal information, we will provide additional notice where appropriate.

Contact us

Questions about this policy? Email [email protected] or write to us at the Pali Hub, 15239 La Cruz Dr., Pacific Palisades, CA 90272.


Effective and last updated: August 18, 2026.