Immediate danger? For injuries, fire, trapped or missing people, gas danger, collapse, live wires, or another threat to life:Call 911

Public-by-design, privacy-aware

Privacy Notice

This notice explains what the Recovery Hub processes and what becomes public when someone posts a listing.

Last updated July 28, 2026

1. Public listing information

Community listings are public. The listing text, general area, timing, provider type, cost status, and chosen contact method are visible to the public and to the site operator. The operator does not receive a separate hidden private version of a listing.

Individual listing pages are marked not to be indexed by search engines, but that is not a promise of secrecy. Public information may still be copied, cached, screenshotted, indexed indirectly, or shared elsewhere. Use at your own risk and submit only information you are willing to make public.

2. Information the site processes

  • Listing information: the public content and contact method selected by the poster.
  • Listing-management records: listing status, expiration dates, terms-acceptance date, and a one-way hash of the private management token. The readable token is not stored.
  • Security records: a salted one-way hash derived from a connection address for rate limiting and abuse prevention. The raw address is not intentionally stored in the Hub database.
  • Reports: the reported listing, reason, explanation, and optional reporter contact. Reporter contact is not public and may be seen by the operator to clarify or address the report.
  • Provider logs: Netlify, Supabase, and Cloudflare may create operational or security logs under their own policies.

3. Why information is used

Information is used to publish and manage listings, connect neighbors, prevent automated abuse, enforce rate limits, investigate reports, remove unsafe or prohibited content, troubleshoot failures, and protect the site and community.

4. Service providers

The Hub uses Netlify for hosting and server functions, Supabase for database storage, and Cloudflare Turnstile for bot and abuse prevention. Optional report-email delivery may use an email delivery provider if enabled. Facebook, Nextdoor, and other external links are separate services governed by their own terms and privacy practices.

The Hub does not sell personal information, use it for targeted advertising, or operate advertising analytics.

5. Retention

  • Active listings remain public until they expire, are fulfilled, or are removed.
  • Inactive listings are ordinarily deleted from the Hub database after about 30 days.
  • Rate-limit hashes are ordinarily deleted within 2 days.
  • Reports are ordinarily retained for up to 90 days, unless a longer period is reasonably needed for safety, fraud, legal, or operational reasons.
  • Infrastructure providers may retain logs according to their own policies.

6. Private management links

A management link acts like a password for one listing. Its token is stored in the URL fragment so browsers do not send it as part of the page request. Keep it private. Anyone who has the link may be able to edit, renew, fulfill, or remove the listing.

7. Children

Children should not submit listings or direct contact information. A parent or legal guardian should post on behalf of a minor without publishing the child's name, address, school, phone number, social profile, or other identifying details.

8. Security and limits

Reasonable safeguards are used, including server-only database access, row-level security, one-way token hashing, rate limiting, and human verification. No website can guarantee absolute security, uninterrupted availability, or that public information will not be copied by others.

9. Correction, removal, and questions

Use the private management link to edit or remove a listing. To report exposed personal information, a lost management link, or another privacy concern, use the report form or email info@foxvalleyrecovery.org.