Privacy Policy | Track It Forward

Privacy Policy

Last updated: February 1, 2022

The privacy of your data — and it is your data, not ours! — is a big deal to us. In this policy, we lay out: what data we collect and why; how your data is handled; and your rights to your data. We promise we never sell your data: never have, never will.

What we collect and why

Our guiding principle is to collect only what we need. Here’s what that means in practice:

Identity & access

When you start a trial on the Track it Forward product, we typically ask for identifying information such as your name, email address, and an organization name. That’s just so you can personalize your new account, and we can send you invoices, updates, or other essential information. We’ll never sell your personal info to third parties.

When you join as a volunteer on Track it Forward, your organization’s administrators set the information that they would like to collect.  This information is only used by your organization and is not used by Track it Forward or sold to any third parties.

Billing information

When you pay for a Track it Forward product, we ask for your credit card and billing address. That’s so we can charge you for service, calculate taxes due, and send you invoices. Your credit card is passed directly to our payment processor and doesn’t ever go through our servers. We store a record of the payment transaction, including the last 4 digits of the credit card number, for account history, invoicing, and billing support.

Geolocation data

We log all access to all accounts by full IP address so that we can always verify no unauthorized access has happened. We keep this login data for as long as your product account is active.

We also log full IP addresses used to sign up a product account.

Web analytics data — described further in the Website Interactions section — are also tied temporarily to IP addresses to assist with troubleshooting cases. 

Website interactions

When you browse our marketing pages or applications, your browser automatically shares certain information such as which operating system and browser version you are using. We track that information, along with the pages you are visiting, page load timing, and which website referred you for statistical purposes like conversion rates and to test new designs. We sometimes track specific link clicks to help inform some design decisions. These web analytics data are tied to your IP address and user account if applicable and you are signed into our Services. 

Anti-bot assessments

We use CAPTCHA services across our applications to mitigate brute force logins and as a means of spam protection. We have a legitimate interest in protecting our apps and the broader Internet community from credential stuffing attacks and spam. When you log into your accounts and fill specific forms, the CAPTCHA service evaluates various information (e.g IP address, how long the visitor has been on the app, mouse movements) to check whether the data is possibly filled out by an automated program instead of a human. 

Cookies 

We do use persistent first-party cookies to store certain preferences, make it easier for you to use our applications, and support some in-house analytics. A cookie is a piece of text stored by your browser to help it remember your login information, site preferences, and more. You can adjust cookie retention settings in your own browser. To learn more about cookies, including how to view which cookies have been set and how to manage and delete them, please visit: www.allaboutcookies.org.

Voluntary correspondence

When you write Track it Forward with a question or to ask for help, we keep that correspondence, including the email address, so that we have a history of past correspondences to reference if you reach out in the future.

We also store any information you volunteer like surveys. Sometimes when we do customer interviews, we may ask for your permission to record the conversation for future reference or use. We only do so if you give your express consent.

Information we do not collect

Your organization may decide to collect a variety of information from Track it Forward, but Track it Forward itself does not collect any characteristics of protected classifications including age, race, gender, religion, sexual orientation, gender identity, gender expression, or physical and mental abilities or disabilities. You may provide these data voluntarily, such as if you include a pronoun preference in your email signature when writing into our Support team.  

How we approach mobile app permissions

We offer optional mobile apps for Track it Forward. Our philosophy is to ask for the bare minimum of permissions from you to give you a great app experience with maximum privacy. By default, we have access to the network to ensure the app can connect to and communicate with the Internet. In most cases, we ask for permission just-in-time so that you can decide if you want to grant access to things like camera and GPS. 

It’s impossible for our apps to try to use a sensitive OS feature without requesting access explicitly from you, so you’ll always know exactly when and what we’re requesting. You will never be required to grant any permission (although a given feature may not work or work well without it).

When we access or share your information

Our default practice is to not access your information. The only times we’ll ever access or share your info are:

To provide products or services you’ve requested. We do use some third-party services to run our applications and only to the extent necessary process some or all of your personal information via these third parties. Having subprocessors means we are using technology to access your data. No Track it Forward human looks at your data for these purposes unless an error occurs that stops an automated process from working and requires manual intervention to fix. These are rare cases and when they happen, we look for root cause solutions as much as possible to avoid them from reoccurring.

To investigate, prevent, or take action regarding restricted uses. Accessing a customer’s account when investigating potential abuse is a measure of last resort. We have an obligation to protect the privacy and safety of both our customers and the people reporting issues to us. We do our best to balance those responsibilities throughout the process. If we do discover you are using our products for a restricted purpose, we will report the incident to the appropriate authorities.

When required under applicable law.

OurVolts, LLC (dba Track it Forward) is a US company and all data infrastructure are located in the US.

  • If US law enforcement authorities have the necessary warrant, criminal subpoena, or court order requiring we share data, we have to comply. Otherwise, we flat-out reject requests from local and federal law enforcement when they seek data. And unless we’re legally prevented from it, we’ll always inform you when such requests are made. In the event a government authority outside the US approaches Track it Forward with a request, our default stance is to refuse unless the US government compels us to comply through procedures outlined in a mutual legal assistance treaty or agreement. We have never received a National Security Letter or Foreign Intelligence Surveillance Act (FISA) order.
  • Similarly, if Track it Forward receives a request to preserve data, we refuse unless compelled by either the US Federal Stored Communications Act, 18 U.S.C. Section 2703(f) or a properly served US subpoena for civil matters. In both of these situations, we have to comply. In these situations, we notify affected customers as soon as possible unless we are legally prohibited from doing so. We do not share preserved data unless absolutely required under the Stored Communications Act or compelled by a court order that we choose not to appeal. Furthermore, unless we receive a proper warrant, court order, or subpoena before the required preservation period expires, we destroy any preserved copies we made of customer data once the preservation period lapses.
  • If we get an informal request from any person, organization, or entity, we do not assist. 
  • If we are audited by a tax authority, we may be required to share billing-related information. If that happens, we only share the bare minimum needed such as billing addresses and tax exemption information.

Finally, if OurVolts, LLC is acquired by or merged with another company, we’ll notify you well before any info about you is transferred and becomes subject to a different privacy policy.

How we secure your data

All data is encrypted via SSL/TLS when transmitted from our servers to your browser. The database backups are also encrypted.

Most data are not encrypted while they live in our database (since it needs to be ready to send to you when you need it), but we go to great lengths to secure your data at rest. 

What happens when you delete data in your product accounts

If you delete your site, all volunteer, hour, and site data is permanently deleted.  We have some limited backups of our application databases, which are kept for up to 30 days.  However, retrieving data for a single account from a backup is cost-prohibitive and unduly burdensome and will be evaluated on an as needed basis.

Location of site and data

Our products and other web properties are operated in the United States. 

Changes & questions

Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Please get in touch by contacting us we’ll be happy to answer them!