Privacy Policy

PRIVACY POLICY Haven for Healing Exchange Network This Privacy Policy describes how Haven for Healing Exchange Network (“Network,” “we,” “us”) may collect, use, disclose, retain, and protect personal information through its website, mobile application, membership processes, Community Network Coordinator activities, business collaboration, youth initiative, and current or future Network programs.

1. Information We May Collect •

Account and profile information: name, contact information, username, profile photo/video, biography, service interests, skills, offerings, requests, and communication preferences. • Identity and trust information: date of birth/age eligibility, government-issued identification, selfie/photo comparison, verification status, and fraud/safety indicators. The production system should minimize storage of raw identification documents whenever feasible. Verification providers and photo matching. Where legally permitted and actually implemented, the Network may use a third-party identity provider to compare identity documents and selfies, validate document authenticity, or perform other fraud-prevention checks. The public policy and in-product consent must identify any use of facial recognition or biometric processing where applicable and provide any notices, choices, retention limits, or consent required by law. • Exchange information: listings, requests, member-to-member messages, agreed terms, Credit amounts, sourcing/material information, completion confirmations, shared-contribution status, ratings, reviews, disputes, and support records. • Payment information: transaction status and limited payment metadata needed to administer shared contributions or hybrid features. Full payment-card data should be handled by a compliant payment processor rather than stored by the Network where feasible. • Business/CNC information: business identity and contact details, licensing or insurance information voluntarily/necessarily submitted, onboarding status, CNC training/verification activity, referrals, events, and earned-credit records. • Safety and eligibility information: driver or vehicle information where applicable; parental/guardian consent and linked youth-account information; and documentation submitted for disputes, incident reports, or verification. • Device and technical information: IP address, device/browser type, app version, identifiers, logs, security events, approximate location inferred from IP, and precise location only when a feature requires it and the user grants permission. • Information from vendors or public sources when necessary for verification, fraud prevention, legal compliance, or user-requested features.

2. Sensitive Information and Data Minimization

The Network should collect only information reasonably necessary for a defined purpose and apply heightened safeguards to government IDs, youth data, precise location, financial information, and other sensitive data. Members should not place unnecessary medical, mental-health, legal, financial, or other Haven for Healing Exchange Network | Privacy Policy highly sensitive information in public profiles or ordinary exchange messages. The Network is not a healthcare provider merely because its mission includes wellness and community support. Verification confidentiality. Government identification images, selfie images used for verification, background or driving-history information, and similar trust-and-safety records should not be publicly displayed or routinely shared with other members. Other members should generally receive only the minimum status or information necessary for the exchange, except where law or a program-specific requirement permits or requires additional disclosure.

3. How We Use Information

To Create, verify, secure, and administer member accounts. • Match and connect members; display listings; facilitate communication, Credits, shared contributions, confirmations, ratings, reviews, and community features. • Operate business collaboration, youth, CNC, Community Credit Pool, transportation, lodging, storage/shared-space, agriculture, education, merchandise, recycling, and other approved programs. • Prevent fraud, abuse, duplicate accounts, unsafe conduct, and Credit manipulation; investigate incidents and enforce policies. • Provide support, resolve disputes, maintain records, improve accessibility and functionality, develop the Platform, and communicate operational updates. • Comply with law, lawful process, nonprofit governance, accounting, tax/reporting, insurance, audit, and safety obligations. • With appropriate consent or lawful basis, send outreach, program, event, or promotional communications and measure their effectiveness.

4. When Information May Be Shared

We may share information with other members as needed for profiles and exchanges; with a parent/legal guardian for an authorized youth account; with vendors that provide hosting, identity verification, payments, communications, analytics, security, background/driver verification, or other Platform functions; with professional advisors, insurers, auditors, or regulators; and when reasonably necessary to comply with law, protect rights or safety, investigate fraud or abuse, or respond to lawful legal process. The Network does not intend to sell personal information for monetary consideration. Pre-Launch Privacy and Data-Processing Review. Before the public launch of the Platform, and before implementing any material change to its data-processing practices, the Organization shall require its qualified legal counsel and appropriate technical personnel to conduct and document a reasonable review of the Platform’s collection, use, processing, storage, disclosure, and transfer of Personal Information. The review shall include all analytics, advertising, attribution, identity-verification, payment-processing, hosting, software-development-kit (“SDK”), tracking-technology, and other third-party service-provider arrangements. Technical personnel shall identify and document the data collected or transmitted, the purposes of the processing, the recipients, and the applicable contractual and technical controls. Qualified legal counsel shall assess, based on the documented practices and applicable law, whether any activity constitutes a “sale,” “sharing,” processing for “targeted advertising,” profiling, or any other regulated disclosure or transfer of Personal Information, including Sensitive Personal Information. To the extent required by applicable law, the Organization shall implement appropriate notices, consents, authorizations, contractual safeguards, consumer-request procedures, and opt-out mechanisms before the applicable processing begins. The Organization’s public-facing privacy notices and consumer-choice mechanisms shall accurately and Haven for Healing Exchange Network | Privacy Policy materially reflect its actual data-processing practices and shall be reviewed and updated whenever those practices materially change.

5. Member Visibility and Public Content

Private or semi-private Platform communications remain subject to the Network’s published access, moderation, safety, retention, legal-process, and security practices. The Network should not represent communications as absolutely confidential or privileged. Members should not use the Platform as a substitute for a legally privileged clinical, legal, or other confidential professional record system unless the applicable professional and technical safeguards have been separately implemented. Members control or influence some information visible to other users, such as profile details, offerings, requests, ratings, reviews, and business information. Members should assume that information intentionally posted to community-visible areas may be seen, copied, or remembered by others. The Network may provide privacy controls but cannot guarantee that another person will not retain information they were lawfully shown.

6. Youth Privacy

The Youth Initiative is currently intended for ages 15–17 and requires parent/legal guardian consent and oversight. The Platform should not permit independent membership by children under 13. COPPA applies to operators of online services directed to children under 13 and to other operators that have actual knowledge they are collecting personal information online from a child under

13. Accordingly, if the Network learns that it has collected personal information online from a child under 13, it should follow a counsel-approved COPPA response process, including deletion or legally compliant parental-consent procedures as applicable.

7. Location, Camera, Photos, and Device Permissions

Certain features may request device permissions for camera/photo access, notifications, location, or other functions. Permissions should be requested only when needed, explained in context, and adjustable through device settings. Precise location should not be collected continuously unless a clearly disclosed feature requires it and the member affirmatively enables it.

8. Retention

The Network retains information only as long as reasonably necessary for operations, safety, dispute handling, accounting, legal obligations, and legitimate nonprofit purposes. Current operational planning includes retaining ordinary exchange messages for approximately 12 months and dispute-related messages/records for up to approximately three years. Identity-verification artifacts, payment records, tax/accounting records, youth consent records, safety reports, and legal-hold data may require different schedules.

9. Security

The Network will use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information, which may include encryption in transit, access controls, least-privilege permissions, secure vendor practices, authentication controls, logging, backups, incident response, and staff/CNC Haven for Healing Exchange Network | Privacy Policy confidentiality requirements. No system is completely secure, and the Network cannot guarantee that unauthorized access, loss, or misuse will never occur.

10. Privacy Choices and Rights

Depending on location and applicable law, individuals may have legal rights to access, correct, delete, obtain a copy of, or restrict certain uses of personal information; opt out of certain sale, targeted advertising, or sharing; withdraw consent where applicable; and appeal certain decisions. Utah’s Consumer Privacy Act contains scope thresholds and exclusions, including provisions relevant to nonprofit corporations, so counsel should determine whether the Act legally applies to the Network at launch or later. Regardless of statutory applicability, the Network may voluntarily offer reasonable access, correction, and deletion processes consistent with safety, fraud prevention, disputes, accounting, and legal-retention needs.

11. Cookies, Analytics, and Communications

The website/app may use essential cookies or similar technologies and may use analytics or performance tools. The final policy and consent mechanism should identify the actual vendors and technologies used at launch. Members may receive transactional communications necessary for account security and exchanges. Marketing communications should include legally required opt-out mechanisms.

12. Data Breach and Incident Response

The Network will maintain a written incident-response process to investigate suspected security incidents, contain risks, preserve evidence, document findings, assess whether personal information was compromised, and provide legally required notices to affected individuals, regulators, law enforcement, or others within applicable deadlines. Breach-Notification Compliance. The Network shall require qualified legal counsel to identify and evaluate all applicable federal, state, territorial, and other legally binding data-breach and security-incident notification requirements based on the nature of the incident, the categories of information involved, and the jurisdictions in which affected individuals reside. The Network shall maintain and periodically update appropriate incident response procedures addressing applicable investigation, documentation, timing, content, method, and record-retention requirements, including any required notifications to affected individuals, governmental or regulatory authorities, consumer-reporting agencies, business partners, insurers, or other persons or entities. Following any actual or reasonably suspected breach or reportable security incident, the Network shall consult qualified legal counsel promptly and provide all notifications required by applicable law within the prescribed time periods.

13. Third-Party Links and Services

Third-party websites, payment processors, verification providers, mapping tools, app stores, and other integrations have their own privacy practices. The Network is not responsible for third-party practices outside its control, but will seek vendors appropriate to the sensitivity of the data they process.

14. Changes to This Policy

We may update this Privacy Policy as the Platform, programs, vendors, or law change. Material changes will be communicated through reasonable means and, when required, consent will be obtained. Haven for Healing Exchange Network | Privacy Policy

15. Contact and Privacy Requests

Privacy contact: exchangenetworkfounders@gmail.com Mailing address: 419 S 600 W, Vernal, UT 84078

Website/privacy request form: https://havenforhealingexchangenetwork.org Legal entity: Haven for Healing Exchange Network and Haven for Healing Community Wellness, Inc.hange2025@gmail.com.

Connect, contribute, and grow with us

Contact Information

+1-435-219-3119

© 2025. All rights reserved.

havenexchange2025@gmail.com