Privacy Policy
This Privacy Policy explains how Minds & Hearts collects, uses, and protects information across our website (mindsandhearts.org), our IMPACT platform (joinimpact.app, iOS, Android), and our other programs. We serve minors, and we take that responsibility seriously.
1. Scope
This Policy applies to all services operated by MINDS N HEARTS INC. (“Minds & Hearts,” “we,” “us,” “our”), including our website mindsandhearts.org, the IMPACT platform (web, iOS, Android), and any related communications. It does not apply to third-party websites or services we may link to.
2. Information We Collect
2.1 Information you provide
- Account information: name, email address, organization affiliation, profile photo (optional).
- Mission submissions: photos, video, text, GPS coordinates, and other content you submit as proof of completing a mission.
- Communications: messages you send to us or to other users via our platforms.
- Donations: billing information (processed by our payment processor; we do not store full card numbers).
2.2 Information collected automatically
- Device and usage: IP address, device type, operating system, browser, pages viewed, session duration, and interaction events.
- Cookies and similar technologies: for authentication, preferences, and analytics. You can disable cookies in your browser, though some features may not function.
2.3 Information from organizations
If you access IMPACT through your school, synagogue, or youth organization, that organization may provide us with information about you (such as enrollment, grade level, or group membership) so we can provision your account.
3. How We Use Information
We use the information we collect to:
- Operate, maintain, and improve our platforms;
- Authenticate users and protect account security;
- Process mission submissions and award points/badges/rewards;
- Send transactional communications (e.g., account verification, mission updates);
- Respond to inquiries and provide support;
- Comply with legal obligations and enforce our Terms of Service;
- Generate aggregated, de-identified analytics for our partner organizations.
We do not sell personal information. We do not use personal information for behavioral advertising.
4. Children & Minors (COPPA)
Our platforms are designed to be used by minors under the supervision of their schools, synagogues, and youth organizations. We comply with the Children's Online Privacy Protection Act (“COPPA”) and the 2025 amendments thereto.
4.1 Verifiable parental consent
For users under 13, we require verifiable parental consent before collecting personal information, except where school authorization is granted under the COPPA School Authorization exception and limited to educational purposes.
4.2 Limited collection
We collect from minors only the information reasonably necessary to operate our services. We do not condition participation on the disclosure of more information than necessary.
4.3 No targeted advertising
We never serve targeted advertising to minors and never sell or share their personal information with third-party advertisers.
4.4 Parental rights
Parents and guardians may review, request deletion of, or refuse further collection of their child's personal information by contacting privacy@mindsandhearts.org.
5. Sharing & Disclosure
We share personal information only as follows:
- With your organization: Schools, synagogues, and youth organizations that administer your account can see your participation data within their group.
- Service providers: Hosting (AWS), email (SendGrid), push notifications (Firebase), analytics (PostHog), payment processing — all bound by data-protection agreements.
- Legal compliance: When required by valid legal process, or to protect rights, property, and safety.
- Business transfers: In the event of a merger, acquisition, or asset transfer, with notice to affected users.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your personal information;
- Object to or restrict processing;
- Receive your information in a portable format;
- Withdraw consent at any time.
To exercise any of these rights, email privacy@mindsandhearts.org.
7. Security
We implement appropriate technical and organizational measures to protect personal information, including encryption in transit (TLS), encryption at rest, access controls, and routine security review. No system is perfectly secure; we do not guarantee absolute security.
8. Retention
We retain personal information for as long as necessary to provide our services and comply with our legal obligations. For minor users, we delete account data within 60 days of account deactivation or upon verified parental request.
9. International Users
Our services are operated from the United States. If you access our services from outside the U.S., your information will be transferred to, stored, and processed in the U.S. By using our services, you consent to that transfer.
10. Changes
We may update this Policy. Material changes will be communicated via in-app notice or email to account holders. The “Last updated” date at the top of this Policy indicates when it was most recently revised.
11. Contact
Questions, requests, or complaints regarding this Policy can be directed to:
MINDS N HEARTS INC.
525 Broadhollow Rd, STE 104
Melville, NY 11747
privacy@mindsandhearts.org