Legal and safety
Privacy Policy
Version 2026-08-10
Togetha Privacy Policy
Effective date: 2026-08-10
Policy version: 2026-08-10
This Privacy Policy explains how Togetha collects, uses, and shares information for volunteer coordination, verified service records, safety, security, and platform operations.
Information collected
Togetha may collect account information such as name, email address, password hash, age band, organization memberships, volunteer profile information, signups, attendance records, service hours, service receipts, calendar feed tokens, beta feedback, trust reports, audit logs, and basic request/security information such as IP address and user agent for consent and safety records.
Data minimization
Togetha collects information needed to operate volunteer signup, coordination, verified service records, safety reports, calendar feeds, and platform security. Togetha does not collect full birthdates in the initial pilot unless a future feature requires it and the policy is updated.
How information is used
Information is used to create accounts, show opportunities, coordinate signups, help organizations manage rosters, confirm attendance, create verified service records, send notifications, provide calendar feeds, investigate safety or privacy reports, prevent abuse, and improve the product.
Information visible to organizations
When a volunteer signs up for an opportunity, the hosting organization may see the volunteer's name, email address, signup status, signup message, attendance status, and service hours for that opportunity.
Information visible to admins
Togetha platform administrators may view information needed to support users, verify organizations, investigate reports, prevent fraud, maintain security, and operate the service.
Calendar feed privacy
Private calendar feed URLs are secret links. Anyone with a user's private calendar feed URL may be able to view that user's Togetha signup calendar. Users should not share private feed URLs publicly and can regenerate them in calendar settings.
Children and minors
Togetha is not available to children under 13. Users under 18 may participate only where permitted by the organization and where required parent or guardian consent is obtained by the organization or responsible adult.
Security
Togetha uses reasonable safeguards for the current stage of the product, including password hashing, signed sessions, CSRF protection, admin-only views, audit logs, private calendar token rotation, and deployment controls. No online service can guarantee complete security.
Retention and deletion
Togetha keeps information while needed to operate accounts, coordinate opportunities, maintain verified records, investigate safety or fraud concerns, satisfy legal obligations, or preserve platform integrity. Users can request deletion or correction by contacting support@togetha.live. Some records may be retained or anonymized when needed for fraud prevention, legal compliance, audit records, or verified service-record integrity.
Service providers
Togetha may use hosting, email, domain, logging, and infrastructure providers to operate the service. These providers process information as needed to provide their services.
Contact
Privacy questions or deletion requests can be sent to support@togetha.live.