What we collect
- Account details you give us: name, email, optional phone number, password (stored only as a secure hash by our authentication provider).
- Loved-one details you give us: name, ID number, jurisdiction and facility.
- Program activity: eligible purchase amounts and dates reported by the discount network, and the savings, credits and payouts calculated from them.
- Security and operational data: IP-derived rate-limit keys (stored as keyed hashes), request logs without passwords or payment details.
Public records we use
For jurisdictions that publish official data (currently Texas open data and the Nebraska Department of Correctional Services' public file), we store only the minimum fields needed to confirm a match: ID number, name, facility and custody status. We do not store dates of birth, offenses or sentence details. Lookup attempts are logged with a hashed identifier, not the raw number.
How we use it
- To run your membership, calculate savings and credits, and send contributions.
- To confirm your loved one's details and keep facility information current.
- To send transactional email (account, credit and payout notices).
- To prevent fraud and keep the service secure.
What we don't do
- We do not sell personal information.
- We do not use your loved one's information for marketing.
- We do not share your information with correctional agencies except as needed to deliver a payout you requested.
Service providers
We use infrastructure providers to host the application and database, send email, and (if paid plans are introduced) process card payments. They process data on our behalf under their terms.
Retention and your choices
Financial records are retained as required for accounting and dispute handling. Operational data such as rate-limit records and delivered-email contents are purged automatically on a schedule. You can request a copy or deletion of your personal information through the Contact page; some financial records must be kept even after an account is closed.
Security
Data is encrypted in transit. Access is enforced at the database level with row-level security so members can only read their own records. Staff access is role-based and audited.