Privacy Policy
Effective date: 1 September 2026
SOS Connect exists to get help to people in crisis. Doing that means handling information that is personal and often sensitive — who needs help, where they are, and what they are facing. This policy explains what SOS Global Inc. ("we") collects, how it is used, who can see it, and the choices you have.
We hold two commitments above everything else in this policy. We do not sell personal information, and we never will. And the coordination record built here is not a saleable asset — see section 10.
1. Information we collect
Account information — name and email when you sign in, handled by our authentication provider, Clerk.
Relief coordination records — when a request for help is logged, by you or on your behalf by a coordinator or partner, we store the details needed to coordinate: names, phone numbers, locations, household information, and the circumstances described. When a helper or partner registers a resource — what they can provide and how to reach them — we store that as well. Reports from the ground and messages sent to our SMS number are stored the same way.
Technical data — basic usage analytics (page views, via Vercel Analytics) and the logs needed to run and debug the service.
Donations are processed by Givebutter. We do not receive or store your payment card details. Givebutter provides us with the donor name, email address, and donation amount so that we can acknowledge the gift and meet our reporting obligations as a nonprofit.
2. How we use it
To coordinate relief — matching requests with resources, routing them to nearby partners and volunteers, tracking them to resolution, and verifying reports.
To operate the service — authentication, security, debugging, and aggregate statistics.
To improve coordination over time — we study patterns in how help gets matched and delivered so that future responses are faster. This work uses outcomes that were confirmed by the person who received help, and no change to how the platform matches is ever applied without a person reviewing and approving it.
We do not sell personal information, and we do not use it for advertising.
3. Who can see it
Access is role-based and purpose-limited. Coordinators see the requests they coordinate. Partner organizations see the requests routed to them. Volunteers see what they need in order to act on a request they have taken. A person always sees their own record.
People's records are never public. Where a request or resource appears on the public map, it appears only because its owner chose to publish it, and only at the level of detail they chose — a general area rather than an address, unless they specifically chose otherwise.
Every time someone opens a person's contact details, that access is recorded — who looked, at what, and when. This is not a background process we may add later; it is how the platform is built.
Some people carry a safety flag on their record, applied when there is reason to believe that being findable would put them at risk. A flagged record cannot be published, cannot appear in the directory, and cannot be made visible by any other means.
Service providers process data on our behalf: Clerk (authentication), Supabase (database hosting), Vercel (hosting and analytics), Resend (email), and msgbubbles (SMS and messaging). Each is bound by its own agreement with us to process data only as we instruct.
We disclose information without consent in one circumstance: when we believe in good faith that doing so is necessary to prevent death or serious physical harm to someone, or where we are required to by law. Coordinating help in genuine emergencies is the reason this platform exists, and we would rather say plainly that this exception exists than bury it.
4. How we protect it
All person records sit behind deny-by-default database access. Nothing is readable from the public internet, and every request passes through the application server with role checks applied.
Contact details and other identifying information are held separately from coordination records, so that seeing a request does not mean seeing the person. Access to that information is gated and logged.
Secrets and credentials are never stored in code. No system is perfectly secure, but limiting who can see what is a design principle of the platform rather than an afterthought.
5. How long we keep it
Coordination records are kept while the response they belong to is active, and for two years after a case is closed. After that they are retained in aggregate form only — counts and areas, with names and contact details removed.
Access logs, which record who viewed personal information, are kept for seven years. They exist to prove that access controls worked, so we deliberately keep them longer than the records they describe.
Contribution records — who gave what — are retained permanently, because a nonprofit must be able to account for what it received and what it did with it.
Technical logs and analytics are kept for 90 days.
You can ask us to delete your information at any time; see section 6.
6. Your choices and rights
You can ask us what we hold about you, ask for corrections, or ask for deletion by emailing team@sosconnect.org. We will respond within 30 days.
If you have chosen to appear in our directory, you can remove yourself at any time, and that change takes effect immediately.
Deletion requests may be limited where a record must be kept for safety reasons, to complete relief already in progress, or because the law requires it. Where we cannot delete something, we will tell you which part and why.
Depending on where you live, you may have additional rights under state or national privacy law. We honour those rights regardless of where you live rather than applying them only where required.
7. Children
The service is for users 18 and older, and we do not knowingly create accounts for children.
Information about a minor may appear inside a household's request for help — a child's age, dietary needs, or medical requirement — entered by an adult in that household. We collect this only where it is needed to coordinate help, and it is treated with the same protections as every other person record. A parent or guardian may ask us to remove it at any time.
8. International use
SOS Connect is operated from the United States, and information is stored and processed there. If you use the service from elsewhere, you are sending information to the United States, where privacy law differs from your own.
9. Changes to this policy
We will post material changes on this page with a new effective date. Where a change meaningfully affects how personal information is used, we will notify affected users directly rather than relying on this page alone.
10. What happens to this information if SOS changes
Coordination records are built out of some of the worst weeks of people's lives. We do not treat them as an asset.
If SOS Global Inc. ceases to operate, personal information will be deleted or returned, never transferred as part of a sale. This commitment is written into our governing documents rather than resting on the intentions of whoever is running the organization at the time.
11. Contact
Privacy questions or requests: team@sosconnect.org
SOS Global Inc., 149 Weaver Blvd #127, Weaverville, NC 28787