CommunoApp Privacy Policy
CommunoApp is a community management platform operated by ClaretCode Technologies LLC, a limited liability company registered in Carlisle, Pennsylvania, USA ("CommunoApp," "we," "us," "our"). This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it, and what rights and choices you have. By creating an account or using the Services, you acknowledge that you have read and understood this Privacy Policy. This Policy should be read together with our Terms and Conditions. The Terms' provisions on dispute resolution, governing law, and limitations of liability apply equally to any claim arising out of or relating to this Privacy Policy or our handling of your information.
1. Scope
This Policy applies to:
- CommunoApp mobile applications (iOS and Android)
- CommunoApp web applications and admin portals
- CommunoApp backend APIs and hosted services
- All platform features: community feeds, events, amenities, services marketplace, chat and messaging, notifications, polls, emergency alerts, and account management
It does not apply to third-party websites, applications, or services linked from or integrated with the platform. Those services have their own privacy policies.
2. Information We Collect
2.1 Account and Profile Data
When you create an account and build your profile, we collect:
- Identity information: first name, last name, username, email address, phone number (and country code)
- Credentials: password (stored as a cryptographic hash — never in plaintext)
- Profile data: profile photo, bio, hometown, current city, street address, city, state, ZIP/postal code, country, birthday, gender, and personal preferences (e.g., dietary preferences)
- Skills, interests, and badges: skills and interests you add to your profile, and volunteer badges you earn through community activity
Information you provide about others. Some features let you enter information about other people — for example, guest counts on an RSVP, a potluck commitment made on someone's behalf, or contact details you type into a service listing or request. You are responsible for having the right to provide that information, and it will be visible to whoever can see the content it appears in.
2.2 Community Content and Activity
When you participate in communities, we collect and store:
- Posts, comments, and reactions you submit to community feeds
- Polls you create or vote in, and your responses
- Event RSVPs (including guest counts) and activity sign-up commitments
- Potluck and volunteer commitments associated with events
- Content moderation and report submissions
- Your community membership records (which communities you have joined and your role within each)
2.3 Services Marketplace Data
When you use the Services Marketplace (as either a Provider or a Customer):
- Provider listings: service name, description, location or service area, contact information included in a listing, photos, pricing, unit types, availability status, and any items or packages within a listing
- Service requests: item selections, quantities, preferred date and time, special requirements, and contact details included in a request
- Request status and history: the lifecycle of each request (Pending, Accepted/In Progress, Declined, Completed)
- In-request chat messages: messages exchanged between a Provider and a Customer within a specific service request thread
- Ratings and reviews: star ratings and written review text you submit about a Provider or service
2.4 Chat and Messaging Data
When you use the in-app chat and community messaging features:
- Message content (text, and any media shared in chat)
- Message timestamps and read/delivery metadata
- Real-time presence signals (e.g., online status and typing indicators) powered by our real-time infrastructure (SignalR)
Chat messages are stored to enable conversation continuity. Presence signals (online/typing) are transient and are not permanently stored.
If you block another member, we store a record of the block so that it can be enforced (see Section 12). Your list of blocked members is visible only to you.
2.5 Event, Amenity, and Activity Data
- Event details you create (title, description, location, date/time, recurrence settings, fees, cover image, potluck categories and items, activity items, and volunteer roles with time slots and capacity)
- Amenity booking records (which amenity, booked by whom, date/time, and booking notes)
- Activity and volunteer sign-up records associated with events
This data is accessible to event organizers and Community Admins within the relevant Community.
2.6 Media and Uploaded Files
When you upload images or files, we store:
- Profile photos, event cover images, and service listing images
- Any other media attached to posts or community content
Media files are stored in cloud object storage (currently Microsoft Azure Blob Storage). Uploaded files are associated with your account and the content they belong to. Profile photos are intended to be visible to members and admins of your Community. Profile photo files may be accessible through direct media URLs (for example, if a URL is shared), so you should only upload photos you are comfortable sharing within your Community context.
The mobile apps request camera and photo-library permission only when you choose to take or attach a photo. We access only the photos you select; we do not scan or upload your photo library.
2.7 Ratings and Reviews
Reviews you submit for service providers are associated with your account and are visible to other members of the relevant Community. We store the rating score, review text, and submission timestamp.
2.8 Notification and Alert Data
- Push notification subscription tokens and device registration identifiers
- Notification preferences (opt-in/opt-out settings per notification type)
- Notification delivery metadata (timestamps, delivery status)
- Emergency alert records created and sent by Community Admins
We do not store the full content of push notifications on our servers after delivery except where the notification references community content already stored.
2.9 Technical and Device Data
We automatically collect:
- Device type, operating system, and version
- App version and platform (iOS / Android / Web)
- Browser type and user agent (for web access)
- Internet Protocol (IP) address
- Approximate geolocation derived from your IP address (city/region/country level)
- App interaction events and feature usage metadata (for diagnostics and improvement)
- Request identifiers, correlation IDs, and error logs
2.10 Security and Authentication Logs
For every login, registration, and sensitive account action we log:
- Event type (e.g., login success, login failure, password reset)
- Outcome (success or failure)
- Timestamp
- IP address
- Request path, method, and correlation ID
These logs are used for security monitoring, incident investigation, and fraud prevention.
We also maintain:
- Device session records — a record per signed-in device (device identifier, IP address, browser/user agent, and last-seen time) so you and we can see and revoke active sessions
- One-time verification codes (OTPs) — short-lived codes generated for registration and password reset, retained only as long as needed to complete or expire the verification
- Transactional email records — a log of system emails we send you (recipient, subject, and message body) used to diagnose delivery problems and investigate abuse; these records are retained for a limited period (see Section 11)
2.11 Support and Feedback Data
- In-app feedback content and any supporting details you provide
- Support request communications
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the platform — run all platform features, process account creation and authentication, deliver community and marketplace functionality
- Enable community and social interactions — display your profile, posts, event RSVPs, service listings, and other community activity to relevant community members and admins
- Facilitate the Services Marketplace — connect Providers and Customers, display service listings, manage request workflows and status, enable in-request messaging, and display ratings and reviews
- Deliver notifications and alerts — send push notifications, emergency alerts (as configured by Community Admins), event reminders, and service request updates
- Support regional relevance and security checks — use approximate location derived from IP address (city/region/country level) at login and other security-sensitive events to support account security, fraud prevention, and regional relevance
- Maintain real-time features — power live chat, presence indicators, and SignalR-based messaging
- Maintain security and prevent abuse — detect suspicious activity, investigate incidents, enforce our Terms and Conditions, and prevent fraud
- Improve the platform — analyze usage patterns, diagnose errors, and improve reliability and performance
- Fulfill legal and contractual obligations — comply with applicable laws, respond to legal requests, enforce our policies, and protect our legal rights
- Respond to support requests — address your questions, feedback, and support submissions
CommunoApp does not access or display device GPS location and does not perform background location tracking. We currently do not use location data for third-party advertising. Approximate location derived from IP may still be processed for login security, fraud prevention, and regional relevance. If this changes, we will update this Privacy Policy and provide any notices or consent choices required by applicable law.
5. Community Administrator Access
Community Admins play a significant role in how data within their Community is managed and visible. Within their Community, Admins can:
- View member profiles, roles, and membership status
- See posts, comments, event RSVPs, amenity bookings, and service listings created within their Community
- Receive reports about content or members
- Enable or disable platform features (e.g., posts, polls, events, services marketplace, amenity bookings) for their Community
- Remove members, content, or service listings from their Community
- Send emergency alerts to all community members
- Link their Community to another Community (which affects data visibility as described in Section 4.2)
Community Admins agree, under our Terms and Conditions, to use member data they can access through the platform solely for administering their Community. However, Community Admins are independent operators — they are not employees, contractors, or agents of ClaretCode Technologies LLC. ClaretCode Technologies LLC is not responsible or liable for a Community Admin's use, disclosure, or retention of member information outside the platform, and your recourse for any such misuse is against that Community Admin. If you believe an Admin is misusing member data, report it to us at support@claretcode.com and we may suspend or remove their access.
6. Data Visibility and Your Privacy Controls
6.1 Privacy Settings You Control
For certain profile fields, you decide who may see them, in Profile → Privacy Settings in the app. Each field can be set to one of:
| Setting | Who can see the field |
|---|---|
| Public | Any signed-in CommunoApp user, including users who are not members of your Communities |
| Community Members | Members and Admins of Communities you belong to |
| Community Admins | Admins of Communities you belong to (not ordinary members) |
| Only Me | You only |
The fields you control, and their default settings:
| Field | Default |
|---|---|
| Email address | Only Me |
| Phone number | Only Me |
| Street address, city, state, ZIP | Only Me |
| Birthday | Only Me |
| Gender | Only Me |
| Hometown | Community Members |
| Current city | Community Members |
| Dietary preferences | Community Members |
| Skills | Community Members |
| Interests | Community Members |
You can change these settings at any time, or restore the defaults above using "Reset to default." If you have never changed your settings, the defaults apply. Changes apply going forward; they do not retroactively remove information you have already published in posts, comments, listings, or chat, or that another member has already viewed, copied, or recorded.
Note that choosing Public for a field makes it visible to any signed-in CommunoApp user anywhere on the platform — a broader audience than your Communities.
6.2 Information Not Covered by Privacy Settings
The following are visible to members of Communities you join and cannot be individually restricted, because they are required for the platform to function:
- Your first and last name, username, profile photo, and bio
- Your role and membership status in the Community
- Content you publish: posts, comments, reactions, poll votes, event RSVPs, potluck and volunteer commitments, service listings, and ratings and reviews
If you do not wish this information to be visible, do not provide it or do not publish that content.
Contact details you type *into* content — a service listing, a post, an event description, or a chat message — are visible to everyone who can see that content, regardless of your privacy settings.
6.3 Visibility Summary
| Type of Data | Other Community Members | Community Admin | CommunoApp |
|---|---|---|---|
| Name, username, photo, bio, role | Yes | Yes | Yes (operational use) |
| Gender | Per your privacy setting (default: hidden) | Per your privacy setting (default: hidden) | Yes |
| Interests | Per your privacy setting (default: visible) | Per your privacy setting (default: visible) | Yes |
| Email address | Per your privacy setting (default: hidden) | Per your privacy setting (default: hidden) | Yes |
| Phone number | Per your privacy setting (default: hidden) | Per your privacy setting (default: hidden) | Yes |
| Address fields | Per your privacy setting (default: hidden) | Per your privacy setting (default: hidden) | Yes |
| Birthday | Per your privacy setting (default: hidden) | Per your privacy setting (default: hidden) | Yes |
| Hometown, current city | Per your privacy setting (default: visible) | Per your privacy setting (default: visible) | Yes |
| Dietary preferences, skills | Per your privacy setting (default: visible) | Per your privacy setting (default: visible) | Yes |
| Posts, comments, reactions, poll votes | Yes | Yes | Operational access |
| Event RSVPs | Event organizers and community members | Yes | Operational access |
| Potluck / activity commitments | Event participants | Yes | Operational access |
| Service listings | Yes (community members) | Yes | Operational access |
| Service request details | Provider and Customer only | Limited (admin moderation) | Operational access |
| In-request chat | Provider and Customer only | No | Operational access |
| Amenity bookings | No | Yes | Operational access |
| Ratings and reviews | Yes (community members) | Yes | Operational access |
| Private chat messages | Chat participants only | No | Operational access |
| Blocked-members list | No | No | Operational access |
| Push notification token, device sessions | No | No | Yes (delivery and security) |
| Security and authentication logs | No | No | Yes |
7. Children's Privacy
CommunoApp requires users to be at least 13 years of age to create an account, consistent with the US Children's Online Privacy Protection Act (COPPA) and our Terms and Conditions.
- We do not knowingly collect personal information from children under the age of 13.
- If a user is between 13 and 18 years of age, we require parental or guardian consent per our Terms.
- If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will promptly delete that information and terminate the account.
- If you are a parent or guardian and believe your child under 13 has created an account, please contact us at support@claretcode.com.
8. US State Privacy Rights
Depending on the US state where you reside, you may have specific privacy rights under applicable state law:
- California (CCPA/CPRA): California residents have the right to know what personal information we collect, use, and disclose; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising); and the right to non-discrimination for exercising these rights. California residents may submit requests to support@claretcode.com.
- Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and similar state laws: Residents of these states may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of profiling and targeted advertising. We do not conduct targeted advertising. Contact us to exercise your rights.
- Pennsylvania: Pennsylvania does not currently have a comprehensive consumer data privacy law, but we apply the rights described above to all US users where feasible.
We will respond to verified privacy rights requests within the timeframes required by applicable law. To submit a request, contact support@claretcode.com with "Privacy Request" in the subject line. We may need to verify your identity before processing your request.
9. Legal Bases for Processing (GDPR/UK GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal bases:
- Contract performance — to provide the Services you have signed up for and fulfill our obligations to you
- Legitimate interests — to operate and improve the platform, maintain security, detect and prevent fraud and abuse, and protect the rights of our users and ClaretCode Technologies LLC, where these interests are not overridden by your rights
- Consent — where required by law (e.g., for certain cookies or marketing communications)
- Legal obligation — to comply with applicable laws and regulations
Security and authentication logging (Section 2.10), including recording of IP addresses and approximate location at login, is processed on the basis of our legitimate interest in protecting accounts and preventing fraud and abuse.
You may have the right to object to or restrict processing based on legitimate interests. Contact us at support@claretcode.com to submit such requests.
10. International Data Transfers
CommunoApp is operated from the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and in any country where our service providers operate.
The United States may not have the same level of data protection as your home country. Where required by applicable law (such as GDPR), we use appropriate safeguards for international transfers, including Standard Contractual Clauses or other lawful mechanisms.
11. Data Retention
We retain your information for as long as:
- you have an active account and use the Services;
- necessary to provide the Services and operate community features;
- necessary to satisfy legal, tax, accounting, and regulatory obligations;
- necessary to resolve disputes, enforce agreements, and protect our legal rights.
Specific retention guidelines:
| Data Type | Retention |
|---|---|
| Account and profile data | Retained while account is active; deleted on verified account deletion request, subject to legal holds |
| Community content (posts, events, RSVPs) | Retained while the Community is active; may be removed if the Community is deleted by the Admin |
| Chat messages | Retained while conversation participants have active accounts; subject to applicable law |
| Service request records | Retained for a reasonable period to support dispute resolution (typically 2 years) |
| Ratings and reviews | Retained while the associated community is active |
| Security and authentication logs | Typically 90 to 365 days, or longer where required for incident response or legal obligations |
| Media files (images/uploads) | Retained while associated content or account is active |
| Support and feedback records | Retained for a reasonable period to support our operations (typically 1 to 3 years) |
| Transactional email records | Typically 90 days |
| Account deletion records | Retained indefinitely in de-identified form (see below) |
Account deletion. You can delete your account in the app (Profile → Delete Account) or via the account deletion page on our website. You must confirm the deletion and re-enter your password. Once it proceeds, deletion is immediate and irreversible — there is no grace period and no restore path. When you delete your account:
- Deleted or irreversibly anonymized: your name, email address, phone number, and profile photo; your bio, birthday, gender, address, hometown, and dietary preferences; your skills, interests, and volunteer badges; your notification settings, saved devices, and push registrations; your notifications and your place in every chat conversation; your privacy settings and blocked-members list; your password and all signed-in sessions.
- Communities you created are deleted along with their content. If a community you created still has other active members, you must remove those members before your account can be deleted. If you are the only admin of a community you joined, you must first make another member an admin.
- Content you posted in communities you joined (posts, comments, poll votes, RSVPs, reactions, and service requests) remains visible to those communities, attributed to "Deleted User," to preserve the integrity of shared conversations and records.
- Messages you already sent remain in the other participants' conversations.
- Security logs are retained for abuse investigation with your identity, location, and device details removed.
- A minimal deletion record is retained: a one-way cryptographic hash of your email address, the deletion date, the platform and country the request came from, and any reason you chose to give. This record exists to prove the deletion occurred and to prevent abuse, and cannot be used to re-identify you.
When deletion is temporarily unavailable. If your account is the subject of an open child safety review, deletion is paused until that review is complete. We are required to preserve the relevant records while a review of that kind is in progress, and deleting the account would remove the very information we must retain. This is the only circumstance in which we hold a deletion request, and it ends when the review closes. If you believe this has been applied in error, contact support@claretcode.com.
Super admin (platform staff) accounts cannot be deleted from the app; contact support@claretcode.com.
If you cannot access the app, you may also request deletion by emailing support@claretcode.com with "Privacy Request" in the subject line; we will verify your identity before processing the request.
12. Your Rights and Choices
Depending on applicable law and your location, you may have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request that inaccurate information be corrected
- Deletion — delete your account yourself at any time in the app (Profile → Delete Account) or via the account deletion page on our website (see Section 11), or request deletion of your personal information by contacting us (subject to legal retention obligations)
- Portability — receive your data in a structured, machine-readable format
- Restriction — request that we restrict processing of your data in certain circumstances
- Objection — object to certain types of processing, including processing based on legitimate interests
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Opt out of notifications — manage your push notification preferences in your device settings or in the CommunoApp app settings at any time
- Block other members — block another member at any time from their profile or chat; while a block is in place, neither of you can message the other. Your blocked-members list is visible only to you, and you can unblock at any time
- Lodge a complaint — if you believe we have handled your information unlawfully, you may contact us or lodge a complaint with a relevant supervisory authority
To exercise any of these rights, contact us at support@claretcode.com with "Privacy Request" in the subject line, or use the in-app Feedback & Support feature or the support page on our website. We will respond within the timeframe required by applicable law.
13. Security, Fraud, and Abuse Prevention
We implement technical and organizational safeguards including:
- Password hashing using industry-standard algorithms (plaintext passwords are never stored)
- Transport security (HTTPS/TLS) for all data in transit
- Role-based access control and authorization enforcement
- Security and authentication event logging (see Section 2.10)
- Monitoring for unusual access patterns, brute-force attempts, and credential abuse
- Least-privilege access practices for internal operational systems
- Incident response processes
No system is completely secure. We cannot guarantee that unauthorized access, hacking, data loss, or security breaches will never occur. If we become aware of a breach that affects your personal information in a manner that requires notification under applicable law, we will notify you as required, using in-app notification, email, or other reasonable means.
You can help protect your account by using a strong password and notifying us immediately if you suspect unauthorized access at support@claretcode.com.
14. Cookies and Local Storage
Our web applications may use cookies and local storage for:
- Authentication and session management
- Remembering user preferences and settings
- Security and fraud prevention
- Analytics and performance monitoring
You can manage or block cookies through your browser settings. Some features may not function correctly if cookies are disabled. Our mobile applications do not use browser cookies but may use similar device-based storage mechanisms for session and preference management.
15. Automated Decision-Making
CommunoApp does not currently make decisions that produce significant legal or similarly significant effects on individuals solely through automated means. Automated security controls — such as rate limiting, login throttling, and temporary blocking of IP addresses showing abusive behavior — may act without human review to protect the platform. Decisions with material, lasting effects on your account are subject to human review.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. Where required by applicable law, or where changes are material, we will provide additional notice (for example, by in-app notification or email). Your continued use of the Services after the updated Policy becomes effective constitutes your acceptance of the changes.
17. Contact Us
For any privacy-related questions, requests, or concerns:
ClaretCode Technologies LLC Carlisle, Pennsylvania, USA Email: support@claretcode.com
You can also reach us through the in-app Feedback & Support feature or the support page on our website.
We aim to respond to all privacy inquiries within 30 days (or the shorter period required by applicable law).
Address
ClaretCode Technologies LLC
25 Long Bend Dr
Carlisle, Pennsylvania, USA
Appendix A: Categories of Personal Information We Collect
| Category | Examples |
|---|---|
| Identifiers | Name, username, email address, phone number, IP address, device identifiers |
| Profile data | Profile photo, bio, hometown, current city, address, birthday, gender, dietary preferences, skills, interests, volunteer badges, privacy settings |
| Community content | Posts, comments, reactions, polls, event and amenity records, RSVPs, potluck and volunteer commitments |
| Marketplace data | Service listings, service requests, request status history, in-request messages, ratings, reviews |
| Chat and messaging data | In-app chat messages, presence signals, message timestamps, blocked-member records |
| Media and uploads | Profile images, event cover photos, service listing photos |
| Technical and device data | Device type, OS, app version, browser, user agent, IP address, approximate location from IP |
| Security and authentication data | Login/logout events, failure logs, IP, timestamp, approximate geolocation, correlation IDs, device sessions, one-time verification codes, transactional email records, de-identified account deletion records |
| Notification data | Push token, notification preferences, delivery metadata |
| Support and feedback | Feedback content, support request details |
Appendix B: Community Administrator Data Access
Community Admins have elevated access to data within their own Community. This table summarizes the key data Community Admins can access:
| Data | Admin Can Access? | Notes |
|---|---|---|
| Member profile (name, photo, bio, role) | Yes | Core membership display |
| Member email address | Per the member's privacy setting | Hidden by default; visible if the member sets it to Community Admins, Community Members, or Public |
| Member phone number | Per the member's privacy setting | Hidden by default; visible if the member sets it to Community Admins, Community Members, or Public |
| Member address or birthday | Per the member's privacy setting | Hidden by default; visible if the member sets it to Community Admins, Community Members, or Public |
| Posts and comments | Yes | Full access for moderation |
| Event RSVPs and guest counts | Yes | Via event management |
| Potluck and activity commitments | Yes | Via event management |
| Amenity booking records | Yes | Via amenity management |
| Service listings in the community | Yes | Can enable/disable/moderate |
| Service requests (Provider/Customer details) | Limited | For moderation of violations only |
| In-request chat between Provider/Customer | No | Private to the two parties |
| Ratings and reviews | Yes | Visible as community content |
| Community-wide emergency alerts | Yes | Can create and send |
| Private chat messages between members | No | Private between participants |
Community Admins are not employed by or acting as agents of ClaretCode Technologies LLC. They are independent operators of their community spaces.
Appendix C: Data Controller and Processor Roles
ClaretCode Technologies LLC acts as the data controller for personal information collected through CommunoApp account registration, platform operation, security functions, and support.
In cases where CommunoApp is deployed as a platform infrastructure for an organizational customer (such as a business or HOA that operates a Community), ClaretCode Technologies LLC may act as a data processor on that organization's documented instructions. Data Processing Agreements (DPAs) are available on request for enterprise or organizational use cases.
Community Admins who independently control how data is used within their Community (including decisions about community rules, content moderation, and member access) may themselves act as data controllers for those processing activities under applicable law (particularly GDPR). Users should contact their Community Admin for questions about data handling decisions specific to their Community.