Skip to main content

Children's Online Privacy Notice

Document: 16 - Children's Online Privacy Notice Publisher: BeneVets, Inc., a California Nonprofit Public Benefit Corporation Adopted: July 4, 2026 Proposed effective date: July 4, 2026 Last revised: 2026-06-02


§ 1. Plain-English Summary

In plain English: BeneVets is a service for adults. You have to be 18 or older to use it. We do not want or expect information from kids under 13, and we don't knowingly collect it. If we find out we did, we delete it quickly (we aim for 10 calendar days or less). If you are a parent or guardian and you think we have information about your child, please email privacy@benevets.org and we will help you review, delete, or stop further collection.

This Notice supplements the BeneVets Privacy Policy and explains how BeneVets, Inc. ("BeneVets," "we," "us") handles children's privacy under the Children's Online Privacy Protection Act of 1998 ("COPPA"), 15 U.S.C. §§ 6501-6506, the Federal Trade Commission's COPPA Rule, 16 C.F.R. Part 312, and applicable California law.


§ 2. Statement of Eligibility

In plain English: You must be at least 18 years old to use BeneVets. The service was not built for kids.

The BeneVets website, web application, and ancillary surfaces (the "Service") are intended for users 18 years of age or older. The Service is not directed to children under 13 within the meaning of COPPA. See 16 C.F.R. § 312.2 (definition of "Web site or online service directed to children"). The Service is not directed to children of any age, and its subject matter (U.S. Department of Veterans Affairs benefits navigation, intent-to-file tracking, compensation and pension preparation, TDIU eligibility, document storage of DD-214, accredited representative directory, and pro se VA form transmission) is targeted to adult U.S. military veterans, their adult spouses, and their adult authorized representatives.


§ 3. COPPA Posture

In plain English: We don't knowingly collect personal information from kids under 13. If we learn we did, we delete it within about 10 days.

BeneVets does not knowingly collect, use, or disclose Personal Information from children under 13. See 16 C.F.R. § 312.3 (general requirements). If BeneVets becomes aware that it has collected Personal Information from a child under 13, BeneVets will:

  1. Stop further collection associated with that account or record;
  2. Delete the Personal Information from production systems and from routine backups according to the BeneVets Data Retention Schedule (Document 14), within a reasonable period not to exceed 10 calendar days from confirmation as an operational target; and
  3. Where parent or guardian contact information is available, notify the parent or guardian of the discovery and the deletion.

BeneVets's reasonable-period target is shorter than the period generally accepted by the FTC for operator-initiated deletion under 16 C.F.R. § 312.10 and is an internal operational commitment, not a regulatory floor.


§ 4. Minor Dependents Listed in a Veteran's Profile

In plain English: A veteran can tell us "I have a dependent child" so we can match benefits like Chapter 35 or Fry Scholarship. We only accept the label (for example, "dependent child"). We will not accept the child's name, date of birth, contact information, or any other identifying detail.

Many VA benefits are conditioned on the existence of a qualifying minor dependent. To support eligibility matching, the Service allows a Veteran User to indicate that a minor dependent exists in their household for purposes of benefit-eligibility-match logic only.

Permitted entries (relationship label only):

  • "Dependent child"
  • "Stepchild"
  • "Adopted child"
  • "Child in legal guardianship"
  • A count of dependent children (integer)

NOT permitted (BeneVets does not solicit and will not knowingly accept):

  • The minor's first or last name;
  • The minor's date of birth, age, or grade level;
  • The minor's home or other physical address;
  • The minor's online contact information (email, screen name, telephone number);
  • The minor's Social Security number, Taxpayer Identification Number, or VA file number;
  • The minor's photograph, video, or audio recording;
  • The minor's geolocation;
  • Any persistent identifier associated with the minor; or
  • Free-text narrative descriptions that would solicit any of the foregoing.

The Service's intake forms are engineered to omit minor-PII fields. Free-text fields that exist for adult-user inputs (for example, "Conditions of Interest") are not directed at minors and BeneVets's published guidance directs users not to enter minor PII in those fields. If a Veteran User nevertheless enters minor PII in a free-text field, BeneVets will remove it on detection and notify the user.


§ 5. What "Personal Information" Means Under COPPA

In plain English: COPPA covers a specific list of information types. Here is the list, so you know what we're talking about.

Under 16 C.F.R. § 312.2, "personal information" collected from a child means individually identifiable information about an individual collected online, including the following:

  1. First and last name;
  2. A home or other physical address including street name and name of a city or town;
  3. Online contact information, including an email address or any other substantially similar identifier that permits direct contact with a person online;
  4. A screen name or user name where it functions as online contact information;
  5. A telephone number;
  6. A Social Security number;
  7. A persistent identifier that can be used to recognize a user over time and across different web sites or online services (including a customer number held in a cookie, an Internet Protocol address, a processor or device serial number, or unique device identifier);
  8. A photograph, video, or audio file where such file contains a child's image or voice;
  9. Geolocation information sufficient to identify street name and name of a city or town; and
  10. Information concerning the child or the parents of that child that the operator collects online from the child and combines with an identifier described above.

BeneVets does not solicit any of the foregoing from children under 13.


§ 6. Parent and Guardian Rights and Procedures

In plain English: If you are a parent or guardian, you can ask us what we have, ask us to delete it, and tell us to stop collecting. Email privacy@benevets.org.

A parent or legal guardian of a child under 13 has the following rights with respect to Personal Information BeneVets may have inadvertently collected from that child:

§ 6.1 Notification

If BeneVets becomes aware of inadvertent collection from a child under 13 and parent or guardian contact information is available, BeneVets will notify the parent or guardian of the collection, of the information at issue, and of the deletion or remediation action taken.

§ 6.2 Access

A parent or legal guardian may request access to Personal Information BeneVets has collected from their child by sending a request to privacy@benevets.org with the subject line "COPPA Access Request." BeneVets will respond as required under 16 C.F.R. § 312.6(a)(1) after reasonable verification of the requester's identity and parental or guardianship status.

§ 6.3 Deletion

A parent or legal guardian may request deletion of Personal Information BeneVets has collected from their child at any time, by emailing privacy@benevets.org with the subject line "COPPA Deletion Request." BeneVets will honor a verified deletion request within 10 calendar days of verification. See 16 C.F.R. § 312.6(a)(2).

§ 6.4 Refusal of Further Collection

A parent or legal guardian may refuse to permit BeneVets's further use or future collection of Personal Information from their child, while still allowing the child to participate in a service if the operator chooses to permit such participation. See 16 C.F.R. § 312.6(a)(3). Because BeneVets does not knowingly collect from children under 13 and does not offer any child-directed feature, the practical effect of this right at v1 is closure and deletion of any inadvertently created child record.

§ 6.5 Verification of Requester

To protect the child, BeneVets will reasonably verify that the person making a request under this Section is in fact the parent or legal guardian of the child. Acceptable verification methods include the verifiable-parental-consent methods enumerated at 16 C.F.R. § 312.5(b)(2) applied to the parental-rights request context.


§ 7. Verifiable Parental Consent

In plain English: We don't have a "verifiable parental consent" system because we don't knowingly collect from kids under 13. If that ever changes, we will build one before we turn on the new feature.

BeneVets does not maintain a Verifiable Parental Consent ("VPC") mechanism at v1 because BeneVets does not knowingly collect Personal Information from children under 13, and the Service is not directed to children under 13.

Reservation. If BeneVets in the future opens any feature directed to or knowingly used by children under 13, BeneVets will implement a VPC mechanism conforming to 16 C.F.R. § 312.5 before activation. Acceptable VPC mechanisms under 16 C.F.R. § 312.5(b)(2) include:

  • A signed consent form returned by postal mail, facsimile, or electronic scan;
  • Use of a credit card, debit card, or other online payment system that provides notification of each separate transaction to the primary account holder;
  • A toll-free telephone number staffed by trained personnel;
  • A video conference with trained personnel;
  • Verification of government-issued identification checked against a database, with prompt deletion of the identification after verification;
  • A knowledge-based authentication challenge with sufficient difficulty; and
  • Other methods approved by the Federal Trade Commission under 16 C.F.R. § 312.5(b)(3).

Implementing a VPC mechanism is a substantial engineering and operational commitment, and BeneVets does not undertake it lightly. No child-directed feature will ship before a VPC mechanism is reviewed and approved by counsel.


§ 8. Users Ages 13 to 17

In plain English: BeneVets is for users 18 and over. We don't knowingly let teenagers register either. State laws that protect minor data don't apply to us right now because our minimum age is 18.

The Service requires self-attestation of an age of 18 or older at registration. The Service is not directed to teens and does not include features designed for teens.

State-specific minor-data protection laws are noted for awareness:

  • California "Eraser Law" for minors. Cal. Bus. & Prof. Code § 22580 et seq., which grants minors under 18 a right to remove content they posted to certain operators, is noted but is not engaged because BeneVets does not knowingly accept users under 18 and the Service has no user-generated-content features at v1.
  • California Age-Appropriate Design Code Act. Cal. Civ. Code § 1798.99.28 et seq. ("CAADCA"). The CAADCA imposes design-and-data-protection obligations on businesses that provide online services, products, or features "likely to be accessed by children" under 18. The CAADCA is subject to ongoing federal litigation in NetChoice, LLC v. Bonta, No. 5:22-cv-08861 (N.D. Cal.), with appellate proceedings in NetChoice, LLC v. Bonta, No. 24-2885 (9th Cir.). As of the date of this draft, portions of the CAADCA have been preliminarily and partially enjoined and other portions remain subject to further proceedings; the precise enjoined-versus-active scope is in flux. BeneVets monitors the CAADCA litigation and updates this Section as the enjoined-versus-active scope changes.
  • Other state minor-privacy statutes. A growing number of states (including but not limited to Connecticut, Utah, Texas, Florida) have enacted minor-specific privacy provisions in their general consumer-privacy or social-media statutes. BeneVets's 18+ posture and absence of user-generated-content features mean these statutes are not directly engaged at v1.

If BeneVets's posture changes or the user base evidences substantial minor use, BeneVets will reassess applicability of these regimes prior to such change.


§ 9. Eligibility Verification - Self-Attestation Limitation

In plain English: Right now we only ask users to confirm they are 18 or older. We do not check IDs. That's a real limit, and we are being upfront about it.

At v1, BeneVets does not perform documentary or biometric age verification at registration. Age eligibility is established by user self-attestation under the BeneVets Terms of Service. BeneVets relies on the self-attestation and on a Service experience that is not directed to children to keep the Service's audience adult.

Counsel-review note: If maintenance of the 18+ posture is enforcement-critical for any program partnership, regulatory regime, or risk allocation in the broader document set, BeneVets should consider documentary or knowledge-based age verification at registration. This is a known limitation of the self-attestation model and is acknowledged here in service of transparency.


§ 10. School-Related Context

In plain English: BeneVets is not a school service. We do describe school benefits a veteran's family might use, but we don't collect anything from kids at school.

At v1 the Service is not directed at school or educational settings and does not function as an "educational technology" or "ed-tech" service. The Service is not subject to a contract with a local educational agency for the provision of student-data services under California A.B. 1584 (Cal. Educ. Code § 49073.1) or comparable statutes.

Some Service content describes VA education benefits available to veterans and their dependents, including the Post-9/11 GI Bill (38 U.S.C. ch. 33), the Survivors' and Dependents' Educational Assistance program (38 U.S.C. ch. 35), and the Marine Gunnery Sergeant John David Fry Scholarship (38 U.S.C. § 3311(b)(9)). Educational content describing these benefits is informational only and is not directed at the school-age beneficiary. The audience for that content is the adult veteran or surviving-spouse account holder.


§ 11. Active-Duty Servicemembers Under 18

In plain English: Some active-duty servicemembers are 17, with parental consent at enlistment. Right now we do not let anyone under 18 register, even active-duty 17-year-olds. We may revisit this later.

A narrow class of U.S. military servicemembers are 17 years of age, having enlisted with parental consent under 10 U.S.C. § 505. BeneVets's age posture is 18+, and an active-duty servicemember who is 17 may not register an account at v1. The Service may be used by a parent, guardian, or other authorized adult on behalf of an under-18 servicemember as a benefit-eligibility research tool, but the under-18 servicemember may not register their own account.

Note. BeneVets recognizes this restriction may exclude a small population that BeneVets ultimately wishes to serve. The posture is reserved for revisitation if BeneVets elects to develop an authorized-adult-mediated under-18 pathway, which would require (a) appropriate parental or guardian verification, (b) data-minimization commitments commensurate with COPPA principles.


§ 12. International Notes

In plain English: BeneVets is a U.S. service. We are not aiming at users in Europe, the UK, or other countries. We have not built our service against international children's privacy laws.

At v1 the Service is targeted to the United States, including the 50 states, the District of Columbia, U.S. territories, and APO/FPO/DPO addresses. International children's privacy frameworks, including:

  • the European Union's General Data Protection Regulation as it applies to children (Regulation (EU) 2016/679, art. 8), and
  • the United Kingdom's Age-Appropriate Design Code (the Information Commissioner's Office's "Children's code"),

are not engaged at v1 because the Service is not targeted to children in those jurisdictions and is not targeted to users in those jurisdictions at all. Reserved for future review if BeneVets's geographic scope expands.


§ 13. California Age-Appropriate Design Code Act - Triggering Conditions for Future Applicability

In plain English: If our user base ever changes in a way that makes BeneVets a service "likely to be accessed by children," more rules under the California Age-Appropriate Design Code Act will apply, and we'll have to do additional work before that happens.

The CAADCA, Cal. Civ. Code § 1798.99.28 et seq., applies to businesses providing online services, products, or features "likely to be accessed by children" under 18. BeneVets's 18+ posture and adult-veteran subject matter are intended to keep BeneVets outside that triggering condition at v1. If any of the following occurs, BeneVets will reassess CAADCA applicability before continuing:

  1. Telemetry or operational signals indicate substantial use by users under 18;
  2. BeneVets introduces a feature directed to or marketed to minors;
  3. BeneVets partners with any entity whose audience includes substantial minor users; or
  4. A statutory amendment, regulatory guidance, or judicial decision (including a further ruling in NetChoice v. Bonta) materially changes the CAADCA's scope of application.

The CAADCA contains provisions including but not limited to: a data-protection impact assessment for covered features, a high-default-privacy obligation, prohibitions on certain "dark patterns," and a prohibition on certain profiling. The precise active-versus-enjoined scope must be confirmed before any features that could trigger the CAADCA are activated.


§ 14. Updates to This Notice

In plain English: If we change this Notice, we'll update the date at the top, and for big changes we'll tell people.

BeneVets may update this Notice from time to time. When BeneVets does, the "Last revised" date at the top of this Notice will change. For material changes affecting parental or guardian rights or BeneVets's COPPA posture, BeneVets will provide reasonable notice consistent with 16 C.F.R. § 312.4(b) before the change takes effect. Continued use of the Service after the effective date of an update constitutes acknowledgment of the updated Notice, subject to any rights that cannot be waived as a matter of law.


§ 15. Contact Information

In plain English: Email privacy@benevets.org for any question about this Notice or about a child's information.

Questions about this Notice, parental or guardian access requests, deletion requests, refusal-of-further-collection requests, or other COPPA-related inquiries may be directed to:

BeneVets, Inc. Attention: Privacy Officer (COPPA) Email: privacy@benevets.org Postal address: 1441 Pomona Road, Suite 20, Corona, CA 92882 Riverside County, California

For non-COPPA privacy questions, please see the BeneVets Privacy Policy (Document 02).

If you believe BeneVets has not adequately responded to a COPPA-related concern, you may contact the U.S. Federal Trade Commission, Consumer Response Center, 600 Pennsylvania Avenue NW, Washington, DC 20580, or visit https://reportfraud.ftc.gov.


§ 16. Cross-References

This Notice is part of the BeneVets document set. Related documents:

  • Document 02 - Privacy Policy
  • Document 03 - Cookie Notice
  • Document 04 - Sub-processor List
  • Document 14 - Data Retention Schedule
  • Document 15 - Automated Decision-Making and AI Notice

End of Document 16 - Children's Online Privacy Notice.