BeneVets Privacy Policy
Effective date: July 4, 2026 Last updated: July 4, 2026 Version: 1.0
§ 1. In Plain English (Summary)
In plain English: BeneVets, Inc. ("BeneVets," "we," "our," or "us") runs a free website that helps U.S. military veterans and their families navigate U.S. Department of Veterans Affairs ("VA") benefits. To do that, we collect information you give us (like your name, contact information, branch of service, and a copy of your DD-214 if you upload one), information we get from VA when you authorize us to (like your claim status or disability rating), and a small amount of information from your browser (like the page you're on). We use this information to run the Service, to keep your account secure, and to help you prepare and submit VA forms on your own behalf. We do not sell your information. We do not share your information for cross-context behavioral advertising as that term is defined in California law. We honor the Global Privacy Control as a universal opt-out signal across the entire Service. You have rights to see, correct, delete, port, and limit our use of your information. You can email us at privacy@benevets.org to exercise any right described in this Policy.
This Policy is written in a hybrid style. Every operative section opens with a plain-English summary. The defined-term and citation-precise text follows.
§ 2. Scope and Jurisdiction
In plain English: This Policy covers the BeneVets website, web application, and related services. We aim the Service at people in the United States. We do not aim the Service at people in the European Economic Area, the United Kingdom, Canada, Mexico, or anywhere else outside the United States.
This Policy applies to Personal Information that BeneVets, Inc. ("BeneVets") collects, processes, discloses, or retains through the BeneVets website at benevets.org, any successor or staging domain operated by BeneVets, and the web application and ancillary surfaces operated by BeneVets (collectively, the "Service"). The Service is directed to natural persons located in the United States, including the fifty (50) states, the District of Columbia, the Commonwealth of Puerto Rico, the U.S. Virgin Islands, Guam, American Samoa, the Commonwealth of the Northern Mariana Islands, and Army Post Office ("APO"), Fleet Post Office ("FPO"), and Diplomatic Post Office ("DPO") addresses. The Service is not directed to, and BeneVets does not intend to offer the Service to, residents of the European Economic Area, the United Kingdom, Canada, Mexico, or any other foreign jurisdiction.
§ 3. Defined Terms
For purposes of this Policy:
- "Personal Information" has the meaning set forth in Cal. Civ. Code § 1798.140(v) (West, 2024).
- "Sensitive Personal Information" ("SPI") has the meaning set forth in Cal. Civ. Code § 1798.140(ae).
- "Sale" has the meaning set forth in Cal. Civ. Code § 1798.140(ad).
- "Share" has the meaning set forth in Cal. Civ. Code § 1798.140(ah).
- "Service Provider" has the meaning set forth in Cal. Civ. Code § 1798.140(ag).
- "Contractor" has the meaning set forth in Cal. Civ. Code § 1798.140(j).
- "Third Party" has the meaning set forth in Cal. Civ. Code § 1798.140(ai).
- "Consumer Health Data" has the meaning set forth in Wash. Rev. Code § 19.373.010(8).
- "User," "you," "your" mean a natural person who interacts with the Service.
- "Helper" means a person granted access to a user's account via BeneVets's account-linking flow.
- "Accredited Representative" or "VSO Rep" means a person accredited under 38 C.F.R. § 14.629.
- "DD-214" means the Certificate of Release or Discharge from Active Duty (U.S. Department of Defense Form DD-214).
- "ITF" means an Intent to File submitted under 38 C.F.R. § 3.155.
- "VA Lighthouse APIs" means the application programming interfaces operated by the U.S. Department of Veterans Affairs at developer.va.gov, including but not limited to the Benefits Intake API, the Veteran Verification API, the Facilities API, and the Health API.
§ 4. Categories of Personal Information Collected
In plain English: Here is a list of the categories of information about you that we collect, where the information comes from, why we collect it, who we share it with, and how long we keep it. The categories below match the categories used in California law (specifically Cal. Civ. Code § 1798.140(v)).
The table below enumerates each category of Personal Information that BeneVets collects, processes, or stores, mapped to source, purpose, recipient categories, and retention period. Retention periods reference the Data Retention Schedule (Document 14) for full detail.
§ 4.1. Cal. Civ. Code § 1798.140(v)(1)(A) - Identifiers
| Element | Examples | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|---|
| Real name | First name, last name, suffix | You | Account identity; form preparation | Service Providers; VA Lighthouse APIs when you authorize a form submission | Life of account + 90 days, then deletion |
| Postal address | Street, city, state, ZIP, country | You | Form preparation; correspondence routing | VA Lighthouse APIs (form submission) | Life of account + 90 days |
| Online identifier | Account user ID; session identifier | System | Authentication; session continuity | Service Providers (Vercel, Sentry) | Session ID rotates per login; account user ID for life of account |
| Internet Protocol address | Truncated source IP | System | Security; rate limiting; abuse prevention | Service Providers (Vercel, Cloudflare if engaged) | 30 days |
| Email address | Primary, recovery, Helper-invite | You | Authentication; transactional messaging; password recovery | Service Providers (Resend) | Life of account + 90 days |
| Account name | Display name | You | Identity within the Service | Service Providers | Life of account + 90 days |
| Social Security Number | SSN (full or last four) | You - only if you elect to enter via ProfileVault for form pre-population | Pro se form preparation requiring SSN field (e.g., VA Form 21-526EZ) | VA Lighthouse APIs at moment of pro se submission only; not shared with any other recipient | AES-256-GCM at rest while account active; purged within 30 days of account deletion or earlier per § 17 |
| Other government-issued identifiers | VA file number; service number | You; VA Lighthouse APIs | Form preparation; claim matching | VA Lighthouse APIs | Life of account + 90 days |
§ 4.2. Cal. Civ. Code § 1798.140(v)(1)(B) - Customer Records Categories
| Element | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|
| Telephone number | You | Optional contact; not used for SMS at v1 | Service Providers | Life of account + 90 days |
| Mailing address | You | See § 4.1 | See § 4.1 | See § 4.1 |
| Insurance / Medicare / VA enrollment status | VA Lighthouse APIs when you authorize | Eligibility surface | None outside the Service | Life of account + 90 days |
| Veteran status | You; VA Lighthouse APIs when you authorize | Eligibility surface; form pre-population | None outside the Service | Life of account + 90 days |
§ 4.3. Cal. Civ. Code § 1798.140(v)(1)(C) - Protected Classification Characteristics
| Element | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|
| Age | You (date of birth) | Verify 18+ Service eligibility; benefit-eligibility surfacing | None outside the Service | Life of account + 90 days |
| Marital status (relationship label) | You | Dependent and spouse-benefit eligibility surfacing | None outside the Service | Life of account + 90 days |
| Sex (binary or self-identified) | You; VA Lighthouse APIs when you authorize | Form pre-population; gender-specific benefit eligibility surfacing | VA Lighthouse APIs upon form submission | Life of account + 90 days |
| Military or veteran status | You; VA Lighthouse APIs when you authorize | Core service function | VA Lighthouse APIs | Life of account + 90 days |
| Race / ethnicity / national origin | You - only if you voluntarily enter | Self-identification on certain forms only | VA Lighthouse APIs upon form submission, if applicable | Life of account + 90 days |
§ 4.4. Cal. Civ. Code § 1798.140(v)(1)(D) - Commercial Information
The Service does not sell goods or services to users and does not collect purchasing or transaction histories from users.
§ 4.5. Cal. Civ. Code § 1798.140(v)(1)(E) - Biometric Information
BeneVets does not collect biometric information.
§ 4.6. Cal. Civ. Code § 1798.140(v)(1)(F) - Internet or Other Electronic Network Activity
| Element | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|
| Pages viewed | First-party telemetry; Google Analytics 4 | Service operation; aggregate usage measurement | Service Providers (Vercel; Google LLC for analytics) | 90 days first-party; GA4 retention set to 2 months (minimum available) |
| Search terms entered within the Service | First-party telemetry | Service improvement | None outside Service Providers | 90 days, then aggregation |
| Referrer | Browser | Service operation | None | 30 days |
| Interaction events | First-party telemetry | Service operation | Service Providers | 90 days |
§ 4.7. Cal. Civ. Code § 1798.140(v)(1)(G) - Geolocation Data
The Service collects coarse geolocation only, derived from the source IP address truncated to the city level for facility-lookup convenience. The Service does not collect or store precise geolocation as defined in Cal. Civ. Code § 1798.140(w) (i.e., location within a radius of 1,850 feet or less). Facility-lookup features that suggest nearby VA facilities operate from a city-level inference and the user's explicit entry of a ZIP code or city, not from device GPS.
§ 4.8. Cal. Civ. Code § 1798.140(v)(1)(H) - Sensory Information
The Service does not collect audio, electronic, visual, thermal, olfactory, or similar information, except: (a) profile photos that you elect to upload, and (b) the contents of any uploaded DD-214 image or PDF.
§ 4.9. Cal. Civ. Code § 1798.140(v)(1)(I) - Professional or Employment-Related Information
| Element | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|
| Branch of service | You | Form preparation; eligibility surfacing | VA Lighthouse APIs | Life of account + 90 days |
| Era of service | You | Eligibility surfacing | None outside the Service | Life of account + 90 days |
| Discharge status / character of service | You; DD-214 | Eligibility surfacing | VA Lighthouse APIs upon form submission | Life of account + 90 days |
| Service-connected disability rating | You; VA Lighthouse APIs when you authorize | Eligibility surfacing; TDIU checker | VA Lighthouse APIs | Life of account + 90 days |
| Employment status (TDIU) | You | TDIU eligibility surfacing | VA Lighthouse APIs upon form submission | Life of account + 90 days |
§ 4.10. Cal. Civ. Code § 1798.140(v)(1)(J) - Education Information (FERPA)
The Service does not collect FERPA-covered education records. Education-benefit surfacing (e.g., GI Bill) operates from your self-attestation of program enrollment, not from records released by an educational institution under 20 U.S.C. § 1232g.
§ 4.11. Cal. Civ. Code § 1798.140(v)(1)(K) - Inferences
| Inference | Source data | Purpose | Recipients | Retention |
|---|---|---|---|---|
| Mental-health-crisis inference (see § 5 and Document 15) | Free-text content you enter into the Service | Surface the Veterans Crisis Line and other supportive resources | None outside BeneVets | The inference itself is not persistently stored; the underlying text is retained per § 4.13 |
| Benefit-eligibility surfacing inference | Profile data you enter or that VA returns | Surface relevant benefits | None outside BeneVets | Recomputed on demand; not persistently stored as an inference |
§ 4.12. Cal. Civ. Code § 1798.140(v)(1)(L) - Sensitive Personal Information
See § 5 for the SPI enumeration.
§ 4.13. Free-text content you enter into the Service
| Element | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|
| Symptom log entries (C&P examination preparation) | You | Help you prepare for a C&P examination under Stefl v. Nicholson, 21 Vet. App. 120 (2007); Nieves-Rodriguez v. Peake, 22 Vet. App. 295 (2008); 38 C.F.R. § 3.159(c)(4); 38 C.F.R. § 4.46 | None outside BeneVets unless you transmit them via a VA form | Life of account + 90 days |
| Notes attached to ITF entries | You | Reminder content | None outside BeneVets | Life of account + 90 days |
| Form-draft field content | You | Form preparation | VA Lighthouse APIs upon your authorized pro se submission | Life of account + 90 days (drafts); permanent VA record after submission |
§ 4.14. Documents uploaded to ProfileVault
| Element | Source | Purpose | Recipients | Retention |
|---|---|---|---|---|
| DD-214 (image or PDF) | You | Eligibility verification; form pre-population; supporting evidence | VA Lighthouse APIs only upon your authorized pro se submission | AES-256-GCM at rest while account active; purged within 30 days of account deletion |
| Other supporting evidence files | You | Form attachments | VA Lighthouse APIs only upon your authorized pro se submission | AES-256-GCM at rest while account active; purged within 30 days of account deletion |
| Profile photo | You | Display within the Service | Service Providers (file storage) | Life of account + 90 days |
§ 5. Categories of Sensitive Personal Information Collected
In plain English: Some of the information we collect is considered especially sensitive under California law. We list each category here so you know exactly what we collect and what we do not. We do not use sensitive information to infer characteristics about you beyond what is necessary to provide the Service you asked for. The one inference we make is whether your typed content suggests a mental-health crisis - this triggers a supportive-resources surface. You can turn that inference off in your Profile (see § 12).
The following enumeration tracks Cal. Civ. Code § 1798.140(ae)(1)(A)-(K):
| § 1798.140(ae) subcategory | Collected? | Specifics |
|---|---|---|
| (ae)(1)(A) - Government-issued identifier | Yes, conditionally | Social Security Number (only if you elect to enter it via ProfileVault for form pre-population); VA file number; service number. Driver's license and state ID are not collected. Passport is not collected. |
| (ae)(1)(A) - Citizenship or immigration status | Conditionally | Citizenship status is collected only insofar as it appears on the DD-214 you upload or is required by a specific VA form you choose to prepare. BeneVets does not independently verify citizenship and does not use citizenship status for any purpose other than form pre-population. |
| (ae)(1)(B) - Racial or ethnic origin | Conditionally | Collected only if you voluntarily self-identify on a specific VA form that requests it. Not collected by default. |
| (ae)(1)(B) - Religious or philosophical beliefs | No | Not collected. |
| (ae)(1)(B) - Union membership | No | Not collected. |
| (ae)(1)(C) - Contents of mail, email, and text messages | Conditionally | The contents of in-Service free-text fields (symptom logs, notes, form fields) are stored as you enter them. The Service does not access the contents of your personal email account or your text messages. |
| (ae)(1)(D) - Genetic data | No | Not collected. |
| (ae)(1)(E) - Biometric information for unique identification | No | Not collected. |
| (ae)(1)(F) - Personal Information collected and analyzed concerning health | Yes | Service-connected disability rating; conditions of interest; symptom-log entries; mental-health-crisis inference derived from free-text content (see § 5.1); content of uploaded DD-214; any health-related field you complete on a VA form. |
| (ae)(1)(G) - Personal Information collected and analyzed concerning sex life or sexual orientation | Conditionally | Collected only if you voluntarily enter such information into a free-text field or a specific VA form that requests it. |
| (ae)(1)(H) - Precise geolocation | No | The Service collects coarse, city-level geolocation only. See § 4.7. |
§ 5.1. Mental-Health-Crisis Inference (Sensitive Personal Information and Consumer Health Data)
The Service automatically scans free-text content you enter (symptom-log entries, form-draft fields, and other in-Service free-text fields) for keywords indicating potential mental-health crisis. When a match is found, the Service routes you to a supportive-resources surface presenting the Veterans Crisis Line (call 988 and press 1, text 838255, chat at veteranscrisisline.net, or TTY 711) and additional resources.
The inference produced by this scan is Sensitive Personal Information under Cal. Civ. Code § 1798.140(ae)(1)(F) and Consumer Health Data under Wash. Rev. Code § 19.373.010(8). For a complete description of how this automated decision-making process operates, the logic involved, and the consequences of the processing, see Document 15 (Automated Decision-Making and AI Notice).
You have a right to limit BeneVets's use of Sensitive Personal Information for the purpose of inferring characteristics about you. To exercise that right, see § 12 (Right to Limit Use of Sensitive Personal Information).
§ 6. Sources of Personal Information
In plain English: We get the information we hold about you from five places: you (the most common source), the VA when you tell us to ask the VA for it, Google if you sign in with Google, your browser through cookies and small bits of technical data, and a basic analytics tool. We do not buy personal information about you from data brokers.
BeneVets collects Personal Information from the following sources:
- Directly from you. Account registration, profile entry, document upload, free-text fields, settings changes, support requests.
- From the VA Lighthouse APIs, with your authorization. When you elect to connect your VA account or to authorize a specific request, BeneVets retrieves data from VA Lighthouse APIs on your behalf. The scope of each request is shown to you before authorization.
- From Google LLC, with your authorization. When you elect to sign in with Google (OAuth), Google transmits to BeneVets the limited identifiers necessary for federated authentication: email address, account identifier, and (optionally) name and profile photo. BeneVets does not receive Google search history, Gmail content, Drive content, Calendar content, or any other Google-account data.
- From cookies and similar technologies set in your browser. See Document 03 (Cookie Notice).
- From first-party telemetry and Google Analytics 4. See § 9 and Document 03.
BeneVets does not purchase Personal Information from data brokers, including data brokers registered under Cal. Civ. Code § 1798.99.82.
§ 7. Purposes of Processing
In plain English: We use your information to run the Service, keep your account safe, help you prepare and file VA forms, send you the messages you ask for, fix bugs, prevent abuse, and meet our legal duties.
BeneVets processes Personal Information for the purposes enumerated in Cal. Civ. Code § 1798.140(e) and Cal. Code Regs. tit. 11, § 7050. Each purpose is necessary, proportionate, and compatible with the context of collection. The full list of purposes:
- To create and maintain your account.
- To authenticate you, including multi-factor authentication when you enable it.
- To present, recommend, and explain VA, state, and federal benefit programs you may be interested in.
- To prepare VA forms with the field values you supply or authorize.
- To transmit VA forms to VA Lighthouse APIs at your pro se election.
- To track Intent-to-File windows under 38 C.F.R. § 3.155.
- To support Compensation and Pension examination preparation under Stefl v. Nicholson and 38 C.F.R. § 3.159(c)(4).
- To support TDIU evaluation under 38 C.F.R. § 4.16.
- To operate the VSO directory.
- To enable the account-linking ("Helper") feature with audit-logged, granular, revocable scopes.
- To detect, prevent, and respond to security incidents, fraud, abuse, and unlawful activity, consistent with Cal. Civ. Code § 1798.140(e)(2).
- To debug, identify, and repair errors that impair existing functionality, consistent with Cal. Civ. Code § 1798.140(e)(3).
- To perform short-term, transient processing consistent with Cal. Civ. Code § 1798.140(e)(4).
- To perform internal research for technological development and demonstration, consistent with Cal. Civ. Code § 1798.140(e)(7).
- To verify, maintain, and improve quality and safety, consistent with Cal. Civ. Code § 1798.140(e)(8).
- To send transactional messages classified under 16 C.F.R. § 316.3.
- To send the opt-in newsletter and (separately) the opt-in donor email program when you affirmatively subscribe.
- To run the mental-health-crisis keyword scanner and present supportive resources (see § 5.1 and Document 15).
- To comply with legal obligations, including responses to lawful process, defense of legal claims, compliance with audit obligations, and compliance with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA," Cal. Civ. Code § 1798.100 et seq.), the Virginia Consumer Data Protection Act ("VCDPA," Va. Code § 59.1-575 et seq.), the Colorado Privacy Act ("CPA," Colo. Rev. Stat. § 6-1-1301 et seq.), and analogous state privacy laws.
§ 8. Disclosure of Personal Information
In plain English: We share your information only with companies we hire to help us run the Service (called "Service Providers"), with the VA when you ask us to send a form, and with anyone you authorize to access your account (a "Helper"). We do not sell your information.
§ 8.1. Service Providers and Contractors
BeneVets discloses Personal Information to Service Providers under Cal. Civ. Code § 1798.140(ag) and Contractors under Cal. Civ. Code § 1798.140(j), each bound by a written contract meeting the requirements of Cal. Civ. Code § 1798.100(d) and Cal. Code Regs. tit. 11, § 7051. Current Service Providers are enumerated in Document 04 (Sub-processor List). The categories of Service Provider and the categories of data they receive:
| Service Provider | Service performed | Categories of data shared |
|---|---|---|
| Vercel, Inc. | Hosting and edge compute | All categories during operation |
| Resend (Resend.com) | Transactional and marketing email transmission | Email address; transactional message content |
| Functional Software, Inc. (Sentry) | Application error monitoring | Identifiers (truncated); telemetry; error context (with PII scrubber) |
| Google LLC | OAuth identity federation | Email address; account identifier; (optional) name and profile photo |
| Backblaze, Inc. (B2) OR Vercel Blob | File storage for encrypted DD-214 envelopes and profile photos | Encrypted file contents; storage object identifiers |
| Anthropic, PBC | Large language model for benefit-content summarization | Source regulatory text and editor-supplied prompt only; no user PII at v1 |
| Cloudflare, Inc. (if engaged) | DNS, edge proxy, DDoS protection | Truncated IP; request metadata |
| Google LLC (Google Analytics 4) | Web analytics | Aggregated, anonymized usage; truncated identifiers |
§ 8.2. Third Parties
BeneVets discloses Personal Information to the following Third Parties under Cal. Civ. Code § 1798.140(ai):
- U.S. Department of Veterans Affairs (VA Lighthouse APIs). When you authorize a pro se form submission, BeneVets transmits the form and supporting documents to VA. VA is a federal agency and is not a "Service Provider" or "Contractor" to BeneVets. VA's use of the data submitted is governed by VA's Privacy Act system-of-records notices and other federal authorities.
- Lawful-process recipients. BeneVets may disclose Personal Information in response to lawful process (subpoena, court order, search warrant) or to defend BeneVets's legal interests. BeneVets requires legal process for any disclosure to law enforcement absent a good-faith belief that disclosure is necessary to prevent imminent harm to life.
- Helpers you authorize. When you grant a Helper access to your account under the account-linking flow, that Helper receives the data you authorize them to see. Each Helper relationship is granular, revocable, and audit-logged.
§ 8.3. Categories disclosed in the preceding 12 months
The categories of Personal Information disclosed for a business purpose in the preceding twelve (12) months are: identifiers; customer records information; protected classification characteristics; internet or electronic network activity; geolocation (coarse); professional or employment-related information; inferences (limited as described in § 4.11); and Sensitive Personal Information (limited as described in § 5).
The categories of Personal Information disclosed to Third Parties in the preceding twelve (12) months are: identifiers; customer records information; veteran status and service history; sensitive elements you authorize to be transmitted on a VA form (e.g., SSN, health information, citizenship status if appearing on the form), each disclosed only to VA Lighthouse APIs upon your pro se authorization.
§ 9. Sale and Share Posture
In plain English: We do not sell your information. We do not share your information for cross-context behavioral advertising. We honor the Global Privacy Control signal everywhere on the Service. The one nuance is that we use Google Analytics 4 to count how people use the site. Some regulators take the position that any GA4 deployment may constitute a "share" under California law. We have configured GA4 to disable advertising features, to anonymize IP addresses, to set the shortest available retention, and to honor the Global Privacy Control sitewide, and we treat any GPC signal as a universal opt-out from any conceivable "sharing" through GA4.
BeneVets does not Sell Personal Information as that term is defined in Cal. Civ. Code § 1798.140(ad). BeneVets does not Share Personal Information for cross-context behavioral advertising as that term is defined in Cal. Civ. Code § 1798.140(ah).
§ 9.1. Google Analytics 4
BeneVets uses Google Analytics 4 ("GA4"), a web-analytics service offered by Google LLC, to measure aggregate Service usage. Some interpretations of Cal. Civ. Code § 1798.140(ah) treat GA4 deployments as potentially constituting "sharing" for cross-context behavioral advertising. BeneVets has configured GA4 as follows to substantiate the no-Share posture and to mitigate regulator risk:
- IP anonymization is enabled (truncation per Google's documented behavior).
- Google Signals is disabled.
- Ad personalization is disabled at the property level and at the event level.
- Data retention is set to the shortest available setting (2 months).
- Global Privacy Control signals received from the user agent are treated as a universal opt-out from any analytics processing that could be characterized as Sharing. When GPC is asserted, the GA4 measurement tag is not loaded for the session.
- The data-sharing settings between the GA4 property and Google products and services are restricted to the minimum necessary for the analytics service itself.
§ 9.2. Opt-out of Sale or Share
Because BeneVets does not Sell or Share Personal Information, no separate opt-out is required for users who have not asserted Global Privacy Control. The Service provides a "Do Not Sell or Share My Personal Information" link in the site footer in accordance with Cal. Civ. Code § 1798.135 and Cal. Code Regs. tit. 11, § 7026 for clarity and user reassurance. Activating that link confirms the no-Sale, no-Share posture and additionally disables the GA4 tag for the session.
§ 9.3. No financial incentives
BeneVets does not offer financial incentives or price or service differences in exchange for Personal Information under Cal. Civ. Code § 1798.125(b).
§ 10. Retention
In plain English: We keep your information only as long as we need it. The Data Retention Schedule (Document 14) is the controlling document and has the full list. The short version is in the table below.
The Data Retention Schedule at Document 14 is the controlling document. The summary table:
| Data category | Retention period |
|---|---|
| Account profile | Life of account + 90 days, then deletion |
| ProfileVault contents (DD-214; SSN if entered; supporting evidence) | While account active; purged within 30 days of account deletion or earlier upon Right-to-Delete request |
| Form drafts | Life of account + 90 days; submitted forms become a permanent VA record outside BeneVets |
| Helper relationships and audit log | Life of relationship; audit-log entries retained 7 years for accountability |
| Email logs | 13 months |
| Sentry error events | 90 days |
| First-party telemetry | 90 days |
| GA4 events | 2 months |
| Truncated source IP | 30 days |
| Backup snapshots | 35 days; rolling |
§ 11. Security
In plain English: We protect your information with industry-standard safeguards. The DD-214 envelope and any Social Security Number you enter are encrypted with AES-256-GCM. All traffic to the site is encrypted in transit with TLS. You can turn on multi-factor authentication. We keep an audit log of sensitive actions, and that log is hash-chained so anyone (including us) can detect tampering.
BeneVets maintains administrative, technical, and physical safeguards reasonably designed to protect Personal Information against unauthorized access, destruction, use, modification, or disclosure. Current measures:
- Encryption at rest. The ProfileVault envelope (DD-214 and any SSN or other sensitive document content) is encrypted with AES-256-GCM using per-user keys derived from a hardware-protected master key.
- Encryption in transit. All traffic to and from the Service is served over HTTPS using TLS 1.2 or higher.
- Authentication. Email + password authentication with secure password storage. Optional Time-based One-Time Password ("TOTP") multi-factor authentication under RFC 6238. Optional Google OAuth federation.
- Audit log. Sensitive operations (profile changes, document access, Helper grants, form submissions) are recorded in an append-only, hash-chained audit log such that tampering can be detected.
- Least-privilege access. BeneVets personnel access to production data is limited to the minimum necessary and is audit-logged.
- Vulnerability disclosure. BeneVets publishes a Security and Vulnerability Disclosure Policy and security.txt (Document 13).
- Incident response. BeneVets maintains an incident response plan that includes user notification consistent with applicable state breach-notification statutes (e.g., Cal. Civ. Code § 1798.82, and analogous statutes in other states).
No system is perfectly secure. BeneVets cannot guarantee absolute security and does not promise any specific security outcome.
§ 12. Right to Limit Use of Sensitive Personal Information
In plain English: California law gives you the right to limit how we use sensitive information about you. The main "sensitive" processing we do is the mental-health-crisis keyword scanner that surfaces the Veterans Crisis Line when your typed content appears to indicate a crisis. You can turn that scanner off in your Profile settings. If you turn it off, we will not run the scan, but you will also not see the crisis-resource surface when you type. The Veterans Crisis Line is always reachable directly at 988 (press 1) or by text to 838255 regardless of the toggle.
You have the right to direct BeneVets to limit its use and disclosure of Sensitive Personal Information to the uses set forth in Cal. Civ. Code § 1798.121(a) and Cal. Code Regs. tit. 11, § 7027. BeneVets's processing of Sensitive Personal Information beyond those use cases is limited to the mental-health-crisis inference described in § 5.1 and the optional collection of citizenship status, race or ethnicity, sex life or sexual orientation, and SSN as described in § 5.
To exercise this right, navigate to Profile → Privacy → Limit Use of Sensitive Personal Information and toggle the setting off. When the setting is off:
- The mental-health-crisis keyword scanner does not run on your free-text input.
- The supportive-resources surface is not automatically presented based on inference.
- The Veterans Crisis Line and all other crisis resources remain available through static links in the Service footer and through direct contact (988 and press 1; text 838255; chat at veteranscrisisline.net; TTY 711).
- Race, ethnicity, sex life, sexual orientation, and SSN remain processed only for form-pre-population purposes for forms you specifically prepare and authorize.
You may also exercise this right by emailing privacy@benevets.org with the subject line "Limit Use of Sensitive Personal Information." BeneVets will confirm receipt within ten (10) business days and effect the limitation within forty-five (45) days of receipt under Cal. Civ. Code § 1798.130(a)(2).
§ 13. Global Privacy Control
In plain English: Some browsers and browser extensions send a "Global Privacy Control" signal that says "do not sell or share my personal information." We honor this signal across the entire Service. If your browser sends GPC, we treat it as a universal opt-out and disable Google Analytics 4 for your session.
BeneVets honors the Global Privacy Control ("GPC") signal sitewide as a universal opt-out from Sale and Share under Cal. Code Regs. tit. 11, § 7025, Colo. Rev. Stat. § 6-1-1313(2), Conn. Gen. Stat. § 42-518(d), and analogous provisions in other applicable state privacy laws. When a request to the Service includes the Sec-GPC: 1 HTTP header or an analogous signal, BeneVets:
- Treats the request as an assertion of the Right to Opt-Out of Sale and Share for the session.
- Does not load the Google Analytics 4 measurement tag for the session.
- Records the opt-out as a session-scoped preference and, where the user is authenticated, as an account-scoped preference.
- Does not respond with a notification that contradicts or seeks to override the GPC signal.
Authenticated users may additionally record a persistent opt-out via Profile → Privacy → Do Not Sell or Share that applies across devices and sessions.
§ 14. Do Not Track
In plain English: Some older browsers send a "Do Not Track" signal. There is no agreed-upon standard for how websites should treat it, so we do not change our behavior based on it. We do honor the more modern Global Privacy Control signal, as described in the section above. We disclose our DNT treatment here as California law requires.
Pursuant to Cal. Bus. & Prof. Code § 22575(b)(5), BeneVets discloses that the Service does not respond differently to a "Do Not Track" signal because no industry standard has been finalized for how such signals should be honored. BeneVets honors Global Privacy Control as described in § 13.
§ 15. State Privacy Rights - California (CCPA / CPRA)
In plain English: If you live in California, you have specific privacy rights. You can ask us what we have on you, ask us to correct it, ask us to delete it, ask for a copy you can take elsewhere, opt out of sale or sharing, limit our use of sensitive information, and not be discriminated against for using any of these rights. We respond within 45 days. If we need more time, we can take another 45 days but we have to tell you why.
Residents of California have the following rights under the CCPA, Cal. Civ. Code § 1798.100 et seq.:
- Right to Know (Access). You may request that BeneVets disclose: (a) the categories of Personal Information collected; (b) the categories of sources; (c) the business or commercial purpose for collection or disclosure; (d) the categories of Third Parties to whom Personal Information has been disclosed; and (e) the specific pieces of Personal Information collected about you. Cal. Civ. Code §§ 1798.100, 1798.110, 1798.115.
- Right to Delete. You may request that BeneVets delete Personal Information about you, subject to the exceptions in Cal. Civ. Code § 1798.105(d).
- Right to Correct. You may request that BeneVets correct inaccurate Personal Information. Cal. Civ. Code § 1798.106.
- Right to Portability. You may receive a copy of Personal Information in a portable and, to the extent technically feasible, machine-readable format. Cal. Civ. Code § 1798.130(a)(2).
- Right to Opt-Out of Sale or Share. Cal. Civ. Code § 1798.120. As described in § 9, BeneVets does not Sell or Share Personal Information, and GPC is honored sitewide.
- Right to Limit Use of Sensitive Personal Information. Cal. Civ. Code § 1798.121. See § 12.
- Right to Non-Discrimination. Cal. Civ. Code § 1798.125. BeneVets does not deny goods or services, charge different prices, provide a different level of quality, or suggest any such treatment because you exercised a privacy right.
§ 15.1. How to exercise California rights
Submit a request by email to privacy@benevets.org with the subject line stating the right invoked (e.g., "Right to Know"). Authenticated users may also submit requests via Profile → Privacy → Submit a Privacy Request.
§ 15.2. Verification
BeneVets verifies the identity of a requestor before responding. For authenticated requests submitted from within a logged-in account, the authentication itself is verification. For requests submitted by email, BeneVets confirms by sending a confirmation link to the email address on file. For requests submitted by a person who is no longer an account holder, BeneVets may require additional information sufficient to match the request to records BeneVets reasonably believes to belong to the requestor (e.g., the email address previously associated with the account, the approximate date of account creation), consistent with Cal. Code Regs. tit. 11, § 7062.
§ 15.3. Authorized agents
You may designate an authorized agent to submit a request on your behalf under Cal. Civ. Code § 1798.140(a) and Cal. Code Regs. tit. 11, § 7063. BeneVets requires the agent to provide signed permission from you, and (unless the agent has a power of attorney under Cal. Prob. Code § 4000 et seq.) BeneVets will confirm directly with you.
§ 15.4. Response timeline
BeneVets confirms receipt of a request within ten (10) business days and substantively responds within forty-five (45) days of receipt under Cal. Civ. Code § 1798.130(a)(2). BeneVets may extend this period by an additional forty-five (45) days when reasonably necessary, with notice to you within the initial 45-day period explaining the reason for the extension.
§ 15.5. Appeal
Although the CCPA does not require a formal appeal mechanism, BeneVets honors the multi-state norm and offers an appeal of any denied request. See § 24.
§ 15.6. Notice at Collection
Pursuant to Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. tit. 11, § 7012, BeneVets provides Notice at Collection of: (a) the categories of Personal Information to be collected; (b) the purposes for which the categories will be used; (c) whether the information is sold or shared; (d) the length of time the categories will be retained; and (e) a link to this Policy. Notice at Collection is provided at or before the point of collection on registration screens, profile screens, document-upload screens, and any other screen at which a new category of Personal Information is first collected.
§ 16. State Privacy Rights - Virginia (VCDPA)
In plain English: If you live in Virginia, you have similar rights. You can ask us what we have, ask us to correct or delete it, get a portable copy, and opt out of certain processing. We respond within 45 days. You can appeal if we say no.
Residents of Virginia have the following rights under the Virginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq.:
- Right to confirm processing and access. Va. Code § 59.1-577(A)(1).
- Right to correct inaccuracies. Va. Code § 59.1-577(A)(2).
- Right to delete. Va. Code § 59.1-577(A)(3).
- Right to portable copy. Va. Code § 59.1-577(A)(4).
- Right to opt out of (a) targeted advertising, (b) sale of personal data, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. Va. Code § 59.1-577(A)(5).
BeneVets does not conduct targeted advertising, does not sell personal data, and does not engage in profiling that produces legal or similarly significant effects concerning you (the crisis-keyword inference at § 5.1 does not produce legal or similarly significant effects; it surfaces resources you may close at any time).
Response timeline. BeneVets responds within forty-five (45) days under Va. Code § 59.1-578(A) and may extend by forty-five (45) days when reasonably necessary.
Appeal. BeneVets provides an appeal mechanism under Va. Code § 59.1-578(C). See § 24.
§ 17. State Privacy Rights - Colorado (CPA)
In plain English: If you live in Colorado, you have similar rights to Virginians. You can ask what we have, correct it, delete it, get a portable copy, and opt out of certain processing. We respond within 45 days. You can appeal if we say no.
Residents of Colorado have the following rights under the Colorado Privacy Act, Colo. Rev. Stat. § 6-1-1301 et seq.:
- Right of access. Colo. Rev. Stat. § 6-1-1306(1)(b).
- Right of correction. Colo. Rev. Stat. § 6-1-1306(1)(c).
- Right of deletion. Colo. Rev. Stat. § 6-1-1306(1)(d).
- Right to data portability. Colo. Rev. Stat. § 6-1-1306(1)(e).
- Right to opt out of (a) targeted advertising, (b) sale of personal data, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. Colo. Rev. Stat. § 6-1-1306(1)(a).
BeneVets honors a universal opt-out mechanism (Global Privacy Control) under Colo. Rev. Stat. § 6-1-1313 sitewide. See § 13.
Response timeline. Forty-five (45) days under Colo. Rev. Stat. § 6-1-1306(2)(b), extendable by forty-five (45) days when reasonably necessary.
Appeal. Appeal mechanism per Colo. Rev. Stat. § 6-1-1306(3). See § 24.
§ 18. State Privacy Rights - Connecticut (CTDPA)
In plain English: If you live in Connecticut, you have similar rights. Same 45-day response, same appeal option.
Residents of Connecticut have rights under the Connecticut Data Privacy Act, Conn. Gen. Stat. § 42-515 et seq.:
- Access, correction, deletion, portability, and opt-out of (a) targeted advertising, (b) sale, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects, per Conn. Gen. Stat. § 42-518(a).
- Universal opt-out (GPC) honored under Conn. Gen. Stat. § 42-518(d). See § 13.
Response timeline. Forty-five (45) days, extendable by forty-five (45) days when reasonably necessary, under Conn. Gen. Stat. § 42-518(c)(1).
Appeal. Per Conn. Gen. Stat. § 42-518(c)(3). See § 24.
§ 19. State Privacy Rights - Texas (TDPSA)
In plain English: If you live in Texas, you have similar rights. There is an extra item: Texas law requires us to tell you specifically that we do not sell sensitive personal information. We do not. We treat your Veterans Crisis Line surfacing as a non-sale, non-share event.
Residents of Texas have rights under the Texas Data Privacy and Security Act, Tex. Bus. & Com. Code § 541.001 et seq.:
- Access, correction, deletion, portability, and opt-out of (a) targeted advertising, (b) sale, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects, per Tex. Bus. & Com. Code § 541.051.
Texas Sensitive-Data Sentence (required by Tex. Bus. & Com. Code § 541.103): "BeneVets does not sell Sensitive Personal Data."
Response timeline. Forty-five (45) days, extendable by forty-five (45) days when reasonably necessary, under Tex. Bus. & Com. Code § 541.052.
Appeal. Per Tex. Bus. & Com. Code § 541.053. See § 24.
§ 20. State Privacy Rights - Oregon (OCPA)
In plain English: If you live in Oregon, you have similar rights. Same 45-day response, same appeal option.
Residents of Oregon have rights under the Oregon Consumer Privacy Act, Or. Rev. Stat. § 646A.570 et seq.:
- Access, including the right to obtain a list of specific Third Parties to whom your personal data has been disclosed (a unique Oregon feature under Or. Rev. Stat. § 646A.578(1)(c)).
- Correction, deletion, portability.
- Opt-out of (a) targeted advertising, (b) sale, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects.
Response timeline. Forty-five (45) days, extendable by forty-five (45) days when reasonably necessary.
Appeal. Per Or. Rev. Stat. § 646A.580. See § 24.
§ 21. State Privacy Rights - Montana (MTCDPA)
In plain English: If you live in Montana, you have similar rights. Same 45-day response, same appeal option.
Residents of Montana have rights under the Montana Consumer Data Privacy Act, Mont. Code Ann. § 30-14-2801 et seq.:
- Access, correction, deletion, portability, and opt-out of (a) targeted advertising, (b) sale, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects.
- Universal opt-out (GPC) honored sitewide.
Response timeline. Forty-five (45) days, extendable by forty-five (45) days when reasonably necessary.
Appeal. Per Mont. Code Ann. § 30-14-2812. See § 24.
§ 22. State Privacy Rights - Other Active State Acts
In plain English: Several other state privacy laws give residents similar rights. The rights and timelines work the way they do above. If you live in one of these states, the same procedures apply.
The following state statutes provide privacy rights that BeneVets honors for residents of the respective state. The rights enumerated mirror those described in §§ 16-21 unless otherwise noted.
| State | Statute | Notable features |
|---|---|---|
| Utah | Utah Consumer Privacy Act, Utah Code § 13-61-101 et seq. (effective 2023-12-31) | Narrower scope; no right of correction; opt-out only for sale and targeted advertising |
| Iowa | Iowa Consumer Data Protection Act, Iowa Code § 715D.1 et seq. (effective 2025-01-01) | No right of correction; ninety (90) day response window |
| Indiana | Indiana Consumer Data Protection Act, Ind. Code § 24-15-1-1 et seq. (effective 2026-01-01) | Mirror of VCDPA |
| Tennessee | Tennessee Information Protection Act, Tenn. Code Ann. § 47-18-3201 et seq. (effective 2025-07-01) | Mirror of VCDPA with affirmative defense for NIST AI RMF compliance |
| Delaware | Delaware Personal Data Privacy Act, Del. Code tit. 6, § 12D-101 et seq. (effective 2026-01-01) | Lower applicability thresholds |
| New Jersey | New Jersey Data Privacy Act, N.J. Stat. § 56:8-166.4 et seq. (effective 2026-01-15) | Adds children-specific protections under sixteen (16) for targeted advertising |
| New Hampshire | New Hampshire Data Privacy Act, N.H. Rev. Stat. § 507-H:1 et seq. (effective 2026-01-01) | Universal opt-out mechanism required |
| Nebraska | Nebraska Data Privacy Act, Neb. Rev. Stat. § 87-1101 et seq. (effective 2026-01-01) | Mirror of TDPSA, Texas-style sensitive data sentence - covered by § 19 sentence above |
| Minnesota | Minnesota Consumer Data Privacy Act, Minn. Stat. § 325O.01 et seq. (effective 2026-07-31) | Adds right to question profiling decisions and right to review of profiling input |
Residents of any of these states may invoke the rights described above through the same privacy@benevets.org channel.
§ 23. Washington Residents - My Health My Data Act
In plain English: Washington has a separate law called the My Health My Data Act that covers "consumer health data." Some of the information we hold - your service-connected disability rating, conditions of interest, symptom logs, content of your DD-214, and the mental-health-crisis inference described in § 5.1 - is consumer health data under that law. If you are a Washington resident, you have additional rights, including the right to withdraw consent and the right to delete your consumer health data. We do not sell consumer health data.
Pursuant to the Washington My Health My Data Act, Wash. Rev. Code § 19.373.005 et seq., BeneVets provides this separate notice with respect to Consumer Health Data:
§ 23.1. Categories of Consumer Health Data collected
BeneVets collects the following categories of Consumer Health Data as defined in Wash. Rev. Code § 19.373.010(8):
- Service-connected disability rating (when you self-report or when you authorize retrieval from VA Lighthouse APIs).
- Claimed conditions and conditions of interest.
- Symptom-log entries that you enter into the C&P preparation tool.
- Content of any uploaded DD-214.
- The mental-health-crisis inference described in § 5.1.
- Any other health-related field that appears on a VA form you elect to prepare.
§ 23.2. Sources
Directly from you; or from VA Lighthouse APIs, with your authorization.
§ 23.3. Purposes
To provide the Service features described in § 2 of the master service description: ProfileVault, ITF tracking, C&P preparation, TDIU evaluation, pro se form preparation, mental-health-crisis resource surfacing.
§ 23.4. Categories of Consumer Health Data shared
BeneVets does not share Consumer Health Data with any Third Party other than (a) VA Lighthouse APIs upon your pro se authorization of a specific form submission, and (b) Service Providers bound by written contract to use the data only for the purposes specified by BeneVets.
§ 23.5. Categories of Third Parties with whom Consumer Health Data is shared
Only the U.S. Department of Veterans Affairs, and only upon your pro se authorization of a specific form submission.
§ 23.6. Rights of Washington consumers
Washington residents have the following rights under Wash. Rev. Code § 19.373.030:
- Right to confirm whether BeneVets is collecting, sharing, or selling Consumer Health Data concerning the consumer and to access such data.
- Right to withdraw consent to BeneVets's collection and sharing of Consumer Health Data.
- Right to have Consumer Health Data deleted.
To exercise any of these rights, email privacy@benevets.org with the subject "MHMDA Request."
§ 23.7. Authorization
BeneVets obtains affirmative consent before collecting Consumer Health Data not necessary to provide a feature that the consumer has expressly requested, in conformance with Wash. Rev. Code § 19.373.030(1) and § 19.373.040.
§ 23.8. No sale
BeneVets does not sell Consumer Health Data within the meaning of Wash. Rev. Code § 19.373.060. No authorization for sale will be solicited because no sale occurs.
§ 23.9. Geofencing
BeneVets does not implement a geofence around any facility providing in-person health care services in violation of Wash. Rev. Code § 19.373.080.
§ 24. Appeal of a Denied Privacy Request
In plain English: If we deny your privacy request, you can appeal. Reply to our denial email or send a new email to the privacy address with the subject "Appeal" within 45 days, and a different person at BeneVets will review the request. We will respond within another 45 days. You may also complain to your state attorney general's office.
If BeneVets denies, in whole or in part, a privacy request submitted under any of §§ 15-23, the requestor may appeal within forty-five (45) days of the denial. To appeal, reply to the denial email or send a new email to privacy@benevets.org with the subject line "Appeal." A BeneVets employee or contractor who did not handle the initial request will review the appeal and respond in writing within sixty (60) days under Va. Code § 59.1-578(C), Colo. Rev. Stat. § 6-1-1306(3), Conn. Gen. Stat. § 42-518(c)(3), Tex. Bus. & Com. Code § 541.053, and analogous provisions of other states. The response will explain in writing the action taken or not taken and the reasons. If the appeal is denied, the response will include a link or other means for the consumer to contact the consumer's state attorney general.
§ 25. Identity Verification
In plain English: Before we can share or change information about you, we need to be reasonably sure you are who you say you are. If you are logged in, the login itself is enough. If you're not logged in, we'll email a confirmation link. If you no longer have an account, we may ask you to confirm details that match our records.
BeneVets verifies a requestor's identity using a method reasonable in light of the sensitivity of the data involved and the nature of the request, consistent with Cal. Code Regs. tit. 11, § 7060-7063 and analogous standards. Methods:
- Authenticated request from within the Service. The session authentication is the verification.
- Email request from a current account holder. Confirmation link sent to the email on file.
- Email request from a former account holder. Confirmation that the requestor can produce the email address previously associated with the account, the approximate date of account creation, and at least one additional non-public data point reasonably likely to be known only to the account holder. BeneVets does not require the requestor to produce sensitive information solely to verify identity.
If BeneVets cannot verify the identity of the requestor by a method reasonable in light of the request, BeneVets will deny the request and explain why, and will not use the information provided for verification for any other purpose.
§ 26. Automated Decision-Making
In plain English: Two features of the Service involve automated processing that we describe in detail in our separate Automated Decision-Making and AI Notice (Document 15): (1) the crisis-keyword scanner that surfaces the Veterans Crisis Line; and (2) the large language model summarization of benefit content. Neither of these makes a decision with legal or similarly significant effect on you.
For a complete description of automated decision-making in the Service, see Document 15 (Automated Decision-Making and AI Notice). In brief:
- Crisis-keyword scanner. Scans your free-text input for keywords indicating potential mental-health crisis and surfaces the Veterans Crisis Line and related resources. Does not change your account status, eligibility, or any service outcome. You may turn it off under § 12.
- Benefit-content summarization. Source regulatory text is summarized by a large language model into plain-English benefit descriptions. Staff review the output before publication. The model does not receive user Personal Information at v1.
§ 27. Cookies and Similar Technologies
In plain English: We use a small number of cookies and similar things to make the Service work. Details are in our Cookie Notice.
For a complete description, see Document 03 (Cookie Notice).
§ 28. Third-Party Processors and Sub-processors
In plain English: Here is a list of the outside companies that handle data for us. Details are in our Sub-processor List.
For a complete current list, see Document 04 (Sub-processor List).
§ 29. Children
In plain English: The Service is for people 18 and older. We do not knowingly collect personal information from children under 13. If we learn that a child under 13 gave us personal information, we will delete it. Veterans can identify a minor dependent for benefit-eligibility surfacing, but only by relationship label, not by name, date of birth, or contact information.
The Service is directed to natural persons who are eighteen (18) years of age or older. The Service is not directed to children under thirteen (13) years of age, and BeneVets does not knowingly collect Personal Information from children under thirteen (13). If BeneVets becomes aware that it has collected Personal Information from a child under thirteen (13) without verifiable parental consent under the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. § 6501 et seq., and the FTC's COPPA Rule, 16 C.F.R. Part 312, BeneVets will delete the information as soon as reasonably practicable and will notify the child's parent or legal guardian if reasonably possible.
A veteran user may identify a minor dependent for purposes of benefit-eligibility surfacing using only the relationship label (e.g., "dependent child"). The Service does not collect or store the minor's name, date of birth, or contact information.
For BeneVets's full children's privacy posture, see Document 16 (Children's Online Privacy Notice).
§ 30. International Users
In plain English: The Service is for people in the United States and U.S. territories. If you are outside the United States and you use the Service anyway, your information may be processed in the United States, where privacy laws may differ from those in your country.
The Service is not intended for individuals located outside the United States and its territories. BeneVets makes no representation that the Service is appropriate or available for use in any non-U.S. jurisdiction. By using the Service from outside the United States, you understand that your Personal Information may be processed in the United States, where data protection laws may differ from those in your jurisdiction.
§ 31. Changes to this Policy
In plain English: If we change this Policy in a meaningful way, we will tell you. For account holders, we will email you and show you a banner on the site. For everyone, we will update the "Last updated" date at the top.
BeneVets may amend this Policy from time to time. Material amendments will be communicated to account holders by email and by a banner on the Service for at least thirty (30) days following publication. Non-material amendments (typographical correction, clarification) take effect upon publication. The "Last updated" date at the top of the Policy reflects the most recent revision.
§ 32. Contact
In plain English: Email privacy@benevets.org for any privacy question or request. You can also write to us at the address below.
For privacy requests, questions, or concerns:
- Email:
privacy@benevets.org - Postal mail: BeneVets, Inc. Attn: Privacy Officer 1441 Pomona Road, Suite 20 Corona, CA 92882
§ 33. Notice at Collection (CCPA)
In plain English: California law requires us to tell you what we will collect at the moment we collect it. We do that on each screen where new information is requested. The full picture is in this Policy.
At or before the point at which BeneVets collects a new category of Personal Information, BeneVets presents an inline notice identifying: (a) the category of Personal Information to be collected; (b) the purposes for which the category will be used; (c) whether the category will be sold or shared (none will); (d) the length of time the category will be retained; and (e) a link to this Policy. This notice complies with Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. tit. 11, § 7012. The categories, purposes, and retention periods so disclosed correspond to those enumerated in §§ 4, 5, 7, and 10 of this Policy.
§ 34. Cross-References to Other Documents
This Policy is part of an integrated document set. It cross-references and incorporates the following documents:
- Document 03 - Cookie Notice
- Document 04 - Sub-processor List
- Document 13 - Security and Vulnerability Disclosure Policy
- Document 14 - Data Retention Schedule
- Document 15 - Automated Decision-Making and AI Notice
- Document 16 - Children's Online Privacy Notice
In the event of a conflict between this Policy and any cross-referenced document with respect to a privacy matter, this Policy controls unless the cross-referenced document expressly states otherwise.
End of Privacy Policy.