Sign In

Privacy Policy

Effective date: October 7, 2026.

1. Introduction

Free Brands (“Free Brands,” “we,” “us,” or “our”) is a survivor-led 501(c)(3) nonprofit based in San Diego, California. We know that for many people in our community, privacy is a matter of safety. This policy explains what information we collect through www.freebrands.org (the “Site”) and our programs, how we use and protect it, and the choices you have. This policy applies to visitors, registered users, Directory members, Tech Match participants, donors, and anyone who contacts us. It should be read together with our Terms of Service. Our core promise: we do not sell your personal information, and we never share information about a person’s survivor status without that person’s consent, except where the law requires it.

2. Information We Collect

We collect only what we need to run our programs. Most of it comes directly from you.
Category Examples When we collect it
Account information Name, email address, password (stored encrypted), account type (guest or survivor) When you register or log in
Optional identity information Whether you identify as a survivor of trafficking or gender-based violence; whether your business is survivor- or thriver-owned; identity labels such as women-, Black-, Indigenous-, Latinx-, Filipino-, disability-, LGBTQ+-, or trans-owned/led Only if you choose to answer during registration or Directory sign-up
Program information Preferred language, business stage, business name, description, logo, photos, website, social links, and equipment or software needs When you join the Directory, a cohort, or Tech Match
Donor information Name, email, mailing address, donation amount and history, in-kind item details When you donate money or equipment
Payment information Card or bank details Collected and processed by our payment processor, AGMS; we do not store full payment details
Communications Messages, emails, and form submissions you send us When you contact us or fill out a form
Search queries Words you type into Directory search, including AI Quick Picks When you search the Directory
Technical information IP address, browser type, device type, pages visited, referring site, cookies Automatically when you visit the Site
Verification codes A one-time code sent to your email When you register or verify your account
We ask you not to include details about your experiences of trafficking or abuse in forms, listings, or search fields. We do not need that information, and you never have to share it to take part in our programs.

3. How We Use Information

We use information to:
  • Create and manage your account and verify your email.
  • Publish and maintain Directory listings you submit, and help visitors find survivor-led businesses.
  • Run our programs, including cohorts and Tech Match, by matching members’ needs with donated equipment and funds.
  • Process donations, send receipts and tax acknowledgments, and keep the financial records nonprofits are required to keep.
  • Communicate with you about your account, programs, events, and, if you opt in, our newsletter.
  • Understand our impact and report to funders, but only in aggregate, de-identified form (for example, “40 survivor-owned businesses joined this year”).
  • Keep the Site secure, prevent fraud and abuse, and comply with the law.

4. How We Share Information

What you choose to make public. Information you put in your Directory listing (such as your business name, description, photos, and identity labels you select) is visible to anyone who visits the Site. Tech Match members are shown under pseudonyms, and we do not publish their real names. Service providers. We share information with vendors who help us run the Site and our programs, only as needed for their work, and they may not use it for their own purposes. These include: our website host and WordPress plugins; AGMS for payment processing; Jotform for sign-up forms; our email provider; and the provider of our AI search feature. Donors and equipment matching. When we match donated equipment, we share only what is needed for delivery. We do not give a member’s real name or contact information to a donor without the member’s consent. Legal requirements. We may disclose information if required by law, subpoena, or court order, or to protect someone’s life or safety. Unless legally prohibited, we will try to notify the affected person first so they can seek protection. What we never do. We do not sell, rent, or trade personal information. We do not share it with advertisers or data brokers. We do not share a person’s survivor status with anyone, including donors, funders, partners, or law enforcement, without that person’s consent, unless the law requires it.

5. Survivor Safety and Sensitive Information

We treat survivor status and identity information as sensitive. That means:
  • Answering identity questions is always optional, and “Prefer not to say” is always an option.
  • We limit access to sensitive information to staff and volunteers who need it, and they are trained to keep it confidential.
  • We use pseudonyms for Tech Match members and in public stories unless a member asks to be named.
  • Before publishing your name, photo, or story anywhere beyond your own Directory listing, we will ask for your permission.
Device safety. The “Safety Exit” button quickly leaves the Site, but it does not erase your browser history or cookies. Emails from us (such as verification codes or receipts) may appear in your inbox. If someone may be monitoring your device or email, consider using private browsing, a safe device, or a separate email account. If you are in danger, call 911, or reach the National Domestic Violence Hotline at 1-800-799-7233 or the National Human Trafficking Hotline at 1-888-373-7888.

6. Cookies and Analytics

We use cookies and similar tools to keep you logged in, remember preferences (such as “Remember Me”), keep the Site secure, and understand how the Site is used.  We do not use cookies for targeted advertising. You can block or delete cookies in your browser settings. Some features, such as logging in, may not work without them. Do Not Track. Browsers offer a “Do Not Track” setting. There is no common standard for responding to it, so the Site does not currently change its behavior when it receives that signal. [If you add analytics, consider honoring Global Privacy Control signals.] Social media and embedded content. Our links to Instagram, Facebook, X (Twitter), TikTok, and Candid are governed by those platforms’ own privacy policies.

7. Your Choices and Rights

You can, at any time:
  • See the personal information we hold about you.
  • Correct inaccurate information, or update your account and listing yourself.
  • Delete your account, listing, or optional identity answers. We will keep only the records the law requires, such as donation receipts.
  • Hide or change identity labels on your public listing.
  • Unsubscribe from marketing emails using the link in any email. You will still receive account and receipt emails.
To make a request, email hello@freebrands.org. We will respond within 30 days and may need to confirm your identity first, to protect you from someone else trying to access your information. California residents. Under California law (CalOPPA), we disclose in this policy what we collect, who we share it with, and how you can review and request changes. As a nonprofit, Free Brands is generally not covered by the California Consumer Privacy Act (CCPA), but we honor the requests above for everyone, wherever they live. We do not share personal information with third parties for their own direct marketing.

8. Data Retention and Security

Retention. We keep personal information only as long as needed for the purposes in this policy:
  • Account and Directory information: while your account or listing is active, then deleted within [90] days of your request or of account closure.
  • Donation records: for at least 7 years, as required for nonprofit tax and accounting purposes.
  • Messages and form submissions: up to [2] years, unless they are part of an ongoing program.
Security. We use reasonable safeguards, including encrypted connections (HTTPS), encrypted passwords, email verification, restricted staff access, and trusted payment processors. No system is perfectly secure. If a data breach affects your personal information, we will notify you as required by California law.

9. Children’s Privacy

The Site is not intended for anyone under 18, and we do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child without parental consent, we will delete it. If you believe a child has given us information, please contact us.

10. Changes to This Policy

We may update this policy as our programs or the law change. We will update the effective date at the top. For significant changes, we will post a notice on the Site or email registered users before the changes take effect.

11. Contact Us

If you have questions about this policy or your information, contact: Free Brands 2931 Canon St #60036, San Diego, CA 92106. Email: hello@freebrands.org Website: www.freebrands.org/about-us/contact