Privacy Policy
Effective Date: March 11, 2026
Last Updated: July 13, 2026
HelloCivic, Inc. ("HelloCivic," "Company," "we," "us," or "our") is committed to protecting the privacy and security of the information entrusted to us by our users and the government organizations we serve. This Privacy Policy describes how we collect, use, disclose, retain, and protect information when you access or use the HelloCivic platform, including all associated websites, applications, services, and tools (collectively, the "Service").
This Privacy Policy applies to all users of the Service, including individual users, administrators, and personnel of government organizations ("Organizations") that use the Service. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to the practices described herein.
1. Information We Collect
1.1 Information You Provide Directly
We collect information that you voluntarily provide to us, including:
- Account Registration Information: When you create an account, we collect your name, email address, password, username, and organizational affiliation. If an administrator creates your account, they may provide this information on your behalf.
- Profile Information: You may choose to provide additional profile information, such as a display name, profile photograph, job title, department, and contact details.
- Workspace and Organizational Data: When Organizations create workspaces, we collect workspace names, descriptions, configuration settings, subscription status, invitations, role assignments, and membership information.
- Authentication and Security Information: We collect information needed to secure your account, such as sign-in method, connected account identifiers, single sign-on attributes, multi-factor authentication settings, recovery status, trusted-device choices, IP address, user agent, and session information.
- Communications: When you contact us for support, submit feedback, or communicate with us through any channel, we collect the content of those communications along with associated metadata such as timestamps and sender information.
- Mobile Phone Number and SMS Information: If you or your Organization use HelloCivic Text, we collect mobile phone numbers, text-messaging opt-in and consent records, the content of text messages sent and received, and related delivery metadata. See Section 4 (HelloCivic Text) for details, including our commitment that no mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
- Payment Information: If you purchase a subscription, we collect billing information such as billing address and payment method details. Payment card information is processed by our third-party payment processor and is not stored on our servers.
- User-Generated Content: Any data, documents, files, or other content that you upload, submit, publish, embed, or create through the Service.
1.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including:
- Device and Browser Information: Device type, operating system, browser type and version, screen resolution, device identifiers, and language preferences.
- Usage Information: Pages viewed, features used, actions taken, time spent on pages, navigation paths, click patterns, widget interactions, form submissions, and search queries within the Service.
- Log Data: IP address, access times, referring URLs, error logs, and server response codes.
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixels, local storage, session storage, and similar technologies as described in our Cookie Policy.
- Location Information: Approximate geographic location derived from your IP address. We do not collect precise geolocation data.
1.3 Information from Third Parties
We may receive information about you from third-party sources, including:
- Organization Administrators: Administrators within your Organization may provide us with your information when provisioning your account or managing workspace memberships.
- Integrated Services: If you or your Organization connects third-party applications, identity providers, or services to the Service, we may receive information from those services as authorized by the integration configuration.
- Publicly Available Sources: We may collect information from publicly available sources to verify organizational affiliations or for fraud prevention purposes.
2. How We Use Information
2.1 Providing and Operating the Service
We use the information we collect to:
- Create, maintain, and secure your account and workspace
- Authenticate your identity and authorize access to appropriate resources
- Support single sign-on, connected accounts, multi-factor authentication, and trusted devices
- Process transactions and manage subscriptions
- Provide customer support and respond to your inquiries
- Deliver notifications, updates, and administrative messages
- Enable collaboration features, public profiles, embedded widgets, and workspace functionality
2.2 Improving and Developing the Service
We use information to:
- Analyze usage patterns and trends to improve the Service
- Conduct research and development to enhance existing features and develop new ones
- Test and evaluate the effectiveness of the Service
- Monitor and analyze the performance, reliability, and security of the Service
- Generate aggregated, de-identified analytics and reports
2.3 Safety and Security
We use information to:
- Detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity
- Enforce our Terms of Service and other policies
- Apply rate limits, abuse prevention controls, and access safeguards
- Verify the identity and authorization of users
- Protect the rights, property, and safety of HelloCivic, our users, and the public
2.4 Communications
We use information to:
- Send service-related communications, including account verification, security alerts, and technical notices
- Respond to your comments, questions, and requests
- Send promotional communications about new features, products, or services, where permitted by applicable law (you may opt out of promotional communications at any time)
2.5 Legal and Compliance
We use information to:
- Comply with applicable laws, regulations, legal processes, and governmental requests
- Enforce our legal rights and resolve disputes
- Fulfill our contractual obligations
- Maintain records as required by applicable law
3. Information Sharing and Disclosure
3.1 Within Your Organization
Information you provide through the Service may be visible to other members of your Organization, including administrators, workspace managers, and other authorized users, in accordance with the access controls and permissions configured for your workspace. Administrators within your Organization may have the ability to view, modify, or delete your account information and workspace data.
3.2 Public and Embedded Features
If you use public profile pages, public badges, embeddable widgets, invitation links, token-protected endpoints, or similar features, information configured for those features may be visible to people outside your Organization. Embedded tools may also collect limited event data, such as configuration requests, interaction events, page context, timestamps, IP address, and user agent, to operate the feature, prevent abuse, and measure reliability.
3.3 Service Providers
We share information with third-party service providers who perform services on our behalf, including hosting and infrastructure providers, payment processors, email delivery services, text-messaging and telecommunications providers, identity and security services, analytics providers, and customer support tools. These service providers are contractually obligated to use your information only for the purposes of providing services to us and are required to maintain the confidentiality and security of your information. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties except as described in Section 3.8 and Section 4 (HelloCivic Text).
3.4 Legal Requirements
We may disclose information if we believe in good faith that disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our Terms of Service or other agreements; (c) protect the rights, property, or safety of HelloCivic, our users, or the public; or (d) detect, prevent, or address fraud, security, or technical issues.
3.5 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or other similar event, information may be transferred as part of that transaction. We will notify affected users and Organizations of any change in ownership or control of their information and any choices they may have regarding their information.
3.6 Aggregated and De-Identified Information
We may share aggregated or de-identified information that cannot reasonably be used to identify you or your Organization. This information may be used for industry analysis, benchmarking, research, and other purposes.
3.7 With Your Consent
We may share your information with third parties when you have given us explicit consent to do so. This does not apply to mobile phone numbers or text-messaging originator opt-in data and consent, which are never shared with third parties or affiliates for marketing or promotional purposes (see Section 3.8 and Section 4).
3.8 Mobile Information
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Mobile phone numbers and text-messaging opt-in and consent data are never sold. See Section 4 (HelloCivic Text) for full details.
4. HelloCivic Text (SMS/Text Messaging)
HelloCivic Text is our SMS/text-messaging product that enables government Organizations to send and receive text messages with residents and other members of the public. HelloCivic operates the underlying messaging infrastructure on behalf of Organizations through licensed telecommunications providers. This Section describes how information is handled specifically in connection with SMS and supplements the rest of this Privacy Policy.
4.1 No Sharing or Sale of Mobile Information
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Mobile phone numbers and text-messaging opt-in and consent data are never sold. Text messaging originator opt-in data and consent will not be shared with any third parties, except for aggregators and providers of the text message services that transmit SMS on our behalf, or where required by law as described in Section 3.4 (Legal Requirements). These providers may use the information only to deliver the Service and are required to protect it.
4.2 Consent and Opt-In
Residents opt in to receive text messages by texting a keyword to an Organization's number, submitting a web form or embedded widget, providing their mobile number directly to the Organization, or otherwise expressly consenting. Consent to receive text messages is never a condition of purchasing any goods or receiving any government service. Organizations are responsible for obtaining and maintaining valid consent from the individuals they message and for honoring all opt-out requests.
4.3 Message Frequency
Message frequency varies. The number of messages you receive depends on how you interact with an Organization and the nature of the Organization's communications (for example, service updates, emergency and community alerts, appointment reminders, or replies to your questions).
4.4 Message and Data Rates
Message and data rates may apply. Any charges for sending or receiving text messages are determined by your mobile carrier and your wireless plan. Neither HelloCivic nor the Organization is responsible for charges imposed by your carrier.
4.5 Opt-Out and Help
You may opt out of text messages at any time by replying STOP to any message. After you reply STOP, you will receive a single confirmation message and will not receive further text messages unless you opt in again (for example, by replying START or JOIN). For help or assistance, reply HELP, or contact the Organization or [email protected]. Message delivery is not guaranteed, and wireless carriers are not liable for delayed or undelivered messages.
4.6 Information We Collect Through SMS
In connection with HelloCivic Text, we collect:
- Mobile phone numbers of residents and other participants
- Opt-in status, consent records, and opt-out (STOP) history
- The content of text messages sent and received
- Delivery metadata such as timestamps, message and segment counts, keywords used, and delivery or error status returned by carriers
4.7 How We Use SMS Information
We use SMS information to:
- Deliver the messages an Organization sends and route inbound replies to staff or automated responses
- Honor STOP, START, and HELP keywords and maintain accurate consent records
- Apply quotas, rate limits, and abuse-prevention and safety controls
- Maintain records of communications as required by the Organization and applicable law
4.8 Public Records
Text messages sent to or received from a government Organization may constitute public records subject to retention, disclosure, and legal-hold obligations under applicable public records and freedom-of-information laws. The Organization, as data controller, determines retention and any legal holds; HelloCivic provides tools to support these obligations as described in Section 5 (Government Data Processing).
4.9 Platform-Managed Credentials
HelloCivic manages the messaging provider relationship and credentials on behalf of Organizations. Organizations and their administrators do not have access to the underlying carrier credentials, and those credentials are never exposed through the Service.
5. Government Data Processing
5.1 Data Processor Role
When processing data on behalf of government Organizations, HelloCivic acts as a data processor (or service provider, as applicable under relevant law). The Organization acts as the data controller and determines the purposes and means of processing. HelloCivic processes such data solely in accordance with the Organization's instructions and applicable law.
5.2 Data Processing Agreements
Where required by applicable law, HelloCivic will enter into data processing agreements with Organizations that specify the scope, nature, and purpose of data processing, the types of personal data processed, the categories of data subjects, and the obligations and rights of each party.
5.3 Subprocessors
HelloCivic engages certain third-party subprocessors to assist in providing the Service. A current list of subprocessors is available upon request. We will notify Organizations of any changes to our subprocessors and provide Organizations with the opportunity to object to new subprocessors in accordance with applicable data processing agreements.
5.4 Government-Specific Obligations
HelloCivic acknowledges that government Organizations may be subject to specific data handling requirements, including public records laws, freedom of information statutes, and sector-specific regulations. HelloCivic will cooperate with Organizations to support compliance with these requirements, including providing reasonable assistance with public records requests and regulatory audits.
5.5 Data Segregation
User Data belonging to each Organization is logically segregated within the Service. HelloCivic implements access controls and technical measures to ensure that one Organization's data is not accessible to other Organizations or unauthorized parties.
6. Data Security
6.1 Security Measures
HelloCivic implements and maintains administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest using AES-256 encryption
- Role-based access controls and principle of least privilege
- Multi-factor authentication support
- Rate limiting, session controls, and abuse prevention safeguards
- Security monitoring and operational alerting
- Secure software development lifecycle practices
- Incident response and disaster recovery procedures
6.2 Incident Response
In the event of a security incident involving unauthorized access to or disclosure of personal information, HelloCivic will promptly investigate the incident and take appropriate remedial action. We will notify affected Organizations and individuals as required by applicable law, and we will cooperate with Organizations in their own incident response and notification efforts.
6.3 Limitations
While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your information.
7. Data Retention
7.1 Retention Periods
We retain information for as long as necessary to fulfill the purposes for which it was collected, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods vary based on the type of information and the purpose for which it was collected:
- Account Information: Retained for the duration of your account and for a reasonable period thereafter to comply with legal obligations and resolve disputes.
- User Data:Retained for the duration of the Organization's subscription. Upon termination, User Data is available for export for thirty (30) days and is subsequently deleted.
- Usage and Analytics Data: Retained in identifiable form for up to twenty-four (24) months, after which it is aggregated or de-identified.
- Security and Session Data: Retained as needed to secure accounts, investigate suspicious activity, enforce rate limits, and comply with legal obligations.
- Communications: Retained for as long as necessary to provide support and for quality assurance purposes.
7.2 Deletion
When information is no longer needed for the purposes for which it was collected, we will securely delete or de-identify it. Deletion may not be immediate due to technical constraints such as backup cycles, but we will ensure that retained data is protected and not used for any purpose other than backup and recovery.
8. Your Rights
8.1 General Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information, including:
- Access: The right to request access to the personal information we hold about you.
- Correction: The right to request correction of inaccurate or incomplete personal information.
- Deletion: The right to request deletion of your personal information, subject to certain exceptions.
- Portability: The right to receive your personal information in a structured, commonly used, and machine-readable format.
- Restriction: The right to request restriction of processing of your personal information.
- Objection: The right to object to processing of your personal information for certain purposes.
- Withdrawal of Consent: Where processing is based on consent, the right to withdraw consent at any time.
8.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"):
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share the information.
- Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you.
- Right to Opt Out of Sale or Sharing: HelloCivic does not sell personal information and does not share personal information for cross-context behavioral advertising purposes. This includes mobile phone numbers and text-messaging originator opt-in data and consent, which are never sold or shared with third parties/affiliates for marketing/promotional purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information to purposes necessary to provide the Service.
To exercise your CCPA/CPRA rights, please contact us at [email protected]. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf by providing written authorization.
8.3 European Economic Area, United Kingdom, and Switzerland (GDPR)
If you are located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, you have rights under the General Data Protection Regulation ("GDPR") and applicable local data protection laws:
- Legal Basis for Processing: We process personal data on the following legal bases: (a) performance of a contract (to provide the Service); (b) legitimate interests (to improve the Service, ensure security, and prevent fraud); (c) compliance with legal obligations; and (d) consent (where you have provided it).
- Data Protection Officer: You may contact our data protection team at [email protected] for any questions regarding our processing of your personal data.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in the EEA member state, UK, or Switzerland where you reside or where the alleged infringement occurred.
8.4 Exercising Your Rights
To exercise any of the rights described above, please contact us at [email protected]. We will respond to your request within the timeframe required by applicable law. In some cases, we may need to verify your identity before processing your request. If your request is made through an Organization, we may direct you to your Organization's administrator, as the Organization is the data controller for data processed through the Service.
9. Children's Privacy
The Service is not directed to children under the age of thirteen (13), and we do not knowingly collect personal information from children under thirteen. If we become aware that we have collected personal information from a child under thirteen without parental consent, we will take steps to promptly delete such information. If you believe that a child under thirteen has provided personal information to us, please contact us at [email protected].
For government Organizations that serve minors, the Organization is responsible for ensuring compliance with the Children's Online Privacy Protection Act ("COPPA") and any other applicable laws regarding children's privacy. HelloCivic will cooperate with Organizations to support compliance with these requirements.
10. International Data Transfers
10.1 Data Location
HelloCivic primarily stores and processes data in the United States. If you access the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where our service providers maintain facilities.
10.2 Transfer Mechanisms
Where we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate transfer mechanisms, including:
- Standard Contractual Clauses approved by the European Commission
- The UK International Data Transfer Agreement or Addendum, as applicable
- Binding Corporate Rules, where applicable
- Your explicit consent, where appropriate
10.3 Data Sovereignty
HelloCivic understands that certain government Organizations may have data sovereignty requirements that restrict the storage or processing of data outside specific jurisdictions. We will work with Organizations to accommodate such requirements where feasible, including offering data residency options where available.
11. Third-Party Links and Services
The Service may contain links to third-party websites, services, or applications that are not owned or controlled by HelloCivic. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services before providing them with your information. HelloCivic is not responsible for the privacy practices or content of third-party services.
12. Changes to This Privacy Policy
12.1 Modifications
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. If we make material changes, we will notify you by posting the updated Privacy Policy on the Service and updating the "Last Updated" date. For Organizations with active subscriptions, we will also provide notice via email to the primary contact on file at least thirty (30) days before the changes take effect.
12.2 Continued Use
Your continued use of the Service after the effective date of any modifications constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated Privacy Policy, you should discontinue your use of the Service.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy Inquiries: [email protected]
- Data Protection Officer: [email protected]
- General Support: [email protected]
By using the HelloCivic platform, you acknowledge that you have read and understood this Privacy Policy.

