Effective and last updated: August 13, 2026
1. Scope and who we are
This Privacy Policy applies to Client Resource Project, including clientresourceproject.org and the articles, directories, downloads, forms, newsletters, and other services that link to this policy (collectively, the “Services”). In this policy, “Client Resource Project,” “we,” “us,” and “our” refer to the operator of the Services.
For privacy laws that use the terms “controller,” “business,” “responsible party,” or similar terms, Client Resource Project is the entity responsible for deciding why and how personal information is processed unless another notice says otherwise.
This policy does not apply to third-party websites, services, or organizations linked from our Services. Their own privacy policies govern their practices.
2. Information we collect
“Personal information” means information that identifies, relates to, describes, can reasonably be linked with, or could reasonably be used to identify an individual. It does not include information that is lawfully public, aggregated, or de-identified where applicable law excludes it.
| Category | Examples | How collected |
|---|---|---|
| Contact and communication information | Name, email address, organization, role, and the contents of messages, questions, feedback, or support requests. | Directly from you when you email us or use a form. |
| Member account information | Username, email address, password hash, account status, verification status, account dates, and security-related login status. We do not store your plaintext password. | Directly from you when you create or use a CRP account. |
| Member visit history | For signed-in members, the CRP page address, page title, and date and time of the visit. This member-history record does not store an IP address, device fingerprint, precise location, or user agent. | Automatically while you are signed into your CRP account so the history can be shown back to you in My CRP. |
| Newsletter and preference information | Email address, subscription status, consent record, communication preferences, and basic delivery or engagement information such as delivery failures or unsubscribes. | Directly from you and from our email service provider. |
| Resource, directory, or content submissions | Information you submit about yourself, an organization, provider, program, resource, correction, or suggested content. This may include professional contact details and public listing information. | Directly from you or an authorized representative. |
| Transaction information | If paid products, donations, or subscriptions are offered, purchase details, amount, date, transaction identifier, and billing contact details. Complete payment-card numbers are handled by the payment provider and are not intended to be stored by us. | From you and the payment provider when a transaction is made. |
| Device and network information | IP address, browser and device type, operating system, language, approximate location derived from IP, referring page, requested page, and date and time of access. | Automatically through hosting, security, and server logs. |
| Usage and cookie information | Pages viewed, links selected, site interactions, session information, preferences, and cookie or similar-technology identifiers. | Automatically when permitted through cookies, local storage, logs, or analytics tools. |
| Privacy-request information | Your request, region, correspondence, verification details, response, and appeal, if applicable. | Directly from you or your authorized agent. |
We may also receive information from public sources, resource providers, professional organizations, referral partners, and service providers. If you provide personal information about another person, you represent that you are authorized to do so and that you have given any required notice.
We do not use the Services to collect precise geolocation, biometric identifiers, government identification numbers, financial-account credentials, or health records from ordinary visitors. If a feature later needs a new category of personal information, we will provide an appropriate notice before or at collection.
3. How we use information
We use personal information only for reasonably necessary and proportionate purposes, including to:
- create, authenticate, verify, secure, and administer CRP member accounts;
- show signed-in members their own CRP visit history and allow them to clear that history;
- provide, maintain, personalize, and improve the Services;
- publish, review, verify, correct, or update requested resource and directory information;
- send newsletters or other communications you requested and manage subscription preferences;
- respond to questions, feedback, support requests, and privacy requests;
- process transactions and keep appropriate financial and business records;
- understand site performance and how visitors use our resources;
- detect, investigate, and prevent spam, fraud, abuse, security incidents, or other harmful activity;
- debug, audit, protect, and administer our systems;
- enforce our terms, establish or defend legal claims, and comply with legal obligations; and
- create aggregated or de-identified information that does not reasonably identify an individual.
We do not use personal information for materially different, unrelated, or incompatible purposes without providing notice and obtaining consent when required.
4. Legal bases for processing
Where a law such as the EU General Data Protection Regulation (GDPR), U.K. GDPR, Brazil’s LGPD, or another law requires a legal basis, we rely on one or more of the following:
- Consent: for example, when you subscribe to optional communications or agree to non-essential cookies. You may withdraw consent at any time without affecting earlier lawful processing.
- Contract or steps requested before a contract: when processing is necessary to provide something you requested or complete a transaction.
- Legitimate interests: to operate, secure, improve, and understand the Services; respond to communications; prevent misuse; and protect our rights, provided those interests are not overridden by your rights and interests.
- Legal obligation: when processing is required by tax, accounting, consumer-protection, court, regulatory, or other applicable law.
- Legal claims and vital interests: when necessary to establish, exercise, or defend legal rights, or to protect someone’s life or safety.
You may contact us for information about the legal basis that applies to a specific activity.
5. When we disclose information
We may disclose personal information only as described below. A disclosure is not necessarily a “sale” or “sharing” under privacy law.
- Service providers and processors: hosting, security, database, email delivery, analytics, form, payment, storage, backup, and technical-support providers that process information for us under appropriate restrictions.
- At your direction or with your consent: when you ask us to publish a listing, send information to another organization, or otherwise authorize disclosure.
- Public submissions: information intentionally submitted for publication in a public resource or provider directory may be visible to anyone and indexed by search engines.
- Legal and safety reasons: when we reasonably believe disclosure is required by law, subpoena, court order, or valid government request, or is necessary to protect rights, safety, security, and the integrity of the Services.
- Professional advisers: lawyers, accountants, insurers, auditors, and similar advisers subject to confidentiality obligations.
- Organizational change: in connection with a merger, financing, reorganization, acquisition, sale of assets, or similar transaction, subject to legally required notice and protections.
We require service providers to use personal information only for the contracted service or another legally permitted purpose and to protect it appropriately.
6. No sale, rental, or targeted advertising
Because we do not engage in these activities, there is no need to submit a request to opt out of them. If our practices change, we will update this policy, provide any required notice, and offer legally required opt-out controls before beginning the new practice.
We do not discriminate against anyone for exercising a privacy right. We do not offer financial incentives for personal information unless a separate notice clearly explains the material terms and obtains any required consent.
7. Cookies, similar technologies, and analytics
Cookies and similar technologies may store or read information on your device. We use these technologies only as described in this Privacy Policy and according to the choices you make through our cookie controls.
- Strictly necessary technologies support security, network management, form operation, accessibility, cookie preferences, and features you request. These technologies are necessary for the site to function and cannot always be disabled through our cookie controls.
- Functional technologies remember certain choices and improve the convenience and operation of the site.
- Analytics technologies help us understand how visitors use the site, which pages and resources are viewed, how visitors reach the site, and how the site performs.
Google Analytics
We use Google Analytics, a website-analytics service provided by Google, to measure and better understand use of Client Resource Project. Google Analytics may process information such as the pages visited, approximate location derived from an IP address, browser and device information, referral source, interactions with the site, and the date and time of a visit. We use this information to evaluate site performance and improve our articles, tools, worksheets, guides, and activities.
Google Analytics may use cookies including _ga,
_ga_*, _gid, and _gat. Information
collected through Google Analytics may be processed by Google under its own
privacy terms. You can learn more about
how Google uses information from sites that use its services
and review
Google’s Privacy Policy.
Your cookie choices
Google Analytics and other non-essential technologies remain disabled unless you choose to accept analytics cookies. You may reject analytics cookies when the cookie notice appears or later change or withdraw your choice through the site’s Cookie Settings control. Withdrawing consent prevents future analytics collection from this browser, but it does not automatically delete information previously processed. If you are signed into a CRP member account, we may also save your selected optional cookie categories as account preferences. Browser consent remains specific to the browser or device in use: an account preference does not automatically activate optional cookies on a new browser before that browser records a consent choice.
You may also use your browser settings to block or delete cookies. Blocking strictly necessary technologies may cause portions of the site to function incorrectly. Google also offers a Google Analytics Opt-out Browser Add-on.
Browser privacy signals
Browser “Do Not Track” signals are not interpreted consistently across the web. Client Resource Project does not sell personal information or use it for cross-context behavioral advertising. Where applicable law requires us to recognize a legally valid opt-out preference signal, such as Global Privacy Control, we will treat that signal as an applicable request for the browser or device that sends it.
8. How long we keep information
We keep personal information only as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, maintain accurate records, resolve disputes, enforce agreements, protect security, and comply with legal obligations.
- Member account information is generally kept while the account remains active and afterward only as reasonably necessary for security, legal, dispute, or account-recovery purposes.
- Member visit history is kept to provide the My CRP history feature. A signed-in member may clear their recorded page-view history from My CRP. Login and logout events may remain separately for limited security and account-operation purposes.
- Password-reset and email-verification tokens are time-limited, stored as one-way hashes, and invalidated after use or replacement.
- Short-lived login-throttling records use keyed hashes rather than raw IP addresses or raw login identifiers and are automatically cleaned up after a short period.
- Newsletter information is generally kept while you are subscribed. After an unsubscribe, we may retain a minimal suppression record so we honor your choice.
- Messages and support records are generally kept while the matter is active and afterward only as needed for legitimate operational, legal, or security purposes.
- Public resource and directory information is kept while the listing remains active and as needed to document corrections, permissions, or removal requests.
- Transaction and tax records are retained for periods required by applicable financial, tax, and accounting laws.
- Technical and security logs are kept for a limited period appropriate to troubleshooting, security, abuse prevention, and legal requirements.
Retention may be longer when information is subject to a legal hold, dispute, investigation, backup cycle, or a valid legal requirement. When information is no longer needed, we delete, de-identify, or securely isolate it.
9. Data security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include access controls, least-privilege practices, encrypted transmission, software updates, backups, logging, vendor review, and incident-response procedures appropriate to the nature of the information.
No system or transmission is completely secure. You are responsible for using appropriate care when sending information online. If we learn of a breach affecting personal information, we will investigate and provide notice to affected individuals and authorities when required by applicable law.
10. Children, health information, and sensitive data
Children
The Services provide general resources and may include information useful to parents, caregivers, professionals, and young people, but they are not intended to collect personal information directly from children under 13 in the United States or under the minimum digital-consent age that applies in another country. Children should not submit names, email addresses, messages, directory entries, or other personal information without involvement and legally valid authorization from a parent or guardian.
If we learn that we collected a child’s personal information in a manner that requires parental consent and did not receive it, we will take reasonable steps to delete the information. A parent or guardian may contact us using the information below.
No clinical records or client-identifying information
If sensitive information is sent to us without a request, we will use it only as reasonably necessary to respond, protect safety, comply with law, or delete it. We do not use sensitive personal information to infer characteristics about visitors.
11. International data transfers
Client Resource Project is based in the United States. If you access the Services from another country, your information may be processed in the United States or another country where our service providers operate. Those countries may have privacy laws different from the laws where you live.
When required, we use recognized transfer safeguards, such as adequacy decisions, contractual protections, data-processing agreements, or approved standard contractual clauses, and supplementary measures appropriate to the transfer. You may contact us for information about safeguards relevant to your information.
12. Your privacy choices and rights
Depending on where you live and whether a particular law applies to Client Resource Project, you may have the right to:
- know whether we process your personal information and obtain access to it;
- receive information about categories, sources, purposes, retention, and recipients;
- correct inaccurate or incomplete personal information;
- request deletion or erasure;
- receive a portable copy of information you provided;
- restrict or object to certain processing;
- withdraw consent at any time where processing relies on consent;
- opt out of sale, targeted advertising, certain sharing, or certain profiling;
- limit certain uses of sensitive personal information;
- appeal a denial of a request where applicable;
- complain to a privacy or data-protection authority; and
- receive equal service and not be retaliated against for exercising a right.
These rights are not absolute. Applicable law may allow or require us to deny or limit a request, such as when we cannot verify identity, must retain information by law, need it to protect rights or safety, or an exception applies.
Member account controls
If you have a CRP member account, you can view your recorded CRP page history in My CRP and clear that page-view history directly from your account. Clearing history cannot be undone.
How to submit a request
Email privacy@clientresourceproject.org with the subject line “Privacy Request.” Describe the right you want to exercise and the Services involved. To protect you, we may request information reasonably necessary to verify identity and authority. Do not send a government ID unless we specifically request it and provide a secure method.
An authorized agent may submit a request where permitted, but we may require proof of authorization and, where allowed, direct verification from the individual. We will respond within the period required by applicable law. If we deny an appealable request, our response will explain how to appeal.
You may unsubscribe from marketing emails at any time by using the unsubscribe link in the message. We may still send non-promotional communications that are necessary to complete a request or transaction.
13. Country and regional privacy notices
This section summarizes additional rights that may apply. It does not limit any right granted by law. A law may not apply because of its territorial scope, organizational or revenue thresholds, the nature of the processing, an exemption, or another legal rule.
United States
Residents of states with comprehensive consumer privacy laws—including, where applicable, California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia—may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal information, and to opt out of sale, targeted advertising, or certain profiling. Some states provide rights concerning sensitive data, authorized agents, appeals, or lists of third parties. We do not sell personal information, share it for cross-context behavioral advertising, or use it for legally significant profiling.
California notice: The categories described in Section 2 are the categories we collect for the business and commercial purposes described in Section 3 and retain under Section 8. We disclose relevant categories to the recipients in Section 5. We do not knowingly sell or share, as those terms are defined by California law, personal information of consumers under 16. California residents may also request information about qualifying disclosures for direct-marketing purposes under California’s “Shine the Light” law; we do not disclose personal information to third parties for their own direct marketing.
Nevada: Nevada residents may submit a verified request concerning a future sale of covered information. We do not currently sell covered information as defined by Nevada law.
European Economic Area, United Kingdom, and Switzerland
Where the GDPR, U.K. GDPR, Swiss Federal Act on Data Protection, or related law applies, you may have rights of access, rectification, erasure, restriction, objection, and portability, the right to withdraw consent, and the right not to be subject to certain solely automated decisions. You may lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. We do not conduct solely automated decision-making that produces legal or similarly significant effects.
Right to object: Where processing is based on legitimate interests, you may object based on your particular situation. You may object to direct marketing at any time.
Canada
Where Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) or applicable provincial law applies—including private-sector laws in Alberta, British Columbia, or Québec—you may request access to and correction of personal information, withdraw consent subject to legal or contractual limits, and challenge our compliance. We follow principles of accountability, identified purposes, appropriate consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and complaint handling where applicable.
Brazil
Where Brazil’s Lei Geral de Proteção de Dados (LGPD) applies, you may request confirmation of processing, access, correction, anonymization, blocking or deletion in qualifying circumstances, portability when regulated, information about recipients and consent choices, withdrawal of consent, and review of qualifying automated decisions. You may also petition Brazil’s National Data Protection Authority (ANPD).
Australia and New Zealand
Where Australia’s Privacy Act 1988 and Australian Privacy Principles apply, you may request access to and correction of personal information and complain about our handling practices. Where New Zealand’s Privacy Act 2020 applies, you may request access and correction and complain to the Office of the Privacy Commissioner. Cross-border disclosures will be handled with safeguards required by applicable law.
South Africa
Where the Protection of Personal Information Act (POPIA) applies, you may request access, correction or deletion, object to certain processing, withdraw consent where applicable, and complain to South Africa’s Information Regulator. We do not use personal information for unsolicited electronic direct marketing without a lawful basis.
Japan, Singapore, and South Korea
Where Japan’s Act on the Protection of Personal Information (APPI) applies, you may have rights to disclosure, correction, suspension of use, deletion, and suspension of third-party provision. Where Singapore’s Personal Data Protection Act (PDPA) applies, you may request access or correction and withdraw consent subject to applicable limits. Where South Korea’s Personal Information Protection Act (PIPA) applies, you may have rights to access, correct, delete, or suspend processing and to receive information about qualifying overseas transfers.
India
Where India’s Digital Personal Data Protection Act and implementing rules are in force and apply, you may have rights to obtain information about processing, correct or erase data, use a grievance process, and nominate another individual to exercise rights in specified circumstances.
Other countries and territories
Privacy laws in other jurisdictions—including China’s Personal Information Protection Law and privacy laws in additional countries and territories—may provide comparable or additional rights. We will honor applicable rights and legally required safeguards even when they are not individually listed in this policy. Contact us to exercise a right or ask how local requirements apply.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in the Services, technology, law, or our practices. We will post the revised policy here and update the effective date. If a change materially affects how we use personal information, we will provide additional notice or obtain consent when required.
15. Contact us
Client Resource Project — Privacy Contact
Email: privacy@clientresourceproject.org
Location: United States
If you have a disability and need this policy or a privacy-request method in another format, contact us and we will make reasonable efforts to assist.