Owner-approved policy
Privacy at COnnect
This plain-language policy explains how COnnect handles guest, member, event, community, safety, and communication information.
Effective when Cloudflare Workers begins serving rscbend.com; last updated August 27, 2026
Who is responsible
COnnect is operated by Corey Martin, an individual operating COnnect. Privacy questions and requests may be sent to rscbend@gmail.com.
What COnnect collects
COnnect collects information you choose to provide, such as a name and email for an RSVP; profile, visibility, and preference details for an account; event registrations and attendance-related choices; last-minute plans, messages, and other community content; and information included in a safety report or support request. The portal also records limited account, event, moderation, delivery-status, and technical activity needed to operate and secure the service.
How COnnect uses information
COnnect uses information to manage events, capacity and waitlists; provide accounts and community features; honor communication preferences; respond to support, privacy, and safety requests; enforce the terms and community guidelines; prevent misuse; troubleshoot delivery and technical issues; and maintain the reliability and security of the portal. Member and guest email addresses are not displayed publicly.
Guest RSVPs
A guest can RSVP without creating an account. Guest contact details are used to administer the event, enforce capacity, maintain the waitlist, honor selected communications, and link the RSVP if the guest later signs in with the same verified email. A private manage link does not display the guest email address. Keep that link private.
Member and community visibility
Member profiles start private. A member can choose to make selected profile details visible to authenticated members; email addresses remain private. Messages and last-minute plans may be visible to eligible signed-in members in the relevant community space. Reports and block choices are handled through protected features and are not disclosed to the reported or blocked person merely because a report or block was submitted.
Safety, reports, and blocking
Safety reports, bounded evidence snapshots, moderation actions, and a limited organizer audit trail are stored so COnnect can investigate concerns and enforce the community guidelines. Reports are available only through protected organizer tools. Blocking choices are private to the member who uses them. Open reviews and records subject to a safety or legal hold may be kept longer than the ordinary retention target.
Communications
COnnect stores event, reminder, and community communication preferences separately. Essential account or joined-event messages may be treated differently from optional community news. Server-side email delivery is attempted only when an approved provider integration is explicitly enabled and the individual message remains eligible. The Brevo adapter remains disabled unless Corey Martin separately approves provider activation.
Service providers and disclosures
COnnect uses Firebase for account, event, RSVP, community, preference, moderation, and delivery-status data, and Cloudflare Workers for hosting. A separately approved email provider may process recipient and delivery information only for enabled messages. These providers process information under their own terms and security practices.
When an authorized organizer searches for a venue, COnnect sends the search terms and visible map area from a trusted server to the Google Places API. The organizer’s browser also loads Google Maps, so Google may receive technical information such as the browser’s network address, device or browser details, and referring page. COnnect keeps only the Google place ID used to link a result to an independently authored COnnect venue record; Google-supplied names, addresses, categories, ratings, review counts, hours, and coordinates are not stored as COnnect venue data. See the Google Privacy Policy.
COnnect may disclose information when reasonably necessary to operate an event or requested feature, investigate a safety or fraud concern, protect a person or the service, comply with law or a valid legal request, or complete a future business transfer with appropriate privacy protections. COnnect does not ask users to send passwords, private RSVP links, payment-card details, or other secrets by email.
Payments
COnnect does not currently process paid memberships or store payment-card details. Before any paid plan launches, COnnect will identify the payment provider and update its terms and privacy disclosures. The intended approach is to use a secure provider-hosted checkout so payment-card details go directly to the provider; COnnect would retain only the customer, subscription, entitlement, and transaction-status information needed to manage access and support.
How long information is kept
COnnect has approved the following launch retention targets, subject to longer retention when reasonably needed for safety, fraud prevention, dispute handling, legal compliance, or a user-requested service:
- Community plans and chats may remain visible in an archive for up to 30 fixed days.
- A complete spontaneous-plan record—including participant and chat records and exact files referenced by that plan—is targeted for removal 90 fixed days after the plan expires, subject to safety or legal holds.
- Other chat content and attachments are targeted for deletion after 90 fixed days once the applicable parent anchor and safety holds are validated.
- RSVP contact information is targeted for removal 90 fixed days after the event.
- Event operational records are targeted for retention for 12 calendar months after the scheduled end. Cancelling or archiving an event does not shorten that period.
- An abandoned draft without a scheduled end becomes eligible for manual review after 12 calendar months without an update.
- A closed safety report is targeted for retention for 24 calendar months after closure. An open report remains held for manual review, and organizer audit records are targeted for 24 calendar months after creation.
- An account becomes eligible for manual inactivity review after 24 calendar months from its latest recorded sign-in or account update. COnnect does not automatically delete inactive accounts.
Some automated enforcement for these periods is not active yet. Until a control is implemented and verified, COnnect may retain affected records longer and will not represent that a record has been deleted unless deletion is confirmed. Applying this schedule to records that already exist, including archived QA records, requires a separate owner approval.
Security
COnnect uses Firebase Authentication, Security Rules, private manage tokens, trusted server functions, and access controls to limit access. No online service can promise absolute security. Contact COnnect if you believe an account, private manage link, or personal information may have been compromised.
Your choices
You can update profile visibility and communication preferences in member settings and can cancel or manage an RSVP using the available account or private link flow. You may ask COnnect to review, correct, export, or delete information connected to you, subject to identity verification and records that must be retained for safety, legal, fraud-prevention, dispute, or operational reasons.
Privacy requests
Email rscbend@gmail.com with the subject “Privacy request.” Include enough information to locate the account or RSVP, but do not email a password or private manage token. COnnect may verify the requester before changing or releasing private information and aims to respond within 45 days.
Policy changes
Material policy changes will be dated and communicated before they take effect when reasonably practical. If future features materially change what COnnect collects or why, this policy will be updated before those features are enabled for the public.

