Privacy Policy

 

1. Who this policy is from

This policy is published by Blossom Foundation NJ, Inc ("we", "us", "our"), a New Jersey nonprofit corporation recognized by the U.S. Internal Revenue Service as a tax-exempt organization under Section 501(c)(3) of the Internal Revenue Code.

Postal address: 27 Dickinson Road, Kendall Park, NJ 08824, United States

Contact email: Inquiries@BlossomFDNJ.com

We organize retreat events. This policy explains what personal information we hold in connection with those events, why we hold it, and what you can ask us to do about it.

2. What this policy covers

This policy covers:

•      the Blossom NJ mobile application, used only by volunteers working at our events;

•      the administrative console used by our organizing team;

•      the event pass emails we send to registered participants;

•      the participant and volunteer records held in the systems behind those.

It does not cover any other website, service or organization, including any third-party site we may link to.

3. What the Blossom NJ app is

Blossom NJ is a private application for volunteers working at our events. It is not available to the general public, has no public sign-up, and is distributed only to volunteers we invite.

Volunteers use it at the registration desk to look up a participant’s registration, confirm their details and agreement status, and record that they have checked in.

Participants do not use the app. Participants receive an event pass by email and present it at the desk.

4. Information we hold

4.1 About participants

Participants register for our events through our registration process. We hold:

•      Identity and contact details: full name, email address, mobile number, date of birth.

•      Registration details: which event, role (attendee, volunteer, or both), registration status, and a reference number for the event pass.

•      Agreement records: whether the participant has accepted each required agreement (participant liability waiver, volunteer waiver, non-disclosure agreement, photo consent), the version of the text accepted, the date and time of acceptance, and an image of the signature given.

•      Where a participant is under 18: the fact that they were under 18 at the time of signing, and the name, relationship and signature image of the guardian who signed on their behalf.

•      Event-day activity: the date and time of check-in and which volunteer recorded it; whether a wristband was issued; and attendance at event stations.

We do not collect this information through the app. It comes from the registration records participants provide to us, and from what happens at the registration desk on the day.

4.2 About volunteers

For volunteers we additionally hold an account used to sign in to the app. This consists of an email address and a password that we do not see or store in readable form, and a record of which events and roles the volunteer is assigned to.

Volunteer accounts are created by our organizing team; there is no public sign-up. A volunteer may delete their account at any time from within the app, or by emailing us at Inquiries@BlossomFDNJ.com. We also deactivate volunteer accounts when an event ends and the volunteer has no further assignments.

4.3 Information the app records as it is used

When a volunteer records a check-in, the app stores the date and time and the identity of the volunteer who performed it. We keep this so that we have an accurate record of who was admitted to an event and by whom.

5. Why we hold this information

We hold this information in order to:

•      run our events, admit registered participants, and know who is present;

•      confirm that the agreements we are required to obtain have been given;

•      identify participants who were under 18 at the time of signing, so that a guardian signature is obtained where it is needed;

•      send participants their event pass and related event communications;

•      keep a record of the agreements given, for our own protection and the participant’s.

We do not use this information to build advertising profiles, and we do not use it for any purpose unrelated to our events.

6. The camera

The app asks for permission to use the device camera. It is used for one purpose: reading the QR code on a participant’s event pass, and reading wristband codes at the desk.

The app does not photograph or record anyone. No image from the camera is saved by the app, transmitted, or retained. The camera view is used only to read the code in front of it.

7. Signatures

Signature images are held because they are the evidence that an agreement was given.

•      They are stored in private storage. They are not published, not made publicly accessible, and are not included in any link that could be shared.

•      They can be viewed only by our senior administrators, and only through an authenticated request.

•      A signature is stored against the registration it belongs to and is not used for any other purpose.

8. Information about people under 18

Some of our participants are under 18. Where that is the case, our registration process requires a parent or guardian to sign the relevant agreements, and we record the guardian’s name, relationship and signature.

The Blossom NJ app is not directed to children and children do not use it. We do not knowingly collect information directly from a child through the app or through any online service we operate. Information about a participant under 18 reaches us through their registration, provided by the participant’s parent, guardian, or the person registering them.

If you are a parent or guardian and wish to see, correct or ask us to delete information we hold about your child, contact us at the address in section 1 and we will respond.

9. What we do not do

•      We do not sell personal information, and we do not share it in exchange for anything of value.

•      We do not use it for advertising, and we do not provide it to advertising networks or data brokers.

•      The app contains no third-party analytics, advertising or tracking software, and does not track you across other apps or websites.

10. Who we share it with

We share personal information only in these circumstances.

Service providers who operate our systems on our behalf. Our systems run on Amazon Web Services (AWS), which hosts our databases, file storage and email sending. AWS processes this information on our instructions in order to provide those services, and is not permitted to use it for its own purposes.

Volunteers at the event. A volunteer working the registration desk will see the name, contact details and agreement status of the participants they are checking in. Volunteers are instructed to use this only for that purpose.

Where the law requires it. We may disclose information if we are required to do so by law, by a court, or by a government authority, or where we reasonably believe it is necessary to protect someone’s safety.

We do not otherwise disclose personal information to third parties. Any service provider or other party that we permit to access personal information is required to protect it to the same or an equivalent standard as described in this policy.

11. Where information is stored

Our systems are hosted in the United States, in the AWS US East (Northern Virginia) region. Email is sent through AWS Simple Email Service in the same region.

If you are outside the United States and provide information to us, it will be stored and processed in the United States.

12. How long we keep it

We keep participant and volunteer records for as long as we need them for the purposes described in section 5, and afterwards for as long as we may need them as a record of the agreements given.

We keep records relating to an event for seven (7) years after that event. This includes registration records, agreement records (such as liability waivers and non-disclosure agreements) and signature images.

Where a participant was under 18 at the time of the event, we keep the agreement records relating to that participant until the later of (a) seven years after the event, or (b) three years after the participant’s 18th birthday.

Records of event-day activity (check-in times, wristband codes and station attendance) that are not needed as evidence of an agreement are kept for three (3) years after the event.

Financial records relating to registration fees, payments and donations are kept for as long as required by U.S. federal tax law and New Jersey charitable-organization law, which is generally at least three years and longer in some cases.

We may keep a record for longer where the law requires it, or where it is needed in connection with an actual or reasonably anticipated legal claim, investigation or insurance matter. Where a person asks us to keep their information for a shorter period, we will agree where we are able to do so.

When a record reaches the end of that period, we delete it or remove the details that identify a person.

13. How we protect it

Information is held in access-controlled systems. Access requires an account we have issued, accounts are limited to what the holder’s role requires, and signature images require a separate authenticated request to view. Information is encrypted in transit and at rest by the services that store it.

No system can be guaranteed to be completely secure. We take the measures described here, but we cannot promise that a breach will never occur. If a breach occurs that affects your personal information, we will act on it and notify you where the law requires us to.

14. Your choices and your rights

You may ask us to:

•      tell you what personal information we hold about you, and provide a copy of it;

•      correct information that is wrong or out of date;

•      delete information, where we are not required to keep it;

•      stop sending you event emails — every event email we send includes a way to do this, and you can also ask us directly.

•      withdraw any consent you have given (for example, photo consent) — this does not affect anything we did before you withdrew it, and does not apply to agreement records we must keep as described in section 12.

Make any of these requests by writing to the contact address in section 1. We will ask you to confirm your identity before we act, so that we do not disclose your information to someone else. We will respond within the time the applicable law allows, and we will tell you if we cannot do what you have asked and why.

Depending on where you live, you may have additional rights under the privacy law of your state or country. Contacting us at the address in section 1 is the way to exercise them.

Asking us to delete your registration information may mean we cannot admit you to an event, because the record of your registration and agreements is what admission depends on.

15. Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date at the top and publish the new version on this page. If a change materially affects how we use information we already hold, we will take reasonable steps to tell affected people directly.

16. Contact

Questions about this policy, or requests about your information:

Blossom Foundation NJ, Inc

27 Dickinson Road, Kendall Park, NJ 08824, United States

Inquiries@BlossomFDNJ.com