Privacy Policy · A Community Service Of The Center for Retirement Readiness™
Privacy Policy

The data you trust us with, and what we do with it.

A specific, plain-English explanation of what we collect, what we use it for, what we never do, and how to get your data back or have it deleted.

Last updated: July 15, 2026

Who is collecting this data.

The Center for Retirement Readiness™ (referred to in this policy as "TCFRR," "we," "us," or "our") operates the Lifeline Card™ community service program. TCFRR is a community service organization, not a financial advisory firm, broker-dealer, or insurance company. For more on what TCFRR is and how it relates to sponsoring advisors, see our Disclosures page.

This privacy policy describes how TCFRR collects, uses, and protects information from users of:

Legal entity identification:

[Attorney to confirm: TCFRR's legal entity name and form (LLC, nonprofit, etc.), state of organization, and physical/mailing address. This information is required for CCPA, GDPR, and most state privacy law contexts. Update placeholder URLs above if final domain selection differs.]

What data we collect, exactly.

We are deliberately specific in this section because vague privacy policies are how trust gets broken. Here is everything we collect, and nothing else.

Card data you enter

When you generate a Lifeline Card™, we collect the information you choose to enter into the card-generation form. This includes the fields documented in our card field specification:

Category Examples of fields Required?
Identity Full name, date of birth, blood type Some required
Medical Allergies, medications, dosages, conditions, devices, comfort notes Optional
Contact Emergency contact names, phone numbers, relationships One required
Care providers Doctor, pediatrician, vet, hospital preferences Optional
Other (optional) DNR pointer, organ donor preference, religious notes, insurance carrier and member ID Optional
Pet-specific Pet name, species, breed, microchip ID, vet contact, behavior notes Some required

Contact information

We collect your email address and phone number. We use your email to send you a copy of your generated cards, the annual reminder, and any required service-related communications (deletion confirmations, security notices, etc.). Your name, email, and phone number are also shared with the local advisor who sponsors the free program in your community, as described in Section 7 (When and how we share data) and disclosed to you at signup.

We do not collect or require: your home address (unless entered into the card form), your Social Security number, your government identification, your financial account information, or your credit card. The Lifeline Card™ is free at every point of use, so we have no payment information to collect.

Technical information

When you use our website, we automatically collect a limited set of technical information — the kind of information any website server logs:

This technical information is described in more detail in Section 10: Cookies and analytics.

What we don't collect

Drafting note: If TCFRR's actual implementation collects any data not listed above — for example, if the email service provider records open/click tracking on emails, if any A/B testing tools are used, or if any third-party widgets are embedded — those collection points must be explicitly added to this section. Counsel should walk through TCFRR's full data inventory with the engineering lead and confirm this section is complete and accurate before publication.

How we use it.

We use the data we collect for the specific purposes listed below, and for no other purposes.

Card generation and delivery

Card data you enter is used to generate the printable PDF Lifeline Cards™ you've requested, and to email that PDF to you for safekeeping. The card data you enter is processed only to build that PDF and is then discarded from our systems; we do not retain it.

Changing your cards

Because we don't keep your card data, there's no saved card to edit. To change anything, just make a new card — it's free and takes a few minutes.

The one annual reminder

On the anniversary of your initial card generation, we send you one email reminder so you can make a fresh card if anything has changed in the past year. (We send this using the email address we hold; we don't store the cards themselves.) This is a single email per year, sent from community@thecenterforretirementreadiness.com, with one-click unsubscribe in every reminder.

The optional community-resources stream

From time to time, TCFRR or the sponsoring advisor in your community may send you occasional helpful resources (separate from the annual reminder), as part of the free program you signed up for. These are sent infrequently, and you can unsubscribe with one click at any time. Unsubscribing from these resources does not delete the contact information we hold — the two are separate.

Security and abuse prevention

We use technical information (IP addresses, browser fingerprints) to detect and prevent abuse of our systems — spam form submissions, automated scraping, brute-force attempts, and similar threats. This use is limited to security purposes and does not feed into any marketing or analytics use case.

Legal compliance

We use data as required to comply with applicable laws, respond to lawful requests from regulators or courts, and document our compliance with privacy regulations (e.g., maintaining a record of deletion requests).

What we never do with it.

For clarity — because the line between "useful service" and "data exploitation" is precisely where trust is built or broken — here is an explicit list of practices the Lifeline Card™ program will never engage in.

If TCFRR ever changes any of the above commitments, we will notify all current cardholders before the change takes effect, and provide a clear path to opt out, delete data, or withdraw from the program. See Section 12: Changes to this policy.

In plain English

The list above is the part of this policy worth taking us at our word on. Programs that quietly violate commitments like these get caught and lose public trust permanently — we know that, and we're not going to be one of them.

When and how we share data.

We share data only in the limited circumstances described below.

With service providers acting on our behalf

We use a small number of carefully selected service providers to operate the program — for example, the company that hosts our website, the email service that delivers our transactional emails, and the cloud provider that stores card data. These providers process data only on our instructions, only for the purposes listed in this policy, and are contractually prohibited from using data for their own purposes. They are not permitted to sell, share, or repurpose the data we entrust to them.

Drafting note: Counsel should review TCFRR's actual list of subprocessors and update this section to disclose them as required by applicable law. Some jurisdictions (notably the EU/UK under GDPR, and increasingly U.S. state privacy laws) require either a published subprocessor list or specific contractual commitments. Common subprocessors that should be disclosed once finalized:

  • Email service provider (e.g., Postmark, SendGrid, Resend) — for transactional and reminder email delivery
  • Hosting and CDN provider (e.g., Cloudflare, Vercel, AWS) — for website hosting and DDoS protection
  • Database / storage provider — where contact records (name, email, phone) are stored. No card or medical data is stored here or with any subprocessor.
  • Customer support tools, if any
  • Backup and disaster recovery providers

Note: If TCFRR uses any analytics, A/B testing, or session replay tools, these are particularly important to disclose because they receive personal data and have higher visibility in regulatory enforcement actions.

With sponsoring advisors

The Lifeline Card™ is free because a local financial advisor sponsors the program in your community. When you sign up, your contact details — name, email, and phone number — are shared with that sponsoring advisor, who may reach out to welcome you to the program and offer retirement-readiness resources at no cost. This sharing is disclosed to you at the point of signup, and you can unsubscribe from communications at any time.

This is the only information shared with the advisor. The medical, health, and family information you enter into your cards — allergies, conditions, medications, doctors, emergency contacts, and any details about children or other household members — is never shared with the sponsoring advisor, under any circumstances, even if the advisor requests it. That information stays between you and your cards.

To comply with law

We may disclose data when required by valid legal process — a subpoena, court order, or other lawful demand from a government authority. We will, where lawful and practical, notify the affected user before disclosure, and we will resist legal process that we believe is overbroad or improper.

To protect rights and safety

We may disclose data when reasonably necessary to investigate or prevent illegal activity, fraud, threats to the physical safety of any person, or violations of our terms of service.

In a corporate transaction

If TCFRR is involved in a merger, acquisition, sale of assets, or similar transaction, your data may be transferred as part of that transaction. We will notify affected users of any such transfer and any material change in privacy practices that results.

Drafting note: The corporate-transaction subsection above is standard but should be reviewed against TCFRR's actual entity structure and any commitments TCFRR wants to make about successor liability for these privacy commitments. Some community-service organizations make stronger-than-standard commitments here (e.g., "any successor must accept these commitments unmodified, or notify users 90 days in advance of any change") that may be worth considering for trust-building purposes.

How we protect it.

Card data is sensitive — it includes medical information, contact information for minors, and information about pets that can be used to locate them. We take corresponding security measures to protect it.

Technical safeguards

Organizational safeguards

What happens if there's a breach

If a security breach affects your personal data, we will notify you in accordance with applicable law. In the U.S., that timing varies by state but typically requires notification within 30–90 days of discovery of a breach involving personal data. In the EU/UK under GDPR, notification to regulators is required within 72 hours of discovery. We will provide notification at least as quickly as the strictest applicable law requires.

Drafting note: The technical and organizational safeguards described above are general descriptions and should be reviewed against TCFRR's actual security posture. If TCFRR has any formal security certifications (SOC 2, HIPAA-aligned controls, etc.), they should be referenced here. If not, the language should be calibrated to what TCFRR can credibly commit to. Misrepresenting security practices is a meaningful regulatory risk.

Note: The breach-notification language should be reviewed against the patchwork of state breach-notification statutes (all 50 states have one, with materially different timing and scope). For a multi-state program, the safe approach is to commit to the strictest applicable timing rather than enumerating per-state.

How long we keep it.

We keep your data only as long as it's useful to you or required by law, and not longer.

What we retain

Card data: not retained. The medical and card information you enter is used only to generate your card in that moment, then discarded — it is never written to our database, logs, or backups. Contact data (name, email, phone): retained so we can send your annual reminder and connect you with your sponsoring advisor, until you ask us to delete it.

If you delete your data

When you request deletion via our deletion page, we delete the contact information we hold from our active systems immediately. Backup copies in our recent operational snapshots are purged within 30 days. After that 30-day window, your data is irrecoverable from our systems.

Drafting note: The dormant-account policy needs a specific timeframe (commonly 3–7 years) and should be coordinated with TCFRR's actual operational practices. State privacy laws are increasingly requiring affirmative deletion of dormant data; pinning down the policy now avoids retroactive compliance issues.

Records we keep after deletion

After you delete your data, we retain a minimal record of the deletion event itself — the date and a confirmation that deletion occurred — for legal-compliance purposes. This record contains no information about your card content; it exists solely to demonstrate, if ever asked, that we honored your deletion request. This retention is also required under several U.S. state privacy laws.

Your rights and choices.

You have a number of rights regarding your data, regardless of where you live. We provide these rights to all users globally, even if your local law doesn't require us to.

The right to access your data

You can request a copy of the contact information we hold (name, email, phone) by emailing community@thecenterforretirementreadiness.com, and we'll send it within 30 days. Your card and medical data isn't stored with us, so there's nothing of that kind to retrieve.

The right to correct your data

Because your card data isn't stored with us, to change a card you simply make a new one — free, anytime. If you'd like us to correct the contact information we hold, email us and we'll correct it.

The right to delete your data

You can delete your data at any time at thecenterforretirementreadiness.com/delete-my-data. The process is one click, requires no justification, and takes effect immediately.

The right to opt out of communications

The annual reminder email and the community-resources stream both have one-click unsubscribe links. Opting out of either does not delete your card data — the two are separate actions.

The right to data portability

If you'd like a machine-readable copy of the contact information we hold (e.g., as a JSON file), email us and we'll provide it within 30 days. We don't hold card or medical data to export.

The right to non-discrimination

We will never charge you a different price, deny you service, or provide a degraded experience because you exercised any of the rights above. The Lifeline Card™ program is free for everyone, regardless of which privacy rights they choose to exercise.

State-specific rights and disclosures:

[Attorney to draft state-specific subsections as required by:]

  • California (CCPA / CPRA): right to know, right to delete, right to correct, right to opt out of sale/sharing, right to limit use of sensitive personal information, right against discrimination, authorized agent provisions, "Do Not Sell or Share My Personal Information" link if applicable, sensitive personal information categories disclosure (medical data is in this category and must be specifically disclosed)
  • Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa (ICDPA), Tennessee (TIPA), Indiana (ICDPA), Florida (FDBR), and others: consumer rights summaries, controller/processor designations, sensitive data definitions, right to appeal denials of rights requests
  • Washington (My Health My Data Act): particularly relevant given the medical data this program processes; specific consent and disclosure requirements may apply
  • Nevada SB 220: opt-out of sale provisions for Nevada residents

Note: state privacy law is a moving target. Counsel should verify the current state of applicable laws at the time of publication and again at each annual review. The list above includes laws in effect or recently enacted as of the project team's knowledge cutoff; new laws may have been enacted since.

Minors' data — the cards for children.

The Lifeline Card™ program offers a Child variant. We take the additional responsibility this creates seriously.

Who can create a card for a child

Card forms for minors must be submitted by a parent or legal guardian. The signup form requires explicit affirmation of guardianship before a child's card is generated. We do not collect data directly from minors; the parent or guardian is the one entering data.

The child variant's design

Child cards are deliberately privacy-first by design:

COPPA compliance

The Children's Online Privacy Protection Act (COPPA) governs the collection of personal information from children under 13. Because TCFRR collects child data only from the parent or guardian (not from the child directly), our COPPA posture is structured around the parent's consent rather than direct collection from the child.

COPPA review required:

The Lifeline Card™ program collects information about children under 13 (medical conditions, name, date of birth, school) but collects it from the parent rather than from the child directly. This is a structurally different posture from a child-facing online service, but COPPA compliance still requires careful drafting:

  • Verify the parental-consent mechanism in the form (the guardianship checkbox) meets COPPA's "verifiable parental consent" standard for the data we collect — which depends on whether we collect any data from the child directly (we don't, in this design) and on whether the child is the user (they aren't — the parent is)
  • Confirm that the child's exterior-card data (first name + last initial only) does not constitute "personal information" under COPPA's expansive definition
  • Coordinate with the broader minor-data provisions of state privacy laws, several of which have heightened protections for users under 18 (not just under 13)
  • Review the deletion-on-request workflow specifically for minor data — some state laws give parents specific deletion rights distinct from the general right to delete

Note: This section is among the highest-stakes drafting on the page. COPPA enforcement actions carry significant per-violation penalties, and the FTC has publicly stated this is an enforcement priority. The structural choice we've made (parent enters child data, child does not interact with the service) is favorable but does not eliminate compliance risk on its own.

Cookies and analytics on our website.

Our use of cookies and similar tracking technologies is intentionally minimal.

Essential cookies

We use a small number of cookies that are strictly necessary for the website to function — for example, to maintain your session while you fill out the card form, to remember your progress if you leave and come back, and to enforce security. These cookies cannot be turned off without breaking the site.

Analytics

Drafting note — analytics disclosure depends on actual implementation:

If TCFRR uses any analytics tool (Google Analytics, Plausible, Fathom, custom server-side analytics, etc.), this section must disclose:

  • Which tool is used
  • What data the tool receives (page views, IP addresses, referrer, etc.)
  • Whether the tool's provider can use the data for their own purposes
  • Whether IP addresses are anonymized
  • How long analytics data is retained
  • Any opt-out mechanism (Do Not Track, browser settings, opt-out cookie)

If TCFRR uses no analytics at all (a defensible choice for a privacy-first community service), this section should explicitly state that no third-party analytics are used.

Advertising trackers

We do not use advertising trackers, retargeting pixels, or social-media tracking pixels (Meta Pixel, Twitter Pixel, etc.) on our website. If you visit our website, you will not subsequently be retargeted with TCFRR ads on other sites — because we don't run ads, and we don't share your visit data with anyone who does.

Your browser-level controls

You can control cookies through your browser's settings. Most browsers let you block all cookies, block third-party cookies, or delete cookies after each session. Blocking essential cookies will break some site functionality (specifically, the multi-step card form will lose your progress).

International users.

The Lifeline Card™ program is operated in the United States. If you access our service from outside the U.S., you are transferring your data to the U.S. for processing.

EU and UK users

If you access our services from the European Union or the United Kingdom, your data is governed by the General Data Protection Regulation (GDPR) and the UK GDPR. This policy is intended to comply with those regulations, including their requirements regarding lawful basis for processing, data subject rights, and international transfers.

GDPR / UK GDPR drafting required if EU/UK users are anticipated:

The Lifeline Card™ program may not actively market to EU/UK users, but the website is accessible from those jurisdictions and a small number of cardholders may be EU/UK residents. Counsel should determine whether GDPR/UK GDPR formally applies and, if so, draft the required additional disclosures:

  • Lawful basis for processing each category of data (likely "consent" for opt-in fields, "contract" for card generation, "legitimate interests" for security)
  • EU/UK data subject rights (these overlap with U.S. rights but have specific procedural requirements)
  • Data Protection Officer designation, if required
  • EU representative designation, if required (Article 27 GDPR)
  • International transfer mechanism (likely Standard Contractual Clauses or Data Privacy Framework certification)
  • Right to lodge a complaint with a supervisory authority

Note: A simpler approach is to geo-fence the service to U.S. users only and clearly state in this policy that the service is not intended for users outside the U.S. That posture has its own tradeoffs and should be evaluated against TCFRR's actual user expectations.

Other international users

If you access our services from a country other than the U.S., EU, or UK, your data may be subject to your local privacy law in addition to U.S. law. We comply with applicable cross-border data transfer requirements where they apply.

Changes to this policy.

If we make material changes to this privacy policy — changes that affect what we collect, how we use it, who we share it with, or your rights — we will:

For non-material changes (clarifications, typo fixes, structural improvements), we will update the "Last updated" date but will not necessarily send notification.

The current version of this policy is always the authoritative version. If you'd like to see what's changed since the last version, email us and we'll send you a redlined comparison.

How to contact us.

For any privacy question, request, or concern, you can reach us at:

We commit to responding to privacy inquiries within 30 days of receipt. For deletion requests submitted through our deletion page, the deletion happens immediately; the email confirmation is sent within minutes.

Drafting note: The 30-day response commitment matches the standard required by most U.S. state privacy laws and GDPR. If TCFRR can commit to a shorter response time, that would strengthen the trust-building posture. Some state laws also require disclosure of a physical mailing address for privacy contacts — if applicable, add that here.