Client Resource Project

Privacy Policy

We believe helpful resources should not come at the expense of your privacy. This policy explains what we collect, why we use it, when it may be disclosed, and the choices available to you.

Effective and last updated: August 28, 2026

We do not sell data. We do not sell or rent personal information to anyone.
No targeted advertising. We do not share personal information for cross-context behavioral advertising.
We collect only what is useful. This generally means information you submit and basic technical data needed to operate the site.
You have choices. You may unsubscribe, manage cookies, or submit a privacy request.

1. Scope and who we are

This Privacy Policy applies to Client Resource Project, including clientresourceproject.org and the articles, directories, downloads, forms, newsletters, and other services that link to this policy (collectively, the “Services”). In this policy, “Client Resource Project,” “we,” “us,” and “our” refer to Client Resource Project, LLC, the operator of the Services.

For privacy laws that use the terms “controller,” “business,” “responsible party,” or similar terms, Client Resource Project, LLC is the entity responsible for deciding why and how personal information is processed unless another notice says otherwise.

This policy does not apply to third-party websites, services, or organizations linked from our Services. Their own privacy policies govern their practices.

2. Information we collect

“Personal information” means information that identifies, relates to, describes, can reasonably be linked with, or could reasonably be used to identify an individual. It does not include information that is lawfully public, aggregated, or de-identified where applicable law excludes it.

Category Examples How collected
Contact and communication information Name, email address, organization, role, and the contents of messages, questions, feedback, or support requests. Directly from you when you email us or use a form.
Member account information Username, email address, password hash, account status, verification status, account dates, security-related login status, and information used to link an account to a third-party sign-in provider. We do not store your plaintext password or your Google or Facebook password. Directly from you when you create or use a CRP account, and from a sign-in provider when you choose a third-party login option.
Third-party sign-in information When you choose an available sign-in option such as Google or Facebook, we may receive a provider-specific user identifier, email address, name or basic profile information, and confirmation or metadata needed to authenticate or link the account. The exact information depends on the provider and permissions you approve. From Google, Meta/Facebook, or another sign-in provider you intentionally choose.
Member visit history For signed-in members, the CRP page address, page title, and date and time of the visit. This member-history record does not store an IP address, device fingerprint, precise location, or user agent. Automatically while you are signed into your CRP account so the history can be shown back to you in My CRP.
Newsletter and preference information Email address, subscription status, consent record, communication preferences, and basic delivery or engagement information such as delivery failures or unsubscribes. Directly from you and from our email service provider.
Resource, directory, or content submissions Information you submit about yourself, an organization, provider, program, resource, correction, or suggested content. This may include professional contact details and public listing information. Directly from you or an authorized representative.
Transaction information If paid products, donations, or subscriptions are offered, purchase details, amount, date, transaction identifier, and billing contact details. Complete payment-card numbers are handled by the payment provider and are not intended to be stored by us. From you and the payment provider when a transaction is made.
Device, network, and anti-abuse information IP address, browser and device type, operating system, language, approximate location derived from IP, referring page, requested page, date and time of access, form timing information, security events, and hashed network identifiers used for rate limiting and spam prevention. Automatically through hosting, security, server logs, contact-form protections, and anti-bot services.
Usage and cookie information Pages viewed, links selected, site interactions, session information, preferences, and cookie or similar-technology identifiers. Automatically when permitted through cookies, local storage, logs, or analytics tools.
Privacy-request information Your request, region, correspondence, verification details, response, and appeal, if applicable. Directly from you or your authorized agent.

We may also receive information from public sources, resource providers, professional organizations, referral partners, and service providers. If you provide personal information about another person, you represent that you are authorized to do so and that you have given any required notice.

We do not use the Services to collect precise geolocation, biometric identifiers, government identification numbers, financial-account credentials, or health records from ordinary visitors. If a feature later needs a new category of personal information, we will provide an appropriate notice before or at collection.

3. How we use information

We use personal information only for reasonably necessary and proportionate purposes, including to:

  • create, authenticate, verify, secure, and administer CRP member accounts, including linking an account to a third-party sign-in provider you choose;
  • show signed-in members their own CRP visit history and allow them to clear that history;
  • provide, maintain, personalize, and improve the Services;
  • publish, review, verify, correct, or update requested resource and directory information;
  • send newsletters or other communications you requested and manage subscription preferences;
  • respond to questions, feedback, support requests, and privacy requests;
  • process transactions and keep appropriate financial and business records;
  • understand site performance and how visitors use our resources;
  • detect, investigate, and prevent spam, automated form submissions, fraud, abuse, security incidents, or other harmful activity, including through form timing checks, honeypots, rate limiting, and human-verification services;
  • debug, audit, protect, and administer our systems;
  • enforce our terms, establish or defend legal claims, and comply with legal obligations; and
  • create aggregated or de-identified information that does not reasonably identify an individual.

We do not use personal information for materially different, unrelated, or incompatible purposes without providing notice and obtaining consent when required.

5. When we disclose information

We may disclose personal information only as described below. A disclosure is not necessarily a “sale” or “sharing” under privacy law.

  • Service providers and processors: hosting, security, database, email delivery, analytics, form, anti-bot and human-verification, authentication, payment, storage, backup, and technical-support providers that process information for us under appropriate restrictions.
  • Third-party sign-in providers: if you choose an available Google or Facebook login option, information is exchanged with that provider as necessary to authenticate you and connect the provider account to your CRP account. The provider also processes information under its own privacy terms.
  • At your direction or with your consent: when you ask us to publish a listing, send information to another organization, or otherwise authorize disclosure.
  • Public submissions: information intentionally submitted for publication in a public resource or provider directory may be visible to anyone and indexed by search engines.
  • Legal and safety reasons: when we reasonably believe disclosure is required by law, subpoena, court order, or valid government request, or is necessary to protect rights, safety, security, and the integrity of the Services.
  • Professional advisers: lawyers, accountants, insurers, auditors, and similar advisers subject to confidentiality obligations.
  • Organizational change: in connection with a merger, financing, reorganization, acquisition, sale of assets, or similar transaction, subject to legally required notice and protections.

We require service providers to use personal information only for the contracted service or another legally permitted purpose and to protect it appropriately.

6. No sale, rental, or targeted advertising

Client Resource Project does not sell or rent personal information. We also do not share personal information for cross-context behavioral advertising or use it to profile visitors in furtherance of decisions that produce legal or similarly significant effects.

Because we do not engage in these activities, there is no need to submit a request to opt out of them. If our practices change, we will update this policy, provide any required notice, and offer legally required opt-out controls before beginning the new practice.

We do not discriminate against anyone for exercising a privacy right. We do not offer financial incentives for personal information unless a separate notice clearly explains the material terms and obtains any required consent.

7. Cookies, local storage, authentication, and similar technologies

CRP uses cookies and similar browser technologies for security, account sessions, privacy choices, optional preferences, and—only with your permission—analytics. We separate these uses into categories so optional technologies can be rejected without disabling the basic security and operation of the site.

Strictly necessary and security technologies

Necessary technologies cannot be switched off through CRP’s cookie controls because they are required to provide a feature you request, maintain a secure session, remember your privacy choice, prevent abuse, or protect a form. Depending on the feature you use, these can include:

  • crp_cookie_consent — records this browser’s cookie choices for about 30 days;
  • PHPSESSID or another server-session cookie — maintains a secure session, including sign-in, CSRF protection, OAuth state, and form security; it generally lasts for the browser session or server-defined session period;
  • crp_newsletter_token and crp_newsletter_prompt, when present — support requested newsletter preference and prompt behavior;
  • Cloudflare Turnstile security signals and, where Cloudflare’s configuration requires it, Cloudflare security cookies such as cf_clearance; and
  • server-side anti-abuse records and keyed hashes used for throttling. These are not browser cookies but are part of the same security controls.

Google and Facebook may use cookies on their own domains when you intentionally choose their sign-in option. Those provider cookies are controlled by Google or Meta rather than CRP’s browser cookie switch. Choosing Google or Facebook sign-in initiates that provider interaction; using CRP’s ordinary username/password login does not require you to use either provider.

Preferences and functionality

Optional preference technologies remember convenience choices that are not required for basic site operation. For example, crp_tools_audience can remember whether Tools is organized for a student, parent/caregiver, or professional. If you turn off Preferences & functionality, CRP removes this browser preference where possible and stops writing it until you opt in again.

Analytics

CRP uses Google Analytics only when Analytics is enabled in this browser’s cookie settings. Analytics can use cookies such as _ga and _ga_* to distinguish visits and measure site use; configurations may also use cookies such as _gid or _gat. CRP configures advertising storage, ad user data, and ad personalization as denied and does not use Google Analytics for cross-site advertising.

Information collected through Google Analytics may be processed by Google under its own terms. Review how Google uses information from sites that use its services and Google’s Privacy Policy.

Advertising and marketing

CRP does not currently enable advertising, remarketing, Meta Pixel, or cross-site marketing cookies. The marketing category is therefore kept off. If that changes, CRP will update this policy and the consent interface before enabling those technologies where consent or another legal basis is required.

Your cookie choices

You can accept all optional cookies, reject all optional cookies, or choose Analytics and Preferences & functionality separately. Use the gear/settings control in the site header, visit Cookie Settings, or, when signed in, use My CRP → Manage Cookies. Necessary security and session technologies remain active.

Browser consent is specific to the browser or device where you make the choice. If you are signed into a CRP account, CRP may also save your optional preference choices to your account so they can be displayed in My CRP; a saved account preference does not silently activate optional cookies on a different browser before that browser records a consent choice.

Turning off Analytics causes CRP to disable Google Analytics for future page activity in that browser and attempt to remove CRP-domain Google Analytics cookies that are accessible to the site. Turning off Preferences removes known optional CRP preference cookies where possible. Browser restrictions, HttpOnly cookies, provider-domain cookies, or previously transmitted information may prevent CRP from deleting every item from the browser itself.

Browser privacy signals

Browser “Do Not Track” signals are not interpreted consistently across the web. CRP does not sell personal information or use it for cross-context behavioral advertising. Where applicable law requires recognition of a legally valid opt-out preference signal such as Global Privacy Control, CRP will treat that signal as an applicable request for the browser or device that sends it.

8. How long we keep information

We keep personal information only as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, maintain accurate records, resolve disputes, enforce agreements, protect security, and comply with legal obligations.

  • Member account information is generally kept while the account remains active and afterward only as reasonably necessary for security, legal, dispute, or account-recovery purposes.
  • Member visit history is kept to provide the My CRP history feature. A signed-in member may clear their recorded page-view history from My CRP. Login and logout events may remain separately for limited security and account-operation purposes.
  • Password-reset and email-verification tokens are time-limited, stored as one-way hashes, and invalidated after use or replacement.
  • Short-lived login-throttling records use keyed hashes rather than raw IP addresses or raw login identifiers and are automatically cleaned up after a short period.
  • Third-party sign-in links may be retained while your CRP account remains active so you can continue signing in with that provider. Provider identifiers may also be retained as reasonably necessary for account security, fraud prevention, or dispute handling.
  • Contact-form anti-abuse records use keyed hashes instead of raw IP addresses in the rate-limit table and are automatically cleaned up after a short period.
  • Newsletter information is generally kept while you are subscribed. After an unsubscribe, we may retain a minimal suppression record so we honor your choice.
  • Messages and support records are generally kept while the matter is active and afterward only as needed for legitimate operational, legal, or security purposes.
  • Public resource and directory information is kept while the listing remains active and as needed to document corrections, permissions, or removal requests.
  • Transaction and tax records are retained for periods required by applicable financial, tax, and accounting laws.
  • Technical and security logs are kept for a limited period appropriate to troubleshooting, security, abuse prevention, and legal requirements.

Retention may be longer when information is subject to a legal hold, dispute, investigation, backup cycle, or a valid legal requirement. When information is no longer needed, we delete, de-identify, or securely isolate it.

9. Data security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These may include access controls, least-privilege practices, encrypted transmission, software updates, backups, logging, vendor review, and incident-response procedures appropriate to the nature of the information.

Public forms may also use layered abuse-prevention controls, including CSRF protection, hidden bot-trap fields, timing checks, server-side validation, rate limiting, and Cloudflare Turnstile or similar human-verification technology. These controls are designed to reduce spam and automated abuse; they do not guarantee that every malicious submission will be blocked.

No system or transmission is completely secure. You are responsible for using appropriate care when sending information online. If we learn of a breach affecting personal information, we will investigate and provide notice to affected individuals and authorities when required by applicable law.

10. Children, health information, and sensitive data

Children

The Services provide general resources and may include information useful to parents, caregivers, professionals, and young people, but they are not intended to collect personal information directly from children under 13 in the United States or under the minimum digital-consent age that applies in another country. Children should not submit names, email addresses, messages, directory entries, or other personal information without involvement and legally valid authorization from a parent or guardian.

If we learn that we collected a child’s personal information in a manner that requires parental consent and did not receive it, we will take reasonable steps to delete the information. A parent or guardian may contact us using the information below.

No clinical records or client-identifying information

Do not submit therapy notes, case records, diagnoses, treatment information, Social Security numbers, insurance details, or information that identifies a client or service recipient. Client Resource Project is a general resource platform and is not a clinical record system, crisis service, or secure channel for protected health information.

If sensitive information is sent to us without a request, we will use it only as reasonably necessary to respond, protect safety, comply with law, or delete it. We do not use sensitive personal information to infer characteristics about visitors.

11. International data transfers

Client Resource Project is based in the United States. If you access the Services from another country, your information may be processed in the United States or another country where our service providers operate. Those countries may have privacy laws different from the laws where you live.

When required, we use recognized transfer safeguards, such as adequacy decisions, contractual protections, data-processing agreements, or approved standard contractual clauses, and supplementary measures appropriate to the transfer. You may contact us for information about safeguards relevant to your information.

12. Your privacy choices and rights

Depending on where you live and whether a particular law applies to Client Resource Project, you may have the right to:

  • know whether we process your personal information and obtain access to it;
  • receive information about categories, sources, purposes, retention, and recipients;
  • correct inaccurate or incomplete personal information;
  • request deletion or erasure;
  • receive a portable copy of information you provided;
  • restrict or object to certain processing;
  • withdraw consent at any time where processing relies on consent;
  • opt out of sale, targeted advertising, certain sharing, or certain profiling;
  • limit certain uses of sensitive personal information;
  • appeal a denial of a request where applicable;
  • complain to a privacy or data-protection authority; and
  • receive equal service and not be retaliated against for exercising a right.

These rights are not absolute. Applicable law may allow or require us to deny or limit a request, such as when we cannot verify identity, must retain information by law, need it to protect rights or safety, or an exception applies.

Member account controls

If you have a CRP member account, you can view your recorded CRP page history in My CRP and clear that page-view history directly from your account. Clearing history cannot be undone. If third-party sign-in is enabled for your account, you may also contact us about unlinking a Google or Facebook identity where technically and legally available. Unlinking a provider does not automatically delete information held by that provider.

How to submit a request

Email privacy@clientresourceproject.org with the subject line “Privacy Request.” Describe the right you want to exercise and the Services involved. To protect you, we may request information reasonably necessary to verify identity and authority. Do not send a government ID unless we specifically request it and provide a secure method.

An authorized agent may submit a request where permitted, but we may require proof of authorization and, where allowed, direct verification from the individual. We will respond within the period required by applicable law. If we deny an appealable request, our response will explain how to appeal.

You may unsubscribe from marketing emails at any time by using the unsubscribe link in the message. We may still send non-promotional communications that are necessary to complete a request or transaction.

13. Country and regional privacy notices

This section summarizes additional rights that may apply. It does not limit any right granted by law. A law may not apply because of its territorial scope, organizational or revenue thresholds, the nature of the processing, an exemption, or another legal rule.

United States

Residents of states with comprehensive consumer privacy laws—including, where applicable, California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia—may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal information, and to opt out of sale, targeted advertising, or certain profiling. Some states provide rights concerning sensitive data, authorized agents, appeals, or lists of third parties. We do not sell personal information, share it for cross-context behavioral advertising, or use it for legally significant profiling.

California notice: The categories described in Section 2 are the categories we collect for the business and commercial purposes described in Section 3 and retain under Section 8. We disclose relevant categories to the recipients in Section 5. We do not knowingly sell or share, as those terms are defined by California law, personal information of consumers under 16. California residents may also request information about qualifying disclosures for direct-marketing purposes under California’s “Shine the Light” law; we do not disclose personal information to third parties for their own direct marketing.

Nevada: Nevada residents may submit a verified request concerning a future sale of covered information. We do not currently sell covered information as defined by Nevada law.

European Economic Area, United Kingdom, and Switzerland

Where the GDPR, U.K. GDPR, Swiss Federal Act on Data Protection, or related law applies, you may have rights of access, rectification, erasure, restriction, objection, and portability, the right to withdraw consent, and the right not to be subject to certain solely automated decisions. You may lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred. We do not conduct solely automated decision-making that produces legal or similarly significant effects.

Right to object: Where processing is based on legitimate interests, you may object based on your particular situation. You may object to direct marketing at any time.

Canada

Where Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) or applicable provincial law applies—including private-sector laws in Alberta, British Columbia, or Québec—you may request access to and correction of personal information, withdraw consent subject to legal or contractual limits, and challenge our compliance. We follow principles of accountability, identified purposes, appropriate consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and complaint handling where applicable.

Brazil

Where Brazil’s Lei Geral de Proteção de Dados (LGPD) applies, you may request confirmation of processing, access, correction, anonymization, blocking or deletion in qualifying circumstances, portability when regulated, information about recipients and consent choices, withdrawal of consent, and review of qualifying automated decisions. You may also petition Brazil’s National Data Protection Authority (ANPD).

Australia and New Zealand

Where Australia’s Privacy Act 1988 and Australian Privacy Principles apply, you may request access to and correction of personal information and complain about our handling practices. Where New Zealand’s Privacy Act 2020 applies, you may request access and correction and complain to the Office of the Privacy Commissioner. Cross-border disclosures will be handled with safeguards required by applicable law.

South Africa

Where the Protection of Personal Information Act (POPIA) applies, you may request access, correction or deletion, object to certain processing, withdraw consent where applicable, and complain to South Africa’s Information Regulator. We do not use personal information for unsolicited electronic direct marketing without a lawful basis.

Japan, Singapore, and South Korea

Where Japan’s Act on the Protection of Personal Information (APPI) applies, you may have rights to disclosure, correction, suspension of use, deletion, and suspension of third-party provision. Where Singapore’s Personal Data Protection Act (PDPA) applies, you may request access or correction and withdraw consent subject to applicable limits. Where South Korea’s Personal Information Protection Act (PIPA) applies, you may have rights to access, correct, delete, or suspend processing and to receive information about qualifying overseas transfers.

India

Where India’s Digital Personal Data Protection Act and implementing rules are in force and apply, you may have rights to obtain information about processing, correct or erase data, use a grievance process, and nominate another individual to exercise rights in specified circumstances.

Other countries and territories

Privacy laws in other jurisdictions—including China’s Personal Information Protection Law and privacy laws in additional countries and territories—may provide comparable or additional rights. We will honor applicable rights and legally required safeguards even when they are not individually listed in this policy. Contact us to exercise a right or ask how local requirements apply.

14. Changes to this policy

We may update this Privacy Policy to reflect changes in the Services, technology, law, or our practices. We will post the revised policy here and update the effective date. If a change materially affects how we use personal information, we will provide additional notice or obtain consent when required.

15. Contact us

Client Resource Project — Privacy Contact

Email: privacy@clientresourceproject.org

Location: United States

If you have a disability and need this policy or a privacy-request method in another format, contact us and we will make reasonable efforts to assist.