Privacy Policy
Casper Youth Hub ("CYH", "we", "us") is operated by Void Outreach Inc., a Wyoming 501(c)(3) nonprofit. We run a free drop-in "third space" for youth ages 12 to 20 in Casper, Wyoming. This Privacy Policy explains what we collect as registration and household information, attendance, program, safety, and account records, optional profile information added after registration, workforce and employment records, and QuickBooks connection and export records. It explains how we use and protect that information and what choices members, families, and workers have.
1. Who this applies to
- Youth age 12: COPPA applies. We will not knowingly collect personal information from a youth under 13 without obtaining verifiable parental consent (VPC) through an FTC-approved method.
- Youth 13-17: We require informed parental or guardian consent. Beginning at age 13, a youth controls their own LGBTQ+ self-identity fields and those fields are not displayed to parents in the portal.
- Youth 18-20: The youth can self-consent. A parent/caregiver contact may still be listed as an emergency contact at the youth's option.
2. What we collect
Provided at registration
- Legal name, chosen name, and pronouns (optional)
- Date of birth, used to compute age, eligibility, and aging-out date
- Address, ZIP, and household composition (optional)
- Parent/caregiver contact information (email and phone)
- At least two emergency contacts and their relationship to the youth
- Answers to a categorical-eligibility question: "Does your family participate in SNAP, free / reduced lunch, Medicaid, TANF, WIC, or Section 8 / HUD?" We do not collect income amounts or dollar figures
- Typed signatures acknowledging each policy document, with policy version, IP address, user-agent, and timestamp captured for audit
Registration does not ask for a youth photo, medical alerts, allergies, or medications. A family may choose to add a photo or health and safety details to the youth's profile later.
Created by usage
These categories include attendance, program, safety, and account records; optional profile information added after registration; workforce and employment records; and QuickBooks connection and export records.
- Check-in and check-out times, via the kiosk, mobile app, or staff badge-in
- Coarse location events only from the mobile app, and only while the parent has enabled presence tracking and the youth has granted location permission. The only data sent is an
enterorexitevent relative to the Hub's geofence, plus a timestamp - Program enrollment, attendance, and session outcomes
- Incident, suspension, and restorative-discipline records
- Mandated-reporter log entries (access strictly limited)
- Anonymous tips, which are never linked to a youth profile
- Safeguarding review records created only from explicit wellbeing answers, youth requests to talk, structured staff-filed incident fields, or an authorized mandated-report creation event
- Account identifiers, roles, sign-in and security events, communication preferences, and audit records
- Workforce profiles, employment status, position and pay information, scheduled and worked shifts, clock events, time entries, pay periods, approvals, and export status
- Employment paperwork and supporting documents required for tax, payroll, and employment-eligibility administration. These documents may contain Social Security numbers, tax-withholding elections, citizenship or immigration attestations, document numbers, signatures, and copies of identity or work-authorization documents
- For a connected QuickBooks Online company: the company identifier and name, authorization scopes, encrypted access and refresh tokens, linked employee and compensation identifiers and labels, approved time exported, QuickBooks time-activity identifiers, and connection or export status
What we never collect
- Precise GPS breadcrumbs, movement history, or location outside the Hub geofence
- Browsing history, social-media contacts, or third-party cookies
- Biometric templates. We do not operate facial recognition or fingerprint matching
- Bank login credentials. We do not ask for or store the username, password, or multi-factor credentials used to sign in to a bank or QuickBooks
- Household income amounts or household bank-account information. Employment documents may contain the limited tax and employment information described above
3. How we use it
- Program operations: identify youth at check-in, flag safety alerts (custody, no-contact, allergy, medical) to staff, track attendance, deliver programs, and communicate with families. Allergy information supports emergency response only and does not mean staff are supervising food choices or kitchen use.
- Grant and public-benefit reporting: we report only aggregated counts (for example, "seventy-two percent of served youth are categorically eligible for poverty programs"). No individual record is exported to any funder.
- Service messages: account-related email and SMS, plus optional community newsletters that you opt into.
- Program improvement: anonymized surveys and youth-voice exercises.
- Safeguarding review: route explicit requests or safety signals to the small group of designated Safety Leads for a human decision.
- Workforce administration: schedule work, record and approve time, maintain worker records, and export approved time records to the QuickBooks Online company authorized by CYH.
The safeguarding system does not predict risk, profile behavior, scan private messages, analyze free text, or combine signals into one score. It does not automatically diagnose, discipline or suspend a youth, contact a parent or caregiver, block check-in or program access, file a mandated report, or change services.
Safeguarding review details are visible only to currently designated Safety Leads. Other administrators, staff, front-desk workers, volunteers, mentors, parents, youth, probation partners, and kiosks cannot see the queue, its counts, or whether a review exists. A Safety Lead still needs separate authorization to open a mandated report. Guardians do not automatically receive wellbeing, self-harm, or talk-request content because disclosure may itself be unsafe.
We do not sell personal information, ever. We do not use it for targeted advertising. We do not share it with data brokers or marketing companies.
4. How long we keep it
| Data | Retention |
|---|---|
| Youth profile | Active + three years after aging-out or deletion request |
| Parental consent evidence | Seven years (legal / audit requirement) |
| Youth employment forms and supporting documents | For the applicable employment, tax, audit, and legal retention period; records subject to a hold are kept until the hold is released |
| Work schedules, time records, pay-period approvals, and QuickBooks export references | For the applicable payroll, audit, grant, and legal retention period |
| QuickBooks OAuth tokens and active connection record | While the company is connected; removed from CYH storage when an authorized administrator disconnects it |
| Photos | Until youth ages out or consent is revoked |
| Check-in and geofence events | Thirteen months rolling |
| Incident and suspension records | Seven years |
| Mandated-reporter log | Seven years |
| Anonymous tips (not actioned) | Two years |
| Audit logs | Seven years |
| Safeguarding signals and reviews | Active triage window, then retained with the underlying youth or safety record and audit evidence |
Core retention includes parental consent evidence for seven years, check-in and geofence events for thirteen months, and incident and mandated-reporter records for seven years. Legal, safety, employment, grant, audit, and litigation holds may require longer retention.
Parents and youth 18+ can request earlier deletion; see section 8.
The active triage window controls whether a safeguarding signal appears as current work. Expiration does not erase legal, safety, or audit evidence. Corrections can be requested through the Privacy Officer contact in section 13.
5. How we protect it
- Encryption at rest: DynamoDB tables and S3 buckets use AWS KMS customer-managed keys. Personally identifying fields (contact information, medical notes, custody narratives, mandated-report bodies, tips) are additionally field-level encrypted with per-record encryption contexts before they ever touch the database.
- Encryption in transit: TLS 1.2 or later on every connection.
- Access control: Role-based via AWS Cognito groups (admin, staff, volunteer, parent, youth). Staff accounts require multi-factor authentication. Mandated reports and anonymous tips are restricted to the Executive Director and a designated Safety Lead under a two-person review rule.
- Audit logging: Every read of sensitive fields, every staff override, and every break-glass action is written to an append-only audit trail.
- Least privilege: Each backend function is granted the minimum AWS permissions it needs, table by table and key by key.
6. The mobile app and location
The mobile app only uses location when your family has enabled presence tracking and a youth has granted the permission. It never records a path or a location history. The only data sent to us is an enter or exit event at the Hub geofence, plus a timestamp.
Parents can turn presence tracking off at any time from the parent portal or the mobile app's settings screen. When tracking is off, youth still check in and out manually, and the app does not request or store location.
Parents see in the mobile app:
- Whether each linked youth is currently at the Hub or away
- Arrival and departure timestamps for the current day
Parents do not see the youth's current GPS coordinates or path. Uninstalling the app fully stops any future location collection.
7. COPPA and verifiable parental consent
For youth age 12, online consent uses a refundable $0.50 card verification through Stripe. A caregiver may instead use staff-attended in-person verification at the Hub.
For youth ages 13-17, staff callback is the default for ages 13-17. A caregiver may instead choose refundable $0.50 card verification or staff-attended in-person verification. Youth ages 18-20 self-consent. The signed document bundle is captured with the method, timestamp, signer, IP address, user-agent, policy-version hash, and applicable verification references.
8. Your rights and choices
- Access: parents can see their household's profile data at any time in the parent portal or mobile app. Youth 18+ can see their own.
- Correction: you can correct any profile field from the portal.
- Granular media release: each release channel (internal use, newsletter, website, social media, external press) is consented to separately on each youth's profile. Changes take effect immediately and apply going forward.
- Presence tracking: parents can toggle location-based check-ins on or off at any time.
- Withdraw consent: revoke parental consent from the portal; the youth is moved to "pending consent" within one business day.
- Deletion: submit a deletion request by following the steps on our account deletion page or by emailing privacy@casperyouthhub.org. Email confirmation is required before deletion. We complete confirmed deletion requests within 10 business days, except for records we must retain for legal, safety, audit, or grant-compliance reasons, which we limit to the minimum required.
9. Third-party processors
We use service providers to operate the Service. Their handling of information is also governed by their own terms and privacy notices.
- Amazon Web Services (US regions): DynamoDB, S3, Lambda, Cognito, SES, SNS, CloudFront, KMS. Data stays in the continental United States.
- Stripe, Inc.: only for the COPPA micro-charge. Stripe never sees a youth's profile data.
- Expo / EAS: mobile app build and release distribution, over-the-air updates, and push-notification delivery. Push delivery sends Expo a device token and the notification content needed for delivery.
- Intuit QuickBooks Online: workforce employee records and approved time records are sent only when authorized staff connect the CYH company and direct a sync or export.
QuickBooks Online connection
CYH requests the QuickBooks accounting authorization needed to identify the authorized company, match or maintain worker employee records, and create time-activity records from time that CYH staff have approved. If Intuit grants CYH access to compensation metadata, authorized staff may use that limited metadata to map a worker's time correctly. The Service does not initiate payroll, calculate payroll taxes, move money, access bank accounts, or collect bank or Intuit login credentials.
QuickBooks OAuth access and refresh tokens are stored encrypted and are used only to maintain the authorized CYH company connection and perform these staff-directed actions. CYH stores the company name and identifier, scopes, worker mapping identifiers, export status, and QuickBooks record identifiers needed to prevent duplicate exports and audit the result. We do not use QuickBooks data for advertising, profiling, or unrelated Hub programs.
An authorized CYH administrator can disconnect QuickBooks in the staff admin. Disconnecting deletes the stored connection and encrypted tokens from CYH and asks Intuit to revoke the refresh token. A QuickBooks company administrator may also revoke access through Intuit. For help disconnecting or questions about retained export or audit records, contact privacy@casperyouthhub.org.
10. Wyoming Student Data Privacy Pledge
We voluntarily adopt the Wyoming Student Data Privacy Pledge:
- We will not sell student personal information.
- We will not use or disclose student information for targeted advertising.
- We will not build personal profiles beyond what is needed to run the Hub's programs.
- We will follow the WY HB 08 notification rules if we ever learn of a breach of student personal information.
11. Children's data and school records
The Hub is not a school and does not create FERPA-covered education records. We do not pull grades, transcripts, or disciplinary records from schools. If a youth's school shares information with the Hub it is only with the family's direct written permission on a per-request basis.
12. Changes to this policy
We post changes on this page with a new effective date. When a change materially affects account holders, we may also provide notice through available email or in-app channels and will say clearly if acknowledgement is required. Version 2026.5 consolidates the registration, consent-method, workforce, QuickBooks, processor, and retention disclosures. For existing families this is notice-only: it requires no signature or reacceptance and does not block check-in, programs, or requests for support.
13. Contact
Privacy Officer, Casper Youth Hub
Email: privacy@casperyouthhub.org
Mail: Void Outreach Inc., 201 E 2nd St, Casper, WY 82601
You may also file a complaint with the Federal Trade Commission (ftc.gov) or the Wyoming Attorney General's Consumer Protection Unit.