Legal
Policies that protect our members and partners
Comprehensive legal documentation covering Privacy, Terms, Cookies, Acceptable Use, Security, and Copyright policies.
Latest updates
Updated December 2025 with comprehensive policy content including Cookie Policy, Acceptable Use Policy, and DMCA procedures.
Privacy Policy
Last updated 2025-12-15
CariClub collects only what we need to connect executives with nonprofit board opportunities. We never sell your personal information. You control your data with access, correction, deletion, and export rights.
- We do NOT sell your personal data
- GDPR & CCPA/CPRA compliant
- 90-day data recovery period after deletion
- Transparent sub-processor disclosures
Information We Collect
How We Use Your Data
Data Sharing
Your Rights
Data Retention
We collect information you provide directly: account details (name, email, password), professional information (employment history, education, skills, board experience), profile content (photo, biography), and payment information processed securely through Stripe. We also collect information automatically: device identifiers, IP addresses, browser type, usage data (pages viewed, features used, time spent), and authentication logs for security.
Terms of Service
Last updated 2025-12-15
The agreement governing your use of CariClub. By creating an account, you agree to these terms, including our arbitration agreement and class action waiver.
- 30-day arbitration opt-out window
- Individual arbitration (no class actions)
- Small claims court exception preserved
- Clear IP ownership and licensing
Eligibility & Accounts
Platform Services
User Responsibilities
Intellectual Property
Dispute Resolution
Limitation of Liability
You must be at least 18 years old and able to form binding contracts. You must provide accurate information and keep it updated. You are responsible for maintaining account security and all activities under your account. One person per account; accounts are non-transferable. We may suspend or terminate accounts for violations of these terms.
Cookie Policy
Last updated 2025-12-15
CariClub takes a privacy-first approach. We currently use only essential cookies for authentication and security. Analytics and marketing cookies are NOT active.
- Analytics cookies NOT currently active
- Marketing cookies NOT used
- Global Privacy Control (GPC) honored
- 30-day notice before activating new tracking
Essential Cookies (Active)
Functional Cookies (Active)
Analytics & Marketing (NOT Active)
Your Cookie Choices
We use strictly necessary cookies that cannot be disabled:
- cc_session (maintains your authenticated session, expires on browser close)
- cc_auth_token (stores encrypted authentication token, 7 days)
- cc_csrf_token (protects against cross-site request forgery, session)
- cc_device_id (identifies your device for security monitoring, 1 year)
- cc_cookie_consent (records your consent choices, 12 months)
- AWS Cognito authentication tokens.
Acceptable Use Policy
Last updated 2025-12-15
Standards for professional conduct on CariClub. As a platform connecting executives with nonprofit board opportunities, we maintain high standards appropriate for senior professionals.
- Credential accuracy is mandatory
- Three-strike enforcement framework
- Professional conduct expected
- Appeals process available
Credential Accuracy
Professional Conduct
Prohibited Activities
Enforcement
Board service carries fiduciary responsibilities. Nonprofit organizations rely on your credentials when making board appointment decisions. You MUST accurately state: employment history, titles, and dates; educational degrees and institutions; past and current board experience; and skills and expertise. Misrepresentation includes: claiming unearned degrees; fabricating board experience; significantly exaggerating responsibilities; or using someone else's credentials. Credential fraud results in immediate account termination.
Security Practices
Last updated 2025-12-15
Enterprise-grade security measures to protect your data. We use encryption, access controls, and continuous monitoring. SOC 2 Type II certification is in progress.
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest
- SOC 2 Type II in progress
- 72-hour breach notification
Infrastructure
Data Protection
Access Controls
Multi-Tenant Security
Incident Response
CariClub is hosted on Amazon Web Services (AWS), which maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications. We use: Amazon RDS (PostgreSQL with automated backups); Amazon S3 (encrypted object storage); Amazon ECS (container orchestration with security isolation); AWS Cognito (user authentication); AWS WAF (web application firewall protecting against OWASP Top 10); and AWS Shield (DDoS protection). All resources are deployed in VPCs with private subnets.
DMCA & Copyright
Last updated 2025-12-15
CariClub respects intellectual property rights and complies with the Digital Millennium Copyright Act. Submit takedown notices to legal@cariclub.com.
- DMCA Safe Harbor compliant
- Designated agent registered
- Counter-notification process
- Repeat infringer policy
Filing a Takedown Notice
Counter-Notification
Repeat Infringer Policy
Misrepresentation Warning
If content on CariClub infringes your copyright, submit a written notification to legal@cariclub.com including: your physical or electronic signature; identification of the copyrighted work; specific URL(s) of infringing content; your contact information (address, phone, email); statement of good faith belief that use is not authorized; and statement under penalty of perjury that you are the copyright owner or authorized agent. We acknowledge receipt within 2 business days and take action within 5 business days.