Skip to main content
    Privacy

    Privacy Policy

    How Community Acquired Finance handles guided-tool answers, customer accounts, purchases, analytics, advertising technology, cookies, and privacy choices.

    Effective date: July 31, 2026

    Overview

    Community Acquired Finance is an independent educational website about personal finance, workplace benefits, healthcare costs, insurance, Medicare, Medicaid, and related money topics. We aim to collect as little personal information as reasonably possible while providing articles, calculators, guided decision tools, and source-backed explanations.

    The site uses hosting and security logs, Vercel performance products, Google Analytics subject to the privacy choice described below, a limited first-party evidence system subject to the same analytics choice, and conditional Google advertising technology on some ordinary pages. Sensitive guided tools and paid workspaces are intentionally excluded from the site's managed AdSense loading system.

    Who operates this site

    Community Acquired Finance is not a hospital, insurer, government agency, financial advisory firm, law firm, tax firm, brokerage, benefits administrator, or medical practice.

    Privacy and correction requests may be sent through the Contact page. Do not send protected health information, account credentials, government identification numbers, insurance member IDs, medical records, tax records, or other sensitive information through ordinary email.

    Information you provide directly

    If you voluntarily use a contact, newsletter, customer-access, or purchase feature, the site may receive the information you submit, such as an email address, name, message, subscription preference, or account-access request.

    Do not submit Social Security numbers, payment card numbers, bank or brokerage account numbers, passwords, claim documents, medical records, diagnosis details, employer-confidential documents, beneficiary details, or other sensitive personal information.

    Guided tools and calculator answers

    The Medicare and Medicaid Eligibility Check, Healthcare Worker Benefits Blueprint, Employer Benefits Action Plan, Healthcare Worker Total Compensation Comparison, and similar public tools are designed to keep answer values in local browser state unless a feature clearly says otherwise. When the account-based Healthcare Worker Benefits Decision System is activated, its workspace inputs will be stored in the user's access-controlled database record so progress can continue across supported devices.

    The public Private Student Loan Payoff Calculator keeps balances, APRs, payments, terms, fees, loan-type selections, and calculated outcomes in temporary page state. Its My Plan action stores only a fixed student-loan review identifier, not the entered assumptions or result.

    Copying, printing, downloading, sharing, or entering the same information into another website is controlled by the user and may create records outside this site. General page-view, device, performance, hosting, security, or consent-state information may still be processed as described below, but the site does not intentionally attach answer-level fields to analytics events.

    Premium purchases, customer accounts, and entitlements

    Paid commerce is not currently active. If later authorized, checkout will be processed by Stripe Checkout. Community Acquired Finance will not intentionally receive or store full payment-card numbers. Stripe may provide customer, checkout-session, payment-intent, payment-status, test-mode, refund, and other transaction information needed to verify a purchase and control access.

    The intended account provider is Supabase Auth using email magic links. Supabase manages authentication sessions; Community Acquired Finance server functions validate the session token before checking product entitlement. Reaching a checkout return page, changing browser storage, or setting a client-side flag does not grant access.

    The intended account database stores the profile, product entitlement, workspace title, completion state, validated workspace answers, assumptions, and final user-selected decision. It is not designed to store uploads, payment-card data, bank information, insurance member identifiers, medical records, diagnoses, claim documents, paystubs, full financial statements, protected health information, or confidential employer documents.

    A development-only local demo may store non-production demo state in that browser when an explicit local flag is enabled. The production build rejects that flag. Browser printing creates a separate local output controlled by the user.

    Data deletion and reset

    The production workspace foundation supports deletion of a user-owned workspace. Account deletion and any required transaction-record retention procedure must be finalized and tested before paid access opens. Deleting a workspace does not automatically delete a transaction record or revoke product access because certain records may be needed to process refunds, prevent fraud, and meet accounting or legal obligations.

    Requests concerning account email, purchase records, access, correction, or legally applicable deletion rights may be sent through the Contact page. Identity verification may be required. Some transaction records may need to be retained for tax, accounting, fraud-prevention, dispute, or legal reasons.

    Information collected automatically

    Hosting, security, analytics, email, account-storage, payment, and performance providers may automatically process technical information such as IP address, browser and device type, operating system, pages visited, referring page, approximate location derived from IP address, timestamps, response performance, email-delivery status, checkout events, and diagnostic or security logs.

    Vercel hosts the site and provides Analytics and Speed Insights. Google Analytics code is loaded only after a visitor chooses Allow analytics. Advertising personalization signals remain disabled through this site's Google Analytics configuration.

    After a visitor chooses Allow analytics, a limited first-party evidence system may also store a random event identifier, a random browser-session identifier, one fixed event name, one fixed site surface, an approved destination identifier, an experiment version, and a server timestamp in Supabase. The browser-session identifier is stored in session storage and is not linked by this system to an account, name, email address, form answer, calculator input, health detail, financial amount, URL, query string, referrer, IP address, or device fingerprint. This evidence is used to count whether a bounded site pathway was viewed and whether a visitor opened one of its predefined next steps.

    Privacy choices and Google Consent Mode

    The site provides a privacy-choice panel with two options: Necessary only and Allow analytics. The choice is stored in the browser so it can be applied on later visits. The panel can be reopened from the Privacy choices button.

    Necessary only keeps Google analytics storage, advertising storage, advertising user data, and advertising personalization denied, and the site does not download the Google Analytics library or send site-generated first-party evidence events. Allow analytics grants Google Analytics storage, loads Google Analytics, and permits the limited first-party evidence events described above, while advertising storage, advertising user data, and advertising personalization remain denied through this site's consent controls.

    Site-generated analytics event URLs are reduced to an origin and pathname before they enter the analytics data layer. Query strings and URL fragments are not intentionally included in page-view, destination-path, or outbound-link event fields. The first-party evidence system stores fixed destination identifiers rather than URLs.

    Necessary hosting, transaction, account-access, security, and diagnostic records may continue because they are required to operate and protect the service. The site does not intentionally send guided-tool answers, employer or role names, salary or wage amounts, benefit amounts, loan balances, principal, APRs, payments, terms, fees, lender names, quote details, calculated outcomes, commute details, names, email addresses, income, health status, free-text notes, or other sensitive form entries as analytics or first-party evidence properties.

    Google advertising technology

    On pages that are not designated as ad-free, the site may conditionally load Google AdSense technology. Google and other authorized advertising vendors may use cookies or similar technologies to serve, limit, measure, or personalize ads when permitted by applicable consent signals and law.

    Paid product pages and authenticated premium workspaces are designated ad-free. Advertising does not control product logic, source selection, rankings, calculations, or editorial conclusions.

    How information may be used

    Information may be used to:

    • Operate, secure, troubleshoot, and maintain the website and customer workspace.
    • Verify purchases, create or revoke entitlements, deliver access links, process refunds, and recover access.
    • Save the minimal progress state a customer chooses to synchronize.
    • Measure performance and understand which pages or product steps are useful.
    • Improve articles, guided tools, calculators, accessibility, navigation, and paid products.
    • Respond to voluntary messages and manage subscriptions.
    • Serve or measure limited, contextual, or other permitted advertising where enabled.
    • Detect abuse, fraud, malware, unauthorized access, or technical failures.
    • Comply with legal, tax, accounting, and contractual obligations.

    Service providers and sharing

    Information may be processed by service providers used to host, secure, measure, email, store account state, process payments, and operate the site. The architecture uses Vercel for hosting and short-lived server functions and may use Supabase for fixed first-party evidence events, authentication, and PostgreSQL workspace storage; Stripe for hosted checkout and signed transaction events; and Resend for access, support, or newsletter messages. A provider is not treated as active for a particular feature merely because it is named here; authentication, commerce, and email capabilities remain unavailable until their relevant integrations are configured, reviewed, and validated.

    Information may also be disclosed when required by law, to protect users or the site, to enforce terms, to resolve disputes, or as part of a legitimate transfer of the website. Community Acquired Finance does not sell personal information directly. Some laws may define certain advertising or analytics disclosures as a sale or sharing even when no money is exchanged; applicable controls should be added before those activities are enabled where required.

    U.S. state and international privacy rights

    Depending on location and whether a law applies to this site, users may have rights to request access, correction, deletion, portability, restriction, objection, or information about personal data processing, and may have rights to opt out of certain targeted advertising, sale, or sharing.

    Privacy requests may be sent through the Contact page. Identity verification may be required before completing a legally protected request.

    HIPAA and medical privacy

    Community Acquired Finance is not intended to receive protected health information and does not provide a secure patient, insurer, employer, or clinician communication channel. The premium workspace does not claim HIPAA compliance. Do not submit medical records, claim documents, diagnosis details, insurance ID numbers, patient account numbers, or other protected health information.

    Data retention and security

    Purchase and entitlement records may be retained as needed to provide access, honor update terms, process refunds, maintain tax and accounting records, resolve disputes, and prevent fraud. Minimal progress remains until the customer deletes it or the service's retention policy requires removal. Access tokens expire automatically; session records expire according to the session period. Technical logs, analytics records, consent preferences, first-party evidence records, and service-provider records may be retained for operational, measurement, security, legal, or troubleshooting purposes.

    No website can guarantee perfect security. Users should avoid providing information the site does not request and does not need.

    Children's privacy

    This site is intended for a general adult audience and is not designed for children under 13. We do not knowingly collect personal information directly from children under 13.

    Third-party links

    Articles and source lists link to government agencies, research organizations, plan resources, and other third-party websites. Community Acquired Finance does not control their content, privacy practices, security, accessibility, or availability after a user leaves this site.

    Policy updates

    This policy may be updated when the site's tools, customer products, analytics, advertising, forms, vendors, or legal obligations change. The effective date above should be revised when material changes are made.

    Educational only. Community Acquired Finance provides general educational information only. It is not financial, investment, tax, legal, insurance, medical, billing, employment, or benefits advice, and its tools do not make official eligibility, coverage, authorization, tax, billing-liability, or plan determinations. Estimates may be incomplete, outdated, or inapplicable to a specific person, plan, state, employer, provider, or claim. Verify important details with current official sources, controlling documents, government agencies, insurers, employers, billing offices, and qualified professionals.
    Effective August 3, 2026

    Benefits Decision System early-access validation

    The bounded Healthcare Worker Benefits Decision System offer asks only for an email address, confirmation that the visitor would seriously consider a $29 one-time purchase if the described product launches, and consent to receive product-specific confirmation and launch updates.

    The service stores the normalized email address, a one-way email hash used to prevent duplicate commitments, a random browser-session identifier, fixed product and offer identifiers, the fixed $29 price, the fixed source surface, consent status, commitment status, and timestamps in a service-role-only Supabase table. The commitment is not a purchase, reservation, account, entitlement, or payment authorization.

    This early-access record is not designed to receive or store employer names, plan documents, plan elections, salary or benefit values, medical information, diagnoses, member IDs, claim information, financial-account information, payment-card information, free-text notes, or uploaded files. Visitors should not submit those details through the form, email, or the Contact page.

    After a visitor chooses Allow analytics, the site may separately store fixed anonymous offer-view and offer-CTA events using a random browser-session identifier. These evidence events do not include the email address or form contents. Choosing Necessary only prevents those optional evidence events, but a visitor who intentionally submits the early-access form still creates the contact and commitment record required to fulfill that request.

    Unsubscribing through the confirmation email marks the Benefits Decision System commitment inactive and also updates the connected email audience when available. A visitor may also use the Contact page to request correction or deletion, subject to identity verification and any legally required retention.