ShelterCurrent Privacy Notice
Version: 1.1 Effective date: 2026-08-12
This Privacy Notice explains how Elm and Ink LLC, a Missouri limited liability company doing business as ShelterCurrent (ShelterCurrent, we, us, or our), collects, uses, discloses, and retains personal information through sheltercurrent.com, the ShelterCurrent application, and our sales, billing, support, privacy, and security operations (Services).
1. Who is responsible
ShelterCurrent determines the purposes and means of processing information about website visitors, prospects, Customer personnel, billing and support contacts, and people who communicate directly with us. For that information, ShelterCurrent acts as the business or controller.
A shelter organization decides what client and operational information its Authorized Users put in the Service, why it is used, how long it is retained, and who may access it (Customer Data). For personal information in Customer Data, the shelter is ordinarily the business, controller, or regulated entity, and ShelterCurrent processes it under the shelter's instructions and our DPA.
If a shelter entered information about you, direct your request to that shelter. We assist the shelter as required by law and the DPA and do not independently decide its request.
2. Information we collect
Depending on the interaction, we may collect:
- name, business email, organization, facility, title, role, permissions, invitation, account, authentication, multifactor-authentication, session, device, recovery, legal-acceptance, and administrative-action records;
- subscription status, billing interval, billing name and address, tax status, transaction identifiers, invoices, refunds, and limited payment-method details returned by Stripe, such as brand and last four digits;
- IP address, browser and device type, operating system, requested and referring pages, timestamps, session identifiers, application version, feature and error events, response time, diagnostic data, and security records;
- information in a sales inquiry, support or privacy request, security report, survey, meeting, email, or other communication; and
- at a shelter's direction, minimum necessary client and operational Customer Data such as names and contact details, household relationships, accompanied minors, shelter or external HMIS identifiers other than Social Security numbers, referrals, controlled intake answers, accommodation needs, facility and bed operations, stays, waitlists, turnaways, census, incidents, tasks, supplies, reports, exports, configuration, retention, and audit history.
Stripe receives complete payment credentials directly; ShelterCurrent does not intend to receive or store complete card numbers or card security codes. Do not send Customer Data, payment credentials, or sensitive client details through ordinary support or billing email.
Customer Data may reveal homelessness, shelter location, family relationships, accommodation or disability needs, safety concerns, or other sensitive circumstances. Customers must not submit the prohibited data identified in the Terms, including Social Security numbers, scanned IDs, unrestricted case files, regulated clinical records, or victim-service comparable-database records.
3. Sources
We collect information from you; Customer administrators and Authorized Users; your device and use of the Services; Stripe and our identity, hosting, database, security, and communications providers; referral and business sources where lawful; and authorities or parties involved in security, fraud, disputes, or legal compliance.
4. How we use information
We use personal information as reasonably necessary to:
- provide, configure, secure, maintain, support, export, and delete the Services;
- administer organizations, accounts, roles, sessions, subscriptions, taxes, renewals, cancellation, refunds, and communications;
- perform shelter workflows on the Customer's instructions;
- authenticate users; monitor availability and reliability; and prevent, investigate, and remediate fraud, abuse, unauthorized access, incidents, and technical failures;
- respond to sales, support, privacy, and security requests;
- enforce agreements, protect rights and safety, comply with law and valid legal process, and establish or defend claims; and
- create statistics only after applying measures designed to prevent reasonable linkage to an individual, household, sensitive shelter location, or Customer.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use identifiable shelter-client records or notes for targeted advertising or to train a general-purpose or cross-customer AI model. We maintain deidentified statistics in deidentified form and do not attempt to reidentify them.
5. When we disclose information
We may disclose information:
- within the Customer organization according to its user roles and facility boundaries;
- to providers that perform cloud delivery and security, workforce identity, database hosting, billing, and approved operational functions, subject to restrictions appropriate to their roles;
- to auditors, insurers, accountants, attorneys, and professional advisers who need it and owe confidentiality duties;
- when reasonably necessary to comply with law or valid process; investigate wrongdoing; protect a person, Customer, ShelterCurrent, or the public; or respond to an emergency; and
- in a financing, reorganization, merger, acquisition, or transfer of relevant business or assets, subject to appropriate confidentiality and this Notice.
The DPA names the Customer Data Subprocessors and explains their functions and change process. Stripe, LLC separately processes Customer administrator, billing, transaction, and payment information for checkout and payment services and may act as an independent controller under its terms and privacy notice.
We do not publish shelter-client data or disclose it for another Customer's use.
6. Cookies and browser signals
We use cookies and similar storage necessary for security, authentication, session continuity, preferences, and essential operation. We do not use third-party advertising cookies or sell or share browser activity for targeted advertising. Because those practices are not used, the Services do not currently respond differently to advertising opt-out or Do Not Track signals. If practices change, we will update this Notice and implement legally required choices first.
7. Security and location
We use administrative, technical, organizational, and physical safeguards described in the DPA. No transmission or storage method is guaranteed completely secure. Report a vulnerability or suspected incident to security@sheltercurrent.com without including sensitive client details in ordinary email.
The Services are offered to U.S.-based organizations for U.S. shelter operations. Providers may process information in locations disclosed by their current terms and the DPA. ShelterCurrent does not promise that every provider operation, network path, storage copy, or support action occurs only in the United States. We do not offer the Services for information subject to non-U.S. data-protection or restricted-transfer requirements.
8. Retention and deletion
Customer Data is retained during the active paid term unless Customer deletes it or gives a lawful instruction. After the paid term, the workspace has a 30-day read-only export period; active-system deletion follows within 30 more days; and Neon recovery history rolls off within 7 days after active deletion. Narrow legal holds and legal duties may delay deletion only for affected data. Restored data is subject to reapplication of recorded deletion and restriction instructions.
For information ShelterCurrent controls, the default periods are:
- authentication and security logs: 12 months;
- support, contact, and privacy-request records: 2 years after closure;
- Security Incident and no-harm determination records: 5 years after closure;
- billing, tax, assent, refund, and deletion evidence: 7 years; and
- deidentified statistics: indefinitely while maintained in deidentified form.
We may retain a narrower record longer when reasonably necessary for a specific legal duty, dispute, fraud or security matter, or documented legal hold. We delete or deidentify it when that basis ends. Annex C of the DPA contains the complete schedule.
9. Privacy requests
To request access, correction, deletion, or a copy concerning information ShelterCurrent controls, email privacy@sheltercurrent.com and describe the request and your relationship with us. We may request information reasonably necessary to authenticate the request and protect others. Where applicable, we respond within the legally required period, explain a permitted extension, and provide an appeal method. We do not unlawfully discriminate for exercising a privacy right.
Authorized agents must provide legally sufficient authority. We may verify the requester directly where law permits. Rights and exceptions vary by jurisdiction and relationship. If a request concerns shelter-controlled Customer Data, we route it to the responsible Customer unless law prohibits doing so.
We do not sell personal information, use it for targeted advertising, or perform profiling in furtherance of decisions producing legal or similarly significant effects. ShelterCurrent processes health-related Customer Data only under the Customer's instructions; the Customer is responsible for required collection notices and consent.
10. Children
The Services are workforce-facing and not directed to children. No person under 18 may create an account or submit information directly. An adult/family shelter may enter minimum necessary information about a minor accompanying an adult when it has lawful authority. Dedicated youth or child-welfare programs are excluded.
11. Changes
We may update this Notice for changes in law, providers, the Services, or our practices. We will post the version and effective date and provide appropriate advance notice of a material change. We will obtain consent before applying a new practice to previously collected information where law requires it.
12. Contact
Elm and Ink LLC d/b/a ShelterCurrent
9755 N Lucerne Ave, Kansas City, MO 64154, USA
Privacy: privacy@sheltercurrent.com
Support: support@sheltercurrent.com
Security: security@sheltercurrent.com
Billing: billing@sheltercurrent.com
Legal: legal@sheltercurrent.com