1. Our privacy approach
MJCarePair is designed around data minimization: collect what is reasonably needed to verify eligibility, operate matching and messaging, maintain safety, administer membership, and comply with legal obligations; avoid exposing sensitive information in public or discovery profiles.
2. Information we may collect
Depending on the feature and production verification design, information may include account details such as email address; profile details such as display name, county, service areas, experience, care-style preferences, and biography; identity-verification information; MMMP role and credential information; caregiver capacity and patient/caregiver status attestations; CarePair requests and status; private messages; block and report records; membership status and billing-event references; notification preferences; legal acceptance records; and limited technical/security data such as timestamps, session information, IP address, and user-agent information where appropriate.
3. Sensitive verification information
Government identification, MMMP credential numbers, and raw verification documents are not intended to appear in member-facing discovery profiles. Production architecture should minimize retention of raw documents, use secure storage or a specialized identity provider where appropriate, restrict access by role, use temporary signed access where needed, and maintain audit records.
4. How we use information
The planned member service would use information to create and secure accounts; verify identity and eligibility; operate caregiver discovery and service-area matching; facilitate mutual CarePairs; provide private messaging; manage membership; send requested or transactional communications; prevent abuse; investigate reports; enforce platform rules; maintain audit and operational records; improve reliability; and comply with applicable legal obligations.
5. Matching information visible to members
Discovery is intended to expose limited compatibility information rather than sensitive identity data. Caregiver profiles may show information such as display name, general location/service counties, experience, profile description, care style, cultivation approach, general medicine-category compatibility, verification status, and available capacity. Exact home addresses and raw credential identifiers should not be displayed.
6. Messages, blocks, reports, and moderation
Private CarePair messages and relationship history may be stored to provide the service. Blocks, reports, moderation notes, and audit events may be retained to enforce rules and investigate safety issues. Administrative CarePair oversight is designed around metadata rather than routine viewing of private message content. Production policies should define when message content may be accessed for safety, legal, or support purposes.
7. Email and notifications
Members can manage supported communication preferences. Transactional email events are designed to avoid including private message bodies or raw verification documents. Production email delivery may involve a third-party provider whose identity and privacy terms must be disclosed before launch.
8. Membership and payment information
MJCarePair intends to use an approved third-party payment processor. The platform should avoid storing full payment-card details itself. Processor identity, payment data flows, and required disclosures will be added after a provider is selected and approved for the business model.
9. How information may be shared
Information may be shared with other members only as needed for platform matching and CarePairs; with service providers acting on MJCarePair's behalf for functions such as hosting, identity verification, communications, security, and billing; when required by law or valid legal process; to protect rights, safety, or platform integrity; or as part of a lawful business transaction subject to appropriate safeguards. MJCarePair does not intend to sell member personal information to advertisers.
10. Retention and deletion
Information should be retained only as long as reasonably necessary for the purpose collected, legitimate safety and audit needs, contractual obligations, dispute handling, or legal requirements. Raw verification material should receive especially limited retention where feasible. Final production retention periods and account-deletion procedures remain to be established before launch.
11. Security
The planned member service is being designed with authenticated sessions, database access controls, row-level security, administrative role restrictions, and audit-oriented controls. These descriptions do not represent a security certification or a claim that member-facing systems are operational on this informational preview. Production controls must be validated before launch; no system can guarantee absolute security.
12. Your choices
Planned member controls include profile editing, notification preferences, membership pause/cancellation, blocking/unblocking, and account/session security tools. These member controls are not available on this informational preview. Production procedures for access, correction, deletion, and other legally applicable privacy requests will be finalized before launch.
13. Children
MJCarePair is not intended for children. The service will enforce role- and jurisdiction-specific minimum-age requirements appropriate to the program and platform before production access.
14. Jurisdiction expansion
MJCarePair is being architected for future state-by-state expansion. Privacy requirements, credential types, program rules, and disclosures will be reviewed before another jurisdiction is enabled rather than assuming Michigan rules apply nationally.
15. Contact and policy updates
Use the Contact Us page for current development inquiries. A production privacy contact and any legally required addresses will be added before launch. Material revisions should receive a new version and effective date.