Privacy Policy
Effective date: October 2, 2026
1. Who we are
MichiganVOB is operated by Triangle Technologies, LLC, a veteran-owned Michigan company. MichiganVOB is a statewide directory created to help people discover and support veteran-owned businesses throughout Michigan.
MichiganVOB is not affiliated with or endorsed by any state or federal government agency. It is a private directory, not a government certification or verification program.
This policy describes the application and the intended retention framework and is effective as of the date shown above. Contact us through /contact.
2. Information you provide
- Business submissions and updates: business name, categories, description, city, county, ZIP code, optional service area, street address, public phone, website/social links and hours; private owner/contact name and email; veteran-ownership and Terms/Privacy acknowledgements and timestamps; optional business logo and photograph. The service also creates status, moderation, source, pending-change and management records.
- Claims: signed-in account identifier, full name, verified account email, phone, relationship to the business, role/title, optional supporting explanation, authority and Terms/Privacy acknowledgements and timestamps, claim status, review information and email status. The current claim form does not accept file attachments.
- Contact: name, email, selected topic and message, together with receipt time and notification-email status. The current Contact form does not accept file attachments.
- Authentication: account and session information handled by Clerk, including account identifiers and verified email addresses used by MichiganVOB. Depending on your sign-in method, Clerk processes credentials and profile information supplied directly or by your chosen identity provider. MichiganVOB's directory database does not store your account password.
- Uploads: image bytes and accompanying filename/type information are processed. Supported images are validated and re-encoded as WebP for storage, normally without preserving original embedded metadata. Visible information in an image is not removed merely by re-encoding.
3. Information from public sources
Administrators may add business information from public websites, directories and program records. We retain source names/references, review dates, ownership-evidence descriptions, import provenance and administrative review information so staff can understand and correct a record.
A public-source record does not mean the business or its owner submitted the listing, accepted our Terms, authorized every use of source material, or completed a MichiganVOB certification. Public information can be inaccurate or outdated; request corrections or removal through Contact.
4. Public and non-public information
After approval, public business fields may include business name, description, categories, location/address and service area, designated public phone/email, website/social links, hours, approved images, veteran-owned designation, claimed indicator and update information. Include only information you intend to make public in these fields. A home address or personal phone placed in a public business field can become public.
Dedicated owner/contact details, claimant identity/contact information, claim explanations and review records, Contact messages, internal notes, source/provenance administration and private management credentials are not included in the public directory response. They are used in authorized private workflows and may be disclosed to appropriate staff and service providers for the purposes below.
Pending, rejected, unpublished and deleted records are excluded from the public directory under its publication rules. This does not mean all copies have been physically deleted. Public information may be copied or cached by others outside our control.
5. Technical information and logs
Requests necessarily expose technical information such as IP address, browser/device information, request times and requested resources to hosting infrastructure and relevant third-party resources. MichiganVOB uses security identifiers, request counters, credential digests and short-lived CAPTCHA replay records.
Routine application request logs record request method, URL path with the query removed, request identifier, response status and timing. Administrative/security events may also record record identifiers, authenticated administrator identifiers and action/error categories. The application logger is configured not to log normal form bodies, authorization headers, cookie values, management tokens or CAPTCHA secrets. Infrastructure and providers maintain their own logs under their practices.
Removing query strings from application logs does not remove them from every provider's telemetry. Hosting infrastructure and required external resources may receive request information under their own practices. The browser-analytics block described below does not disable those separate forms of processing.
6. Cookies, security identifiers and browser storage
Browser settings can restrict cookies/storage, but required features may stop working. Clearing or replacing an anonymous browser cookie can change its security identity; these controls are not a hard per-person quota.
- Anonymous security cookie: __Host-mivob_rate is a signed, first-party, host-only cookie used to recognize a browser for submission/Contact abuse prevention. It is Secure, HttpOnly and SameSite=Lax, with a 30-day lifetime from issuance rather than renewal on every request. The server derives a protected security identifier from it; it does not establish a person's identity.
- Claim rate limiting uses a protected identifier derived from the authenticated Clerk account ID. Certain other endpoints use protected identifiers derived from server-observed IP addresses. Rate-limit counters and expiration times are stored in the database.
- Where private submission-management access is used, mivob_manage is an HttpOnly, SameSite=Strict management-session cookie, Secure in production. Its expiry is bounded by the underlying private management credential, currently configured for 90 days. Expiration prevents use but does not necessarily delete stored digests.
- Clerk and Google reCAPTCHA may use cookies or browser storage for authentication, security and fraud prevention under their own practices. Blocking them may prevent sign-in or protected form submission.
- The Replit-provided browser-analytics script and its collection endpoint are blocked by the site's Content Security Policy, rather than relying on an opt-out cookie, browser-storage setting or URL cleanup after the page starts. No application-owned localStorage/sessionStorage persistence is used in the active directory pages; provider-managed storage for required features is separate.
7. Google reCAPTCHA
Add Business, Claim Business and Contact use Google's reCAPTCHA v2 checkbox to help prevent automated abuse. Loading and using it sends technical/browser information and challenge interactions to Google under Google's Privacy Policy and Terms of Service. MichiganVOB sends the response token to Google's verification service and validates the result.
The application stores a digest, not the raw response token, to prevent reuse. The verification window and replay entry are short-lived operational controls; physical deletion of expired replay rows is not guaranteed on that schedule. We do not use successful CAPTCHA verification as proof of a business's veteran status or a claimant's authority.
Google's Privacy Policy: https://policies.google.com/privacy. Google's Terms: https://policies.google.com/terms.
8. Providers and external resources
We provide these services the information needed for their functions; providers may also process information for security, operational or other purposes under their own terms. We do not promise that information is never shared or that providers keep no records.
- Clerk: account creation, sign-in, sessions and verified-email/account information for access controls. Clerk processes authentication information and associated technical data; the tenant is managed through Replit. See https://clerk.com/legal/privacy.
- Resend: transactional submission, claim, decision and Contact-notification email. It processes recipient/sender information, message content, private management links where included, and delivery/status information. An email accepted by Resend or reported delivered does not establish inbox placement or reading. See https://resend.com/legal/privacy-policy.
- Replit: production hosting, request routing, managed PostgreSQL database, infrastructure logs, backups and hosting-level traffic measurements. Replit browser-analytics collection is blocked as described below. Directory records, claims, messages, provenance and security/management records are stored in the Replit-managed PostgreSQL database. This disclosure does not identify the current database as a separate Neon account. See https://replit.com/privacy-policy.
- Replit App Storage / Google Cloud Storage: validated business images are held in private object storage, with paths recorded in the database. Approved images are served through application access rules; storing an object privately does not keep an approved directory image non-public. Google Cloud supports the underlying storage service. See https://cloud.google.com/terms/cloud-privacy-notice.
- Google Fonts: the live site loads font styles and files from fonts.googleapis.com and fonts.gstatic.com, including Inter, DM Sans and Bricolage Grotesque. Those requests disclose ordinary network/request information to Google. See https://policies.google.com/privacy.
- Chosen sign-in providers and linked websites: if you use an external identity provider through Clerk or follow a business/social/resource link, that provider/site processes information under its own practices.
9. Browser analytics and hosting measurements
MichiganVOB uses an enforcing Content Security Policy to block the Replit-supplied browser-analytics script at i.replit.com/script.js and its collection endpoint before browser collection occurs. The hosting platform may still insert the script's markup, but the browser policy prevents it from executing and sending browser analytics. This block applies across the site, including pages containing sensitive query strings or fragments; it does not depend on the management page clearing its credential fragment.
Blocking this browser collector does not disable hosting-level traffic measurements, ordinary request/security logs, database/storage operations or the required external resources described in this policy. Those providers may process network and request information under their own practices. Their logs, retention and backups remain provider-controlled rather than governed by a directory-database cleanup timer.
MichiganVOB does not add advertising pixels, session recording, Google Analytics or another marketing tracker, and has not replaced the blocked script with another browser-analytics provider. A browser's Do Not Track setting does not necessarily disable required authentication, CAPTCHA, security or infrastructure processing.
10. Purposes and disclosures
We process information to operate and improve the directory; evaluate submissions and claims; publish and reasonably promote approved business content; manage authorized listing access; respond to corrections, removals and messages; send service email; diagnose problems; prevent abuse; and maintain source and review history.
Information is available to authorized personnel and disclosed to providers as necessary for these functions. Approved public business information is disclosed publicly. Where required or reasonably necessary, information may also be disclosed to comply with law or valid legal process, investigate fraud or security incidents, resolve ownership disputes, or protect users and legal rights.
This policy does not authorize unrelated resale of private submission or claim information. Hosting-level traffic measurements and provider operational processing are separate from the blocked browser collector. Providers may process information outside your state or country under their own infrastructure arrangements; no particular data-location guarantee is made here.
11. Retention framework and current limitations
We retain information while needed for the directory, administration, security and applicable legal obligations. The following are the intended administrative targets, not a claim that automatic deletion currently enforces each deadline. Most directory, claim, Contact and provenance records currently remain until an appropriate manual or implemented cleanup action occurs, and can therefore remain beyond these targets.
- Active listings: while listed, subject to periodic review. Rejected listings: target 90 days. Withdrawn/unpublished private records: target 12 months.
- Rejected/withdrawn claims: target 12 months. Approved claims: while the relationship is active plus a reasonable administrative period.
- Contact messages: target 12 months after resolution. The current system does not record a resolution date or run a resolution-based deletion schedule.
- Uploaded images: while needed for active listings; rejected content target 90 days; withdrawn content target 12 months; unreferenced/replaced images target 30 days. Certain rejection, replacement, failed-upload and deletion actions already attempt earlier file removal; deletion can fail, and no comprehensive age-based orphan cleanup is enforced.
- Source/provenance records: while the listing is active plus a reasonable administrative period. Unused import candidate data: target 90 days.
- Security/rate-limit records: operational expiration. Rate-limit rows are cleaned during later rate-limited requests. CAPTCHA verification/replay validity is approximately two minutes, but expired replay rows can remain physically stored until cleanup. Logical expiration is not physical deletion.
- Routine logs controlled by MichiganVOB: target approximately 30 days. Replit documents a 30-day deployment-log retention window; other provider telemetry follows provider schedules.
- Incident/security records: longer where reasonably needed for investigation, legal obligations or protection of the service.
- Private management credentials: usable only for their configured lifetime, currently 90 days; related sessions are bounded by that lifetime. Stored digests can remain after expiry.
- Account/business relationships: while needed for the account/claim relationship plus a reasonable cleanup period. Clerk account/session information follows its account controls and provider practices.
- Backups, delivered/email-provider copies and infrastructure-provider records: provider-controlled schedules and restoration/deletion limitations may apply.
12. Security and deletion limitations
The application uses authentication and role/ownership checks, private-response controls, protected credential digests, signed security cookies, input/image validation, CAPTCHA and persistent rate limits. These are safeguards, not a guarantee of absolute security or anonymization. Protect your account and private management links.
Unpublishing removes public directory availability while preserving private records. The administrative delete action is a soft deletion, not immediate database erasure; related ownership or import history can block that action. Some image-removal actions attempt physical file deletion, but failures and provider copies can persist. Search engines, caches, prior email and backups are not guaranteed to disappear immediately.
Current workflows do not request DD214s, disability records, Social Security numbers or sensitive military/personal documentation. Do not submit sensitive military, identity, medical, financial or similar records in free text, images or Contact messages unless we specifically provide an authorized future process. Free text and uploads can still contain such information; they do not make it technically impossible to submit.
13. Requests and choices
Use Contact at /contact for listing corrections/removal, privacy questions, access assistance or a request concerning your information. Identify the relevant record and what you want changed without sending passwords, tokens or sensitive documents. Where applicable law gives you access, correction, deletion, objection, restriction or other rights, you may request them through this channel.
We may verify identity or authority before disclosing private records or changing control of a business. Requests are considered subject to applicable law, necessary administrative/security history and provider/backup limitations. There is no promise of complete immediate deletion or a current one-click account-and-record erasure feature. If the web Contact form is unavailable, you may send privacy-related requests to shawn@triangletek.com. Do not include passwords, management links, tokens or sensitive documents in your email.
14. Children's privacy
MichiganVOB is not directed to children under 13. Business submissions and claims are restricted to adults 18 or older as a participation requirement; the current forms do not independently verify age. We do not knowingly seek children's personal information.
If you believe a child has provided personal information, contact us so we can investigate and take appropriate action, including removal where required and practicable. Do not submit unnecessary information about children in business descriptions, photographs or messages.
15. External links, updates and contact
External business websites, social profiles, identity providers and linked resources have their own information practices. This policy does not control their collection after you visit or use them.
We will post approved policy changes and their effective date, with additional notice or consent where required by law. A changed policy does not rewrite prior submission acknowledgements or imply that public-source businesses accepted the Terms.
For questions and privacy/correction/removal requests, contact MichiganVOB, operated by Triangle Technologies, LLC, through the Contact page at /contact. If the web Contact form is unavailable, privacy-related requests may also be sent to shawn@triangletek.com.