Privacy Policy

Privacy at a glance
We care about your privacy. Here’s a quick summary of how NCOA.org handles your information:
What Information do we collect?
- Non-personal data (pages visited, clicks, browser/device type)
- Personal data you provide (name, email, donations, sign-up forms, checkup responses such Falls Free CheckUp)
How do we use it?
- To process donations and send receipts
- To connect you with resources and updates
- To improve our website and digital tools
- To keep our systems secure
Who do we share it with?
We work with trusted partners who help us run NCOA.org. For example:
- Analytics: Google Analytics, Microsoft Clarity, Mouseflow
- Donations & Forms: Stripe, EveryAction (Bonterra)
- Hosting: Amazon Web Services (AWS), Salesforce
- Videos & Social Media: YouTube, Facebook, Instagram, Threads, LinkedIn, X (Twitter), Bluesky
- Security (partners): MOVEit (for secure file transfers with program partners; e.g., Healthy Aging Programs Integrated Database (HAPID))
Each partner has its own privacy policy.
How long do we keep it?
We keep information only as long as needed to provide services or meet legal requirements (for example, donation records for tax reporting).
Where is data stored?
Your information may be stored in secure cloud servers, mainly in the United States.
What rights do you have?
Depending on where you live, you may have the right to:
- Access your personal data
- Ask us to correct or delete it
- Opt out of certain sharing
- Request a portable copy of your data
To use these rights, email us at nicole.knowles@ncoa.org (Privacy Policy) or newsletters@ncoa.org (Data Preferences).
Children’s Privacy
NCOA.org is not directed to children under 13, and we don’t knowingly collect data from them.
Introduction
About this privacy policy and using the website
The National Council on Aging (“NCOA”, “we” or “us”), created this Privacy Policy in support of our commitment to protecting your online privacy. This Privacy Policy co-exists with our Terms of Service and together both policies govern your use of www.ncoa.org (the “Website”). By accessing, browsing, or using the Website, you acknowledge that you have read, understand, and agree to this Privacy Policy and our Terms of Service. We encourage you to familiarize yourself with both this Privacy Policy and our Terms of Service. If you do not agree with these terms (including any revisions to them), do not use the Website.do not use the Website.
Purpose of this privacy policy
This Privacy Policy informs you about information we collect and how we use it. We will inform you of:
- What information we collect;
- How the information is used;
- With whom the information may be shared;
- Your choices regarding collection and use of the information;
- Security measures in place; and
- How to update your information or request deletion.
Purpose of the website
The purpose of the Website is to provide information and resources to help older adults in the United States to live healthy and independent lives. Information on the Website is provided for educational purposes and is not a substitute for financial, legal, medical, or other professional advice.
Information we collect
Non-personal / technical data (analytics)
When you visit the Website, we and our analytics partners collect non-personal information using cookies, pixels, and similar technologies. This may include pages visited, time on page, referring/exit pages, links clicked, approximate location (city/country), device and browser type, operating system, and clickstream data.
We also use:
- Google Analytics 4 (GA4), including Google Signals;
- Microsoft Clarity; and
- Mouseflow.
We partner with Microsoft Clarity and Microsoft Advertising to capture how You use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our website and tools/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses Your data, visit the Microsoft Privacy Statement
Mouseflow may record clicks, mouse movements, scrolling, form interactions (excluding certain sensitive fields), pages visited, time on site, device/browser, anonymized IP, location, and metadata. It does not collect information on pages where it is not installed. You may opt-out at https://mouseflow.com/opt-out.
You can control or disable cookies in your browser settings, and you may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.
We use non-personal information to:
- Measure and improve Website performance and content;
- Understand how visitors navigate the Website;
- Diagnose technical issues and maintain security; and
- Develop new features and services.
We may also use aggregate analytics to assess the effectiveness of outreach or public-interest campaigns.
Personal data (what you provide)
We collect personal information you voluntarily provide, such as name, email address, mailing address, phone number, and information you enter into forms, questionnaires, or tools (e.g., Falls Free CheckUp). If you make a donation, limited billing details are collected securely by our payment provider; we do not store full payment card numbers.
We use personal information to:
- Respond to inquiries and provide tailored resources;
- Process donations and send receipts;
- Communicate program updates and events;
- Improve Website features and services; and
- Protect the Website and comply with legal obligations
Some tools, such as the Falls Free CheckUp, may collect information related to your health or well-being. We treat this information as sensitive and use it only to provide the requested service or in de-identified, aggregate form for program evaluation. We do not share sensitive information with third parties for their own use.
We do not disclose personal information except as described here:
- With service providers/contractors under obligations to protect information;
- With advocacy partners or program partners in aggregate or de-identified form;
- With your consent;
- For legal reasons (law, regulation, subpoena, court order); and
- In connection with organizational needs, such as restructuring or transfer of operations.
Together with our use of non-personal information, these purposes reflect the full set of ways we use data collected through NCOA.org.
Our legal bases for processing personal information include your consent, compliance with legal obligations, performance of a contract, and NCOA’s legitimate interests in improving services and advancing our mission.
How we share information
We do not sell your personal information. We may share it only as described here:
- With service providers/contractors who help us run NCOA.org (e.g., analytics, hosting, payment processing, forms, secure file transfer);
- With partners in aggregate or de-identified form to support advocacy and research;
- With your consent when you ask us to share information;
- For legal reasons when required by law, subpoena, or court order; and
- For organizational changes, such as transfer of program operations or restructuring, consistent with nonprofit obligations.
We also do not share personal information for cross-context behavioral advertising.
Third-party services
We rely on trusted third-party providers to operate NCOA.org and deliver services. These providers may collect or process information as part of their services. Each provider has its own privacy policy, which we encourage you to review.
Analytics & user insights
- Google Analytics 4 (GA4) and Google Signals: Google Privacy Policy
- Microsoft Clarity: Microsoft Privacy Statement
- Mouseflow: Mouseflow Privacy Overview and Mouseflow Privacy Policy
Payments & forms
- Stripe for donation/payment processing: Stripe Privacy Policy
- EveryAction (Bonterra) for forms, sign-ups, engagement: Bonterra Privacy Notice
Hosting & databases
- Amazon Web Services (AWS) for website hosting and data storage: AWS Privacy Notice
- Salesforce for contact management: Salesforce Privacy Information
Video & embedded content
- YouTube (Google): YouTube Privacy and Google Privacy Principles
Social media & external links
- Facebook (Meta): Facebook Privacy Policy
- Instagram (Meta): Instagram Privacy Policy
- Threads (Meta): Threads Supplemental Privacy Policy
- LinkedIn: LinkedIn Privacy Policy
- X (formerly Twitter): X Privacy Policy
- Bluesky: Bluesky Privacy Policy
Security & File Transfer
- MOVEit (Progress) for secure file transfers with program partners (e.g., Healthy Aging Programs Integrated Database (HAPID)): Progress Privacy Policy
Data retention
We retain personal information only as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements. Donation records may be retained for financial reporting and tax purposes. For example, donation and transaction records are generally retained for at least seven years to comply with tax and accounting requirements.
Applicability of this privacy policy
This Privacy Policy applies to information (both personal and non-personal) that NCOA collects through the Website and related services. It does not apply to:
- Content, business information, ideas, concepts, or inventions that you send to NCOA by email, through the Website contact function, or by posting in public forums; or
- Information that is already publicly available.
If you want to keep content, business information, ideas, concepts, or inventions private or proprietary, do not submit them through the Website or by email.
How NCOA handles privacy and security
We use administrative, technical, and physical safeguards to protect your information, including Secure Socket Layer (SSL) encryption. However, no method of transmission or storage is 100% secure.
Changes to this privacy policy
We may change this Privacy Policy at any time by posting revisions to our Website. Your use of this Website means that you accept the terms of this Privacy Policy and your continued use after such changes are posted means that you accept the revised Privacy Policy.
Your privacy rights
Depending on your location, you may have rights under laws such as GDPR (European Union) or CCPA/CPRA (California). These may include:
- Accessing the personal data we hold about you;
- Requesting corrections or deletions;
- Opting out of certain types of data sharing;
- Restrict the processing of your personal data in certain circumstances;
- Object to the processing of your personal data for specific purposes; and
- Receiving a copy of your data in portable format.
To exercise these rights, please contact us (see “How to Contact Us” below).
Children’s privacy
The Website is not designed to attract or be used by children under the age of 13. NCOA does not knowingly collect personal data from anyone under the age of 13, unless we first obtain permission from that child’s parent or legal guardian.
How to contact us
For more information about our privacy practices, or to exercise your rights:
By Email:
- Privacy Questions: nicole.knowles@ncoa.org (Subject: Privacy Policy)
- Data Preferences: newsletters@ncoa.org (Subject: Privacy Policy – Data Preferences)
By Mail:
National Council on Aging
251 18th Street South, Suite 500
Arlington, VA 22202
Attn: Nicole Knowles
Contact Us
Since 1950, we’ve walked beside generations of Americans. NCOA delivers the resources, tools, best practices, and advocacy our nation needs to ensure that every person can age with health and financial security. But we can't do this work without you. Ask a question, suggest an idea, or tell us what's happening near you.
