Provisional notice · Effective 6 October 2026

Privacy notice

This is a provisional notice written to describe how the service actually works today. It has not been reviewed by a lawyer, and formal legal review is recommended. It is not legal advice. Please contact the operator for privacy requests at mhopkins8587@gmail.com.

Who runs Benefits Commons

Benefits Commons is operated by Mike Hopkins personally, as an individual based in the United States. It is not operated by a company, LLC or other legal entity. In this notice “we” and “us” mean Mike Hopkins as the operator, together with any volunteer moderators he appoints.

Contact for anything in this notice: mhopkins8587@gmail.com. No postal address is published at this time.

What we collect

When you apply: your name, job title, employer, the email address you sign up with, employer type, professional category, and your written description of your responsibilities and reason for joining. Optionally: years in benefits, region, company domain and a LinkedIn profile URL. We record that you accepted the community rules. We never ask for identity documents, payslips, or LinkedIn credentials.

As a member: content you create (posts, comments, channel messages, resource submissions, events and RSVPs), bookmarks, reactions, reports, connection requests, and your profile and privacy settings.

Optional profile details: a profile photo; where you are based (city, state/province, country and whether that is an office or hometown, never a street address); the regions your benefits work covers; and whether you are open to virtual or in-person coffee chats, with a short note. Photos are kept in private storage, are visible only to you, approved members and moderators, and are delivered through links that expire after a few minutes. Your location is hidden unless you turn on “Show my general location to approved members”. Coffee chat settings are off by default and only appear if you are listed in the directory. When you accept a coffee chat invitation, you and the other member can each see the other's sign-in email; nothing is shared before acceptance. You can change or remove any of these at any time in Profile & settings; removing a photo deletes the stored file.

For review and safety: application status history, moderator decisions and notes, and a moderation audit log.

Technical: your sign-in session is kept in your browser's local storage so you stay signed in. Our hosting and authentication providers keep standard request logs (such as IP address and time) to run and secure the service. We do not use advertising trackers and do not sell personal information.

Why we use it

  • To review applications and keep membership limited to employer-side benefits professionals.
  • To run the community: show your contributions, profile and settings to approved members as you choose.
  • To moderate, enforce the community standards and non-solicitation rules, and investigate reports.
  • To secure the service, prevent spam and abuse, and keep an audit trail of decisions.
  • To send account emails you request or need, such as email confirmation and password reset.

We use your information only for these purposes and for complying with valid legal obligations. We do not use it for marketing to you or anyone else.

Who can see it

  • Your application details and email address are visible only to you and to moderators.
  • Your directory profile (name, title, employer, headline and any fields you choose to show) is visible only to approved members, and only while directory listing is on.
  • Your email address is never shown to other members.
  • Reports you submit are visible only to you and to moderators.
  • Posts marked anonymous hide your name from members; moderators can still see who wrote them.
  • Nothing inside the community is shown on the public website or to people without an approved account.

These rules are enforced by database access controls, not only in the interface.

Service providers

The service is built and hosted with Lovable, and uses Lovable Cloud (which runs on Supabase) for the database, sign-in and account emails. These providers process data on our behalf to operate the service. Passwords are handled by the authentication provider; we never see them. No other third-party integrations receive member data.

Data may be processed in the United States or wherever these providers operate their infrastructure.

How long we keep it

  • Your profile and content are kept while your account exists, or until you or a moderator delete them.
  • Application records, status history, reports and the moderation log are kept for as long as needed to audit decisions and protect the community, and are reviewed for deletion when an account is closed.
  • Content you delete is removed from the community; some records may remain briefly in provider backups.

We do not currently promise a fixed retention period for each category.

Your choices and requests

You can edit your profile, directory listing, LinkedIn visibility, connection settings and digest preference in Settings, and delete your own posts, comments and messages.

Please contact the operator for privacy requests — for example to access, correct or delete your information, or to close your account — at mhopkins8587@gmail.com. We will confirm the request comes from your account's email address before acting and aim to respond within 30 days. Depending on where you live, you may have additional rights under local law; we will honor requests that apply to us.

Security

Access is limited by role and membership status, sign-in requires a confirmed email, and passwords are checked against known breach lists. No online service is perfectly secure; if we learn of a breach affecting you, we will tell you.

Children

The service is for working professionals and is not intended for anyone under 18.

Changes

If this notice changes, we will update the date at the top and, for material changes, notify members in the community.