This sanctuary is strictly 21+. By entering, you confirm you are of legal adult age.

Privacy Policy & Fellowship Data Terms

Privacy is part of the sanctuary.

Effective August 19, 2026. This policy explains what Vestivi.org collects, why it is collected, where fellowship inquiry data is stored, which service providers may process it, and how you may request correction or deletion.

01

Information you intentionally provide

Vestivi collects personal information when you choose to submit the Contact & Inquiry form. The exact fields depend on the path you select.

  • General inquiries: given or chosen names, email address, pronouns when provided, city or region, referral information, optional social or contact handles, accessibility requests, comments, and inquiry-specific responses.
  • Rush applications: legal name, chosen name, date of birth, email address, geographic location, Discord username, Rush statement, and required eligibility and consent acknowledgments.
  • Other fellowship paths: information relevant to Legacy, Alumna, chapter, support, collaboration, or general-inclusion inquiries.

The form also records the selected nature of inquiry and the acknowledgments you actively submit. A hidden anti-spam field, duplicate email-confirmation field, and Cloudflare Turnstile response token are not retained in the stored submission.

02

Why we collect it

Inquiry information is used to receive and evaluate your request, correspond with you, understand the appropriate fellowship path, arrange screening or follow-up when relevant, protect the safety of the community, and administer the inquiry process.

We do not use fellowship inquiry data to build advertising profiles, sell marketing audiences, or determine unrelated commercial eligibility.

03

Storage and notification architecture

Accepted submissions are stored in a private Cloudflare D1 database. The D1 record is the system of record for the inquiry. There is no public website endpoint that lists or retrieves stored submissions.

Before an inquiry is accepted into D1, the site uses Cloudflare Turnstile to verify that the submission is associated with a legitimate visitor rather than automated abuse. Turnstile verification is evaluated server-side and a failed verification is rejected before the inquiry record is created.

After storage, the Worker may send a limited administrator notification to SororitasVestitae@gmail.com. That notification is intentionally narrower than the stored application and contains the submission reference, inquiry type, contact or preferred name, email address, and region when provided. Full Rush statements, legal-name details, dates of birth, and other sensitive intake text are not intentionally duplicated into the notification email.

If the notification service fails, the stored D1 record remains the authoritative copy of the submission.

04

Service providers and disclosure

Cloudflare provides hosting, Worker execution, database storage, asset delivery, Turnstile abuse prevention, and related infrastructure used to operate Vestivi.org. Standard technical request, browser, device, and network signals may be processed by that infrastructure as necessary to deliver, secure, verify, troubleshoot, and observe the service.

Google/Gmail may process the limited administrator notification when a notification is successfully delivered to the Sororitas Vestitae administrative mailbox.

We do not sell, rent, or trade fellowship inquiry data to data brokers, advertising networks, or unrelated third parties. Disclosure may still occur when reasonably necessary to operate the service, protect users or the community, respond to a lawful requirement, or investigate abuse or security incidents.

05

Browsing data, local storage, and tracking

The public site uses a small local-browser value named vestivi-thread-depth to vary an ambient visual effect according to repeat visits in that browser. It is stored locally in your browser and is not part of the contact submission payload.

Cloudflare Turnstile may process technical browser and network signals when the Contact & Inquiry form is used so that automated or abusive submissions can be distinguished from legitimate use. Vestivi uses that verification for site security and form integrity, not for behavioral advertising.

Vestivi does not intentionally deploy third-party behavioral advertising pixels or sell browsing histories for cross-context behavioral advertising. Hosting and security infrastructure may still process ordinary technical request data such as timestamps, request metadata, or network information needed to operate the site.

Because the current site does not sell or share personal information for behavioral advertising, browser Do Not Track or Global Privacy Control signals do not trigger a separate advertising opt-out workflow. Those signals are consistent with our existing no-sale and no-behavioral-advertising practices.

06

Retention and deletion

A fixed automatic purge interval is not currently configured for the D1 inquiry database. We therefore do not promise a 45-day, 60-day, or other automatic deletion period that the system cannot yet guarantee.

Inquiry records are retained only for as long as reasonably necessary for correspondence, screening, administration, safety, dispute handling, and applicable recordkeeping needs. A specific automated retention schedule may be adopted later, and this policy should be updated before such a schedule is represented as guaranteed.

You may request deletion of a prior submission by writing to sisterhood@vestivi.org from the email address used in the inquiry and, when available, including the submission reference.

07

Correction, access, and withdrawal

Regardless of whether a particular statutory privacy right applies to a specific request, Vestivi accepts reasonable requests to correct inaccurate inquiry information, ask what inquiry information is still held, request deletion, or withdraw from an active fellowship inquiry.

We may need to verify that a person making a request is the person associated with the submission before changing or disclosing stored information. Information provided for verification is used for that purpose.

08

Security and sensitive information

Vestivi uses HTTPS for transmission, private Cloudflare D1 storage, server-side field validation, server-side Turnstile verification, same-origin submission controls, an anti-spam honeypot, and a design that keeps full application content out of routine administrator email notifications. Access to stored applications is not exposed through a public read API.

No internet service can guarantee perfect security. Please do not submit information that the form does not request and that you do not want used for the fellowship inquiry.

09

Adult-only service and policy changes

Vestivi and Sororitas Vestitae are intended for adults age 21 and older. The inquiry process requires an age affirmation, and Rush applicants provide a date of birth for server-side age validation.

This policy may be revised when the contact architecture, retention practices, service providers, or fellowship process materially changes. The effective date at the top of this page will be updated when substantive revisions are published.

10

Contact

Privacy, data correction, deletion, security, and fellowship-data questions may be directed to sisterhood@vestivi.org.