Effective April 30, 2026 · Pending attorney review
Privacy Policy.
Plain language about what this site collects, what I do with it, and where the limits are.
Read this first
This site is informational and educational. Visiting it, signing up for the newsletter, downloading a toolkit, or contacting me through the form does not create a clinician-client, therapist-patient, or any other professional clinical relationship between you and Stephanie A. Smith, LCSW, ASW-G, C-ASWCM. Stephanie does provide clinical services through The Social Work Progressive PLLC; clinical engagement is established only by a separate intake process and signed engagement letter, not by your use of this Site. If you are in crisis, call or text 988 (the Suicide and Crisis Lifeline) or go to your nearest emergency room.
1. Who runs this site
This website is owned and operated by Stephanie A. Smith, LCSW, ASW-G, C-ASWCM, doing business as The Social Work Progressive (the “Site,” “I,” or “me”). I am a Licensed Clinical Social Worker in the State of Colorado.
For questions about this Privacy Policy, contact me at Stephanie@TheSocialWorkProgressive.com.
2. Categories of personal information I collect
I try to collect as little as possible. Under the Colorado Privacy Act and California Consumer Privacy Act frameworks, the categories of personal information I collect are:
- Identifiers. Name, email address, account username if you create an account.
- Internet or other electronic network activity. IP address, browser type, device type, pages viewed, referring URL, timestamps.
- Geolocation. Approximate location derived from IP address (city/region level, not precise GPS).
- Professional or employment-related information. If you tell me your role, license, or employer in a message or form.
- Commercial information. Products purchased and transaction history. Payment card data is processed by third-party payment processors and is not stored by me.
- Inferences. Aggregate engagement patterns drawn from the above.
Sources: directly from you, automatically through your browser, and from my service providers (hosting, analytics, payment processors).
Recipients: my hosting and email infrastructure providers (Automattic / WordPress.com / Jetpack), payment processors (only when you make a paid purchase), and otherwise no third parties for marketing purposes.
I do not knowingly collect Social Security numbers, payment card data, health insurance information, or protected health information (PHI) through this Site.
3. How I use your information
- To respond to messages you send me.
- To send the newsletter you signed up for, and the welcome message that goes with it.
- To deliver paid products and services and provide related customer support.
- To understand how the Site is used, in aggregate, so I can improve it.
- To detect, prevent, and address fraud, abuse, or violations of my Terms.
- To comply with legal obligations, including mandated reporting (see section 7), tax recordkeeping, and applicable law.
I do not sell your personal information. I do not share your personal information with third parties for cross-context behavioral advertising or for their independent marketing purposes.
4. Newsletter and email
The newsletter is delivered through Jetpack Subscriptions / WordPress.com. By signing up, you consent to receive an automatic welcome email and periodic newsletter messages from me. The newsletter is marketing content within the meaning of CAN-SPAM. You can unsubscribe at any time using the link at the bottom of every newsletter email or by emailing me directly. I will honor unsubscribe requests within ten business days.
5. Cookies, analytics, and international transfers
This Site is hosted on WordPress.com (Automattic Inc.) and uses Jetpack features including Subscriptions and Stats. Their privacy practices are governed by their own privacy policy. Embedded videos, fonts, and similar third-party content may set their own cookies when you load a page that includes them. You can disable cookies in your browser; some Site features may not work as a result.
International data transfers. Automattic operates servers and personnel in multiple countries, including the United States. If you visit this Site from outside the U.S., your information may be transferred to and stored in the U.S. Where required by EU/EEA or UK law, Automattic relies on Standard Contractual Clauses approved by the European Commission as the lawful transfer mechanism. By using the Site, you understand that information may be processed in the United States and other jurisdictions.
6. Important limits on confidentiality
This is the section that matters most for a clinician-run site. Please read carefully:
- This Site is not a clinical practice. Submitting a message, signing up for the newsletter, downloading a toolkit, or buying a course does not make you my client, patient, or supervisee. It does not create any professional duty of care between us beyond responding to your message.
- Email and web forms are not secure. Even though my forms are transmitted over HTTPS, web forms and standard email are not HIPAA-compliant communication channels. Do not send protected health information (PHI), confidential clinical details about yourself or others, or any sensitive information you would not be comfortable seeing in a non-clinical email exchange.
- HIPAA does not apply to this Site. The information collected through this Site is not protected health information under HIPAA. If you become a client through a separate, signed engagement, that clinical work is governed by separate clinical agreements and is HIPAA-protected; this Site is not.
- I may need to share information. I may disclose information you provide if I am legally required to (court order, subpoena, mandated reporting, threat of imminent harm) or if disclosure is necessary to protect someone’s safety. See section 7.
7. Mandated reporter notice
As a Licensed Clinical Social Worker in Colorado, I am a mandated reporter under C.R.S. § 19-3-304 (suspected child abuse or neglect) and C.R.S. § 26-3.1-102 (suspected mistreatment of an at-risk adult), and as required by my professional license. If, in the course of any communication, I learn information that gives me reasonable cause to suspect child abuse or neglect, abuse or exploitation of an at-risk adult, or imminent threat of harm to self or others, I am required by law to make the appropriate report to the appropriate agency (which may include child protective services, adult protective services, or law enforcement). This duty applies regardless of how I receive the information, including through this website’s contact form, email, or phone. Communications through this Site are not legally privileged.
8. Children’s privacy
This Site is intended for adults (18+). I do not knowingly collect personal information from children under 13, in compliance with COPPA. For California residents, I do not knowingly sell or share the personal information of consumers under 16. If you believe a child has provided information through this Site, contact me and I will delete it promptly.
9. Your rights and how to exercise them
Depending on where you live, you have rights regarding your personal information. Colorado residents have rights under the Colorado Privacy Act (CPA). California residents have rights under the CCPA / CPRA. Residents of the EU/EEA and UK have rights under the GDPR / UK GDPR. Residents of other states with comprehensive privacy laws have similar rights.
Depending on your jurisdiction, your rights may include:
- Access. Receive a copy of the personal information I have about you.
- Correction. Correct inaccurate personal information.
- Deletion. Request deletion of your personal information.
- Portability. Receive your personal information in a portable, machine-readable format.
- Opt out. Opt out of the sale or sharing of personal information for cross-context behavioral advertising. (I do not sell or share, but you can confirm this with me.)
- Limit use of sensitive personal information. Limit my use of your sensitive personal information to what is necessary to provide the service.
- Non-discrimination. I will not discriminate against you for exercising any of these rights.
- Appeal. Appeal any denial of a request.
To exercise any of these rights:
- Email me at Stephanie@TheSocialWorkProgressive.com with the subject line “Privacy Request.”
- Tell me which right you want to exercise and provide enough information for me to identify and respond.
- I will verify your identity by confirming the email address on file or asking for additional information.
- I will respond within 45 days for Colorado and California residents and within 30 days for EU/EEA and UK residents. If I need an extension, I will tell you within the original window.
- There is no charge for the first request in any 12-month period. Manifestly unfounded or excessive requests may be subject to a reasonable fee or denial.
- If I deny your request, you can appeal by replying within 60 days. I will reconsider within 45 days.
- If you are dissatisfied, you can lodge a complaint with the Colorado Attorney General, the California Privacy Protection Agency, or your local data protection authority.
You may use an authorized agent to submit a request on your behalf. I may require the agent to provide proof of authorization and may verify your identity directly.
10. Data retention
- Contact form submissions. Up to three years after the last interaction, then deleted on a rolling basis.
- Newsletter subscriber records. Until you unsubscribe, then 30 days for unsubscribe confirmation; a suppression record may be kept to honor your opt-out.
- Customer records for paid services. Seven years from the date of the last transaction (IRS retention period for tax records).
- Server logs and analytics. Per WordPress.com / Jetpack policies, typically rolling 30 to 90 days.
- Records required by my professional license or by law. Retained for the period required, then deleted.
You can request earlier deletion at any time, subject to legal retention requirements I cannot waive (for example, tax records).
11. Security and breach notification
This Site uses HTTPS encryption. WordPress.com hosting provides standard infrastructure-level security. No web service is perfectly secure. Please consider this whenever you decide what information to share.
In the event of a confirmed personal data breach that creates a risk to affected users, I will notify affected users without undue delay and no later than 72 hours after I become aware of the breach (consistent with GDPR Article 33), and I will comply with the notification timelines required under the Colorado Privacy Act, CCPA, HIPAA where applicable to a separate clinical engagement, and any other applicable law.
12. Changes to this policy
I may update this Privacy Policy. The “Effective” date at the top will reflect the most recent version. Continued use of the Site after a change indicates acceptance. Material changes will be flagged on the Site or by email to subscribers where required by law.
13. Contact
Questions, requests, or concerns about this Privacy Policy: Stephanie@TheSocialWorkProgressive.com.