<?xml version="1.0" encoding="UTF-8"?>
<!--
  Homepage and /privacy. The client proposal pages (/csa-proposal/,
  /rossville-proposal/, /slhs-proposal/, /ccp-proposal/) and
  /audit/harding-academy/ each carry a <meta name="robots" content="noindex">
  tag and are intentionally excluded.

  /privacy is listed deliberately. Meta's ad reviewers and A2P 10DLC carrier
  vetting both fetch it, so it must stay publicly crawlable and indexable.

  Note: those paths are deliberately NOT blocked in robots.txt. Blocking them
  there would stop crawlers from fetching the pages, which means they'd never
  read the noindex tag — making de-indexing less reliable, not more.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://havenroll.co/</loc>
    <lastmod>2026-07-28</lastmod>
    <changefreq>monthly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://havenroll.co/privacy/</loc>
    <lastmod>2026-07-29</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
</urlset>
