Privacy Policy
Effective Date: April 7, 2026
Last Updated: April 7, 2026
This Privacy Policy applies to all community websites operated on the Community-Websites.com platform, the Community-Websites.com website itself, and all associated applications and services.
Community-Websites.com, including its parent companies, subsidiaries, and affiliates (collectively, “Company,” “we,” “us,” or “our”) operates a network of local community websites and the Community-Websites.com platform (collectively, the “Site” or “Service”). This Privacy Policy describes how we collect, use, disclose, store, and protect personal information when you access or use the Site. By using the Site, you acknowledge and consent to the practices described herein.
This Privacy Policy is incorporated into and forms part of our Terms of Service.
1. Definitions
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you as an individual. It does not include de-identified, aggregated, or publicly available information that is not combined with Personal Information.
“Processing” means any operation performed on Personal Information, whether automated or manual, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
“Service Provider” means a third party that processes Personal Information on our behalf pursuant to a written agreement.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration: Full name, email address, and authentication credentials (one-time password tokens; we do not store plaintext passwords)
- Contact forms: Name, email address, phone number, subject, and message content
- Comments and user-generated content: Comment text, display name, and associated article metadata
- Newsletter subscriptions: Email address and subscription preferences
- Business directory submissions: Business name, address, phone, email, website, description, and category
- Advertising inquiries: Business name, contact name, phone, email, and areas of interest
- Correspondence: Any information you provide when communicating with us via email or other channels
2.2 Information Collected Automatically
- Log and usage data: IP address, browser type and version, operating system, device type, screen resolution, referring/exit URLs, pages visited, articles viewed, click paths, date/time stamps, and session duration
- Cookies and similar technologies: Data collected via cookies, web beacons, pixel tags, and local storage (see Section 6)
- Approximate location: City and region-level geographic location inferred from IP address only (we do not collect precise GPS coordinates)
- Interaction data: Newsletter open rates, click-through rates, comment engagement, and search queries
2.3 Information from Third Parties
- Analytics providers: Aggregated and pseudonymized usage data from Google Analytics or similar services
- Advertising partners: Ad impression, click, and conversion data
- Payment processors: Transaction confirmation and subscription status from Stripe (we never receive or store full payment card numbers)
Information We Do NOT Collect
- Full payment card numbers, bank account numbers, or financial credentials (all payment processing is handled exclusively by PCI DSS-compliant third parties)
- Social Security numbers, tax identification numbers, driver’s license numbers, or government-issued identification
- Biometric data (fingerprints, facial recognition, retinal scans)
- Genetic or health-related data
- Precise geolocation data (GPS coordinates)
- Personal information from children under 13 (see Section 14)
3. How We Use Your Information
We process Personal Information for the following purposes:
- Service provision and improvement: To operate, maintain, develop, and improve the Site, its features, and its content
- Account management: To create, manage, authenticate, and secure your account
- Communication: To send newsletters, community updates, editorial content, service announcements, and responses to your inquiries
- Personalization: To customize your experience and deliver content relevant to your interests and geographic area
- Analytics and research: To analyze usage patterns, measure content effectiveness, understand reader demographics, and make editorial and business decisions
- Advertising: To display relevant advertisements from local businesses and measure advertising campaign performance
- Fraud prevention and security: To detect, investigate, prevent, and respond to fraud, unauthorized access, abuse, and other harmful or illegal activities
- Legal and regulatory compliance: To comply with applicable laws, regulations, legal processes, subpoenas, court orders, and enforceable governmental requests
- Business operations: To manage internal operations including billing, auditing, compliance, record-keeping, and dispute resolution
- Enforcement: To enforce our Terms of Service and other agreements, and to protect the rights, property, and safety of the Company, our Users, and the public
- Business transactions: To facilitate due diligence and complete transactions involving a merger, acquisition, reorganization, asset sale, financing, or similar corporate event
4. Legal Bases for Processing (GDPR)
Where the General Data Protection Regulation (“GDPR”) or similar legislation applies, we rely on the following legal bases:
- Consent (Art. 6(1)(a)): Where you have given explicit, informed, and freely given consent (e.g., newsletter opt-in, non-essential cookies). You may withdraw consent at any time.
- Contract performance (Art. 6(1)(b)): Where processing is necessary to perform a contract with you or to take pre-contractual steps at your request (e.g., account registration, providing the Service)
- Legitimate interests (Art. 6(1)(f)): Where processing is necessary for our legitimate business interests, provided those interests are not overridden by your fundamental rights and freedoms (e.g., analytics, security, fraud prevention, direct marketing to existing subscribers)
- Legal obligation (Art. 6(1)(c)): Where processing is necessary to comply with a legal obligation to which we are subject
5. How We Share Your Information
We do not sell, rent, or trade your Personal Information to third parties for their own marketing purposes.
We may share Personal Information in the following limited circumstances:
- Service Providers: We engage trusted third-party service providers to perform functions on our behalf, including but not limited to: cloud hosting and infrastructure (Vercel, Supabase/AWS), email delivery (Resend), web analytics (Google Analytics), payment processing (Stripe), content delivery networks, and customer support tools. These providers are contractually bound to process Personal Information solely on our instructions, to maintain confidentiality, and to implement appropriate technical and organizational security measures.
- Within our corporate family: We may share information with our parent companies, subsidiaries, and affiliates for the purposes described in this Privacy Policy, subject to the same protections.
- Advertising measurement: We may share anonymized, aggregated, or de-identified data with advertising partners solely to measure campaign effectiveness. We do not share personally identifiable information with advertisers without your explicit consent.
- Legal requirements: We may disclose information when we believe in good faith that disclosure is required by law, regulation, subpoena, court order, search warrant, or other valid legal process, or is necessary to: (a) protect the safety of any person; (b) address fraud, security, or technical issues; (c) protect the rights or property of the Company; or (d) investigate or prevent illegal activity.
- Business transfers: In the event of a merger, acquisition, reorganization, bankruptcy, receivership, dissolution, or sale of all or a portion of our assets, Personal Information may be among the assets transferred. You will be notified via email and/or prominent notice on the Site of any such transaction and of any choices you may have regarding your information.
- With your consent: We may share information for other purposes with your express, informed consent.
6. Cookies and Tracking Technologies
6.1 Types of Cookies
Strictly Necessary
Authentication, session management, security tokens, CSRF protection. Cannot be disabled. No consent required.
Functional
Remember user preferences such as dark mode, language, and display settings.
Analytics
Anonymized usage data via Google Analytics (with IP anonymization enabled). Helps us understand traffic patterns and content performance.
Advertising
Third-party ad networks may set cookies to deliver relevant advertisements and track campaign performance across websites.
6.2 Managing Cookies. You can control and manage cookies through your browser settings. Most browsers allow you to block, delete, or alert you to cookies. However, if you disable or reject cookies, some parts of the Site may become inaccessible or function improperly. For more information, visit allaboutcookies.org.
6.3 Do Not Track Signals. The Site does not currently respond to “Do Not Track” (DNT) browser signals because no industry-standard protocol for DNT compliance has been established. If a universal standard is adopted, we will update this Policy accordingly.
6.4 Google Analytics. We use Google Analytics with IP anonymization enabled. Google processes data in accordance with its own privacy policy. You may opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on.
7. Data Retention
We retain Personal Information only for as long as reasonably necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by applicable law. Specific retention periods:
- Account data: For the duration of your active account. Upon account deletion request, we will delete or anonymize your data within thirty (30) days, except as otherwise required for legal compliance, fraud prevention, dispute resolution, or enforcement of our agreements.
- Comments and user-generated content: For as long as the associated article remains published. Comments may be anonymized (author name removed) rather than deleted upon account closure.
- Server logs: Retained for up to ninety (90) days for security and debugging purposes, then automatically deleted or anonymized.
- Analytics data: Individual-level analytics data retained for up to twenty-six (26) months. Aggregated and de-identified data may be retained indefinitely.
- Newsletter subscription records: Retained until you unsubscribe. We maintain an unsubscribe record indefinitely to honor your opt-out preference.
- Transactional email logs: Retained for up to twelve (12) months for deliverability monitoring and compliance.
- Legal holds: We may retain information for longer periods as required for pending or anticipated litigation, regulatory investigations, audits, or legal preservation obligations.
8. Data Security
We implement and maintain reasonable technical, administrative, and organizational security measures designed to protect Personal Information against unauthorized access, alteration, disclosure, destruction, loss, or misuse. These measures include:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS enforced site-wide)
- Encryption at rest: Sensitive data stored in our databases is encrypted at rest
- Access controls: Access to Personal Information is restricted to authorized personnel on a strict need-to-know basis, with role-based permissions
- Authentication: Secure authentication using one-time passwords (OTP) delivered via email; no plaintext passwords stored
- Vendor security: We assess the security practices of our service providers and require contractual commitments to data protection
- Infrastructure: Our infrastructure is hosted on enterprise-grade platforms (Vercel, Supabase/AWS) with their own SOC 2, ISO 27001, and PCI DSS compliance certifications
No Guarantee. Despite these measures, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security. In the event of a data breach, we will comply with all applicable breach notification laws (see Section 16).
9. Your Rights and Choices — All Users
Regardless of your location, you have the following rights with respect to your Personal Information:
- Access: You may request a copy of the Personal Information we hold about you.
- Correction: You may request that we correct inaccurate or incomplete Personal Information.
- Deletion: You may request that we delete your Personal Information, subject to exceptions for legal compliance, fraud prevention, and contractual obligations.
- Opt-out of marketing: You may unsubscribe from marketing communications at any time by clicking the “unsubscribe” link in any email or by contacting us.
- Cookie preferences: You may manage cookie settings through your browser (see Section 6).
- Data portability: Where technically feasible, you may request a copy of your data in a structured, commonly used, machine-readable format.
To exercise any of these rights, contact us at email@community-websites.com. We will verify your identity before processing requests and will respond within the timeframe required by applicable law (generally 30–45 days).
10. Additional Rights — California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, “CCPA/CPRA”):
- Right to Know: You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your Personal Information, subject to certain exceptions under CCPA/CPRA.
- Right to Correct: You may request correction of inaccurate Personal Information.
- Right to Opt Out of Sale/Sharing: We do not “sell” or “share” (as those terms are defined under CCPA/CPRA) your Personal Information. If this practice changes, we will provide a “Do Not Sell or Share My Personal Information” link.
- Right to Limit Use of Sensitive Personal Information: We do not use or disclose sensitive Personal Information for purposes beyond those permitted by CCPA/CPRA.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
Verification: To protect your privacy, we will verify your identity before fulfilling any request. We may ask for information that matches data we have on file. An authorized agent may submit a request on your behalf with proper documentation.
Response Time: We will acknowledge your request within ten (10) business days and provide a substantive response within forty-five (45) calendar days. If additional time is needed, we will notify you of the extension (up to 90 total days).
To submit a CCPA/CPRA request, email email@community-websites.com with the subject line “CCPA Request.”
11. Additional Rights — EEA, UK, and Swiss Residents (GDPR)
If you are located in the European Economic Area (“EEA”), United Kingdom (“UK”), or Switzerland, you have the following additional rights under the General Data Protection Regulation (“GDPR”) and/or the UK GDPR:
- Right of Access (Art. 15): Right to obtain confirmation of whether we process your Personal Information and to receive a copy.
- Right to Rectification (Art. 16): Right to have inaccurate Personal Information corrected without undue delay.
- Right to Erasure (Art. 17): Right to have your Personal Information erased under certain circumstances (“right to be forgotten”).
- Right to Restriction (Art. 18): Right to request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): Right to receive your Personal Information in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to Object (Art. 21): Right to object to processing based on legitimate interests or for direct marketing purposes.
- Right Not to Be Subject to Automated Decision-Making (Art. 22): Right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently engage in such processing.
- Right to Withdraw Consent: Where we process your Personal Information based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority. A list of EEA authorities is available at edpb.europa.eu.
To exercise your GDPR rights, contact email@community-websites.com. We will respond within thirty (30) days.
12. Additional Rights — Nevada Residents
Under Nevada Revised Statutes Chapter 603A, Nevada residents have the right to opt out of the sale of certain “covered information.” We do not sell covered information as defined under Nevada law. If you are a Nevada resident and wish to submit a request, contact us at email@community-websites.com.
13. International Data Transfers
Your Personal Information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from and may be less protective than those in your jurisdiction.
By using the Site, you expressly consent to the transfer of your information to the United States and other countries as described herein. Where required by applicable law (such as the GDPR), we implement appropriate safeguards for cross-border data transfers, including Standard Contractual Clauses approved by the European Commission or equivalent mechanisms.
14. Children’s Privacy
The Site is not intended for and is not directed at children under thirteen (13) years of age. We do not knowingly collect, solicit, or maintain Personal Information from anyone under 13. If you are a parent or guardian and believe that your child under 13 has provided us with Personal Information, please contact us immediately at email@community-websites.com. We will take prompt steps to verify and delete such information from our records.
If we become aware that we have inadvertently collected Personal Information from a child under 13 without verified parental consent, we will delete that information as quickly as possible.
15. Third-Party Services and Links
The Site may contain links to, or integrate with, third-party websites, applications, platforms, and services (“Third-Party Services”). This Privacy Policy does not apply to Third-Party Services. We do not control the privacy practices of third parties and are not responsible for how they collect, use, or disclose your information. We encourage you to carefully review the privacy policy of each Third-Party Service you access.
Specific third-party services we use include, but are not limited to: Google Analytics (analytics), Stripe (payments), Resend (email delivery), Vercel (hosting), and Supabase (database). Each has its own privacy policy governing its use of your data.
16. Data Breach Notification
In the event of a data breach involving your Personal Information that poses a risk to your rights and freedoms, we will:
- Notify affected individuals without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach (or as otherwise required by applicable law)
- Notify applicable regulatory authorities as required by law
- Provide information about the nature of the breach, the types of information involved, the likely consequences, and the measures we are taking to address and mitigate the breach
- Cooperate with law enforcement and regulatory bodies as appropriate
17. Changes to This Privacy Policy
We may update, revise, or amend this Privacy Policy from time to time in our sole discretion. When we make material changes, we will: (a) update the “Last Updated” date at the top of this page; and (b) where required by law or where changes are significant, notify registered Users via email.
Your continued use of the Site after the effective date of any revised Privacy Policy constitutes your acceptance of and agreement to the updated terms. If you do not agree, your sole remedy is to discontinue use of the Site and request deletion of your account.
We encourage you to review this Privacy Policy periodically to stay informed of how we protect your information.
18. Contact Information and Data Requests
Data Controller: Community-Websites.com
General Inquiries & Privacy Requests: email@community-websites.com
Website: community-websites.com
CCPA Requests: Email with subject line “CCPA Request”
GDPR Requests: Email with subject line “GDPR Request”
Data Deletion Requests: Email with subject line “Data Deletion Request”
We aim to acknowledge all privacy-related inquiries within five (5) business days and provide a substantive response within thirty (30) calendar days, or within the timeframe required by applicable law, whichever is shorter.
Questions? Contact us at email@community-websites.com
