Privacy Policy
1. Who We Are
Marin Buzz ("we," "us," or "our") operates the website at app.marinbuzz.com and marinbuzz.com. We publish local news, event coverage, and community content focused on Marin County, California.
This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our website, sign up for our newsletter, join our Marin Buzz Insider Texts list, or purchase event tickets. By using our services, you agree to the practices described in this Policy.
For questions or to exercise your rights, contact us at: privacy@marinbuzz.com or by mail at: Marin Buzz, [Address], Marin County, CA.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples | Collected On |
|---|---|---|
| Contact Information | First name, last name, email address | /subscribe, /ticket |
| Phone Number | Mobile phone number (E.164 format) | /insider-texts, /ticket (optional) |
| Payment Information | Credit/debit card (processed by Stripe; we never see raw card numbers) | /ticket |
| Consent Records | Checkbox confirmation, legal text version, timestamp | All form pages |
2.2 Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Device & Browser Info | User agent string, browser type, operating system, device type | Security, fraud prevention, consent verification |
| IP Address | Your internet protocol address at time of form submission | Jurisdiction verification (California), fraud prevention |
| Interaction Data | Pages visited, buttons clicked, form interactions | Analytics (only after you consent — see Section 4) |
| Cookies & Tracking Pixels | GTM cookies, Meta Pixel, Google Analytics | Marketing analytics (only after you consent — see Section 4) |
2.3 Sensitive Personal Information
We collect your precise geolocation only in the form of your IP address (used solely to determine California vs. non-California jurisdiction for legal compliance). We do not use this for advertising targeting. We do not collect biometric data, health information, racial/ethnic origin, religious beliefs, or financial account numbers (payment is handled entirely by Stripe).
3. How We Use Your Information
- To fulfill your requests: Subscribe you to our newsletter, add you to our Marin Buzz Insider Texts list, or process your event ticket purchase.
- To send communications you've opted into: Email newsletters via Beehiiv; SMS event alerts and news via Twilio (only if you've provided prior express written consent).
- To process payments: Create a Stripe Checkout session; confirm ticket purchases via Stripe webhook.
- To maintain a consent audit trail: Store proof of your consent in our database to defend against legal claims (TCPA, CIPA). This is a legal obligation and the data is retained indefinitely.
- For analytics and marketing (with your consent only): After you check the consent checkbox, we may record and process your site interactions via Google Tag Manager, Meta Pixel, Google Analytics, and similar tools.
- For fraud prevention and security: IP address and user agent data are used to detect abuse, spam signups, and fraudulent purchases.
- To comply with legal obligations: Respond to California CCPA/CPRA data requests; maintain records required by law.
4. Analytics & Tracking Technologies
4.1 Consent-Gated Tracking
When you check the "I agree" checkbox on any of our forms, you are providing prior express written consent for us to activate the following tracking tools during your session and thereafter:
- Google Tag Manager (GTM): Container that loads and manages our marketing
tags. GTM fires the
consent_grantedevent only after your checkbox interaction. Google's Privacy Policy: policies.google.com/privacy - Meta Pixel (Facebook): We set Meta's
dataProcessingOptions: ['LDU'](Limited Data Use mode) for California IP addresses before loading the pixel, restricting Meta from using your data for targeted advertising without your further consent. Meta's Privacy Policy: facebook.com/privacy/policy - Google Analytics 4: Aggregated, anonymized analytics on site usage. IP anonymization is enabled.
- TikTok Pixel (if applicable): Activated only after consent.
4.2 Global Privacy Control (GPC)
Our site honors the Global Privacy Control (GPC) browser signal, a recognized opt-out
mechanism under California law. If your browser sends a GPC signal
(navigator.globalPrivacyControl === true), our site will automatically
disable all marketing tracking, hide the consent checkbox, and display a notice that your
preference has been honored. We will never override a GPC signal.
4.3 Cookies
We do not set any third-party marketing cookies until you provide consent. We may set a first-party session cookie for form security (CSRF protection). Third-party cookies set after consent are governed by the respective third parties' policies linked above.
You can manage or delete cookies at any time via your browser settings. Note: deleting cookies does not retroactively delete consent records already stored in our database.
4.4 CIPA Compliance
California's Invasion of Privacy Act (CIPA) governs the recording of electronic communications and session activity. We do not activate session recording, heatmap tools, or interaction replay tools (such as Hotjar, FullStory, or similar) without prior express written consent. Our consent checkbox explicitly covers "the recording and processing of my site interactions for analytics and marketing."
5. SMS / Text Message Communications
5.1 Marin Buzz Insider Texts
If you join our Marin Buzz Insider Texts list at app.marinbuzz.com/insider-texts or opt in during ticket purchase, you are providing prior express written consent under the Telephone Consumer Protection Act (TCPA) for Marin Buzz to send you recurring marketing text messages at the mobile number you provided.
Message content may include: early access to event ticket sales, event invitations, and promotional offers. Message and data rates may apply. Approximately 1–4 messages per week.
5.2 How to Opt Out
Reply STOP to any text message to immediately unsubscribe. After opting out, you will receive a single confirmation message and no further marketing texts will be sent. Reply HELP for assistance or contact us at privacy@marinbuzz.com.
5.3 Our SMS Provider: Twilio
We use Twilio, Inc. to send text messages. Twilio may process your phone number on our behalf as a service provider. Twilio does not use your phone number for their own marketing purposes. Twilio Privacy Policy: twilio.com/legal/privacy
5.4 No Sharing of SMS / Mobile Information with Third Parties
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of personal information described in this Privacy Policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We share your mobile phone number only with the service providers strictly necessary to deliver the messages you have requested — specifically Twilio (our SMS gateway) and Beehiiv (our email/CRM platform, where the phone number is stored on your subscriber record). Neither vendor is permitted to use your phone number for their own marketing.
We will never sell, rent, lease, or share your mobile phone number, your SMS opt-in status, or your SMS consent record with advertisers, data brokers, marketing partners, sponsors, event venues, or any other third parties for their marketing or promotional use.
5.5 Consent is Not a Condition of Purchase
You are never required to consent to SMS marketing as a condition of purchasing event tickets or accessing any Marin Buzz content. On the /ticket page, SMS opt-in is clearly marked as optional.
6. Email Communications & Beehiiv
We use Beehiiv, Inc. as our email newsletter platform. When you subscribe to our newsletter, your name and email address are transmitted to Beehiiv's servers and stored in your subscriber record. We also transmit the following custom data fields to Beehiiv for compliance record-keeping:
sms_consent_status— whether you opted in to SMS marketinglegal_terms_version— the version of the legal text you agreed toconsent_timestamp— the date and time you submitted the formsource_page— which page you subscribed from
Beehiiv acts as a data processor on our behalf. Beehiiv does not sell your email address to third parties for their own marketing. Beehiiv Privacy Policy: beehiiv.com/privacy
You may unsubscribe from our email newsletter at any time by clicking "Unsubscribe" in any email we send, or by emailing privacy@marinbuzz.com.
7. Payments & Stripe
Event ticket purchases are processed by Stripe, Inc. via Stripe Checkout, a PCI-DSS Level 1 certified hosted payment page. We never receive, store, or process your full credit card number, CVV, or raw payment credentials. Stripe receives your payment information directly.
We receive from Stripe: a payment confirmation, your email address, and the Stripe Checkout Session ID (which we link to your consent record in our database). We use this to confirm your ticket purchase and trigger your newsletter/SMS enrollment if applicable.
Stripe Privacy Policy: stripe.com/privacy
8. Event Photography & Media
Marin Buzz hosts and co-hosts live events (for example, the Sausalito Music Party and the Spring Gala). Photographers and videographers engaged by Marin Buzz — as well as members of the press — may take photos, audio recordings, and video of attendees at these events, including wide shots of the venue, audience, and performers.
By purchasing a ticket and attending a Marin Buzz event, you acknowledge and agree that:
- You may be photographed, filmed, or recorded at the event.
- Marin Buzz, its affiliates, sponsors, and assigns may use your likeness, voice, and any recording of your attendance in photos, video, social media posts, press releases, newsletters, our website, advertising, promotional materials, and editorial coverage of the event — in all media, worldwide, in perpetuity, without further notice, approval, or compensation to you.
- We will not use your likeness in a manner that falsely endorses a product or service, and we will not pair your image with defamatory or degrading content.
- If you prefer not to be photographed or filmed, please notify a Marin Buzz staff member at the event and we will make a reasonable effort to accommodate — we cannot, however, guarantee exclusion from wide crowd shots or incidental capture.
Removal requests. If you appear in published Marin Buzz content and would like it removed, email privacy@marinbuzz.com with a link to the content and a description of where you appear. We will review and act on reasonable requests promptly. Note that we may not be able to remove content that has been re-shared by third parties outside our control.
Minors. If you bring a minor to the event, you are responsible for the same acknowledgment on their behalf as parent or legal guardian. See Section 11 (Children's Privacy) for additional information.
9. How We Share Your Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising without your consent. We share your information only in the following limited circumstances:
- Service Providers (Processors): Beehiiv (email), Twilio (SMS), Stripe (payments), Cloudflare (hosting/infrastructure). These parties process data on our behalf and are contractually prohibited from using it for their own purposes.
- Analytics Partners (with consent only): Google (GTM, Analytics), Meta (Pixel), and similar tools — activated only after you check the consent checkbox.
- Legal Obligations: We may disclose your information if required by law, court order, subpoena, or government request. We will notify you if legally permitted to do so.
- Business Transfer: If Marin Buzz is acquired, merged, or sold, your information may be transferred as part of that transaction. We will notify you of such a change via email or prominent notice on our website.
We do not share your phone number or email with event venues, sponsors, or advertising partners without your separate, explicit consent.
SMS / mobile information is not shared with third parties for marketing or promotional purposes under any circumstances. See Section 5.4 for the full SMS data-sharing disclosure. SMS originator opt-in data and consent are excluded from every other sharing category described in this Policy.
10. Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| Consent Audit Records (D1 database) | Indefinitely (minimum 5 years) | Legal defense under TCPA/CIPA; proof of consent |
| Email Subscriber Data (Beehiiv) | Until unsubscribe + 90 days | Newsletter delivery; reactivation window |
| SMS Subscriber Data (Twilio) | Until STOP reply + 90 days | Opt-out list management; TCPA compliance |
| Payment Records (Stripe) | 7 years | Financial/tax records requirement |
| IP Address & User Agent (consent log) | Indefinitely | Jurisdiction verification; anti-fraud |
11. Children's Privacy
Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected information from a child under 13, we will delete it promptly. If you believe we have collected information from a child under 13, please contact us at privacy@marinbuzz.com.
12. Your California Privacy Rights (CCPA / CPRA 2026)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), effective January 1, 2023 and as updated through 2026:
How to Submit a Request
To exercise any of the rights above, submit a request via:
- Email: privacy@marinbuzz.com with subject line "CCPA Privacy Request"
- Our Your Privacy Choices page
We will verify your identity before processing requests. For deletion requests, we may ask you to confirm your email address and provide the approximate date you submitted a form on our website. We will respond within 45 days. If we need more time, we will notify you and may extend the deadline up to 90 days total.
Authorized Agent
You may designate an authorized agent to submit requests on your behalf. The agent must provide a signed written authorization from you. We may still require you to directly verify your identity.
Do Not Sell or Share My Personal Information
We do not sell your personal information in the traditional sense. We may share information with analytics and advertising platforms (Google, Meta) after you provide consent. If you wish to opt out of this sharing, you can:
- Visit our Your Privacy Choices page
- Enable Global Privacy Control in your browser
- Email us at privacy@marinbuzz.com
13. Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- All data is transmitted over HTTPS (TLS 1.2 or higher)
- API keys and secrets are stored in encrypted Cloudflare Worker Secrets, not in source code
- Our consent database is hosted on Cloudflare's D1 with access restricted to our Workers
- Payment data is handled entirely by Stripe (PCI-DSS Level 1 compliant)
- Rate limiting is applied to all form submission endpoints to prevent abuse
No security system is impenetrable. If you believe your information has been compromised, please contact us immediately at privacy@marinbuzz.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Effective Date" and "Version" at the top of this page
- Increment the legal text version identifier (e.g., from April-2026-v2 to May-2026-v3)
- Send notice to email subscribers if the changes materially affect how we use their data
Continued use of our services after the effective date constitutes your acceptance of the updated Policy. We encourage you to review this page periodically.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:
- Email: privacy@marinbuzz.com
- Subject Line: "Privacy Request" or "CCPA Request"
- Response Time: We aim to respond within 5 business days for general inquiries and within 45 days for formal CCPA requests.