Effective date: August 18, 2026
1. Who We Are and What This Policy Covers
Community 1 Marketing LLC (“Community 1 Marketing,” “we,” “us,” or “our”) is a digital marketing agency based in Phoenix, Arizona. We serve small and mid-market businesses across the United States and Canada, with a particular focus on private practices such as medical and dental offices.
This Privacy Policy explains what happens to personal information when you visit or contact us through community1marketing.com (the “Site”). It describes the information we collect on the Site, why we collect it, who else sees it, and what choices you have.
This policy covers the Site. It is not your services agreement. If you are a paying client, the handling of your accounts and your business data is governed by the contract between us and by our Terms of Service. Section 8 below explains, in general terms, how we treat client data, but your signed agreement controls if there is any conflict.
This policy is a description of our privacy practices. It is not a contract, and it does not create rights beyond the ones the law gives you. The binding terms for your use of the Site are in our Terms of Service. If you are not comfortable with the practices described here, please do not submit information through the Site.
If more than one of our documents applies to you, they rank in this order: a signed Business Associate Agreement controls for Protected Health Information, then a signed services agreement or statement of work, then our Terms of Service, then this Privacy Policy.
2. Information We Collect
Information you give us directly
There is one form we use to collect inquiries on the Site: the contact form on our Contact page. It is built with Elementor Pro Forms and collects only these fields:
- First Name
- Last Name
- Message (whatever you choose to write)
There is no phone number field on the form. We do not ask for your company size, your budget, or any other detail through the form.
When you submit that form, the entry is stored in the WordPress database behind the Site (in the Elementor Submissions area) and is also emailed to us so a human sees it.
Comments. WordPress includes a built-in commenting feature, and it is enabled on this install. We do not run a comment program and we do not take inquiries that way. If a comment form appears on a page and you submit a comment, WordPress records the name, email address, and website address you type, the text of your comment, your IP address, and your browser’s user agent string, and stores them in the site database. Comments are moderated, and we may decline to publish any comment. If we later turn on a spam filtering service, comment data will also pass to that service, and we will name it in Section 4 before that happens. To have a comment and the data attached to it removed, use the contact details in Section 12.
You can also reach us outside the form, by emailing help@community1marketing.com or by calling +1 (952) 237-4251. In that case we have whatever you choose to tell us: your name, your email address, your phone number, your business name, and the contents of your message. If you call us, we may keep a written note of the conversation. Please do not include sensitive personal information, such as health information, financial account numbers, or government ID numbers, in a form submission, an email, or a voicemail.
Information collected automatically
Like nearly every website, the Site and its hosting infrastructure record basic technical information when a page loads:
- Server access logs kept by our web host, which typically include your IP address, the date and time of the request, the page or file requested, the referring page, and your browser’s user agent string.
- Browser details contained in those requests, such as browser type and version, operating system, and the preferred language your browser sends. Because no analytics or session recording script runs on the Site, we do not collect screen size, mouse movement, scroll depth, clicks, or time on page.
- WordPress and Elementor cookies, described in Section 3 below.
We do not use these logs to build a profile of you. They exist so the Site can run, so we can investigate errors, and so we can spot abuse such as brute-force login attempts.
What we do not collect on the Site
We want to be specific here, because many privacy policies claim tracking that is not actually happening. As of the effective date of this policy:
- No analytics tag is installed on the Site. There is no Google Analytics or GA4 tag, no Google Tag Manager container, no Meta (Facebook) pixel, no LinkedIn or TikTok pixel, and no Hotjar or Microsoft Clarity session recording. We verified this by inspecting the pages the Site actually serves.
- No advertising or retargeting pixels. We do not build advertising audiences from visitors to the Site, and we do not retarget you across the internet based on your visit here.
- No payments are taken through the Site. We do not have a checkout, a shopping cart, or a payment form. We never collect credit card numbers, debit card numbers, or bank account details through the Site. Client invoicing happens elsewhere.
- No sensitive category data is requested. We do not ask for Social Security numbers, driver’s license numbers, passport numbers, precise geolocation, biometric data, or health information through the Site.
- No information from children. This is a business-to-business site. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. We have never sold or shared the personal information of anyone under 16, and we do not do so. If you believe a person under 16 has given us information, email help@community1marketing.com and we will delete it promptly.
We may add analytics or advertising measurement tools in the future, since measurement is part of the work we do. If we do, we will update this policy and the list above before or at the time those tools go live. If a tool would involve selling or sharing personal information as California law defines those terms, or would set a cookie that requires consent, we will add the opt out and the consent mechanism described in Sections 3 and 6 at the same time.
3. Cookies and Similar Technologies
A cookie is a small text file a website stores in your browser. The Site uses only functional cookies, meaning cookies that help it work rather than cookies that track you for advertising.
| Set by | Purpose |
|---|---|
| WordPress | Core site functions. Login and session cookies are set only for our own staff when we log in to administer the Site. If a comment is left on the Site, WordPress may store the commenter’s name, email, and website in a cookie so the fields can be pre-filled next time. |
| Elementor and Elementor Pro | Page display and form handling. Elementor and Elementor Pro may set functional cookies that help pages and forms behave correctly as you move around the Site. They are not used to advertise to you or to track you on other websites. |
| Google reCAPTCHA | Spam and bot protection on pages that contain a form. See Section 4. |
We do not set any advertising or analytics cookie on the Site, and we do not use cookies to track you across other websites. The only third-party cookie involved is the one Google’s reCAPTCHA service uses for bot detection on pages that contain a form. For that reason we do not display a cookie consent banner. If we later add cookies that require consent, we will add an appropriate consent mechanism at that time.
How to control cookies: every major browser lets you see the cookies a site has set, delete them, block third-party cookies, or block cookies entirely. Look under Settings, then Privacy or Site Settings, in Chrome, Safari, Firefox, or Edge. Blocking cookies may break the contact form’s spam protection and could prevent your message from going through.
Some browsers send a “Do Not Track” or Global Privacy Control signal. Because we do not run cross-site advertising trackers on the Site and do not sell or share personal information for cross-context behavioral advertising, there is nothing here for such a signal to turn off. We honor it by default simply by not doing that tracking.
4. Third Parties That Receive Data
We keep our vendor list short. These are the service providers that can come into contact with information from the Site, and what each one does:
- Google reCAPTCHA (Google LLC) protects the contact form from bots and spam. It is loaded on pages containing a form, and to reduce page weight it loads only after a short delay or when you interact with the form. reCAPTCHA collects device and browser information, and may also collect your IP address and how you interact with the page. It sends that information to Google, which scores whether you are a human. Your use of reCAPTCHA is subject to Google’s Privacy Policy and Google’s Terms of Service. We do not receive a copy of the underlying data Google collects. What comes back to the Site is Google’s verification result, which indicates how likely it is that the submission came from a person rather than a bot.
- Our web hosting provider stores the Site files and the WordPress database, which means it stores your contact form submission, and it generates the server access logs described in Section 2.
- Our transactional email tooling (Site Mailer and WP Mail SMTP) sends the contact form notification from the Site to our inbox. Site Mailer is an email delivery service. WP Mail SMTP is the plugin on our site that hands the message to a delivery service. The contents of your message pass through that delivery service on the way to us.
- Our backup provider (WPvivid) creates backup copies of the Site and its database so it can be restored after a failure or a security incident. Because form submissions live in the database, they are included in those backups.
- Google (Gmail) delivers the notification emails this Site sends and hosts our company inboxes, so your message sits in a Google-hosted mailbox once it reaches us.
We may also disclose information when the law requires it, in response to a valid legal request, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of all or part of our business. If ownership of the business changes, we will note it here.
We do not authorize any of these vendors to use your information to market to you on their own behalf, and our agreements with them limit them to providing the service we bought. One exception is worth naming: Google sets its own terms for reCAPTCHA and may use what it collects to improve reCAPTCHA and for general security purposes, as described in the Google policies linked above. We do not control that use, and it is the reason we load reCAPTCHA only on pages that have a form, and only after a delay or when you interact with the form.
5. How We Use the Information
We use the information described above only for these purposes:
- To answer you. If you fill out the contact form, email us, or call us, we use your contact details to reply, to schedule a conversation, and to prepare a proposal for the services and package levels you asked about.
- To provide and improve our services. If you become a client, your contact information becomes part of our client records so we can perform the work and reach you.
- To follow up on an inquiry. We may send you a small number of follow-up messages about the specific inquiry you made. We do not add contact form submitters to a general marketing mailing list without asking. If you tell us to stop contacting you, we will.
- For security and integrity. To block spam, detect abuse, investigate suspicious activity, and keep the Site online.
- For legal and accounting reasons. To keep records, resolve disputes, enforce our Terms of Service, and comply with applicable law.
6. We Do Not Sell or Rent Personal Information
We do not sell your personal information. We do not rent it, and we do not trade it. We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding twelve months. If we ever add an advertising or measurement tag to the Site that would count as selling or sharing under California law, we will update this policy before that tag goes live and add the opt out California requires at the same time, including a “Do Not Sell or Share My Personal Information” link and honoring the Global Privacy Control signal.
Under laws that require a legal basis for processing, we rely on:
- Your consent, when you voluntarily submit the form or send us a message.
- Our legitimate interests, in responding to business inquiries and keeping the Site secure.
- Steps taken at your request before entering into a contract, such as preparing a proposal.
- Compliance with legal obligations.
7. How Long We Keep Information, and How It Is Protected
Retention
- Contact form submissions. We keep an inquiry while the conversation is live and then for our business records. Our criteria are these: how long we need it to answer you, whether it became a client relationship, and whether we still need it for a tax, accounting, or legal record. If an inquiry does not become a client relationship, we delete it once it is no longer useful for follow up and no longer needed for a legal record, and in any event no later than 24 months after our last contact with you. If the inquiry becomes a client relationship, the record is kept as a client record under the next bullet.
- Client records are kept for the length of the engagement and afterward for as long as we need them for tax, accounting, contractual, and legal purposes.
- Server logs are kept on our host’s rolling schedule, typically a matter of weeks, and are then overwritten. Backups are kept on a rolling schedule and overwritten in the ordinary course, which means a copy of your submission may sit in a backup for a period after we delete it from the live site. We do not open backups to edit individual records, but any restored backup is re-cleaned against deletion requests we have already honored.
If you ask us to delete your information sooner, see Section 9.
Security
We take website security seriously, because it is part of what we sell. We use HTTPS across the Site, apply WordPress core and plugin updates, limit administrative access to the people who need it, use bot protection on the contact form, and run regular file and database backups with WPvivid.
That said, we will be honest with you: no website, no server, and no method of transmitting data over the internet is completely secure. We cannot guarantee that information sent to us or stored by us will never be accessed by an unauthorized party. Please do not send us sensitive personal information through the Site’s contact form or by unencrypted email.
If something goes wrong. If we discover a security incident that compromises personal information we hold, we will investigate it, take steps to contain it, and notify affected individuals, regulators, and clients where notice is owed, in the manner and within the time applicable law requires. That includes Arizona’s data breach notification statute, the breach notification law of any other state that applies to the affected individuals, and, for personal information of individuals in Canada, reporting to the Office of the Privacy Commissioner of Canada where the incident creates a real risk of significant harm. If an incident affects a client’s website, hosting account, or data, we will notify that client promptly so the client can meet its own notification obligations, including any obligation under the HIPAA Breach Notification Rule.
Nothing in this section is a warranty or a guarantee. We describe our security practices so you know what we do, not to promise a particular outcome, and we may change specific tools and practices as better ones become available. Our liability for any claim relating to this policy, to the security of the Site, or to information you send us is limited as set out in our Terms of Service.
8. Client Data: Information We Handle While Performing Services
This section is different from everything above. Sections 1 through 7 describe visitors to community1marketing.com. This section describes the data we touch when we do paid marketing work for a client.
One clarification, since this section describes our services: nothing in this Privacy Policy is a promise about marketing results. Search rankings, advertising performance, lead volume, and traffic depend on factors outside our control, including the platforms themselves and the client’s own market. What we commit to on performance, and what we do not, is set out in our Terms of Service.
What we handle
To deliver services such as Google Ads management, SEO, website design and development, hosting, content and social media posting, and reporting, a client may give us access to systems including:
- Website admin accounts, hosting accounts, domain registrars, and DNS
- Google Ads, Google Business Profile, Google Search Console, Google Analytics, and Apple Maps listings
- Social media accounts such as Facebook and Instagram
- Business content: photos, service descriptions, staff bios, logos, reviews, and similar material
- Leads and inquiries generated through a website we build or manage for that client
How we treat it
Roles matter here. For data we handle on a client’s behalf, the client is the business or controller and we act as a service provider under the California Consumer Privacy Act, as a processor under comparable state laws, and as a supplier processing personal information on the client’s behalf under PIPEDA. We process that data only on the client’s documented instructions and only to perform the services we were engaged for. We do not retain, use, or disclose it for any other purpose, we do not combine it with data from other clients or from other sources, and we do not sell or share it. The specific contract terms these laws require, along with each party’s confidentiality, security, and indemnity obligations and the client’s responsibility for the data it gives us the right to handle, are set out in the client’s services agreement and our Terms of Service, not in this policy.
- We access client accounts only to perform the services the client engaged us for.
- Credentials go to the smallest number of team members who need them. Where a platform allows it, we ask for delegated or invited access (for example, being added as a user on an ad account or a Google Business Profile) instead of a client’s own password.
- Where a client’s website collects leads, that data belongs to the client. We are handling it on the client’s behalf, not for our own purposes. We do not use one client’s data to benefit another client, and we do not sell it.
- When an engagement ends, the client may ask us to return or delete the material we hold and to remove our access to their accounts, and we will do that within a reasonable period, keeping only what we must keep for legal, tax, or routine backup reasons. Ownership of custom content we create is set out in our Terms of Service and on the service levels page, where full ownership of custom content is included from the Bronze package upward. In short: ownership of the custom content we create for a client transfers to that client, licensed and registered in the client’s name, once the amounts due for that work are paid in full, and until then the client has a limited license to use it. Ownership does not extend to third-party material we license on a client’s behalf, such as stock photography, fonts, plugins, themes, and software, which stay subject to their own licenses. It also does not extend to the general tools, templates, know-how, and processes we use across our business. Unless a client asks us in writing not to, we may show completed work in our portfolio and case studies.
- Clients should ask their own visitors for consent and publish their own privacy policy. We can help implement it, but the client remains the party responsible for its own site’s privacy compliance.
Protected Health Information, HIPAA, and Business Associate Agreements
Many of our clients are medical and dental practices, so we want to be precise about this.
We do not seek, want, or ask to receive Protected Health Information (PHI). Our services are designed so that we work with marketing material, website content, advertising accounts, and aggregate performance data, not with patient records. We ask practices not to send us patient names, patient charts, appointment details tied to an identifiable patient, or any other PHI, including in screenshots, email attachments, or shared folders.
When we build, host, or manage a website for a healthcare practice, we may become a business associate by operation of law, whether or not anyone uses that term. If a practice’s website carries a patient appointment request, new patient, or contact form, what a patient submits through it can be Protected Health Information, and we transmit and store it. For that reason we require a signed Business Associate Agreement (BAA) before we build, host, or administer any client system through which patient inquiries flow, and we configure hosting, access, and retention for those clients accordingly. The BAA, not this Privacy Policy, sets our obligations for that data. Where no BAA is in place, we are not authorized to receive PHI, and any PHI sent to us in error should be reported to help@community1marketing.com so we can secure it, return or delete it at the practice’s direction, and tell the practice what happened.
Tracking and advertising technology on healthcare client websites. Analytics tags, conversion tags, advertising pixels, session recorders, and chat widgets can transmit patient identifiers and browsing activity to third parties. We do not place any of these on a healthcare client’s website, appointment pages, or patient portal pages without the client’s written direction. We do not configure tracking that would disclose individually identifiable health information to an advertising platform unless the practice has its own written agreement with that platform permitting it. Where a practice asks us to measure conversions, we configure the tags to avoid sending identifiable patient data, and we document for the practice what each tag collects. The practice, as the covered entity, makes the final decision about what its own HIPAA policies permit.
Our marketing materials describe a HIPAA and ADA compliance commitment. That commitment is about how we build and maintain a client’s website and marketing assets: for example, building forms and pages with appropriate safeguards and following recognized accessibility guidance. It is not a legal opinion, a certification, or a guarantee that a practice as a whole is HIPAA compliant or that a website will never draw an accessibility complaint. Compliance depends on the practice’s own policies, staff, and other systems. Please see our Terms of Service for the full scope of that commitment.
9. Your Privacy Rights
Everyone
Whatever state or country you live in, you can ask us to tell you what information we hold about you, correct it, or delete it. Email help@community1marketing.com with the request and enough detail for us to find your record, such as the email address you used when you contacted us. We will respond within a reasonable time, and in any event within the timeframe the applicable law requires.
We may need to verify who you are before acting, usually by confirming that you control the email address associated with the information. We will not ask you for sensitive documents to verify a routine request. An authorized agent may submit a request on your behalf with written proof of authorization.
California residents (CCPA and CPRA)
If you are a California resident, you have the right to:
- Know what categories of personal information we have collected about you, the sources, the business purpose, and the categories of third parties we disclosed it to.
- Access the specific pieces of personal information we hold about you.
- Delete personal information we collected from you, subject to legal exceptions such as records we must keep.
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information, and to limit the use of sensitive personal information. As stated in Section 6, we do not sell or share personal information and we do not collect sensitive personal information through the Site, so there is nothing to opt out of. This includes the personal information of anyone we know to be under 16.
- Not be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or give you a lower quality of service because you made a privacy request.
For reference, using the categories the California Consumer Privacy Act uses, we collect identifiers (first name, last name, email address, the phone number you give us if you call or write, and IP address) and internet or other electronic network activity information (the server log entries and browser details described in Section 2). We collect them from you directly and automatically from your device, and we use them for the business purposes listed in Section 5. In the preceding twelve months we disclosed them for a business purpose only to the categories of recipients named in Section 4: our web hosting provider, our email delivery providers, our website backup provider, our bot protection provider, and the providers of our own email and business software. We did not disclose personal information to any third party for that third party’s own purposes. We do not collect sensitive personal information as the CCPA defines it.
We retain each of these categories for the periods and on the criteria described in Section 7. Where a fixed period is not practical, the criteria we use are how long we need the information to answer you or perform a contract, how long we must keep it for tax, accounting, or legal reasons, and whether we need it to resolve a dispute or enforce our agreements.
How we handle a request. Email help@community1marketing.com or call +1 (952) 237-4251. We will confirm we received your request within ten business days and respond within forty five days. If we need more time, we will tell you within that first forty five days and take no more than forty five additional days. If we deny your request in whole or in part, we will tell you why. You may appeal. Reply to our decision with the word “appeal” in the subject line, or write to us at the address in Section 12. We will decide the appeal within sixty days and give you our reasons in writing, and if we still deny the request we will tell you how to complain to your state attorney general or privacy regulator. Residents of other US states with comparable privacy laws, including Colorado, Connecticut, Virginia, Texas, Oregon, and Montana, may make the same requests and use the same appeal process.
Canada (PIPEDA)
We serve businesses in Canada, and the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to personal information we collect from individuals in Canada in the course of commercial activity. Consistent with PIPEDA:
- We collect personal information with your knowledge and consent, and only for the identified purposes described in Section 5. Submitting the contact form is your consent to be contacted about your inquiry.
- We limit collection to what is necessary. The form asks for four fields, not fourteen.
- You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by emailing help@community1marketing.com. If you withdraw consent, we will stop contacting you and delete your inquiry, unless we are required to keep it for legal, tax, or contractual reasons.
- You may request access to the personal information we hold about you and challenge its accuracy or completeness, and we will correct it where warranted.
- The individual accountable for our privacy compliance is our Privacy Officer, reachable at help@community1marketing.com, by phone at +1 (952) 237-4251, or by mail at the address in Section 12. Address privacy questions, access requests, and complaints to that role by name.
- Our website hosting and our principal service providers are located in the United States, which means personal information collected from individuals in Canada is stored and processed in the United States and may be accessible to US courts and government authorities under US law.
- If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
We also follow Canada’s Anti-Spam Legislation (CASL) for commercial electronic messages sent to Canadian recipients, including identifying ourselves and giving you a working way to unsubscribe.
Visitors in the United Kingdom and the European Economic Area
To be straightforward with you: the Site is aimed at businesses in the United States and Canada. We do not target advertising to the EEA or the UK, we do not offer services in EEA or UK currencies, and we do not monitor the behavior of people in those regions. We therefore do not operate as a full GDPR or UK GDPR controller with an EU representative and a full records-of-processing regime.
That said, if you are in the UK or the EEA and you contact us, we will treat your information with the same care described in this policy, and we will honor a request to access, correct, delete, or receive a copy of the information you sent us. Email help@community1marketing.com. Note that any information you send us is transferred to and stored in the United States.
10. Links to Other Websites
The Site contains links to other websites, such as Google properties and social media platforms, and it may link to the websites of businesses we work with. Those sites are run by other people. Once you leave community1marketing.com, this policy no longer applies, and we are not responsible for the content, privacy practices, or security of any third-party site. Please read the privacy policy of any site you visit before giving it your information.
11. Changes to This Policy
We may update this Privacy Policy as the Site, our tools, or our legal obligations change. When we do, we will revise the effective date at the top of the page. If we make a change that materially affects how we handle information already collected from you, we will take reasonable steps to let you know, such as posting a clear notice on this page.
The current version takes effect on August 18, 2026.
12. How to Contact Us
If you have a question about this policy, want to exercise a privacy right, or believe we hold information about you that should be corrected or removed, contact us:
- Community 1 Marketing LLC
- Attention: Privacy Officer
- 15842 S 13th Pl, Phoenix, AZ 85048, United States
- Phone: +1 (952) 237-4251
- Email: help@community1marketing.com
- Contact page: community1marketing.com/contact/
Response times for privacy requests are described in Section 9.
This policy is governed by the laws of the State of Arizona, United States, without regard to its conflict of laws rules. Any dispute relating to this policy is subject to the dispute resolution, venue, limitation of liability, and time to bring a claim provisions in our Terms of Service, which control. Nothing here limits your right to complain to a privacy regulator.