Effective date: August 18, 2026

1. Who We Are and What This Policy Covers

Community 1 Marketing LLC (“Community 1 Marketing,” “we,” “us,” or “our”) is a digital marketing agency based in Phoenix, Arizona. We serve small and mid-market businesses across the United States and Canada, with a particular focus on private practices such as medical and dental offices.

This Privacy Policy explains what happens to personal information when you visit or contact us through community1marketing.com (the “Site”). It describes the information we collect on the Site, why we collect it, who else sees it, and what choices you have.

This policy covers the Site. It is not your services agreement. If you are a paying client, the handling of your accounts and your business data is governed by the contract between us and by our Terms of Service. Section 8 below explains, in general terms, how we treat client data, but your signed agreement controls if there is any conflict.

This policy is a description of our privacy practices. It is not a contract, and it does not create rights beyond the ones the law gives you. The binding terms for your use of the Site are in our Terms of Service. If you are not comfortable with the practices described here, please do not submit information through the Site.

If more than one of our documents applies to you, they rank in this order: a signed Business Associate Agreement controls for Protected Health Information, then a signed services agreement or statement of work, then our Terms of Service, then this Privacy Policy.

2. Information We Collect

Information you give us directly

There is one form we use to collect inquiries on the Site: the contact form on our Contact page. It is built with Elementor Pro Forms and collects only these fields:

There is no phone number field on the form. We do not ask for your company size, your budget, or any other detail through the form.

When you submit that form, the entry is stored in the WordPress database behind the Site (in the Elementor Submissions area) and is also emailed to us so a human sees it.

Comments. WordPress includes a built-in commenting feature, and it is enabled on this install. We do not run a comment program and we do not take inquiries that way. If a comment form appears on a page and you submit a comment, WordPress records the name, email address, and website address you type, the text of your comment, your IP address, and your browser’s user agent string, and stores them in the site database. Comments are moderated, and we may decline to publish any comment. If we later turn on a spam filtering service, comment data will also pass to that service, and we will name it in Section 4 before that happens. To have a comment and the data attached to it removed, use the contact details in Section 12.

You can also reach us outside the form, by emailing help@community1marketing.com or by calling +1 (952) 237-4251. In that case we have whatever you choose to tell us: your name, your email address, your phone number, your business name, and the contents of your message. If you call us, we may keep a written note of the conversation. Please do not include sensitive personal information, such as health information, financial account numbers, or government ID numbers, in a form submission, an email, or a voicemail.

Information collected automatically

Like nearly every website, the Site and its hosting infrastructure record basic technical information when a page loads:

We do not use these logs to build a profile of you. They exist so the Site can run, so we can investigate errors, and so we can spot abuse such as brute-force login attempts.

What we do not collect on the Site

We want to be specific here, because many privacy policies claim tracking that is not actually happening. As of the effective date of this policy:

We may add analytics or advertising measurement tools in the future, since measurement is part of the work we do. If we do, we will update this policy and the list above before or at the time those tools go live. If a tool would involve selling or sharing personal information as California law defines those terms, or would set a cookie that requires consent, we will add the opt out and the consent mechanism described in Sections 3 and 6 at the same time.

3. Cookies and Similar Technologies

A cookie is a small text file a website stores in your browser. The Site uses only functional cookies, meaning cookies that help it work rather than cookies that track you for advertising.

Set by Purpose
WordPress Core site functions. Login and session cookies are set only for our own staff when we log in to administer the Site. If a comment is left on the Site, WordPress may store the commenter’s name, email, and website in a cookie so the fields can be pre-filled next time.
Elementor and Elementor Pro Page display and form handling. Elementor and Elementor Pro may set functional cookies that help pages and forms behave correctly as you move around the Site. They are not used to advertise to you or to track you on other websites.
Google reCAPTCHA Spam and bot protection on pages that contain a form. See Section 4.

We do not set any advertising or analytics cookie on the Site, and we do not use cookies to track you across other websites. The only third-party cookie involved is the one Google’s reCAPTCHA service uses for bot detection on pages that contain a form. For that reason we do not display a cookie consent banner. If we later add cookies that require consent, we will add an appropriate consent mechanism at that time.

How to control cookies: every major browser lets you see the cookies a site has set, delete them, block third-party cookies, or block cookies entirely. Look under Settings, then Privacy or Site Settings, in Chrome, Safari, Firefox, or Edge. Blocking cookies may break the contact form’s spam protection and could prevent your message from going through.

Some browsers send a “Do Not Track” or Global Privacy Control signal. Because we do not run cross-site advertising trackers on the Site and do not sell or share personal information for cross-context behavioral advertising, there is nothing here for such a signal to turn off. We honor it by default simply by not doing that tracking.

4. Third Parties That Receive Data

We keep our vendor list short. These are the service providers that can come into contact with information from the Site, and what each one does:

We may also disclose information when the law requires it, in response to a valid legal request, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of all or part of our business. If ownership of the business changes, we will note it here.

We do not authorize any of these vendors to use your information to market to you on their own behalf, and our agreements with them limit them to providing the service we bought. One exception is worth naming: Google sets its own terms for reCAPTCHA and may use what it collects to improve reCAPTCHA and for general security purposes, as described in the Google policies linked above. We do not control that use, and it is the reason we load reCAPTCHA only on pages that have a form, and only after a delay or when you interact with the form.

5. How We Use the Information

We use the information described above only for these purposes:

6. We Do Not Sell or Rent Personal Information

We do not sell your personal information. We do not rent it, and we do not trade it. We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding twelve months. If we ever add an advertising or measurement tag to the Site that would count as selling or sharing under California law, we will update this policy before that tag goes live and add the opt out California requires at the same time, including a “Do Not Sell or Share My Personal Information” link and honoring the Global Privacy Control signal.

Under laws that require a legal basis for processing, we rely on:

7. How Long We Keep Information, and How It Is Protected

Retention

If you ask us to delete your information sooner, see Section 9.

Security

We take website security seriously, because it is part of what we sell. We use HTTPS across the Site, apply WordPress core and plugin updates, limit administrative access to the people who need it, use bot protection on the contact form, and run regular file and database backups with WPvivid.

That said, we will be honest with you: no website, no server, and no method of transmitting data over the internet is completely secure. We cannot guarantee that information sent to us or stored by us will never be accessed by an unauthorized party. Please do not send us sensitive personal information through the Site’s contact form or by unencrypted email.

If something goes wrong. If we discover a security incident that compromises personal information we hold, we will investigate it, take steps to contain it, and notify affected individuals, regulators, and clients where notice is owed, in the manner and within the time applicable law requires. That includes Arizona’s data breach notification statute, the breach notification law of any other state that applies to the affected individuals, and, for personal information of individuals in Canada, reporting to the Office of the Privacy Commissioner of Canada where the incident creates a real risk of significant harm. If an incident affects a client’s website, hosting account, or data, we will notify that client promptly so the client can meet its own notification obligations, including any obligation under the HIPAA Breach Notification Rule.

Nothing in this section is a warranty or a guarantee. We describe our security practices so you know what we do, not to promise a particular outcome, and we may change specific tools and practices as better ones become available. Our liability for any claim relating to this policy, to the security of the Site, or to information you send us is limited as set out in our Terms of Service.

8. Client Data: Information We Handle While Performing Services

This section is different from everything above. Sections 1 through 7 describe visitors to community1marketing.com. This section describes the data we touch when we do paid marketing work for a client.

One clarification, since this section describes our services: nothing in this Privacy Policy is a promise about marketing results. Search rankings, advertising performance, lead volume, and traffic depend on factors outside our control, including the platforms themselves and the client’s own market. What we commit to on performance, and what we do not, is set out in our Terms of Service.

What we handle

To deliver services such as Google Ads management, SEO, website design and development, hosting, content and social media posting, and reporting, a client may give us access to systems including:

How we treat it

Roles matter here. For data we handle on a client’s behalf, the client is the business or controller and we act as a service provider under the California Consumer Privacy Act, as a processor under comparable state laws, and as a supplier processing personal information on the client’s behalf under PIPEDA. We process that data only on the client’s documented instructions and only to perform the services we were engaged for. We do not retain, use, or disclose it for any other purpose, we do not combine it with data from other clients or from other sources, and we do not sell or share it. The specific contract terms these laws require, along with each party’s confidentiality, security, and indemnity obligations and the client’s responsibility for the data it gives us the right to handle, are set out in the client’s services agreement and our Terms of Service, not in this policy.

Protected Health Information, HIPAA, and Business Associate Agreements

Many of our clients are medical and dental practices, so we want to be precise about this.

We do not seek, want, or ask to receive Protected Health Information (PHI). Our services are designed so that we work with marketing material, website content, advertising accounts, and aggregate performance data, not with patient records. We ask practices not to send us patient names, patient charts, appointment details tied to an identifiable patient, or any other PHI, including in screenshots, email attachments, or shared folders.

When we build, host, or manage a website for a healthcare practice, we may become a business associate by operation of law, whether or not anyone uses that term. If a practice’s website carries a patient appointment request, new patient, or contact form, what a patient submits through it can be Protected Health Information, and we transmit and store it. For that reason we require a signed Business Associate Agreement (BAA) before we build, host, or administer any client system through which patient inquiries flow, and we configure hosting, access, and retention for those clients accordingly. The BAA, not this Privacy Policy, sets our obligations for that data. Where no BAA is in place, we are not authorized to receive PHI, and any PHI sent to us in error should be reported to help@community1marketing.com so we can secure it, return or delete it at the practice’s direction, and tell the practice what happened.

Tracking and advertising technology on healthcare client websites. Analytics tags, conversion tags, advertising pixels, session recorders, and chat widgets can transmit patient identifiers and browsing activity to third parties. We do not place any of these on a healthcare client’s website, appointment pages, or patient portal pages without the client’s written direction. We do not configure tracking that would disclose individually identifiable health information to an advertising platform unless the practice has its own written agreement with that platform permitting it. Where a practice asks us to measure conversions, we configure the tags to avoid sending identifiable patient data, and we document for the practice what each tag collects. The practice, as the covered entity, makes the final decision about what its own HIPAA policies permit.

Our marketing materials describe a HIPAA and ADA compliance commitment. That commitment is about how we build and maintain a client’s website and marketing assets: for example, building forms and pages with appropriate safeguards and following recognized accessibility guidance. It is not a legal opinion, a certification, or a guarantee that a practice as a whole is HIPAA compliant or that a website will never draw an accessibility complaint. Compliance depends on the practice’s own policies, staff, and other systems. Please see our Terms of Service for the full scope of that commitment.

9. Your Privacy Rights

Everyone

Whatever state or country you live in, you can ask us to tell you what information we hold about you, correct it, or delete it. Email help@community1marketing.com with the request and enough detail for us to find your record, such as the email address you used when you contacted us. We will respond within a reasonable time, and in any event within the timeframe the applicable law requires.

We may need to verify who you are before acting, usually by confirming that you control the email address associated with the information. We will not ask you for sensitive documents to verify a routine request. An authorized agent may submit a request on your behalf with written proof of authorization.

California residents (CCPA and CPRA)

If you are a California resident, you have the right to:

For reference, using the categories the California Consumer Privacy Act uses, we collect identifiers (first name, last name, email address, the phone number you give us if you call or write, and IP address) and internet or other electronic network activity information (the server log entries and browser details described in Section 2). We collect them from you directly and automatically from your device, and we use them for the business purposes listed in Section 5. In the preceding twelve months we disclosed them for a business purpose only to the categories of recipients named in Section 4: our web hosting provider, our email delivery providers, our website backup provider, our bot protection provider, and the providers of our own email and business software. We did not disclose personal information to any third party for that third party’s own purposes. We do not collect sensitive personal information as the CCPA defines it.

We retain each of these categories for the periods and on the criteria described in Section 7. Where a fixed period is not practical, the criteria we use are how long we need the information to answer you or perform a contract, how long we must keep it for tax, accounting, or legal reasons, and whether we need it to resolve a dispute or enforce our agreements.

How we handle a request. Email help@community1marketing.com or call +1 (952) 237-4251. We will confirm we received your request within ten business days and respond within forty five days. If we need more time, we will tell you within that first forty five days and take no more than forty five additional days. If we deny your request in whole or in part, we will tell you why. You may appeal. Reply to our decision with the word “appeal” in the subject line, or write to us at the address in Section 12. We will decide the appeal within sixty days and give you our reasons in writing, and if we still deny the request we will tell you how to complain to your state attorney general or privacy regulator. Residents of other US states with comparable privacy laws, including Colorado, Connecticut, Virginia, Texas, Oregon, and Montana, may make the same requests and use the same appeal process.

Canada (PIPEDA)

We serve businesses in Canada, and the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to personal information we collect from individuals in Canada in the course of commercial activity. Consistent with PIPEDA:

We also follow Canada’s Anti-Spam Legislation (CASL) for commercial electronic messages sent to Canadian recipients, including identifying ourselves and giving you a working way to unsubscribe.

Visitors in the United Kingdom and the European Economic Area

To be straightforward with you: the Site is aimed at businesses in the United States and Canada. We do not target advertising to the EEA or the UK, we do not offer services in EEA or UK currencies, and we do not monitor the behavior of people in those regions. We therefore do not operate as a full GDPR or UK GDPR controller with an EU representative and a full records-of-processing regime.

That said, if you are in the UK or the EEA and you contact us, we will treat your information with the same care described in this policy, and we will honor a request to access, correct, delete, or receive a copy of the information you sent us. Email help@community1marketing.com. Note that any information you send us is transferred to and stored in the United States.

10. Links to Other Websites

The Site contains links to other websites, such as Google properties and social media platforms, and it may link to the websites of businesses we work with. Those sites are run by other people. Once you leave community1marketing.com, this policy no longer applies, and we are not responsible for the content, privacy practices, or security of any third-party site. Please read the privacy policy of any site you visit before giving it your information.

11. Changes to This Policy

We may update this Privacy Policy as the Site, our tools, or our legal obligations change. When we do, we will revise the effective date at the top of the page. If we make a change that materially affects how we handle information already collected from you, we will take reasonable steps to let you know, such as posting a clear notice on this page.

The current version takes effect on August 18, 2026.

12. How to Contact Us

If you have a question about this policy, want to exercise a privacy right, or believe we hold information about you that should be corrected or removed, contact us:

Response times for privacy requests are described in Section 9.


This policy is governed by the laws of the State of Arizona, United States, without regard to its conflict of laws rules. Any dispute relating to this policy is subject to the dispute resolution, venue, limitation of liability, and time to bring a claim provisions in our Terms of Service, which control. Nothing here limits your right to complain to a privacy regulator.