1. Who we are
Beacon Web Services (“BWS,” “we,” “us,” “our”) builds, hosts, and maintains websites for local businesses. This Privacy Policy explains what data we collect about you, how we use it, who we share it with, and what rights you have. It applies to your use of BWS’s website at beaconwebservices.com, our customer dashboard at app.beaconwebservices.com, and any related services.
By using BWS, you agree to the practices described in this Privacy Policy. If you don’t agree, don’t use the service.
2. What we collect
2.1 Information you give us directly
- At signup: your name, email, phone number, business name, and selected plan
- From your dashboard: business hours, address, business category, edit requests, photos or images you upload, and any other content you submit to be displayed on your site
- Account changes: name and email updates, account deletion requests with optional reasons
- Email and phone contact: the contents of any email or phone communication you initiate with us
2.2 Information we collect automatically
- IP address — collected at signup and on every login, used for security, fraud prevention, and rate limiting
- Browser type and user agent — collected automatically by our web servers and CDN
- Login timestamps — when you sign in to your dashboard
- Server access logs — standard web server logs of requests to our infrastructure (URL, status code, timestamp, IP)
- Email engagement — whether you opened or clicked links in transactional emails we send (collected by our email provider, see Section 4)
2.3 Information from payment processing
Subscription payments are processed by Square. We receive from Square: your name, billing address, the last 4 digits of your card, the card brand, and the status of each charge. We do not store your full card number, expiration date, or CVV. Square stores those and is responsible for their security under PCI DSS Level 1 compliance.
2.4 What we don’t collect
- We don’t store full payment card numbers
- We don’t run third-party analytics, advertising trackers, or session replay on the BWS dashboard
- We don’t sell, rent, or trade your data to anyone, ever
- We don’t share your data with advertisers
- We don’t collect Social Security Numbers, government IDs, or financial account numbers
- We don’t track your activity on third-party sites
3. Why we collect it
- To provide the service — build, host, and maintain your website
- To bill you — process subscription payments through Square
- To communicate with you — send account notifications, edit-request status updates, billing receipts, and security alerts
- To prevent fraud and abuse — rate limiting, IP-based throttling, and chargeback handling
- To improve the service — understand which features customers use and where they encounter problems
- To comply with the law — respond to subpoenas, court orders, or other legal requests; retain billing records for tax purposes
- To market to existing customers — send promotional emails and display in-product messages about new features, plan upgrades, or add-ons (see Section 5)
4. Who we share data with
We share your data only with the third-party services we use to run BWS. These are called “subprocessors”:
| Service | What they receive | Why |
|---|---|---|
| Square | Name, billing address, payment info | Subscription payment processing |
| Brevo (Sendinblue) | Name, email, message contents | Sending transactional and promotional emails |
| Cloudflare | IP address, request metadata | DNS, DDoS protection, CDN |
| DigitalOcean | Server logs, all stored data | Hosting infrastructure (servers, database) |
| Namecheap | Name, business name, address (if you opt to register a domain through us) | Domain registration |
| Sherweb | Name, email (if your plan includes a Microsoft 365 or Google Workspace mailbox) | Hosted email mailbox provisioning |
We may also share data when required by law (subpoena, court order, regulatory request), to investigate fraud or abuse, to enforce our Terms of Service, or to protect the rights, property, or safety of BWS, our customers, or others.
In the event of a merger, acquisition, or sale of all or substantially all of BWS’s assets, your data may be transferred to the acquiring entity. You will be notified by email if this happens.
5. Marketing communications
BWS may send promotional emails about new features, plan upgrades, add-ons, and BWS news to active customers. You can opt out of these at any time by clicking the “unsubscribe” link in any promotional email or by emailing us at hello@beaconwebservices.com.
You cannot opt out of transactional emails. These include billing notifications, account alerts, edit-request status updates, security notifications, and other messages required to operate your account.
BWS may also display promotional content within your customer dashboard (banners, notifications, suggested add-ons or upgrades). You can dismiss individual messages, but in-product marketing is part of the product experience and cannot be disabled entirely.
6. Cookies and tracking
BWS uses cookies only for essential authentication and security purposes. Specifically:
- Session cookies issued by NextAuth to keep you logged in to your dashboard
- CSRF tokens to protect against cross-site request forgery
We do not use cookies for analytics, advertising, retargeting, or third-party tracking. Your customer-facing website built by BWS uses no cookies by default. If you request analytics tools (like Google Analytics) be added to your site as part of an edit, those tools have their own cookie policies and you are responsible for disclosing them on your site.
7. Your rights
7.1 Access
You have the right to request a copy of all personal data BWS holds about you. We’ll respond within 30 days of receiving your request at hello@beaconwebservices.com.
7.2 Correction
You can correct most of your data directly from your account dashboard (name, email, business info, hours, address, etc.). For anything you can’t edit yourself, email us.
7.3 Deletion
You have the right to request deletion of your account and personal data. Submit a deletion request from your dashboard or by emailing hello@beaconwebservices.com. We will honor deletion requests within 30 days, subject to legal retention requirements (e.g., billing records must be retained for 7 years for tax purposes).
7.4 Portability
On cancellation, you can request an export of your site files (HTML, images) and your account data (in JSON format), free of charge, within 30 days of cancellation.
7.5 Marketing opt-out
You can opt out of promotional emails at any time. See Section 5.
8. Data retention
- Active accounts: data is retained for the life of your account
- After cancellation: your site is removed from active service within 24 hours and your account access is revoked. Your data may be retained in cold storage for up to 90 days for recovery, dispute resolution, and compliance, after which it is permanently purged from active systems.
- Billing and tax records: retained for 7 years as required by U.S. tax law
- Deletion requests: honored within 30 days, subject to the legal retention exceptions above
- Server logs: retained for up to 90 days for security and fraud-prevention purposes
9. Security
BWS takes security seriously. We use the following practices:
- All data in transit is encrypted with TLS 1.2 or higher
- Data at rest is encrypted at the hosting provider level
- Payment card data is never stored on our servers — Square handles it under PCI DSS Level 1
- Authentication uses industry-standard session management and rate limiting
- Production secrets are stored in environment variables with restricted file permissions
- We regularly review and patch our infrastructure
However, no security measure is perfect. We cannot guarantee that our systems will be free from breaches, vulnerabilities, or unauthorized access. By using BWS, you accept that some level of risk is inherent to all online services.
10. Children’s data
BWS is intended for use by businesses and adults. We do not knowingly collect personal information from children under 13. If you become aware that a child under 13 has provided us with personal information, please contact us at hello@beaconwebservices.com and we will delete it.BWS will not host websites that are directed at children under 13 or that collect data from them.
11. International users
BWS is operated from the United States. By using BWS, you consent to your personal data being transferred to and processed in the United States, even if you are located in a country with different data-protection laws.
11.1 EU and UK residents
If you are located in the European Union, the United Kingdom, or another jurisdiction with comprehensive data-protection laws, you have additional rights under those laws, including the right to lodge a complaint with your local data-protection supervisory authority. To exercise your rights, contact us at hello@beaconwebservices.com.
11.2 California residents (CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act, including the right to know what personal information we collect about you, the right to request deletion of that information, and the right not to be discriminated against for exercising those rights.BWS does not sell personal information to third parties as the term “sell” is defined in the CCPA. To exercise your rights, contact us at hello@beaconwebservices.com.
12. Changes to this Privacy Policy
BWS may update this Privacy Policy from time to time. Material changes will be communicated to active customers via email at least 30 days before the change takes effect. The current version and effective date are displayed at the top of this page. Continued use of the service after the change date constitutes acceptance of the new policy.
13. Contact us
For any privacy questions, data access requests, or deletion requests, contact us at:
Version 2026-04-11 · Effective April 11, 2026