Privacy Policy

The Coastal Collaborative, LLC
Effective May 17, 2026 · Last updated July 12, 2026

The Coastal Collaborative, LLC ("Company," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect when you visit thecoastalcollab.com (the "Site"), use our customer portal (the "Portal"), use our free assessment tools, purchase our services, communicate with us, or otherwise interact with us, and how we use, share, and protect that information.

By using the Site, Portal, or Services, you agree to the practices described in this Privacy Policy.

1. Who We Are

The Coastal Collaborative, LLC is a North Carolina limited liability company located at 322 S College Rd #1159, Wilmington, NC 28403. We provide systems integration and automation, AI search visibility (AEO, GEO, and SEO), website and funnel development, fractional operations consulting, and related digital products through our website, customer portal, and direct engagements.

For privacy questions or to exercise any of the rights described below, contact erin@thecoastalcollab.com.

2. Information We Collect

2.1 Information You Provide Directly

  • Contact information: name, email address, mobile phone number, company name, and other details you submit through forms, scheduling tools, the Portal, or email.
  • Account credentials: username and password used to access the Portal.
  • Project information: business details, goals, workflows, onboarding responses, uploaded files, and other information shared during the course of services.
  • Payment information: handled directly by our payment processor, Stripe. We do not store full credit card numbers on our systems.
  • Signed agreements: contracts and related documents signed through our e-signature provider, Documenso, including signature data, timestamps, and audit-trail metadata.
  • Communication preferences: your selected channels (email, Slack Connect, SMS, voice) and opt-in/opt-out status for each.
  • Communication content: messages you send to us via email, Slack, SMS, the Portal, or other channels.
  • Call recordings and transcripts: audio, video, and AI-generated transcripts of meetings you join with us. See Section 6.

2.2 Information Collected Automatically

When you visit the Site or use the Portal, we and our service providers automatically collect:

  • Device and browser information: IP address, browser type, operating system, device identifiers, and referring URL.
  • Usage data: pages viewed, time on site, clicks, scroll behavior, Portal activity, and similar interaction data.
  • Cookies and tracking technologies: see Section 9.
  • Visitor identification data: see Section 10.

2.3 Information You Submit Through Our Free Assessment Tools

We offer free assessment tools, including the 5-Minute Operations Audit and the AI Visibility Scan. When you use them, we collect:

  • The information you enter, which may include your name, email address, company name, website URL, the tools you use, and your answers about how your business currently operates.
  • For the AI Visibility Scan: we analyze the public content of the website address you provide, and we may submit queries about your business, brand, or industry to third-party search engines and AI systems (including services such as ChatGPT, Claude, Perplexity, and Google) in order to measure whether and how those systems surface your business. We do not submit your personal information to those systems as part of this analysis. We analyze only publicly available web content.
  • The results we generate for you, which we retain so that we can reproduce, explain, or follow up on your report.

Submitting a free assessment creates a record in our customer relationship management system, and we may follow up with you about your results. You can opt out of that follow-up at any time using the instructions in Section 15.

2.4 Information From Third-Party Tools

  • Stripe: when you make a purchase, Stripe collects your payment method, billing details, and transaction information.
  • Twilio: when you opt in to SMS messaging, Twilio processes your phone number and message content to deliver text messages.
  • Documenso: when you sign an agreement, Documenso records signature data, timestamps, IP address, and audit-trail information to authenticate the signing event.
  • Slack and Slack Connect: when you communicate with us through a shared Slack Connect channel, your Slack profile information and message content are processed by Slack.
  • Calendly: when you book a call, Calendly collects your name, email, time zone, and any details you provide on the scheduling form.
  • Zoom and Granola: video conferencing and AI transcription services may process audio, video, and meeting metadata.
  • Kit (formerly ConvertKit): if you subscribe to our email list, Kit collects your email address, subscription source, and engagement data.
  • Google Analytics, Meta Pixel, and Snitcher: see Sections 9 and 10.

2.5 Information From Authorized Agents

If you use a third-party AI-powered agent or other Authorized Agent to make a purchase on your behalf (including through Stripe's agentic commerce protocol), we may receive information that agent transmits to complete the transaction, such as your name, email, billing address, and payment method.

2.6 Sensitive Information

We do not intentionally collect sensitive personal information (such as Social Security numbers, government IDs, financial account numbers beyond what is required for payment, precise geolocation, biometric data, racial or ethnic origin, religious beliefs, health information, or sexual orientation). Do not send us sensitive personal information unless we have specifically requested it for a legitimate business purpose. If you provide sensitive information voluntarily, you consent to our use of it solely for the purpose you provided it.

3. How We Use Your Information

We use the information we collect to:

  • Provide access to and operate the Site and Portal.
  • Deliver the services and digital products you purchase.
  • Generate and deliver the results of our free assessment tools.
  • Process payments, send receipts, and manage your account.
  • Send and authenticate contracts and electronic signatures.
  • Communicate with you through your selected channels (email, Slack Connect, SMS, voice) about your project, scheduled calls, contracts, payments, and support requests.
  • Send marketing emails or SMS only if you have separately opted in (you can opt out at any time).
  • Record and transcribe meetings for accuracy, training, and AI-assisted summarization (see Section 6).
  • Identify the businesses and, where applicable, the business professionals researching our services, so that we can prioritize and personalize our outreach (see Section 10).
  • Improve the Site, Portal, our services, and our marketing.
  • Detect, prevent, and respond to fraud, security incidents, abuse, and violations of our Terms of Service.
  • Comply with legal obligations, enforce our Terms of Service, defend against legal claims, and protect our rights.

4. SMS Text Messaging and Mobile Information

We use Twilio, Inc. as our SMS messaging provider for text communications sent under our A2P 10DLC registered campaign.

Consent. We send SMS messages only after you have actively opted in by providing your mobile number and selecting SMS as a preferred channel inside the Portal or another consent form. SMS consent is not a condition of purchasing any Service. By providing a mobile number you also consent under the Telephone Consumer Protection Act (TCPA) to receive autodialed and prerecorded messages from us at that number.

Types of messages. SMS messages may include project updates, appointment reminders, contract status notifications, payment reminders, onboarding prompts, and (only if you opt in separately) marketing or promotional content.

Frequency and rates. Message frequency varies. Message and data rates may apply.

Opt-out and help. You can opt out at any time by replying STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message. Reply HELP for assistance. You can also update your SMS preferences inside the Portal or by emailing erin@thecoastalcollab.com.

No sharing for third-party marketing. Mobile phone numbers, SMS opt-in data, and SMS consent are never shared with third parties or affiliates for their marketing or promotional purposes. We share this information only with Twilio (and any successor SMS provider) solely to deliver the messages you have agreed to receive, and as otherwise described in Section 13 of this Privacy Policy.

Retention. We retain SMS records, opt-in/opt-out history, and related metadata as required for legal compliance, dispute resolution, and audit purposes.

5. Email Communications

We use your email address to send transactional messages (receipts, contract notifications, project updates, scheduled call confirmations) and, where you have opted in, marketing messages.

We comply with the federal CAN-SPAM Act and with applicable international email marketing laws. Every marketing email includes our physical mailing address and a working unsubscribe link, and we honor opt-out requests within ten (10) business days. Transactional emails related to your account or active engagements continue regardless of marketing preferences. You can update your email preferences inside the Portal at any time.

6. Call Recordings, Meeting Transcripts, and Notes

Calls, meetings, and video conferences with us (including those conducted via Zoom or other platforms) may be recorded and transcribed for accuracy, accountability, internal training, and AI-assisted summarization, using tools such as Granola or comparable services.

By scheduling, joining, or participating in a call or meeting with us, you consent to being recorded and transcribed. If you do not consent, notify us in writing before the meeting and we will disable recording. This notice satisfies disclosure requirements under "two-party consent" laws in jurisdictions including California, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington.

Recordings and transcripts are treated as confidential client records. We retain them for as long as needed to deliver the Services, for our internal recordkeeping, and as required by law. You may request deletion of a specific recording or transcript by contacting us. We will honor the request unless we are legally required to preserve the record.

7. Access to Your Business Systems, Credentials, and Your Customers' Data

This section applies when you engage us to build, integrate, automate, or maintain your business systems. It is important, and we encourage you to read it in full.

7.1 Access to Your Systems

To deliver our services, you may grant us access to platforms you control, including customer relationship management systems (such as HubSpot, GoHighLevel, or Asana), automation platforms (such as Zapier or Make), email and SMS platforms, payment systems, hosting and domain providers, analytics accounts, and similar tools.

Our access practices:

  • We request the minimum level of access required to do the work. Where a platform supports scoped, role-based, or delegated access, we use it rather than requesting full administrative credentials.
  • Where a platform supports it, we use our own named user account on your system rather than sharing your personal login.
  • Credentials you share with us are stored in an encrypted password manager, never in email, chat, plain-text documents, or spreadsheets.
  • We use credentials only to perform the work you have engaged us to do.

7.2 Offboarding and Revocation

When an engagement ends, or at any time on your written request, we will remove our access to your systems and delete stored credentials. You should also independently revoke our access from your side, because that is the only step fully within your control and is the security practice we would recommend to any client parting ways with any vendor. We will confirm removal in writing on request.

7.3 Your Customers' Personal Information

When we work inside your systems, we will often encounter personal information belonging to your customers, leads, employees, and contacts. We may build automations that read, transform, route, or send messages to that data.

With respect to that data, we act as a service provider and processor, not as a controller. Specifically:

  • We process your customers' personal information only on your documented instructions and only as needed to deliver the services you engaged us for.
  • We do not sell it, share it, retain it for our own purposes, or use it to market our own services.
  • We do not combine it with personal information we obtain from other clients or from other sources, except as permitted by applicable law.
  • We will not use it to train AI models for our own benefit.
  • On termination of the engagement, we delete or return it, except where retention is required by law.

You remain the controller of that data. You are responsible for having a lawful basis to collect and process it, for maintaining a privacy policy that accurately describes what you do with it, and for obtaining any consents your own customers are owed. Nothing in this Privacy Policy is a substitute for your own compliance obligations.

Data Processing Agreement. If you are subject to GDPR, UK GDPR, CCPA/CPRA, or another regime that requires a written processor or service-provider agreement, we will execute a Data Processing Agreement with you on request. Contact erin@thecoastalcollab.com.

7.4 Our Team and Subcontractors

We work with a small number of team members and independent contractors who may have access to your information and your systems in the course of delivering services. Every person with access is bound by written confidentiality obligations and is held to the same standards described in this Policy. We remain responsible to you for their conduct. A current list of personnel and subcontractors with access to your account is available on request.

8. Artificial Intelligence and Automated Processing

AI is central to how we work and to what we build for our clients. We would rather be specific about it than vague.

8.1 How We Use AI Internally

We use artificial intelligence and machine learning tools, including large language models, transcription services, and AI-assisted automation platforms, to help deliver the Services. This may include summarizing meetings, drafting deliverables, generating ideas, analyzing your website content, classifying messages, and similar tasks.

The AI providers we currently use include Anthropic (Claude), OpenAI, and Google, along with transcription providers such as Granola. This list may change as tooling evolves. A current list of AI providers with access to your data is available on request.

8.2 Model Training

We select providers that offer reasonable data protection terms and, where the option exists, we configure them so that your data is not used to train their general-purpose models. Where a provider does not offer that option, we do not submit client confidential information to it.

We do not use your information, or your customers' information, to train AI models for our own benefit or for the benefit of other clients.

8.3 AI Systems We Build For You

When we design AI-assisted workflows inside your business, those systems may process your data and your customers' data automatically, on an ongoing basis, after our engagement ends. Before deployment, we will identify for you:

  • what data the system reads and writes,
  • which AI providers it sends data to,
  • what it does automatically versus what requires a human to approve.

You own and are responsible for the systems we build for you once delivered. If you require an entirely AI-free workflow, notify us in writing before the engagement begins.

8.4 Automated Decision-Making

We do not make solely automated decisions about you that produce legal or similarly significant effects without a human in the loop.

9. Cookies and Tracking Technologies

We use cookies and similar technologies for several purposes:

  • Essential cookies: required for the Site and Portal to function (such as authentication and remembering form input).
  • Analytics cookies: provided through Google Analytics 4 (GA4) (Measurement ID: G-W9NKVY1L80), which help us understand how visitors use the Site and Portal.
  • Advertising and conversion cookies: provided through the Meta Pixel (Pixel ID: 926761830343186), which helps us measure ad performance and reach relevant audiences on Meta platforms. This constitutes "sharing" of personal information for cross-context behavioral advertising under some state privacy laws. See Section 16.
  • Visitor identification technologies: provided through Snitcher and comparable business-identification providers. See Section 10.

You can control cookies through your browser settings and opt out of certain tracking:

Do Not Track and Global Privacy Control. Some browsers offer a "Do Not Track" signal. There is no industry consensus on how to honor that signal, and we do not respond to it. We do honor the Global Privacy Control (GPC) signal. When we detect a GPC signal from your browser, we treat it as a request to opt out of the sale or sharing of your personal information, and we will not load our advertising or visitor identification technologies for that session.

10. Website Visitor Identification

We use third-party visitor identification services to understand which businesses are interested in our services.

What we collect. When you visit the Site, these services use your IP address, along with third-party business and professional data, to attempt to identify:

  • The company or organization associated with your visit. This is derived from your IP address and does not, on its own, identify you personally.
  • In some cases, the individual professional associated with the visit. Where a match is available, this may include your name, job title, professional email address, employer, and professional social media profile.

This information is combined with the pages you viewed, how long you spent on them, how many times you have visited, and how you arrived at the Site.

How we use it. We use this information solely for business-to-business purposes: to understand which organizations are researching our services, to prioritize our outreach, and to make our follow-up relevant rather than generic. Identified business contacts may be added to our customer relationship management system. We do not build profiles of individuals for any purpose unrelated to a potential business relationship, and we do not sell this information.

Geographic limits. We do not perform person-level identification for visitors located in the European Economic Area, the United Kingdom, or Switzerland. Visitors from those regions may still be identified at the company level, which we perform on the basis of our legitimate interest in understanding our business market. See Section 18.

How to opt out. You have three options:

  1. Email us. Send a message to erin@thecoastalcollab.com with the subject line "Do Not Identify" and include the IP address, company name, or email address you would like suppressed. We will add you to our permanent suppression list within ten (10) business days and will not identify future visits associated with that record.
  2. Enable Global Privacy Control in your browser. We will not load visitor identification technologies when we detect a GPC signal.
  3. Use a tracker-blocking browser extension.

11. Free Assessment Tools

Our free tools (the 5-Minute Operations Audit and the AI Visibility Scan) are provided as-is, for informational purposes, and are not a substitute for professional advice. Results are automatically generated and may be incomplete or inaccurate.

When you submit a free assessment, you are giving us your contact information and consenting to receive your results and reasonable follow-up communication about them. You may opt out of follow-up at any time (Section 15). Opting out of follow-up does not delete your submission. To have your submission deleted, use the process in Section 15.

AI Visibility Scan. By submitting a website address, you represent that you are authorized to request an analysis of that website. We analyze publicly available content only. We do not attempt to access private, gated, or authenticated areas of any site.

12. Data Retention

We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention periods:

  • Email marketing data: until you unsubscribe, then suppression-list retention as required to honor your opt-out.
  • SMS records and consent history: for the period required by applicable telecom regulations and our recordkeeping needs.
  • Signed contracts: for the life of the agreement plus any applicable statutory retention period.
  • Client project records and deliverables: at least seven (7) years for tax and recordkeeping purposes.
  • Client system credentials: deleted at the end of the engagement or on written request, whichever is earlier.
  • Your customers' personal information accessed during an engagement: deleted or returned at the end of the engagement, except where retention is required by law.
  • Call recordings and transcripts: for the duration of the engagement plus a reasonable archival period, or longer if required by law.
  • Free assessment submissions and results: twenty-four (24) months, unless you request earlier deletion.
  • Visitor identification records: twenty-four (24) months, unless you request earlier deletion or suppression.
  • Analytics and cookie data: per the retention defaults of the underlying tool, typically not longer than 26 months.
  • Suppression and opt-out records: retained indefinitely, because we need them in order to keep honoring your opt-out.

13. How We Share Your Information

We do not sell your personal information for monetary consideration. We share information only with:

  • Service providers that help us run our business, including Stripe (payments), Twilio (SMS delivery), Documenso (e-signatures), Slack (communication and Slack Connect), Kit (email), Calendly (scheduling), Zoom (video conferencing), Granola (transcription), Google (analytics and workspace), Meta (advertising), Snitcher (website visitor identification), Asana (project management), Toggl (time tracking), Vercel (website hosting), and the AI providers listed in Section 8. Each of these providers has its own privacy policy.
  • Our team members and independent contractors, bound by written confidentiality obligations, as described in Section 7.4.
  • Authorized Agents acting on your behalf, to the extent needed to complete a transaction or service you have authorized.
  • Legal and regulatory bodies when required by law, subpoena, or court order, or to protect our rights, property, or safety, or the rights, property, or safety of others.
  • Professional advisors (accountants, attorneys, insurers) bound by confidentiality obligations.
  • Successors in interest in the event of a merger, acquisition, financing, reorganization, or sale of business assets.

Mobile phone numbers, SMS opt-in data, and SMS consent are never shared, sold, rented, or otherwise transferred to third parties or affiliates for their own marketing purposes. This applies regardless of any other sharing described in this Privacy Policy.

14. Security

We use reasonable administrative, technical, and physical safeguards to protect personal information, including encrypted Portal authentication, secured third-party processors, encrypted credential storage, access controls on internal systems, least-privilege handling of client credentials, and written confidentiality obligations for everyone with access.

However, no method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.

If a data breach affects your personal information, we will notify you and applicable regulators in accordance with applicable law. If a breach affects personal information we process on behalf of a client, we will notify that client without undue delay so that they can meet their own notification obligations.

15. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your personal information.
  • Object to or restrict certain types of processing.
  • Request a portable copy of your information.
  • Withdraw consent for marketing communications (email or SMS) at any time.
  • Opt out of website visitor identification (Section 10).
  • Lodge a complaint with a data protection authority.

To exercise any of these rights, email erin@thecoastalcollab.com with your request. We will respond within the timeframes required by applicable law (typically 30 to 45 days). We may need to verify your identity before responding. We will not discriminate against you for exercising your rights.

If your information is held inside a client's systems (for example, if you are a customer of a business we work with), we are acting as a processor on that business's behalf. Send your request to that business directly. If you send it to us, we will forward it to them and assist them in responding.

16. California Privacy Rights

California residents have specific rights under the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"):

  • The right to know what categories of personal information we collect, the sources, the purposes, and the categories of third parties we share with.
  • The right to delete personal information we hold about you, subject to legal exceptions.
  • The right to correct inaccurate personal information.
  • The right to opt out of the sale or sharing of personal information.
  • The right to limit the use of sensitive personal information.
  • The right to non-discrimination for exercising your rights.

On sale and sharing. We do not sell personal information for monetary consideration. We do use the Meta Pixel for advertising measurement and audience targeting, and we use visitor identification technologies as described in Section 10. Under California law, these may be considered "sharing" personal information for cross-context behavioral advertising. You have the right to opt out. To do so:

  • Email erin@thecoastalcollab.com with the subject line "Do Not Sell or Share My Personal Information."
  • Or enable Global Privacy Control in your browser, which we honor automatically.

Shine the Light. California Civil Code Section 1798.83 permits California residents to request information about disclosures of personal information to third parties for direct-marketing purposes. We do not make such disclosures.

Our role as a service provider. When we process personal information on behalf of a client, we act as a "service provider" under the CCPA/CPRA and process that information only as permitted by our contract with that client.

17. Other US State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights similar to those described in Section 15, including access, correction, deletion, portability, and the right to opt out of targeted advertising and the sale of personal information.

To exercise these rights, contact erin@thecoastalcollab.com. If a request is denied, you may have the right to appeal by replying to our decision, and we will respond to the appeal within the timeframe required by your state's law.

18. EU/UK Rights and Legal Bases

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information based on one or more of the following legal bases:

  • Consent, for marketing communications and non-essential cookies.
  • Performance of a contract with you, to deliver services you have purchased.
  • Legitimate interests, including operating and improving our business, securing our systems, and understanding at a company level which organizations are interested in our services. We have assessed that these interests are not overridden by your rights, in part because we limit this processing to organizational rather than individual identification for visitors in your region.
  • Compliance with legal obligations.

You have the rights described in Section 15, plus the right to lodge a complaint with your local data protection authority and the right to withdraw consent at any time.

We do not perform person-level website visitor identification for visitors in the EEA, the UK, or Switzerland.

When we act as a processor. Where we process personal information on behalf of a client who is a controller, we do so under a Data Processing Agreement containing the terms required by Article 28 of the GDPR, and we rely on Standard Contractual Clauses or another lawful mechanism for any international transfer.

We do not maintain an EU representative because we do not regularly target the EU market. If you have an EU or UK-specific concern, contact us directly.

19. Marketing Communications

If you opt in to marketing communications, we may send promotional emails or SMS messages about new services, content, and offers. Every marketing email includes an unsubscribe link, and every marketing SMS includes the opt-out instructions described in Section 4. You can also update your marketing preferences inside the Portal at any time. Even after unsubscribing from marketing, we may still send transactional messages related to your account, contracts, payments, or active engagements.

20. Children's Privacy

The Site, Portal, and our services are not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. SMS messaging is restricted to individuals 18 or older. If you believe a child has provided us with personal information, contact us and we will delete it.

21. International Transfers

We are based in the United States and process information here. If you access the Site or Portal from outside the US, your information will be transferred to and processed in the US, which may have data protection laws different from those of your country. By using the Site or Portal, you consent to this transfer. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our service providers.

22. Third-Party Links

The Site and Portal may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those sites. Review their privacy policies before providing information.

23. Data From Third Parties

We may receive information about you from third parties such as referrers, social-media platforms (when you interact with our profiles), event organizers, visitor identification providers (Section 10), business data providers, and publicly available sources. We use this information for the same purposes described in Section 3 and protect it under the same standards.

24. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new "Last Updated" date. Material changes will be communicated through the Site, the Portal, or by email. Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes.

25. Contact

Questions, requests, or concerns about this Privacy Policy or our handling of your information? Reach out:

The Coastal Collaborative, LLC
322 S College Rd #1159
Wilmington, NC 28403
erin@thecoastalcollab.com