1. Scope and who we are
This Privacy Policy applies to the Myrtle Beach's Best website, applications, accounts, directory, business-listing tools, and related services that link to this policy (collectively, the “Service”). Myrtle Beach's Best, based in Myrtle Beach, South Carolina, is the operator responsible for the personal information described here and is referred to as “we,” “us,” or “our.”
You may browse the public directory without creating an account. This policy does not govern a local business, booking provider, social network, identity provider, or other third party that you reach through the Service.
2. Information we collect
Information you provide
- Account information, such as your name, email address, profile image, and authentication method.
- Business and listing information, including contact details, ownership or authorization evidence, corrections, photos, and content submitted through a claim or listing workflow.
- Communications, support requests, survey responses, marketing preferences, and information you send to us.
- Transaction and advertiser information if paid products are offered, including billing name and postal address, invoice metadata, and subscription history. Stripe is our selected payment processor. Stripe Elements collects complete payment-card details within our billing pages and sends them directly to Stripe. We retain provider customer, product, price, subscription, invoice, and event identifiers plus normalized subscription status, not complete card or bank account details.
Information collected automatically
- Device and network information, such as IP address, browser type, operating system, referring page, requested URLs, approximate region derived from IP address, and timestamps.
- Usage information, such as directory searches, pages viewed, listing interactions, outbound clicks, and error or security events.
- Security-verification information when you request a sign-in code, report a correction, or claim a listing. Cloudflare Turnstile may process IP address, browser and device signals, challenge interactions, and the verification result to detect automated abuse.
- Cookie, local-storage, and similar identifiers used for sessions, security, theme preferences, analytics, and—only if later enabled with required notices or choices—advertising.
A bank or card issuer may require a Stripe-controlled authentication challenge to approve a payment. Although the normal billing workspace remains on Myrtle Beach's Best, that challenge is provided by Stripe and the issuer.
We do not intentionally request precise device location, contacts, photos, microphone access, or other sensitive device permissions for ordinary directory browsing. If a future feature needs such access, we will explain why and request permission in context.
3. Sign in with Google
If you choose Sign in with Google, Google authenticates you and may provide us with the basic account information you approve, such as your Google account identifier, name, email address, email verification status, and profile image. We use this information to create or connect your Myrtle Beach's Best account, maintain your session, secure the account, and provide account features you request.
We do not receive your Google password. We do not request access to Gmail, Google Drive, contacts, calendars, or other Google services unless a future feature clearly explains the additional access and you separately authorize it. We do not sell Google sign-in data, use it to build advertising profiles, or disclose it to advertisers.
Our access, use, storage, and disclosure of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements. You may manage or revoke our Google access through your Google Account connections. You may also disconnect Google from your signed-in account page. We then delete the locally stored Google connection and attempt to revoke the stored authorization token with Google. Revoking or disconnecting Google access does not, by itself, delete other information in your Myrtle Beach's Best account; see Section 9 for account deletion.
4. Sign in with Apple
If you choose Sign in with Apple, Apple authenticates you and provides a provider-specific account identifier and, when you authorize it, your name and email address. Apple may provide your name only during the first authorization. We use this information only to create or connect your account, maintain your session, secure the account, communicate about requested account features, and provide the Service.
If you select Hide My Email, we receive and retain Apple's private relay address instead of your personal email address. We respect that choice and do not require you to replace the relay address merely because it is a relay. Messages sent to it are routed by Apple according to Apple's settings and policies. We do not use Apple sign-in information for targeted advertising or disclose it to advertisers.
You can manage Sign in with Apple and private relay settings from your Apple Account settings. You may also disconnect Apple from your signed-in account page. We then delete the locally stored Apple connection and, when a revocable token and current Apple client credentials are available, attempt to revoke it with Apple. Stopping or disconnecting Sign in with Apple may stop future provider access or relay delivery, but it does not automatically delete your Myrtle Beach's Best account. See Section 9 for account deletion.
5. How we use information
We use information to:
- operate, maintain, secure, and improve the Service;
- authenticate users and prevent fraud, abuse, and misuse;
- publish, verify, correct, and moderate directory and editorial content;
- process listing claims, advertiser requests, and transactions;
- personalize requested features, such as saved listings or account preferences, without repurposing provider identity data for ads;
- measure performance and understand how visitors use the Service;
- send service, security, support, and—with your choice where required—marketing communications;
- comply with law and enforce our Terms of Service.
6. Cookies and analytics
Essential cookies support sign-in, session security, and core Service functions. A local-storage value remembers your light, dark, or system theme preference. Another local-storage value remembers whether you allowed or declined optional analytics. These functions are not used for cross-site advertising.
Cloudflare Turnstile provides security checks on selected account and submission forms. Cloudflare processes the challenge under its Privacy Policy and Turnstile Privacy Addendum. We use the result only to prevent fraud and automated abuse and do not store the Turnstile token.
Optional cookies and analytics stay off unless you choose Allow Cookies in the site's cookie controls. If configured and allowed, Google Analytics may receive online identifiers, device and browser information, approximate location derived from IP address, and viewed pages and usage events under Google's terms. The Service may also record strictly limited first-party interaction counts using a short-lived pseudonymous session. We intend to configure Google Analytics event-level retention for no more than 14 months. Learn more in Google's Privacy Policy.
You may change your choice at any time through Cookie choices in the footer. Choosing Keep only necessary cookies or withdrawing consent stops new optional analytics, asks the Service to expire its first-party analytics session, and removes accessible Google Analytics cookies for this site. Global Privacy Control overrides a stored grant and keeps optional analytics off for that browser. We do not currently respond to legacy “Do Not Track” signals because there is no consistent industry standard for them.
7. How information is disclosed
We may disclose information:
- to service providers that perform hosting, database, storage, email, authentication, analytics, payment (including Stripe), security, and support services under appropriate contractual or confidentiality duties;
- to a business or organization when you submit or approve public listing information, request a claim, or direct us to communicate;
- when required by law or reasonably necessary to protect rights, safety, security, users, or the public;
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable notice and consent requirements;
- with your direction or consent.
Providers that receive personal information must protect it consistently with this policy, their contractual obligations, and applicable law. Public listing content is visible to anyone and may be indexed or copied by search engines and other services.
8. Advertising and sponsored content
The Service may display clearly labeled sponsored listings, direct advertisements, affiliate links, or third-party display advertising such as Google AdSense after the applicable approval and privacy controls are complete. Google AdSense may process online identifiers, device and browser information, approximate location derived from IP address, page context, and advertising interactions under Google's policies. We do not currently sell personal information for money. Google and Apple sign-in data will not be provided to advertisers or used to create targeted advertising profiles.
Before enabling display advertising, we will complete the applicable provider consent configuration and any notices, choices, or opt-out rights required by law. Google requires a certified consent management platform when serving ads to visitors in the EEA, United Kingdom, or Switzerland. Before enabling interest-based or cross-context behavioral advertising, we will also configure the Service to honor legally required privacy-choice signals.
9. Retention and deletion
We retain account and provider-link information while your account is active and for only as long afterward as reasonably necessary to complete deletion, protect the Service, resolve disputes, enforce agreements, or meet legal obligations. Listing claims, transactions, consents, and moderation or audit records may be kept longer when needed for fraud prevention, ownership disputes, accounting, or law. Security logs are ordinarily kept for up to 12 months unless an incident or legal duty requires longer retention. Deleted information may remain temporarily in encrypted backups until overwritten through the ordinary backup cycle.
A signed-in account holder may download a JSON copy of account-linked data from the account page. The export includes the profile, sessions, connected-provider metadata, organization access, listing claims and submissions, corrections associated with the account email, reviews, favorites, uploaded-media metadata, account-linked engagement events, and audit-entry metadata. It excludes passwords, session tokens, provider tokens, other secrets, and internal reviewer notes.
A signed-in account holder may permanently delete the account from the account page after a recent sign-in and explicit confirmation. Deletion removes the profile, sessions, provider credentials, memberships, favorites, and reviews. It de-identifies retained listing-claim, submission, correction, uploaded-media, engagement, and audit records. Pending claims and submissions are withdrawn or revoked, and pending claim notifications are suppressed. Listing claims and de-identified audit history may remain for ownership disputes, fraud prevention, accountability, or legal obligations. Public business facts and media may remain when they are operated independently of the deleted account. Where the deleted user was the only member of an organization, its listings are detached from that organization rather than deleted.
Account deletion deletes locally stored provider credentials and then attempts to revoke stored Google or Apple authorization tokens. Because provider revocation depends on an external service, it may not be confirmable; provider access can also be removed from the corresponding Google or Apple account settings. To request assistance or deletion without using the account control, email [email protected] from the address associated with your account and use the subject “Account Deletion Request.” If you used Apple Hide My Email, send the request from or identify the private relay address connected to the account. We may verify your identity before acting.
10. Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, or a copy of personal information; object to or restrict certain processing; withdraw consent; and opt out of certain targeted advertising, sale, sharing, or profiling. You may also appeal a denied request where applicable.
Submit a request to [email protected] with the subject “Privacy Request.” Tell us the right you want to exercise and the account or email involved. We will verify requests and respond as required by applicable law. Authorized agents may submit requests where permitted, but we may require proof of authority and identity. We will not discriminate against you for exercising a privacy right.
Signed-in account holders may use the account page to download a copy of account-linked data, disconnect Google or Apple, or delete the account without first emailing us.
You can unsubscribe from promotional email using its unsubscribe link. Service, security, claim, billing, and legal messages may continue when necessary. You can also manage provider access in your Google or Apple account settings.
11. Security and international transfers
We use administrative, technical, and physical safeguards designed to protect personal information, including transport encryption, access controls, secure session cookies, and provider credential protections. No system is perfectly secure, and we cannot guarantee absolute security.
The Service is operated from the United States. Information may be processed in the United States or other places where our providers operate. Where required, we use recognized transfer mechanisms and contractual safeguards for international transfers.
12. Children's privacy
The Service is a general-audience local directory and is not directed to children under 13. Public browsing does not require an account. We do not knowingly collect personal information from a child under 13 without legally valid parental consent. If you believe a child provided personal information improperly, contact us so we can investigate and delete it as appropriate.
13. Changes to this policy
We may update this policy as the Service, providers, and legal requirements change. We will post the updated policy and change the date above. If a change materially expands how previously collected personal information is used, we will provide additional notice and request consent when required before applying the new use.
14. Contact us
Questions, complaints, privacy requests, and account-deletion requests may be sent to [email protected]. Please include enough information for us to understand and verify your request without sending sensitive identity documents unless we specifically request them through a secure method.