Skip to main content
Myrtle Beach's BestThe Grand Strand guide
DirectoryGuidesAdvertiseSign inExplore the area

Legal

Privacy Policy

This policy explains our current and planned data practices for visitors, account holders, business representatives, and advertisers.

Effective and last updated: August 9, 2026

On this page

  1. Scope and who we are
  2. Information we collect
  3. Sign in with Google
  4. Sign in with Apple
  5. How we use information
  6. Cookies and analytics
  7. How information is disclosed
  8. Advertising and sponsored content
  9. Retention and deletion
  10. Your choices and privacy rights
  11. Security and transfers
  12. Children's privacy
  13. Changes to this policy
  14. Contact us

1. Scope and who we are

This Privacy Policy applies to the Myrtle Beach's Best website, applications, accounts, directory, business-listing tools, and related services that link to this policy (collectively, the “Service”). Myrtle Beach's Best, based in Myrtle Beach, South Carolina, is the operator responsible for the personal information described here and is referred to as “we,” “us,” or “our.”

You may browse the public directory without creating an account. This policy does not govern a local business, booking provider, social network, identity provider, or other third party that you reach through the Service.

2. Information we collect

Information you provide

  • Account information, such as your name, email address, profile image, and authentication method.
  • Passkey information when you add one, including its public key, credential identifier, label, authenticator type, backup status, supported transports, creation time, and security counter. Your private key and biometric or device-unlock data remain with your device or passkey provider and are not sent to us.
  • Agent-authorization information when you approve an outside application, including the registered client, requested scopes, consent record, token metadata, and submissions attributed to your account.
  • Business and listing information, including contact details, ownership or authorization evidence, corrections, photos, and content submitted through a claim or listing workflow.
  • Communications, support requests, contributor story pitches, survey responses, marketing preferences, and information you send to us.
  • Transaction and advertiser information if paid products are offered, including billing name and postal address, invoice metadata, and subscription history. Stripe is our selected payment processor. Stripe Elements collects complete payment-card details within our billing pages and sends them directly to Stripe. We retain provider customer, product, price, subscription, invoice, and event identifiers plus normalized subscription status, not complete card or bank account details.

Information collected automatically

  • Device and network information, such as IP address, browser type, operating system, referring page, requested URLs, approximate region derived from IP address, and timestamps.
  • Usage information, such as directory searches, pages viewed, listing interactions, outbound clicks, and error or security events.
  • Security-verification information when you request a sign-in code, report a correction, or claim a listing. Cloudflare Turnstile may process IP address, browser and device signals, challenge interactions, and the verification result to detect automated abuse.
  • Cookie, local-storage, and similar identifiers used for sessions, security, theme preferences, analytics, and—only if later enabled with required notices or choices—advertising.

A bank or card issuer may require a Stripe-controlled authentication challenge to approve a payment. Although the normal billing workspace remains on Myrtle Beach's Best, that challenge is provided by Stripe and the issuer.

We do not intentionally request precise device location, contacts, photos, microphone access, or other sensitive device permissions for ordinary directory browsing. If a future feature needs such access, we will explain why and request permission in context.

3. Sign in with Google

If you choose Sign in with Google, Google authenticates you and may provide us with the basic account information you approve, such as your Google account identifier, name, email address, email verification status, and profile image. We use this information to create or connect your Myrtle Beach's Best account, maintain your session, secure the account, and provide account features you request.

On selected sign-in and public directory pages, we may load Google's One Tap sign-in prompt for signed-out visitors. Your browser then communicates with Google, which may use your Google session and browser information to determine whether and how to display the prompt. We receive Google identity information only after you choose to continue. The standard Google button and email sign-in remain available if you dismiss or cannot use One Tap.

If Google verifies the same email address already used by your Myrtle Beach's Best account, we connect Google to that existing account rather than create a duplicate. We do not automatically merge accounts with different email addresses.

We do not receive your Google password. We do not request access to Gmail, Google Drive, contacts, calendars, or other Google services unless a future feature clearly explains the additional access and you separately authorize it. We do not sell Google sign-in data, use it to build advertising profiles, or disclose it to advertisers.

Our access, use, storage, and disclosure of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements. You may manage or revoke our Google access through your Google Account connections. You may also disconnect Google from your signed-in account page. We then delete the locally stored Google connection and attempt to revoke the stored authorization token with Google. Revoking or disconnecting Google access does not, by itself, delete other information in your Myrtle Beach's Best account; see Section 9 for account deletion.

4. Sign in with Apple

If you choose Sign in with Apple, Apple authenticates you and provides a provider-specific account identifier and, when you authorize it, your name and email address. Apple may provide your name only during the first authorization. We use this information only to create or connect your account, maintain your session, secure the account, communicate about requested account features, and provide the Service.

If Apple verifies the same email address already used by your Myrtle Beach's Best account, we connect Apple to that existing account. We do not automatically merge different email addresses.

If you select Hide My Email, we receive and retain Apple's private relay address instead of your personal email address. We respect that choice and do not require you to replace the relay address merely because it is a relay. Messages sent to it are routed by Apple according to Apple's settings and policies. We do not use Apple sign-in information for targeted advertising or disclose it to advertisers.

You can manage Sign in with Apple and private relay settings from your Apple Account settings. You may also disconnect Apple from your signed-in account page. We then delete the locally stored Apple connection and, when a revocable token and current Apple client credentials are available, attempt to revoke it with Apple. Stopping or disconnecting Sign in with Apple may stop future provider access or relay delivery, but it does not automatically delete your Myrtle Beach's Best account. See Section 9 for account deletion.

5. How we use information

If you authorize an outside agent, we issue it a short-lived access token limited to the capabilities shown on the approval screen. The token identifies your account and the approved client and scopes; it does not give the agent your password or identity-provider token. Agent-created listings, corrections, and ownership requests remain subject to the same validation, rate limits, verification, and editorial review as other submissions.

We use information to:

  • operate, maintain, secure, and improve the Service;
  • authenticate users and prevent fraud, abuse, and misuse;
  • review contributor pitches and publish, verify, correct, and moderate directory and editorial content;
  • process listing claims, advertiser requests, and transactions;
  • personalize requested features, such as saved listings or account preferences, without repurposing provider identity data for ads;
  • measure performance and understand how visitors use the Service;
  • send service, security, support, and—with your choice where required—marketing communications;
  • comply with law and enforce our Terms of Service.

6. Cookies and analytics

Essential cookies support sign-in, session security, and core Service functions. A local-storage value remembers your light, dark, or system theme preference. These functions are not used for cross-site advertising.

Cloudflare Turnstile provides security checks on selected account and submission forms. Cloudflare processes the challenge under its Privacy Policy and Turnstile Privacy Addendum. We use the result only to prevent fraud and automated abuse and do not store the Turnstile token.

When configured, Google Analytics loads automatically and may receive online identifiers, device and browser information, approximate location derived from IP address, and viewed pages and usage events under Google's terms. We disable Google advertising storage, advertising personalization, advertising user data, and Google Signals in this integration. The Service may also record strictly limited first-party interaction counts using a short-lived pseudonymous session when first-party analytics is enabled. We intend to configure Google Analytics event-level retention for no more than 14 months. Learn more in Google's Privacy Policy.

You may block or delete cookies through your browser settings, although doing so may reset analytics identifiers or affect essential Service functions. A Global Privacy Control request stops new first-party interaction events and expires the first-party analytics session, but it does not disable Google Analytics. We do not currently respond to legacy “Do Not Track” signals because there is no consistent industry standard for them.

7. How information is disclosed

We may disclose information:

  • to service providers that perform hosting, database, storage, email, authentication, analytics, payment (including Stripe), security, and support services under appropriate contractual or confidentiality duties;
  • to a business or organization when you submit or approve public listing information, request a claim, or direct us to communicate;
  • to an agent client you expressly authorize, through a scoped access token and API responses needed to carry out the approved submission workflow;
  • when required by law or reasonably necessary to protect rights, safety, security, users, or the public;
  • in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable notice and consent requirements;
  • with your direction or consent.

Providers that receive personal information must protect it consistently with this policy, their contractual obligations, and applicable law. Public listing content is visible to anyone and may be indexed or copied by search engines and other services.

8. Advertising and sponsored content

The Service may display clearly labeled sponsored listings, direct advertisements, affiliate links, or third-party display advertising such as Google AdSense after the applicable approval and privacy controls are complete. Google AdSense may process online identifiers, device and browser information, approximate location derived from IP address, page context, and advertising interactions under Google's policies. We do not currently sell personal information for money. Google and Apple sign-in data will not be provided to advertisers or used to create targeted advertising profiles.

Before enabling display advertising, we will complete the applicable provider consent configuration and any notices, choices, or opt-out rights required by law. Google requires a certified consent management platform when serving ads to visitors in the EEA, United Kingdom, or Switzerland. Before enabling interest-based or cross-context behavioral advertising, we will also configure the Service to honor legally required privacy-choice signals.

9. Retention and deletion

We retain account and provider-link information while your account is active and for only as long afterward as reasonably necessary to complete deletion, protect the Service, resolve disputes, enforce agreements, or meet legal obligations. Listing claims, transactions, OAuth client registrations and consents, and moderation or audit records may be kept longer when needed for fraud prevention, ownership disputes, accounting, or law. Dynamically registered agent access tokens expire after 15 minutes and are not issued with a refresh token, although registration, consent, revocation, and audit records may remain under these purposes. Security and application logs are kept only as long as needed for operations, incident response, and legal obligations. Current container logs are bounded by size and rotate automatically; no longer-lived centralized log-retention period has been established. Deleted information may remain temporarily in caches, provider-held records, or backup copies when those copies exist. A coordinated production catalog backup is not currently operating. Before backups are enabled, we will document their access controls, retention cycle, and deletion handling, and update this policy if those practices materially change.

A signed-in account holder may download a JSON copy of account-linked data from the account page. The export includes the profile, sessions, connected-provider metadata, organization access, listing claims and submissions, corrections associated with the account email, reviews, favorites, uploaded-media metadata, account-linked engagement events, and audit-entry metadata. It excludes passwords, session tokens, provider tokens, other secrets, and internal reviewer notes.

A signed-in account holder may permanently delete the account from the account page after a recent sign-in and explicit confirmation. Deletion removes the profile, sessions, provider credentials, passkeys, memberships, favorites, and reviews. It de-identifies retained listing-claim, submission, correction, uploaded-media, engagement, and audit records. Pending claims and submissions are withdrawn or revoked, and pending claim notifications are suppressed. Listing claims and de-identified audit history may remain for ownership disputes, fraud prevention, accountability, or legal obligations. Public business facts and media may remain when they are operated independently of the deleted account. Where the deleted user was the only member of an organization, its listings are detached from that organization rather than deleted.

Account deletion deletes locally stored provider credentials and then attempts to revoke stored Google or Apple authorization tokens. Because provider revocation depends on an external service, it may not be confirmable; provider access can also be removed from the corresponding Google or Apple account settings. To request assistance or deletion without using the account control, email [email protected] from the address associated with your account and use the subject “Account Deletion Request.” If you used Apple Hide My Email, send the request from or identify the private relay address connected to the account. We may verify your identity before acting.

10. Your choices and privacy rights

Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, or a copy of personal information; object to or restrict certain processing; withdraw consent; and opt out of certain targeted advertising, sale, sharing, or profiling. You may also appeal a denied request where applicable.

Submit a request to [email protected] with the subject “Privacy Request.” Tell us the right you want to exercise and the account or email involved. We will verify requests and respond as required by applicable law. Authorized agents may submit requests where permitted, but we may require proof of authority and identity. We will not discriminate against you for exercising a privacy right.

Signed-in account holders may use the account page to download a copy of account-linked data, disconnect Google or Apple, or delete the account without first emailing us.

You can unsubscribe from promotional email using its unsubscribe link. Service, security, claim, billing, and legal messages may continue when necessary. You can also manage provider access in your Google or Apple account settings.

11. Security and international transfers

We use administrative, technical, and physical safeguards designed to protect personal information, including transport encryption, access controls, secure session cookies, and provider credential protections. No system is perfectly secure, and we cannot guarantee absolute security.

The Service is operated from the United States. Information may be processed in the United States or other places where our providers operate. Where required, we use recognized transfer mechanisms and contractual safeguards for international transfers.

12. Children's privacy

The Service is a general-audience local directory and is not directed to children under 13. Public browsing does not require an account. We do not knowingly collect personal information from a child under 13 without legally valid parental consent. If you believe a child provided personal information improperly, contact us so we can investigate and delete it as appropriate.

13. Changes to this policy

We may update this policy as the Service, providers, and legal requirements change. We will post the updated policy and change the date above. If a change materially expands how previously collected personal information is used, we will provide additional notice and request consent when required before applying the new use.

14. Contact us

Questions, complaints, privacy requests, and account-deletion requests may be sent to [email protected]. Please include enough information for us to understand and verify your request without sending sensitive identity documents unless we specifically request them through a secure method.

Myrtle Beach's Best

A visitor-focused guide to discovering the Grand Strand. Listing information should always be confirmed with the business before making plans.

Explore

  • Directory
  • Guides
  • Advertise
  • About
  • Contact
  • Write for us
  • Report a correction

Policies and preferences

  • Editorial policy
  • Advertising disclosure
  • Accessibility
  • Privacy
  • Terms

© 2026 Myrtle Beach's Best. Sponsored placements are labeled.