Privacy Policy
This Privacy Policy describes how Go Local LLC (“GoLocal,” “we,” “us,” or “our”) collects, uses, and discloses information when you use the GoLocal platform at golocal.org and related subdomains (the “Platform”).
GoLocal is a business-to-government software platform that supports local government boards and commissions. The Platform is used by appointed board members, staff liaisons, city clerks, and other authorized personnel of subscribing local governments. It is not a consumer product, and it is not supported by advertising.
1. Plain-Language Summary
We provide a closed, multi-tenant workspace for local government boards and commissions. The information you give us, or that your jurisdiction provides on your behalf, is used to operate that workspace and nothing else.
- We do not sell your personal information.
- We do not show advertising on the Platform.
- We do not share your information with marketing partners, advertising networks, or data brokers.
- We do not build behavioral profiles for advertising purposes.
- The Platform is hosted in the United States on AWS infrastructure through our subprocessors.
- Some of the information you place on the Platform may be subject to your jurisdiction’s public records, open meetings, or ethics laws. The Platform supports compliance, but legal obligations belong to your jurisdiction.
2. Who This Policy Covers
This Policy applies to:
- Appointed and elected board and commission members who use the Platform in their official capacity.
- Staff liaisons, clerks, and other authorized government personnel who administer boards through the Platform.
- GoLocal platform administrators who provide support across jurisdictions.
- Visitors to our public marketing website at golocal.org.
It does not apply to information you provide to your jurisdiction outside the Platform, or to third-party services your jurisdiction may use alongside the Platform.
3. Information We Collect
3.1 Account and Profile Information
When your account is created, we collect:
- Your name and email address.
- Your role on the Platform (such as appointee, staff liaison, or platform admin).
- The board or commission you are associated with, your seat or title, and the start and end dates of your term.
- Optional profile information you choose to provide (such as a photo, biography, or contact preferences).
Most accounts are created by invitation from a staff liaison or platform administrator. We do not run an open consumer signup process.
3.2 Authentication Information
We support two authentication methods: email and password, or Google OAuth. We do not support Facebook login or other social authentication. If you authenticate with Google, we receive only the basic profile information needed to create and link your account (name, email address, and Google account identifier).
3.3 Content You Create or Upload
In the course of using the Platform, you may create or upload:
- Documents (such as meeting agendas, minutes, packets, and reference materials).
- Messages (direct messages with other authorized users on your board, and board announcements).
- Tasks, task notes, and task attachments.
- Meeting attendance and RSVP records.
- Onboarding responses, including quiz answers, acknowledgments, and form submissions.
- Notification preferences.
Content scoped to a board is visible only to authorized members and liaisons of that board, in accordance with the access rules described in our Terms of Use.
3.4 Information Collected Automatically
When you use the Platform, our systems automatically log certain technical information for security, troubleshooting, and aggregate analytics. This includes:
- IP address and approximate geographic region derived from it.
- Browser type and version, operating system, and device type.
- Pages or screens you accessed, timestamps, and basic interaction events (such as login, document open, or message send).
- Error logs and performance data.
We use a small number of cookies and similar storage to keep you signed in and to remember session preferences. We do not use third-party advertising cookies, retargeting pixels, or behavioral tracking technologies.
3.5 Information We Do Not Collect
We do not collect:
- Payment card information from individual users. Subscription fees are paid by your jurisdiction under the GoLocal SaaS Agreement.
- Precise GPS location.
- Information from advertising networks, data brokers, or marketing partners.
- Information from social media platforms other than the basic profile data needed for Google OAuth login (if you use it).
- Health information, financial account information, or other categories of sensitive personal information beyond what is necessary to operate the Platform.
4. How We Use Information
We use the information described above to:
- Operate the Platform and the features your jurisdiction has subscribed to.
- Authenticate users and enforce role-based and board-based access controls.
- Send transactional communications (such as account invitations, password resets, meeting reminders, document delivery notifications, and task reminders).
- Send notifications you have opted into through your notification preferences.
- Maintain the security and integrity of the Platform, detect abuse, and respond to security incidents.
- Generate aggregated, de-identified analytics that help us understand and improve the Platform.
- Respond to support requests and communicate with you about the Platform.
- Comply with our legal obligations and enforce our Terms of Use.
We do not use your information for advertising, marketing partner targeting, or behavioral profiling.
5. How We Share Information
5.1 Within Your Jurisdiction and Board
Information you place on the Platform is shared with other authorized users on your board in accordance with the access rules described in the Terms of Use. For example, documents a liaison delivers to a board are visible to all members of that board; direct messages between two users are visible only to those two users.
5.2 Subprocessors
We use a small set of third-party service providers (“Subprocessors”) to operate the Platform. All Subprocessors are contractually bound to handle information consistent with this Policy and applicable law. Our current Subprocessors are:
- Supabase, Inc. — database, authentication, and file storage. United States, on AWS infrastructure.
- Vercel, Inc. — application hosting. United States, on AWS infrastructure.
- Resend, Inc. — transactional email delivery. United States.
From time to time we also engage development and security contractors who may access personal information under written confidentiality and data-handling obligations. Contractors with ongoing access to personal information are treated as Subprocessors and disclosed to subscribing jurisdictions. We will provide reasonable advance notice to subscribing jurisdictions before adding or replacing a Subprocessor that processes their data.
5.3 Legal Process and Safety
We may disclose information if we believe in good faith that disclosure is necessary to comply with applicable law, valid legal process, or a lawful government request; to enforce our Terms of Use; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of GoLocal, our users, or the public.
5.4 Public Records and Open Meetings Laws
Users of the Platform are typically acting in their official capacity as appointed members or employees of a local government. Some content placed on the Platform may, depending on the jurisdiction, constitute a public record subject to disclosure under FOIA, state public records statutes, or open meetings laws. The Platform supports your jurisdiction’s compliance, but the legal obligation to respond to records requests and to comply with open meetings laws rests with your jurisdiction. GoLocal will reasonably cooperate with your jurisdiction’s lawful requests for records held in its workspace.
5.5 Business Transfers
If GoLocal is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to confidentiality protections at least as protective as those in this Policy.
5.6 What We Do Not Share
We do not share, sell, rent, or otherwise disclose personal information to:
- Advertising networks or ad-tech platforms.
- Marketing partners, joint-venture marketers, or data brokers.
- Social media companies for the purpose of audience targeting (such as Facebook Custom Audiences or X Tailored Audiences).
- Analytics providers that combine your data with information from other services for advertising purposes.
6. Data Retention
We retain personal information for as long as your account is active and as long as your jurisdiction’s subscription with us remains in effect, plus any additional period required to comply with our legal obligations or to resolve disputes.
When a user’s board membership ends, the user’s account is deactivated, but content they created or contributed in their official capacity (such as documents, meeting attendance records, and messages) remains in their jurisdiction’s workspace consistent with public records expectations. Specific retention periods are documented in the SaaS Agreement and Data Processing Addendum applicable to your jurisdiction.
Upon termination of your jurisdiction’s subscription, customer data is exported and deleted on the timeline specified in the SaaS Agreement.
7. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, unauthorized access, disclosure, alteration, or destruction. Current safeguards include:
- Encryption of data in transit using TLS.
- Encryption of data at rest in our managed database and storage layers.
- Role-based access controls and database-level row-level security to enforce tenant isolation.
- Logging of platform-administrator access for audit purposes.
- Regular backups maintained by our database Subprocessor.
- Incident response procedures and breach notification practices.
No system can be made perfectly secure. If we become aware of a security incident affecting your personal information, we will notify your jurisdiction without undue delay and, where required by law, notify you directly.
8. Your Rights
8.1 All Users
You may:
- Access and review the personal information associated with your account through your account settings.
- Request correction of inaccurate personal information.
- Request export of your personal information in a portable format.
- Request deletion of your account and personal information, subject to records-retention obligations of your jurisdiction.
- Update your notification preferences at any time.
To exercise any of these rights, contact us at info@golocal.org. Because some of the data on the Platform belongs to your jurisdiction as a matter of public records law, certain deletion requests may need to be coordinated with your jurisdiction.
8.2 California Residents
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides you with the rights described above and additional rights, including the right to know what personal information we collect, the right to correct inaccurate information, the right to delete personal information, and the right not to be discriminated against for exercising your rights. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
8.3 EU and EEA Residents
If the General Data Protection Regulation applies to your use of the Platform, GoLocal generally acts as a processor on behalf of your jurisdiction (the controller). For accounts that are not associated with a subscribing jurisdiction, GoLocal acts as the controller. You have the right to access, rectify, restrict processing of, and erase your personal information, the right to data portability, and the right to lodge a complaint with your local supervisory authority. The legal basis for our processing is the performance of a contract (the SaaS Agreement with your jurisdiction or the Terms of Use with you) and our legitimate interest in operating and securing the Platform.
9. Children
The Platform is intended for use by adults serving in official capacities for local governments. It is not directed to children under 18, and we do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will delete it.
10. International Data Transfers
Personal information processed through the Platform is stored in the United States. GoLocal personnel and approved service providers located in the Netherlands, where GoLocal maintains an office, may access personal information remotely in order to operate, develop, and support the Platform. That access is subject to the safeguards described in Section 7. If you access the Platform from outside the United States, you understand that information will be transferred to and processed in the United States. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) for cross-border transfers.
11. Do Not Track
Because we do not engage in cross-site tracking for advertising purposes, our practices do not change in response to Do Not Track signals from your browser.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify subscribing jurisdictions and active users by email or through the Platform at least 30 days before the changes take effect, unless a shorter period is required by law. The current version of this Policy is always available at golocal.org/privacy.
13. Contact
Questions, requests, or complaints about this Privacy Policy should be directed to:
Go Local LLC
Attn: Privacy Officer
440 Monticello Avenue, #967654, Suite 1802
Norfolk, Virginia 23510
Email: info@golocal.org