1. Scope
This Privacy Notice explains how Local Disco LLC, a Florida limited liability company doing business as Local Disco (“Local Disco,” “we,” “us,” or “our”), handles information through localdisco.com, the Attention Playbook funnel, the Attention Audit, partner applications, communications, and related operations.
The service is directed to businesses and people authorized to act for them. It is not directed to children or designed to receive patient information or other regulated personal data.
2. Information we collect
Information you provide
- Contact details, including name, business email, phone number, and business role.
- Business details, website, service area, offers, audience, markets, capacity, and operating information.
- Audit intake, objectives, constraints, channel links, named competitors, creative examples, performance information, source links, and uploaded or linked materials.
- Partner-application details, licensing and insurance assertions, reviews, CRM use, commercial preferences, and territory interest.
- Marketing preferences, support requests, feedback, and communications.
Payment and order information
Stripe processes payment-card information. Local Disco receives transaction identifiers, payment status, amount, customer details, refunds, and limited billing information needed to operate and reconcile the order. We do not request or store complete payment-card numbers through our intake forms.
Information collected automatically
We and our hosting and communications providers may collect IP address, device and browser information, timestamps, referring pages, campaign and UTM parameters, requested URLs, error and security logs, email delivery events, and similar operational information. With your permission, Google Analytics and Microsoft Clarity also collect the public-page usage information described in Section 6. They remain off until you allow analytics and do not run on checkout, intake, login, private operator, or other excluded routes.
Permitted public sources
For a paid Audit, we may capture authorized public webpages and conversion paths identified through intake. Material public claims in the Audit include a source URL and supporting excerpt or are labeled as inferences or unknowns. We do not bypass credentials or approved source-access boundaries.
3. How we use information
- Process checkout, orders, refunds, and reconciliation.
- Deliver purchased books and services.
- Validate intake and produce evidence-backed Audit drafts.
- Conduct human evidence, quality, and delivery review.
- Send transactional confirmations, reminders, deliverables, scheduling messages, and recaps.
- Send consent-based education and relevant offers.
- Attribute campaigns and understand funnel performance.
- Secure, troubleshoot, test, and improve the service.
- Prevent fraud, abuse, duplicate processing, and prohibited data use.
- Comply with law, enforce agreements, and resolve disputes.
- Create the limited aggregated or de-identified learnings described in the Terms.
4. AI-assisted processing
Local Disco uses the OpenAI API to assist with Audit research, structured analysis, scoring drafts, and report drafting. The application sends API requests with response storage disabled. OpenAI states that API data is not used to train or improve its models unless the customer explicitly opts in. Local Disco does not opt Audit data into training without a new recorded policy and appropriate authorization.
Under OpenAI’s standard API controls, abuse-monitoring logs may retain customer content for up to 30 days unless an approved reduced-retention control applies. AI output is a draft and cannot be delivered without Local Disco’s recorded human evidence and quality gate.
Local Disco may use Higgsfield to render the concise video walkthrough from a separately approved production script. The script may contain permitted public observations and the business objectives, constraints, metrics, or other business information the Buyer supplied to Local Disco and authorized for vendor processing under the Terms. Local Disco sends only the minimum approved script and production instructions needed for the walkthrough—not the Audit PDF, raw intake, evidence packet, customer contact details, access links, or internal identifiers.
Under Higgsfield’s standard service terms, submitted inputs and outputs may be used to train or improve its models. The Terms authorize this limited provider processing for Audit fulfillment. Local Disco minimizes the submitted material, reviews every output before delivery, imports the approved video into Local Disco-controlled private storage, and deletes the provider copy within 30 days after approval. Vendor processing does not authorize public posting, marketing use, or disclosure outside the provider’s applicable service terms.
Do not submit patient records, protected health information, passwords, financial credentials, or other prohibited data for AI processing.
5. Service providers and disclosures
We use service providers for defined operating purposes, including:
- Stripe: checkout, payment, refunds, billing records, and fraud controls.
- Supabase: application data, authentication, operational records, database services, and private delivery-file storage.
- Resend: transactional email, consent-based marketing, delivery events, suppression, and automation.
- Cal.com: Decision Session availability, booking, calendar invitations, rescheduling, cancellation, and appointment reminders.
- OpenAI: AI-assisted Audit research and drafting.
- Higgsfield: AI-assisted rendering of a human-approved Audit walkthrough script, including authorized business information supplied for fulfillment, into narration, captions, presentation visuals, and video.
- Vercel: application hosting, request processing, deployment, and operational logs.
- Google Analytics: consent-based public-page measurement and funnel analysis.
- Microsoft Clarity: consent-based public-page interaction analytics, heatmaps, and masked session replay.
- Approved scheduling, storage, security, and professional providers: when reasonably necessary and identified in the current Notice or applicable service documentation.
We may also disclose information when authorized by you; during a merger, financing, reorganization, or sale subject to appropriate obligations; to professional advisors; to protect rights, safety, and service security; or when required by law. We do not sell personal information.
Service providers and their approved subprocessors may process information in the United States or other locations where they operate. We disclose only information reasonably necessary for the assigned service. Vendor processing does not make nonpublic Buyer information public.
6. Analytics and session replay
On eligible public pages, Local Disco asks before loading Google Analytics or Microsoft Clarity. If you allow analytics, these providers may receive page path, permitted campaign and UTM parameters, approximate location derived from IP address, device and browser information, timestamps, referrer, page interactions, scroll and click behavior, and performance or diagnostic signals. Clarity may create a masked replay of how the public page was used.
Local Disco does not use these tools on checkout, intake, login, authenticated, private operator, or other excluded routes. The public partner-application form is explicitly masked from Clarity, and input and select values are not intentionally sent as analytics event parameters. Analytics events use approved names and non-personal labels only. Do not place personal or confidential information in a public-page URL.
Analytics permission is separate from marketing consent. Advertising storage, Google Signals, and ad-personalization signals remain disabled in the website implementation. You can decline without losing access to the site or change your choice later through “Analytics settings” in the footer. Withdrawing permission stops future consent-based collection and instructs the integrated tools to revoke analytics storage; it cannot remove reports already aggregated or retained under an applicable legal obligation.
7. Marketing choices
Paid-product fulfillment emails are transactional and do not depend on marketing consent. General education, nurture, and unrelated offers require the applicable consent. Marketing messages include an unsubscribe method. We honor unsubscribe, complaint, bounce, and suppression signals across applicable sends.
We retain a minimal suppression record when needed to prevent prohibited future marketing. Unsubscribing from marketing does not stop necessary order, security, billing, fulfillment, or legal messages.
8. Prohibited data
Do not submit:
- Passwords, authentication secrets, or account credentials.
- Complete payment-card, bank-account, or financial-account credentials.
- Social Security, passport, driver-license, or other government-ID numbers.
- Patient records, protected health information, or medical records.
- Children’s personal data or biometric identifiers.
- Confidential legal records belonging to another person.
- Data you lack authority to provide or authorize us to process.
Local Disco does not offer a HIPAA-regulated Audit service and does not authorize PHI processing through the Audit intake.
9. Retention
- Incomplete checkout attempts: 90 days.
- Raw intake, captured evidence, source excerpts, and AI drafts: 12 months after completion, cancellation, or refund.
- Final report, roadmap, scorecard, and walkthrough records: three years after completion.
- Higgsfield generation copies: deleted from the provider workspace within 30 days after the final video is approved and imported; prior model-training use and provider backups remain governed by the provider terms disclosed above.
- Support, transactional email, and lifecycle records: three years.
- Orders, payments, refunds, accepted terms, and tax or accounting records: seven years.
- Security and access logs: 12 months unless needed for an incident.
- Analytics and masked session-replay data: according to the shortest approved provider and project retention settings reasonably available for the measurement purpose, then deleted or aggregated.
- Marketing consent: while active and afterward as reasonably necessary to demonstrate consent.
- Unsubscribe and suppression records: in minimal form for as long as needed to prevent prohibited sends.
Deleted data may remain in protected backups for up to 90 additional days. A legal hold, dispute, security incident, or statutory obligation may extend a period. We otherwise delete or de-identify information when its retention period ends.
10. Security
We use administrative, technical, and organizational measures designed to protect information, including server-side credential handling, verified webhooks, access controls, row-level database security, bounded public-source collection, and idempotent processing. No system or transmission method can be guaranteed completely secure.
If you believe you sent prohibited data or identified a security issue, contact admin@localdisco.com promptly.
11. Privacy requests
To request access, correction, deletion, or a marketing opt-out, email admin@localdisco.com. We verify requests through the purchase email, order record, a secure link, or other proportionate non-sensitive information. Do not send passwords or complete payment-card data for verification.
We target a substantive response within 30 calendar days and will explain a legally permitted extension. We may retain information required for tax, accounting, fraud prevention, security, contract enforcement, dispute resolution, or other legal obligations. Rights and exceptions vary by jurisdiction.
12. Children
Local Disco’s services are directed to businesses and are not intended for children. Do not submit children’s personal information. Contact us if you believe such information was submitted so we can evaluate and remove it where appropriate.
13. Changes
We version material changes to this Notice and publish the updated effective date. Changes apply prospectively. If a change materially affects an active purchased service, we will provide notice or obtain consent when required.
14. Contact
Local Disco LLC
PO Box 190032
Miami Beach, FL 33119
admin@localdisco.com