Policy
Privacy policy
We collect as little as we can. We don’t sell your information, and we don’t use advertising trackers.
In short
- You can read this whole site without giving us any personal information.
- If you subscribe to our newsletter, we keep your email address and a record of your consent.
- Our analytics don’t use cookies and don’t identify you.
- We don’t sell or rent personal information, and we don’t share it for others’ marketing.
- We don’t receive customer data from any cannabis business, and we don’t give any data to one.
- We don’t take reports or health information through this site.
Who this covers
This policy covers the website at cannabishealthandsafety.org and our email newsletter, The Safety Brief. Both are run by the Cannabis Health & Safety Alliance (“CHSA,” “we”), a California nonprofit public benefit corporation. Other websites we link to, including government agencies, have their own privacy policies.
What we collect
| When | What | Where it comes from |
|---|---|---|
| You subscribe to the newsletter | Your email address, and your state if a form asks and you choose to give it. Whether you have confirmed or unsubscribed, and when. | You |
| Consent record for the newsletter | Each time you sign up, confirm or unsubscribe: what you did, when, how (form, email link or unsubscribe link), which form and page you used, the exact consent wording you saw, and the general type of device (for example “mobile browser”). It also holds a scrambled code made from your IP address with a secret key that changes daily. We never store your IP address itself. | You and your browser |
| You email us | Your email address, name if you give it, and what you write | You |
| You visit any page | IP address and basic request details (browser type, page requested, time), used to deliver and protect the site | Your browser, via our hosting provider |
To match addresses and stop abuse without reading them, we also keep scrambled codes (keyed hashes) of email addresses and IP addresses. A hash can’t be turned back into the address.
We don’t collect: reports about stores or products, health information, payment card details, precise location, or accounts and passwords. If you choose a state or location on our site, that choice is stored only in your own browser.
How we use it
- To send the newsletter you asked for, and to prove you asked for it
- To answer your messages
- To keep the site running and protect it from abuse, such as bots and repeated sign-ups
- To count visits in total, so we know which pages help people
We don’t use your information for advertising, and we don’t build profiles of visitors.
Cookies and tracking
- We don’t use advertising cookies, tracking pixels or social media trackers.
- Our analytics (Cloudflare Web Analytics) don’t use cookies or browser storage, and don’t fingerprint visitors. They report totals, not individuals.
- We don’t load marketing or advertising scripts. The only outside scripts on our pages come from Cloudflare: the bot check (Turnstile), only on forms that send us information, and Web Analytics.
- If you pick your state on our site, your choice is saved in your browser’s local storage. It never leaves your device.
Do Not Track and Global Privacy Control
Some browsers send a “Do Not Track” or “Global Privacy Control” signal. We don’t track visitors across other websites, and we don’t sell or share personal information for advertising, so the site works the same whether or not your browser sends these signals. If we ever add something these signals apply to, we will honor them.
Your choices and rights
- Unsubscribe from the newsletter with the link in any email. We act on it within 10 business days. When you unsubscribe, we erase your email address and keep only a scrambled code, so we don’t email you again.
- To see, correct or delete the information we hold about you, email privacy@cannabishealthandsafety.org. We may need to confirm it’s you before we act. We will answer within 45 days.
- CHSA is a nonprofit. California’s main consumer privacy law, the California Consumer Privacy Act (CCPA), generally doesn’t apply to nonprofits, so it may not cover us. We still give everyone its core rights, wherever you live: to know what we hold about you, to have it deleted, to have it corrected, and to opt out of its sale. We never sell personal information, so there is nothing to opt out of.
- We won’t treat you differently for using any of these rights.
Children
This site is written for adults, including parents and caregivers. It is not directed to children under 13, and we don’t knowingly collect personal information from them. If you think a child has given us information, contact us and we will delete it.
How long we keep it
| Information | How long |
|---|---|
| Sign-ups you never confirm | Deleted after 30 days |
| Your email address, if you subscribe | Until you unsubscribe. Then we erase it. |
| Consent record | 3 years after you last sign up, confirm or unsubscribe, so we can show that you asked for the newsletter. Then we delete it. |
| Scrambled code of your email address, after you unsubscribe or ask us to delete your data | Kept, so we never email you again and can show we did what you asked. It can’t be turned back into your address. |
| Emails you send us | 2 years after our last reply, unless we need them longer to handle a legal claim or a correction demand |
| Abuse-prevention counters (scrambled codes of IP and email addresses) | Deleted after 2 days |
| Our own server and security logs | Up to 7 days. Cloudflare also processes request data, including IP addresses, to deliver and protect the site, and handles it under its own privacy policy. |
Security and data breaches
We use reasonable security measures to protect the information we hold, including encryption in transit, limited staff access, and strong sign-in for anyone who can publish or see personal data.
If a security breach exposes your personal information, we will tell you within 30 calendar days of finding out, as California law requires (Civil Code section 1798.82). The law allows a delay only if law enforcement needs one, or if we need time to find out how big the breach is and secure our systems. If we have to notify more than 500 California residents about one breach, we will also send a sample copy of the notice to the California Attorney General within 15 days of notifying them.
Our service providers may store and process information in the United States and in other countries where they operate.
Changes to this policy
When we change this policy, we post the new version here with a new effective date. If a change affects how we use your email address, we will tell newsletter subscribers by email before it takes effect.
Contact
Questions or requests: email privacy@cannabishealthandsafety.org. We don’t have a postal address yet. We will add one here when we have one.
Please don’t send health details
We can’t give medical advice, and we don’t want to hold health information about you.