Legal
Privacy Policy
Operator: Elevare Studio LLC, Connecticut. Last updated August 4, 2026.
1. Who we are
Thames Coast is a community hub for New London, Groton, and Mystic, Connecticut. It is owned and operated by Elevare Studio LLC (“we,” “us,” “Thames Coast”). We are the data controller for the information described here.
The site has three parts, and they collect different amounts of information. The events calendar and the town pages are open to everyone and need no account. The community board is open to read without an account, but posting to it needs a free account. Membership is a paid subscription and involves billing. This policy covers all three.
2. The short version
- You can read the whole site without an account: the calendar, the town pages, and the community board.
- An account needs one thing, an email address, and it exists so posts on the board come from a real person. There is no password to leak, because we sign you in with a code we email you.
- Anything you post to the community board is public. Your chosen display name is shown with it. Your email address is never shown.
- Membership billing runs through Stripe. Your card number never reaches our servers.
- We don’t set advertising or cross-site tracking cookies, and we don’t sell your personal information.
- You can ask us to show you, correct, or delete what we hold, and you can unsubscribe from email in one click, any time.
3. What we collect, why, and our legal basis
We collect only what a given action needs, and most of the site needs nothing.
- Browse the site: standard server and request logs (IP address, browser type, pages requested, timestamp), handled by our hosting provider, to serve the site, keep it secure, and prevent abuse (legitimate interest). Nothing on a page you only read is written to your account.
- Create an account: your email address, a display name you choose, your confirmation that you are 18 or older, and the town you pick as your home town if you set one. We also keep account status flags (whether you hold a membership, whether you run a business listing, whether you moderate, whether the account has been suspended) and your account settings. Used to sign you in, attribute your posts, and apply the 18+ rule (consent + contract). We do not ask for a date of birth, a photo of you, or any form of ID; the age check is your own confirmation.
- Sign in: we email you a six-digit code. The code itself is never stored in our database, only a keyed hash of it in a short-lived cookie in your browser. See Section 5 for the cookies.
- Post to the community board, or reply: the text you write, the town and type you tag it with, your display name and account, and the IP address the post came from for spam and abuse prevention. Posts and replies are public. Used to publish what you wrote and to screen it (consent + legitimate interest in running a moderated public board).
- Add a photo to a post: the image file itself, its type, size and pixel dimensions, and which account uploaded it. Photos go into a private storage bucket and are only ever shown through a short-lived signed link. See Section 6 for how photos are screened, and Section 4 for what a photo file can carry inside it (consent).
- Report a post or reply: the reason you pick, any detail you type, and your IP address. If you are signed in we also record which account reported it. You do not need an account to report something. We never tell the person you reported who reported them (legitimate interest in keeping the board safe).
- Block someone: we record that your account has blocked theirs, so we can keep their posts out of your view (contract).
- Take out a membership: your plan and price, your subscription status and billing period, whether you hold a founding rate lock, and the customer and subscription identifiers Stripe gives us. Card details are entered directly into Stripe’s payment form and never touch our servers. We also keep a payment record for each charge, and, because the Connecticut sales-tax position on a digital subscription is still open, a note of what tax would be owed on it. That note is a bookkeeping record; no tax is added to what you pay (contract + legal obligation).
- Agree to the automatic renewal terms at checkout: we write a separate, permanent record that you agreed. It holds the time on our server, the version of the renewal terms that were on your screen, the plan and price, your IP address, and the time your browser claimed you ticked the box. Connecticut law lets a subscriber take a business to court over automatic renewals, and this record is how we can show what you were told and what you agreed to. It cannot be edited afterwards, by us or by anyone (legal obligation).
- Post an event: organizer name, organizer email, and the event details you type (title, category, dates, venue name, address, description, price or free, ticket or RSVP link, optional image). We also record the submitting IP for spam prevention. Used to publish your event, contact you about the listing, and screen for spam and quality (consent + legitimate interest). Posting an event does not need an account.
- Subscribe to the Friday email: your email address, an optional town or category interest preference, subscription status, and a random unsubscribe token, to send the weekly “This Weekend on the Thames Coast” email you asked for (consent, double opt-in).
- Claim a business listing: business name, town, category, contact name, contact email, and optionally phone and website, to set up your listing, confirm your founder spot, and follow up about featuring (consent + legitimate interest).
We do not collect government IDs, dates of birth, passwords, precise device geolocation, or biometric data. The latitude and longitude we store for an event is the venue’s location for the map, not yours.
4. Sensitive information, and being honest about it
The community board is a free-text noticeboard, so people write what they need to write. Someone asking for a therapist who takes their insurance, a support group, a place of worship, or help with a disability is telling us something sensitive about themselves, and it will be published, because that is what posting means. We do not ask for any of it and we do not sort or profile anyone by it. But we would be lying if we said we never hold it.
So: treat a post as public and permanent from the moment you press Post. Don’t put anything in a post, a reply, or a photo that you wouldn’t want a neighbour, an employer, or a search engine to read. If you post something and change your mind, you can delete it yourself (Section 7 explains exactly what deleting does).
Photos carry more than the picture. A photo taken on a phone often has camera and location data embedded inside the file, including the exact coordinates where it was taken. We take that out. Every photo is rebuilt on our server before it is stored, keeping the picture itself and one small value that records which way up it should be shown. The coordinates, the date and time, the camera and phone details, and any caption or credit hidden inside the file are all dropped. The stripped version is the only one we store; we don’t keep the original. Two things this doesn’t cover: a copy you have already sent somewhere else still carries everything it always did, and an address you type into the post yourself is words you wrote, which we publish as you wrote them.
5. Cookies, local storage, and analytics
Thames Coast does not use cookies for tracking or advertising, and does not use any advertising pixels or cross-site trackers. The cookies we do set exist only to keep you signed in.
- tc-session keeps you signed in for 90 days. It contains your account id, signed so it can’t be forged. Signing out deletes it.
- tc-authchal lasts 10 minutes and holds the pending sign-in code challenge while you type the code in.
- tc-emailok lasts 15 minutes and marks “this email is confirmed, but there’s no account yet” while you pick a display name.
All three are first-party, cannot be read by JavaScript, and are sent only to this site. None of them is used to track you anywhere else.
We also use a small amount of first-party browser local storage on your own device, for things you trigger: your light or dark theme choice (tc-theme), an autosaved draft of the event submission form (tc-submit-draft), autosaved drafts of board posts (tc_draft_ask, tc_draft_classified, tc_draft_job), and an autosaved draft of a reply you are part way through. These stay in your browser so a reload doesn’t lose your work. The event draft includes the organizer name and email you typed. Clearing your browser storage clears all of it.
Analytics: we use Vercel Web Analytics, which is active on this site today. It is cookieless: it counts aggregate visits without setting cookies, without collecting personal data, and without tracking you across other sites. That is why you are not asked to accept a cookie banner here.
6. Who we share data with
We use a small set of vendors to run the site. They process data on our instructions only, under their own security and data-processing terms. We do not sell your personal information and we do not share it with advertisers.
- Supabase (database, authentication store, and file storage): everything we store, including your email address, your account, board posts and replies, uploaded photos, event submissions, organizer contact details, subscribers, and business leads.
- Stripe (payments): your card details, which you enter into Stripe’s own payment form, plus your email address and display name so your receipts make sense. We hold Stripe’s customer and subscription identifiers and the amounts. We never hold your card number.
- Resend (email delivery): email addresses and message content, for sign-in codes, the weekly email, and billing notices.
- Anthropic (Claude) (automated screening): the text of what you submit, and, for photos, the image itself. The classifier that screens text receives the title, body, town, and the listing or job fields, and never receives your email address or your display name. Uploaded photos are sent to the same provider for a safety check before they are ever shown. Nothing is served publicly until that check comes back clean.
- Vercel (hosting, content delivery, and analytics): server request logs, including IP address.
- Meta Platforms (Facebook) (auto-posting published events to our Facebook page): only public event information, no resident personal data.
- OpenStreetMap (map tiles) and Unsplash (some event photography): these load directly in your browser on the pages that use them, so your IP address reaches them the same way it would if you visited them yourself. Neither receives anything you typed.
Reported posts. Reports go to the operator, who reviews them and decides whether a post stays up. No one else has access to reported content, and no volunteer or third party moderates this site.
Elevare Studio LLC also operates Thames Coast and, where you submit a business listing, may use your business contact details to follow up about Elevare’s own web and marketing services. This is first-party use by the operator, not a sale to a third party; you can opt out at any time (Section 9). We may also disclose information if required by law, to enforce our Terms, or to protect the safety and rights of users and the public.
7. How long we keep it, and what deleting really does
- Board posts and replies: visible until you delete them, or until they expire. Classified listings drop out of the feed 30 days after posting unless you renew them; an event pointer drops out a day after the event. When you delete a post it stops being visible to anyone straight away, and we keep the row marked as deleted rather than erasing it, so that an accidental delete can be undone and so we still have a record if the post is later the subject of a complaint or a legal request. If you want a post erased outright rather than hidden, ask us and we will do it.
- Photos: when you remove a photo, the image file is deleted from storage immediately. The database row recording that a photo existed is kept, marked deleted. Photos are also deleted when the post they belong to is erased.
- Your account: kept until you close it. You can close it yourself, from your account page, and it happens straight away: we remove your posts and replies, delete the photo files you uploaded, delete your saved events, your follows and your blocks, cancel any membership, and replace the email you sign in with so nobody can sign in as you again. The account row itself is kept marked as closed rather than erased, because your posts and your payment records point at it. You can still ask us instead, at the address in Section 12, and we will do it by hand. Tell us at the same time if you want your posts erased outright rather than removed, because closing the account removes them.
- Moderation records: the screening result on a post (the scores, the reason, the model and version used), the IP a post or report came from, and any hide or escalation, are kept up to 12 months for spam and abuse prevention, then deleted, unless a specific item is still the subject of a complaint or a legal request.
- Reports: kept with the moderation records, on the same basis and for the same period.
- Membership and payment records: retained as long as required by tax and accounting law.
- The automatic-renewal consent record: kept for as long as the membership exists and for a reasonable period after, because its whole purpose is to evidence what you were shown. It is deleted with your account.
- Published events: kept while relevant and as a public archive. Past events remain viewable unless you ask us to remove your listing.
- Newsletter subscribers: kept until you unsubscribe. After you unsubscribe we keep your address on a suppression list so we can honor your opt-out and not email you again.
- Business listing leads: kept as a business record while the relationship is active and for a reasonable period after.
- Server logs: retained by our hosting provider for a short operational window.
8. How we protect it
The public site can only read a limited set of display fields. Your email address, your account row, uploaded photo records, reports, blocks, and everything to do with billing are not readable by the public site at all, not even by a client that goes around it: the database refuses those reads outright. What is public on a board post is the display name, the text, and the photos. What is not is the account behind it, the IP it came from, and the screening result.
Photos live in a private bucket with a file type allowlist and a size cap. They are never served from a public URL. Every view is a fresh signed link that expires in ten minutes, and no link is issued at all for a photo that has not passed screening.
Sign-in codes are stored only as a keyed hash and expire after ten minutes. There are no passwords. Card data is handled entirely by Stripe and never touches our servers. The table that rate-limits abuse stores only a hash of the email or IP it is counting, never the address itself. No system is perfectly secure, but we design for least exposure and review access regularly.
9. Your choices and rights
You can, at any time:
- Edit or delete your own posts on the board, yourself, without asking us — the Edit and Delete buttons sit on your own post, at its own address. This is the fastest route for most privacy requests. An edit is screened the same way a new post is, and if a change does not pass, your post stays as it was and we tell you why. Replies work differently: a reply cannot yet be edited or removed by the person who wrote it, so ask us and we will take it down for you.
- Cancel a membership in your account or at thamescoast.com/cancel. No survey, no retention offer, no phone call.
- Unsubscribe from the Friday email using the one-click link in every message. We stop within 10 business days (usually immediately).
- Access, correct, or delete the personal information we hold about you, close your account, or ask us to remove an event or business listing you submitted. Use our contact form or email nyriian@thamescoastevents.com.
Depending on where you live, you may have additional rights under state or national law, including under the Connecticut Data Privacy Act, the California CCPA/CPRA, and the EU/UK GDPR. Under Connecticut law those rights include confirming what we process, getting a copy, correcting it, deleting it, and appealing if we turn a request down. We aim to answer within 45 days and will tell you if we need the one extension the law allows. If we refuse a request we will tell you why and how to appeal it. We do not sell personal data or run targeted advertising. To exercise any right, reach us through the contact form or the email above; we may ask you to confirm the email address tied to the data. We will not discriminate against you for exercising any of these rights.
10. Children
Thames Coast is a general-audience site and is not directed to children. Reading is open to everyone, but you must be 18 or older to create an account or post to the community board, and you confirm that when you sign up. We do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us and we will delete it.
11. Changes to this policy
If we change this policy we will update the date above and, for material changes, note it on the site. Continued use after an update means you accept the revised policy.
12. Contact
Questions or requests: use our contact form or email nyriian@thamescoastevents.com.
Published by Elevare Studio LLC, Connecticut. See also our Terms of Service.