Privacy Policy
What we collect, why we collect it, who ever sees it, and exactly how to get it back or get it deleted. Written to be read, not to be skipped.
Who we are, and the two ways this applies to you
This Privacy Policy explains how LA Media Group, LLC ("LA Media Group," "we," "us," "our") handles information. We are a Florida limited liability company at 3134 Peachtree Cir, Davie, FL 33328.
There are two quite different relationships covered here, and which one you are in changes what we hold and why.
This policy covers lamediagrp.com, its subdomains, any mobile version, the Bluu dashboard at bluu.lamediagrp.com and dashboard.lamediagrp.com, the websites we build and host for clients where we operate them on the client's behalf, and every service reachable from any of those.
Information we collect
Information you give us
- Contact details : your name, business name, email address, mobile or landline number, and postal address when you enquire, book a call, subscribe, or become a client.
- Account details if you are given access to the Bluu dashboard: your name, email address, role, and a password that is stored only as a one way hash, never in a form anyone here can read.
- What you tell us in emails, text messages, chat conversations, forms, and calls, including anything you choose to put in a free text box.
- Business information you give us so we can do the work: your services, prices, opening hours, locations, staff, photographs, brand assets, and the logins you choose to connect.
- Billing information : what you have bought, what you have paid, and your prepaid balance. We never see or store your full card number. Card details go directly to Stripe, our payment processor, and we hold only the last four digits, the card brand, and an expiry date.
Information we collect automatically
- Device and connection data : IP address, browser type and version, operating system, screen size, language, and the referring page.
- Usage data : which pages you looked at, when, for how long, what you clicked, and in the dashboard, which actions were taken and by which user.
- Cookies and similar technologies , described in section 6.
- Call data where a call tracking number is in use: the number you called from, the time, the duration, whether it was answered, and in some cases a recording. Where a call is recorded you are told at the start of the call.
Information from other sources
- Accounts you connect , covered in sections 8, 9 and 10.
- Advertising platforms , which tell us that a click or an enquiry came from a particular campaign, without telling us who you are.
- Publicly available business information , such as your own website and your Google Business Profile, which we read to build and improve your marketing.
How we use information
- To answer you, to give you a quote, and to carry out the work you have engaged us for.
- To operate, secure, support and improve this website, the Bluu dashboard and the websites we build and host.
- To send you service messages you would expect: appointment confirmations and reminders, booking notifications, invoices, receipts, password resets, and notices about your account.
- To send you marketing emails you have agreed to receive, and to stop the moment you tell us to.
- To take payment, keep accounts, and meet our tax and record keeping obligations.
- To measure how our own marketing performs, in aggregate.
- To detect, investigate and prevent fraud, abuse, and anything that threatens the security of the service or the people using it.
- To comply with the law, and to establish, exercise or defend a legal claim.
We do not use your information to make an automated decision that produces a legal or similarly significant effect on you, and we do not profile you for that purpose.
Text messaging (SMS)
What happens to your number
Your mobile number is held so that we can send you the messages described above and so that we can honour an opt out permanently. It is stored in our systems and passed only to the communications provider that physically delivers the message, which today is Twilio. It is not passed to anybody else, and it is never used for another organisation's marketing.
United States carriers require every business that sends text messages to register its identity and its messaging program with them before messages are delivered. As part of that registration we supply our company details and a description of this program. We do not supply any customer's mobile number or personal information as part of registration.
If you are a client of ours who sends text messages
The Bluu dashboard lets a business send text messages to its own customers. If that is you, the messages are yours, not ours. You are responsible for having a lawful basis to contact each person, for honouring every opt out, and for complying with the Telephone Consumer Protection Act and the rules the carriers apply. We register your business and your messaging program with the carriers on your behalf, using the details you give us, and we process opt outs automatically at the network level so that a STOP is honoured even if your own records are not updated.
We send two kinds of email and they are treated differently.
- Service email : receipts, invoices, appointment confirmations, password resets, and notices about your account. These are part of the service and cannot be switched off while you have an account, because switching them off would leave you unaware of things that affect you.
- Marketing email : newsletters, offers, and updates about what we do. Every one carries an unsubscribe link, and unsubscribing takes effect immediately. You can also reply and ask, or email info@lamediagrp.com.
Our marketing emails may record whether the email was opened and whether a link in it was clicked, so we can tell what is worth sending. If you would rather we did not, tell us and we will exclude you.
Cookies, analytics and other tracking
Cookies are small text files a website stores on your device. We use them, and technologies that do a similar job such as pixels, tags, local storage and software development kits, for four purposes.
You can refuse or delete cookies through your browser settings, usually under Privacy or Security, and most browsers explain how in their Help section. If you block them, parts of this website and most of the dashboard will stop working, because we use a cookie to keep you signed in.
Advertising and remarketing
We advertise. That means an advertising platform may be told that a visit, a click or an enquiry happened on our website, so that we can measure whether the money was well spent and so that we can show our adverts to people who have already visited us.
In practice this means Meta Platforms, Inc. (Facebook and Instagram) and Google LLC. Where we match an enquiry back to an advert, the identifier we send is hashed before it leaves us. Both companies act as independent controllers of the data they receive under their own terms, including Meta's Custom Audiences terms.
You can limit this. Google's Ads Settings and Meta's Ad Preferences both let you control what they use, and the Digital Advertising Alliance opt out covers many advertisers at once. Blocking third party cookies in your browser also stops most of it.
We do not sell your information to advertisers, and no advertising platform gets access to the information a client puts into the Bluu dashboard.
Accounts you connect to the dashboard
The Bluu dashboard can connect to accounts you already own so that it can do useful work with them. Every connection is optional, every one is started by you, and every one can be undone by you from inside the dashboard.
When you connect an account we store an access token, which is a credential that lets our server act for you within the narrow permissions you granted. Tokens are stored in database tables with row level security enabled and no policy that any browser can satisfy, so they are reachable only by our own server. Disconnecting deletes the token.
Those services are run by their own companies under their own terms and privacy policies, and we do not control them.
Google user data
What we access
If you connect a Google account, we request only these permissions:
-
openidanduserinfo.email, to identify which Google account is connected and show you that address, so you can tell which account is linked before you rely on it. -
calendar.events, to create calendar events and Google Meet links for appointments booked through the service. We only write events. We do not read, list or import the events already in your calendar , and we never see your existing schedule. -
business.manage, to list the Google Business Profile locations you manage so you can choose one, read the reviews left on it, and post a reply you have written. We never create, edit or delete a location. -
analytics.readonly, to display your own Google Analytics traffic inside your dashboard. It is read only , and it is the narrowest Analytics permission Google offers. We never change your Analytics configuration.
How we use it
Google data is used only to provide the feature you connected it for: putting a booked appointment on your calendar, showing and replying to your reviews, and displaying your own website traffic. We do not use it for advertising, for lending decisions, for profiling, or for any purpose other than the features described above.
What we share, and with whom
We do not sell, rent or transfer Google user data to third parties, data brokers or advertisers. The only parties that process it are our own infrastructure providers acting on our instructions under contract, solely to run the service: our hosting provider (Vercel) and our database and file storage provider (Supabase). A reply you choose to publish is sent back to Google to appear on your own listing.
Artificial intelligence and machine learning
No data received from Google APIs is used with, or transferred to, any artificial intelligence or machine learning system. We do not use it to develop, improve or train any AI or ML model, our own or anyone else's, and we do not pass it to a third party AI service. The service does include AI features, and they operate only on information created inside the dashboard or taken from your own public website.
How we protect it
OAuth tokens are stored server side in a table with row level security enabled and no client readable policy, so they are reachable only by our server and never by a browser. All traffic is encrypted in transit. Access is controlled per user and per business, and each client's data is isolated at the database row level from every other client's.
How long we keep it, and how to delete it
We keep Google data only while the connection is active. Disconnecting removes our access and deletes the stored tokens and the review data we pulled from that listing. Calendar events we created stay in your calendar, because they belong to you. You can disconnect at any time inside the dashboard, revoke our access directly at myaccount.google.com/permissions, or ask us to delete everything. Deletion requests are actioned within 30 days.
Meta (Facebook) Page data
If you connect a Facebook Page, we request pages_show_list
(to let you choose which Page), pages_read_engagement
and pages_read_user_content
(to read that Page's reviews and recommendations), pages_manage_engagement
(so a reply you write is posted to the Page), leads_retrieval
and pages_manage_metadata
(so a lead from a Facebook lead form arrives in your dashboard), ads_read
(so your own advertising figures appear in your reporting), and business_management
(so Pages owned by a business portfolio, rather than by you personally, can be found at all).
We read your Page's reviews and recommendations, the leads submitted to your own lead forms, and read only advertising statistics for the ad account you select. We do not access your personal Facebook profile, your friends, or your private messages. We do not use Meta data for advertising, we do not sell or transfer it, and we do not use it to train machine learning models.
You can disconnect at any time inside the dashboard, which removes our access and deletes the data we pulled from that Page. You can also remove our access from Facebook Settings, Business Integrations. Disconnecting changes nothing on Facebook itself: your Page and its reviews stay exactly as they are, because they belong to you and to the people who wrote them.
Artificial intelligence in our products
Some parts of the dashboard use AI: a chat assistant that can answer a visitor on a client's website, an assistant that helps a client use the dashboard, and tools that draft written content. Here is precisely what that does and does not mean.
- We do not train models on your data. Not on your information, not on your customers' information, and not on anything received from Google or Meta.
- The AI is given only what it needs to answer : the business profile, services, locations and public website page summaries of the business it is answering for. It cannot see another business's information.
- It is bounded in code, not by instruction. It will not give professional or regulated advice, quote a price it has not been given, or promise a result, whatever anyone types at it. Those conversations are handed to a human.
- Conversations are stored so the business can read them and follow up, exactly like an email would be.
AI processing is carried out by Anthropic, PBC as our subprocessor under contract, on the basis that submitted content is not used to train their models.
Information belonging to our clients' customers
When a client uses the Bluu dashboard, they put their own customers' details into it: names, email addresses, phone numbers, appointments, notes, messages, form submissions and files. For all of that, the client is the controller and we are the processor. We:
- process it only to provide the service, and on the client's instructions;
- isolate every client's data from every other client's at the database row level, and check that isolation with automated tests rather than trusting that we wrote it correctly;
- never sell it, never use it to advertise to anybody, and never use it to train an AI model;
- give it back or delete it when the client asks, or when their account closes;
- pass it on only to the subprocessors in section 13, each of which is under contract to do the same.
If you are the customer of one of our clients and want your details corrected or removed, the fastest route is to ask that business directly , because it is their record. If you cannot reach them, contact us at info@lamediagrp.com and we will pass your request to them and follow up.
Who we share information with
We share information only with companies that help us run the service, and only as much as the job requires. Each is under contract to process it on our instructions and to keep it secure. As of the date at the top of this page:
We also disclose information where we are required to by law, a court order, or a valid request from a public authority; where it is necessary to establish, exercise or defend a legal claim; and to a buyer or successor if our business is sold or merged, in which case we will say so on this page before your information moves.
We publish a separate policy on how we handle government and law enforcement requests, and we will tell you about a request for your information unless we are legally forbidden from doing so.
We do not sell or share your personal information
We have not sold personal information in the preceding twelve months and we do not intend to. We do not sell it now, we have never sold it, and we do not rent, trade or otherwise release it to a data broker.
California law also uses the word "sharing" for disclosing personal information for cross context behavioural advertising. Our use of the Meta pixel and Google Ads tags described in section 7 could be treated as "sharing" under that definition. You can stop it by blocking third party cookies, by using the opt out links in section 7, or by sending a Global Privacy Control signal, which we honour (see section 19).
We have never sold or shared the personal information of anyone we know to be under 16.
How we protect information
- Everything travels over an encrypted connection, and our own applications are served only over HTTPS.
- Data is encrypted at rest by our hosting and database providers.
- Access is controlled per person and per business. Signing in to one business's dashboard gives no route to another's, and that boundary is enforced by the database itself rather than only by application code.
- Credentials for connected accounts are held in tables no browser can read, reachable only by our server.
- Passwords are stored as one way hashes. Nobody here can read your password, including us.
- Files uploaded through a form are stored in a private bucket and are downloadable only through a short lived signed link issued to somebody who is already authorised to see them.
No system is perfectly secure, and no honest company will tell you otherwise. Sending information over the internet is never entirely without risk. If a breach affects your personal information we will notify you and the relevant authorities as the law requires.
How long we keep information
Your rights, and how to use them
Wherever you live, you can ask us to do all of the following, and we will.
- Tell you what we hold about you, where we got it, what we do with it, and who we have disclosed it to.
- Give you a copy in a portable format.
- Correct anything that is wrong.
- Delete it, unless the law requires us to keep a specific record such as an invoice.
- Stop marketing to you , by any channel, immediately.
- Limit or object to a particular use.
- Withdraw a consent you previously gave, without that affecting anything done before you withdrew it.
California residents
The California Consumer Privacy Act, as amended by the CPRA, gives California residents the rights above, plus the right to know what categories we collect, use, disclose and sell or share; the right to limit the use of sensitive personal information, which is moot here because we do not collect any; and the right not to be discriminated against for exercising any of them. We will never give you a worse price or a worse service because you asked.
Other states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and every other state with a comprehensive privacy law have equivalent rights, including the right to appeal if we refuse a request. If we refuse, we will tell you why and how to appeal, and we will answer an appeal within 45 days.
How to make a request
Email info@lamediagrp.com with the word PRIVACY in the subject line, or call (954) 800-8383, or write to us at the address in section 22. We will acknowledge within 10 days and answer within 45 days, and we will tell you if we need a further 45 days and why.
We may need to verify who you are before we hand over personal information, which usually means replying from the email address we already hold. An authorised agent may act for you with your written permission.
Children
This website, the dashboard, and our services are for businesses and for adults. They are not directed at children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us information, email info@lamediagrp.com and we will delete it promptly.
We do not knowingly sell or share the personal information of anyone under 16, and as stated in section 14 we do not sell personal information at all.
Do Not Track and Global Privacy Control
There is still no common standard for how a website should respond to a browser Do Not Track signal, so like most websites we do not respond to it.
We do honour the Global Privacy Control. If your browser or an extension sends a GPC signal, we treat it as a valid request to opt out of any sharing of your personal information for cross context behavioural advertising, for that browser.
Where your information is held
We are based in the United States and our providers store data in the United States. If you are visiting from outside the United States, your information will be transferred to, stored in, and processed in the United States , where privacy laws may differ from those in your country. By using this website or our services you understand that.
Our services are aimed at businesses in the United States. We do not target the European Economic Area or the United Kingdom, and we do not knowingly market to people there.
Changes to this policy
We may update this policy. The date at the top always shows when it last changed, and the current version is always the one on this page.
Where a change materially affects you, for example a new category of information or a new purpose, we will give reasonable notice before it takes effect, by email where we have your address or by a notice on this website. Continuing to use the website or the service after a change takes effect means you accept it.
How to contact us
A person reads these. Ask us anything about this policy, or tell us to delete everything we hold about you, and we will handle it.
See also our Website Use Policy and our Copyright Policy.
Nothing in this policy matches that. Try a shorter word, or email info@lamediagrp.com and we will answer it directly.
Everything else we publish
Ask us anything about this
A real person reads these emails. If you want to know what we hold about you, or you want it gone, say so and we will handle it.




