Privacy Policy — 38 Flags
Effective date: 2026-05-09
Last updated: 2026-05-09
This Privacy Policy describes how [pending confirmation: 38 Flags Inc.? Lew Firm DBA? Nonprofit if restructured? — confirm] ("we", "us", or "our") collects, uses, and discloses your personal information when you visit
38flags.com (the "Site"). By using the Site, you agree to the practices described below.
1. What We Collect
We collect a limited set of information, only as needed to operate the Site.
a) Information you provide
When you fill out a form on the Site (for example, an enrollment form, contact form, or newsletter signup), we collect:
Not applicable — this Site does not have any forms.
b) Information collected automatically
When you visit the Site, our analytics tools may collect:
Google Analytics 4 (anonymized IP) records page views, session duration, referrers, and device/browser type — only after you accept the consent banner. Standard server logs (30-day retention) are kept regardless.
c) Information from third parties
We do not purchase personal information from data brokers. We do not combine information about you from external sources unless you have directly provided it to us.
2. How We Use It
We use the information we collect to:
- Provide and improve the Site and its services
- Respond to inquiries, fulfill enrollments, and deliver requested materials
- Send transactional or service-related communications (we do not send
- Comply with legal obligations and protect against fraud or abuse
unsolicited marketing without your opt-in)
We do not sell your personal information to third parties for monetary consideration. We do not share your personal information for cross-context behavioral advertising.
3. Who We Share It With
We share information only with service providers that help us run the Site, under contracts that limit their use of your information to providing services to us. These include:
- Netlify — hosting. Privacy policy: https://www.netlify.com/privacy/
- Google Analytics — anonymized site-traffic analytics (only if you accept). Privacy policy: https://policies.google.com/privacy
- Google Fonts — typography. Privacy policy: https://policies.google.com/privacy
We may also disclose information when required by law, in response to a valid legal request, or to protect the rights, property, or safety of [pending confirmation: 38 Flags Inc.? Lew Firm DBA? Nonprofit if restructured? — confirm], our users, or others.
4. Your Rights — California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we have collected about you in the
- Access a portable copy of your personal information.
- Delete your personal information (with limited exceptions).
- Correct inaccurate personal information.
- Limit the use and disclosure of sensitive personal information.
- Opt out of the sale or sharing of your personal information.
- Non-discrimination — we will not deny you services or charge you
past 12 months and the categories of sources from which it was collected.
different prices because you exercised these rights.
How to exercise your rights
You may submit a request by either of these methods:
- Email: [pending confirmation: suggest privacy@38flags.com]
- Web form: 38flags.com/privacy-choices
We will verify your identity before fulfilling a request. We respond within 45 days (or up to 90 days for complex requests, with notice).
"Do Not Sell or Share My Personal Information"
We do not sell or share your personal information for monetary consideration or cross-context behavioral advertising. If you wish to opt out as a precaution, visit 38flags.com/privacy-choices or click the "Your Privacy Choices" link in the footer.
Global Privacy Control (GPC)
We honor the Global Privacy Control signal as a valid opt-out request. If your browser sends a GPC signal, we treat it as your opt-out from sale or sharing of your personal information automatically — no further action required from you.
5. Cookies and Tracking
The Site uses a minimal set of cookies and similar technologies:
| Cookie | Purpose | Duration | Type | |---|---|---|---| | babycakes-consent-v1 | Stores your consent preference | 12 months | First-party, essential | | _ga, _ga_VQ3DRCZQR4 | Google Analytics — only set after consent | Up to 2 years | Third-party, optional |
Your choices
- In-browser controls: most browsers let you block or delete cookies.
- Site banner: when you first visit the Site, you may see a consent
- GPC: if your browser sends GPC, we treat it as a "reject" signal
banner letting you accept or reject non-essential tracking. The Accept and Reject buttons are presented with equal visual weight — no design preference is given to one option over the other.
for sale/share automatically.
6. Email Marketing & Communications
If you receive marketing or promotional email from us:
- Every marketing email includes a clear unsubscribe link at the
- Every marketing email includes our physical mailing address, as
- Our mailing address: 9440 Santa Monica Blvd Suite 301, Beverly Hills, CA 90210
- Transactional and service-related messages (e.g., enrollment
bottom of the message. Clicking it processes your opt-out within
10 business days (typically faster).
required by the U.S. CAN-SPAM Act.
confirmations, password resets) are not subject to unsubscribe because they are required to deliver the service you've engaged. We will never bundle marketing into transactional messages without your consent.
To unsubscribe from all marketing communications at once, email [pending confirmation: suggest privacy@38flags.com] with the subject line UNSUBSCRIBE and we will process the request within 10 business days.
7. Children's Privacy
The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected such information in error, please email [pending confirmation: suggest privacy@38flags.com] and we will delete it.
8. Visitors from the EU / UK
We are based in the United States, and any information you provide is transferred to and processed in the U.S. By using the Site, you consent to that transfer. EU/UK residents have rights similar to those listed in Section 4 (access, correction, deletion, objection, portability) and may contact us at [pending confirmation: suggest privacy@38flags.com] to exercise them.
9. Data Security
We use commercially reasonable technical and organizational measures to protect personal information — including HTTPS encryption in transit, access controls on backend services, and limiting data collection to what is necessary. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Data Retention
We retain personal information only as long as necessary to fulfill the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Form submissions: Not applicable.
- Analytics data: Google Analytics data is retained for 14 months (default GA4 retention).
- Email communications: Email correspondence is retained for as long as the underlying matter requires, plus 24 months.
11. Changes to This Policy
We review this Privacy Policy at least once every 12 months and update it when our practices change. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be announced via a notice on the Site for at least 30 days before they take effect.
12. Contact
For privacy questions or to exercise your rights:
[pending confirmation: 38 Flags Inc.? Lew Firm DBA? Nonprofit if restructured? — confirm] 9440 Santa Monica Blvd Suite 301, Beverly Hills, CA 90210 Email: [pending confirmation: suggest privacy@38flags.com]
This Privacy Policy is provided in plain English to be readable. It is not legal advice. If you have a specific concern, please contact us using the information above.