Privacy Policy

Effective: May 12, 2026
Last updated: July 8, 2026

1. About This Policy

Bakersfield Home Magazine ("we," "us," "our") operates HomeMag (the "Service") at crm.hmprs.com. This policy explains how we collect, use, store, and share information when the Service integrates with third-party services on your behalf, and when we communicate with you and your contacts by telephone and text message — specifically QuickBooks Online, Gmail, RingCentral (business telephone and SMS text messaging), Convirza (inbound call tracking), and our payment processors Stripe and NMI. By connecting an integration to your HomeMag account, or by providing your telephone number to us, you authorize us to access, process, and communicate using that information as described below. It also covers our public business directory — including quote-request forms and customer reviews — in section 8, along with how our public websites use cookies and similar technologies for analytics and advertising (including remarketing), and how we may use the information you submit to improve and personalize our services for our advertiser clients and to market our own and our advertisers' offerings.

2. QuickBooks Online Integration

2.1 What we access

When an administrator connects QuickBooks Online, the Service requests the OAuth scope com.intuit.quickbooks.accounting. Within that scope we read and write only the following data:

  • Read — customer records (display name, phone, billing address); invoices (line items, amounts, dates, class assignments); payments; and class definitions used for publication-level P&L segmentation.
  • Write — we create customer records for advertisers, post invoices and their line items, record payments against invoices, and assign QuickBooks classes to line items so each publication's revenue posts to the correct P&L segment.

We do not access bank feeds, payroll data, employee records, vendor records, or any QuickBooks data outside the categories listed above.

2.2 How we use QuickBooks data

  • Synchronize advertiser billing between HomeMag and QuickBooks Online so finance teams have one source of truth.
  • Segment revenue by publication (Bakersfield, Fresno, Central Coast) for internal reporting.
  • Reconcile payments received via Stripe and NMI against QuickBooks invoices.

We do not use QuickBooks data for marketing, advertising, profiling, or training machine-learning models.

2.3 How we store QuickBooks data

QuickBooks access tokens and refresh tokens are encrypted at rest using Laravel's encrypted cast (AES-256-CBC with an application-scoped key) and stored in the quickbooks_tokens table on our managed Laravel Cloud database. Connection metadata (realm ID, connecting user, last-refresh timestamp) is stored alongside the tokens for audit purposes. QuickBooks customer, invoice, and payment records are queried on demand at the time they are needed for display or reconciliation; we do not maintain a long-term mirror of your QuickBooks data.

2.4 Sharing

We do not sell, rent, or share QuickBooks data with third parties. Access is limited to authorized employees of Bakersfield Home Magazine for the purposes described in section 2.2, and to the following sub-processors strictly as required to operate the Service:

  • Laravel Cloud — application hosting and database.
  • Intuit, Inc. — the source of the data (QuickBooks Online API).

2.5 Retention and disconnection

The connection is established once per QuickBooks company (realm) and shared by your authorized team. You may disconnect QuickBooks Online at any time from the Integrations settings page in HomeMag, which immediately revokes our refresh token with Intuit and deletes the stored token record from our database. You may also revoke the connection directly from your QuickBooks Online account under Apps → Connected Apps.

2.6 Intuit's privacy policy

Your underlying use of QuickBooks Online is also governed by Intuit's own privacy policy: https://www.intuit.com/privacy/statement/.

3. Gmail Integration

3.1 What we access

When a user connects their Gmail account, the Service requests the following Google OAuth scopes:

  • https://www.googleapis.com/auth/gmail.readonly — read access to messages and metadata.
  • https://www.googleapis.com/auth/gmail.send — permission to send messages on the user's behalf.

Within those scopes, for each connected user we sync messages exchanged with email addresses that match advertisers and contacts already stored in your CRM, going back up to twelve (12) months from the date of connection, plus all new messages thereafter. For each matching message we store: headers (from, to, cc, subject, date, snippet), full body text (plain-text and HTML parts), and attachment metadata (filename, MIME type, size). We do not store the binary contents of attachments. We do not access calendar events, contacts, Drive files, or any other Google service.

3.2 How we use Gmail data

  • Surface advertiser-related emails on the relevant advertiser timeline in the CRM so sales reps and account managers have a complete picture of customer communications.
  • Associate emails to the correct advertiser/contact record using the sender and recipient email addresses.
  • Send outbound emails on the connected user's behalf when the user composes a message from within the CRM.

We do not use Gmail data for advertising, marketing to third parties, profiling, or training generalized machine-learning models.

3.3 How we store Gmail data

Per-user OAuth access and refresh tokens are encrypted at rest using Laravel's encrypted cast (AES-256-CBC with an application-scoped key) and stored in the gmail_accounts table on our managed Laravel Cloud database. Tokens are scoped to the individual user who connected Gmail and are not shared between users. Synced email records are stored in the emails table on the same database. All data is encrypted in transit via TLS.

3.4 Sharing and team visibility

We do not sell, rent, or share Gmail data with third parties. Synced emails are visible inside the CRM to authorized employees of Bakersfield Home Magazine with access to the linked advertiser record (a "Copper-style" team-visibility model). Administrators may restrict the visibility of any individual email or thread to specific users via the email_visibility_rules table.

We use the following sub-processors strictly as required to operate the Service:

  • Laravel Cloud — application hosting and database.
  • Google LLC — the source of the data (Gmail API).
  • Anthropic, PBC — used on a per-request basis to help associate incoming emails to the correct advertiser record. Only the sender, recipient, subject, and a short content excerpt are sent for matching purposes. Anthropic processes this data solely to return a matching result to HomeMag for the originating user. Per Anthropic's commercial API terms, content sent to Anthropic is not retained beyond the request lifecycle and is not used to train or improve any AI/ML models. No cross-customer use of this data occurs.

3.5 Retention and disconnection

You may disconnect Gmail at any time from the Integrations settings page in HomeMag, which immediately revokes our refresh token with Google and deletes the stored token record from our database. You may also revoke our access directly from your Google Account at myaccount.google.com/permissions.

Disconnecting stops further sync but does not by default delete previously synced messages from our database. To request deletion of previously synced Gmail data — at the time you disconnect or at any time afterward — email kevin@bakhomemag.com. We will permanently delete the requested data within thirty (30) days of receiving the request.

3.6 Google API Services User Data Policy (Limited Use)

HomeMag's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

  • transfer Gmail data to others unless doing so is necessary to provide or improve the Service, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users;
  • use Gmail data for serving advertisements;
  • allow humans to read Gmail data unless we have obtained your explicit consent to read specific messages, it is necessary for security purposes (e.g., investigating abuse), it is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations; and
  • use Gmail data to develop, improve, or train generalized AI/ML models. The narrow, per-request matching described in section 3.4 operates on minimal message metadata and is performed only to provide the Service to the user from whom the data originated. The Anthropic sub-processor disclosed in section 3.4 performs narrow inference for the originating user only and does not retain or train on transmitted content.

3.7 Google's privacy policy

Your underlying use of Gmail is also governed by Google's own privacy policy: https://policies.google.com/privacy.

4. Telephone Calls and Text Messages (RingCentral)

We use RingCentral, Inc. ("RingCentral") as our business telephone and text-messaging provider. This section describes how we process call and text-message information.

4.1 Call logging and recording

  • We sync the call log for our company RingCentral account, including each call's date and time, the calling and called telephone numbers, direction (inbound or outbound), duration, and result (for example, connected or missed).
  • Where a call is recorded, we store the audio recording and, where the feature is enabled, an automated text transcript of that recording.
  • We associate calls with the relevant advertiser or contact record by matching telephone numbers.
  • We do not ingest calls that involve administrative or agency telephone lines that we have configured to be excluded.

4.2 Notice and consent for recording

Some U.S. states, including California, require the consent of all parties to record a telephone call. Where calls are recorded, we do so in accordance with applicable law, including by providing notice (such as an announcement at the start of the call) where required.

4.3 How we use call data

  • Maintain a record of communications with advertisers and contacts on the relevant advertiser timeline.
  • Support sales, account management, and customer service.
  • Review recordings and transcripts to fulfill advertising-related requests (for example, to build or revise an advertisement from the customer's own instructions) and for quality assurance and training.

4.4 SMS / text messaging program

With your consent, we may send SMS text messages from a business number to customers and advertisers in connection with their advertising account and related services — for example, customer-care replies, scheduling and appointment messages, advertising proof/approval requests, and account or service notifications.

  • Consent. By providing your mobile telephone number to us and opting in (verbally, in writing, or electronically), you consent to receive recurring text messages from us at that number, including messages sent using automated technology. Consent to receive text messages is not a condition of any purchase.
  • Message frequency. Message frequency varies based on your interactions with us.
  • Cost. Message and data rates may apply, depending on your mobile carrier and plan.
  • Opt-out. You can opt out at any time by replying STOP to any text message. After you reply STOP, we will send one final message confirming your opt-out and will not send further texts unless you opt in again. Reply HELP for help, or contact us using the details in section 9.5.
  • Carriers. Mobile carriers are not liable for delayed or undelivered messages.

4.5 We do not share mobile or SMS data for marketing

We do not share or sell mobile telephone numbers, text-messaging opt-in information, or SMS consent to any third parties or affiliates for their own marketing or promotional purposes. No mobile information collected for the purpose of sending text messages is shared with third parties or affiliates for marketing or promotional purposes. We share information only with the service providers (sub-processors) and for the limited operational purposes described in this policy.

4.6 Storage and sub-processors

Call and message records are stored on our managed Laravel Cloud database; RingCentral API tokens are encrypted at rest. Recordings are retrieved from RingCentral over an authenticated, encrypted connection when played within the Service. We use the following sub-processors for this feature:

  • Laravel Cloud — application hosting and database.
  • RingCentral, Inc. — telephony and messaging provider, together with the underlying mobile carriers that deliver text messages.

Your underlying use of RingCentral is also governed by RingCentral's own privacy notice: https://www.ringcentral.com/legal/privacy-notice.html.

5. Inbound Call Tracking (Convirza)

We use Convirza to provision tracking telephone numbers that we place in our advertising and marketing. When a consumer calls one of these tracking numbers:

  • We receive call detail (date and time, the caller's telephone number, duration, result, and the tracking number called), a recording of the call, and, where available, an automated transcript.
  • We use this information to attribute and measure the performance of advertising campaigns and to support our advertisers.
  • Recordings are made in accordance with applicable law, including notice where required.

Call records are stored on our managed Laravel Cloud database and recordings are retrieved from Convirza over an authenticated, encrypted connection. Sub-processors for this feature are Laravel Cloud (application hosting and database) and Convirza (call-tracking provider). Convirza's handling of data is also governed by its own privacy policy at https://www.convirza.com/privacy-policy/.

6. Payment Processing (Stripe and NMI)

When an advertiser makes a payment, payment-card and bank-account information is collected and processed by our payment processors, Stripe, Inc. ("Stripe") and Network Merchants, Inc. ("NMI"), each of which maintains PCI-DSS compliance.

  • We do not store full payment-card numbers. We store payment-method tokens and limited metadata (such as card brand, last four digits, expiration, and funding type) returned by the processor, which we use to take payment, apply any applicable card surcharge, and reconcile against invoices.
  • Card and bank-account details entered to make a payment are transmitted to the processor over an encrypted connection.

Sub-processors for this feature are Laravel Cloud (application hosting and database), Stripe, Inc., and Network Merchants, Inc. Their handling of payment data is also governed by their own privacy policies: https://stripe.com/privacy and https://www.nmi.com/privacy-policy/.

7. Electronic Signatures and Contract Audit Trail

When we send an advertising agreement or other contract for electronic signature, we maintain an audit trail to evidence that the agreement was delivered, reviewed, and signed, and to support the validity of the electronic signature under the federal Electronic Signatures in Global and National Commerce Act (ESIGN) and the Uniform Electronic Transactions Act (UETA). For each agreement we may record:

  • the recipient email address the agreement was sent to, and the date and time it was sent;
  • when the recipient first opened the signing link, and how many times it was opened;
  • the name and email address entered by the signer, and the date and time of signature; and
  • the IP address of the device used to sign.

Where an agreement also authorizes payment (for example, a one-time charge or a recurring ACH/card authorization or "mandate"), we additionally record the IP address and browser user-agent at the time the authorization is accepted, together with the signature and timestamp, as evidence of the payer's consent to the authorization.

This information is stored on our managed Laravel Cloud database and is used solely to administer the agreement, evidence consent, and resolve any dispute about whether or when an agreement or payment authorization was signed. We do not use it for marketing, and we do not sell or share it.

8. Public Business Directory, Quote Requests, and Reviews

We operate a public business directory where local businesses that advertise with us maintain profile pages, and where visitors can submit a request for a quote to a specific business or write a review of a business. This section describes what we collect on those pages and who it is shared with.

8.1 What we collect

  • Contact information — your name, email address, and telephone number, when you submit a quote request or create a reviewer account.
  • Project details — the message and any project information you enter in a quote request (for example, the type of work you want done).
  • Review content — your display name, city, star rating, review text, optional project details, any photos you attach (we remove embedded location/EXIF metadata from photos before storing them), and your attestations that you are a real customer and not an insider of the business.
  • Technical data — your IP address, browser user agent, the page you submitted from, the referring page, and campaign parameters (UTM tags) in the page URL.

8.2 Who it is shared with

When you submit a quote request, we share the contact details and project information you enter with the business whose profile you submit the request on — the one business named on the form — so it can respond to you. We do not sell quote-request information, and we do not forward it to any business you did not select. Published reviews (your display name, city, rating, text, and photos) are visible to the public and to the reviewed business, which may post one public response; we do not share your email address with the reviewed business. Categories of third parties that may receive directory data are: the business whose profile you submit a request or review on, and the service providers that host and secure the Service (Laravel Cloud for hosting and database; Cloudflare, Inc. for form protection as described in section 8.3; and our transactional email providers, Postmark (Wildbit, LLC) and Twilio SendGrid, Inc., which deliver confirmation and verification emails such as "your request was sent" and review email-verification links). Company profile pages offer an optional embedded map: it loads from Google Maps only if you click "Load map," and we do not contact Google until you do — the "Get Directions" link likewise opens Google Maps in a new tab only when you choose it.

In addition, we may use the information you submit through the directory (such as a quote request or review) and your activity on our public websites to improve and personalize the services we provide to our advertiser clients, and to market and advertise our own and our advertisers' services to you — including through the analytics and advertising partners, cookies, and remarketing technologies described in section 8.7. We do not sell your quote request to, or forward it to, any business you did not select, and the SMS and mobile carve-out in section 4.5 continues to apply — mobile telephone numbers and SMS opt-in information are never used or shared for third-party marketing.

8.3 Form protection (Cloudflare Turnstile)

We use Cloudflare Turnstile to protect our forms from automated abuse. Turnstile evaluates technical signals from your browser to distinguish people from bots; its handling of data is governed by Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/.

8.4 Consent records for quote requests

Each quote-request form displays a disclosure, above the submit button, naming the business that will receive your information and describing how it may contact you. When you submit the form we keep a record of the exact disclosure text shown, the date and time, your IP address, your browser user agent, and the page you submitted from, as evidence of your consent. This record is retained for four (4) years (see the retention schedule in section 8.5). This consent record — the disclosure text and version, date and time, IP address, and browser user agent — is used solely to administer the request and evidence your consent, never for marketing; the separate use of the contact and project details you submit is described in sections 8.2 and 8.7.

8.5 Retention

  • Quote requests (leads) — the personal information you submit (your name, email, phone number, and project message) is anonymized twenty-four (24) months after submission. The consent record described in section 8.4 (the disclosure text and version, date and time, IP address, and browser user agent) is retained alongside the anonymized record for four (4) years from submission, after which the entire record is permanently deleted.
  • Reviews — published reviews remain posted while the business's profile is listed. Reviews that are rejected in moderation or later removed for violating our published review criteria are retained, unpublished, together with the moderation decision log, to document that our moderation is applied uniformly and without regard to sentiment. Those criteria, the "Verified customer" badge, and how a business flags a review are described in our Review Integrity Policy.

8.6 Reviewing, correcting, or deleting your information

To review, correct, or request deletion of information you submitted through the directory — a quote request, a review, or your reviewer account — email kevin@bakhomemag.com. We will respond within thirty (30) days. Material changes to this policy are announced as described in section 9.4 (posted on this page with an updated effective date).

8.7 Cookies, analytics, and advertising (including remarketing)

Our public websites (including the business directory) use cookies, web beacons and pixels, software development kits, local storage, and similar technologies. Some are strictly necessary to operate and secure the site (for example, the Cloudflare Turnstile script described in section 8.3). Others let us remember preferences, measure and analyze traffic and how the site is used, and deliver, measure, and improve advertising — including remarketing (also called retargeting), which shows you advertisements for us or for our advertisers on other websites, apps, and platforms after you have visited our site.

These technologies may be set by us (first party) or by third-party analytics and advertising partners acting on our behalf. Those partners may include providers such as Google (Google Analytics and Google Ads) and social-media advertising platforms. They may combine the information collected on our site with information they hold from other sources, and may use it to build audiences and serve targeted advertising across the web. We may also combine the information you submit to us (for example, a quote request or a review) with this activity data to gauge interest, to improve and personalize the services we provide to our advertiser clients, and to market our own and our advertisers' services to you.

Where required by law, we ask for your consent to non-essential cookies and honor opt-out preference signals; your choices are described in section 8.8 and, for California residents, section 9.3. This advertising and analytics use does not extend to the SMS and mobile information covered by the carve-out in section 4.5 — we never use or share mobile telephone numbers or SMS opt-in information for third-party marketing.

8.8 Your tracking choices, Global Privacy Control, and Do Not Track

You can control tracking in several ways:

  • adjust your browser or device settings to block or delete cookies (blocking strictly necessary cookies may break parts of the site);
  • use industry opt-out tools, including the Digital Advertising Alliance at optout.aboutads.info and the Network Advertising Initiative at optout.networkadvertising.org;
  • opt out of Google Analytics with the Google Analytics opt-out browser add-on; and
  • for California residents, exercise the right to opt out of "sharing" for cross-context behavioral advertising as described in section 9.3.

Global Privacy Control (GPC). We treat a GPC signal sent by your browser or extension as a valid request to opt out of the sale or sharing of personal information for that browser or device.

Do Not Track (DNT). There is no common industry standard for interpreting browser "Do Not Track" signals, so our websites do not respond to them; please use the controls above instead.

9. General

9.1 Security

All data is transmitted over TLS. Third-party integration tokens are encrypted at rest. Access to data within the CRM is gated by role-based permissions. On our public websites we use analytics and advertising technologies, including remarketing, as described in section 8.7, and you can exercise choices over that use as described in sections 8.8 and 9.3. We do not sell personal information for money, and we never use or share mobile telephone numbers or SMS opt-in information for third-party marketing (section 4.5).

9.2 Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children.

9.3 California residents (CCPA / CPRA)

In the past twelve months, we have collected the following categories of personal information: identifiers (e.g., name, email, telephone and mobile number); commercial information (e.g., transaction and advertising history); audio and electronic information (e.g., telephone-call recordings and transcripts); and internet or other electronic network activity (e.g., IP address, usage logs, and electronic-signature audit records). California residents have the right to know what we collect, request deletion or correction, and opt out of the sale or sharing of personal information. We do not sell personal information for money. We do share personal information — as "share" is defined under the CCPA/CPRA — for cross-context behavioral advertising when we use the analytics and advertising technologies described in sections 8.7–8.8 (for example, advertising cookies and remarketing tags). We do not share mobile telephone numbers or SMS opt-in information for cross-context behavioral advertising or third-party marketing (section 4.5). You have the right to opt out of this sharing: use the cookie and advertising controls in section 8.8, send a Global Privacy Control signal (which we honor as an opt-out of sharing for that browser or device), or email kevin@bakhomemag.com. To exercise your other rights (to know, delete, or correct), email the same address.

California residents also have the right not to be discriminated against for exercising any of these rights, and the right to limit the use and disclosure of sensitive personal information. HomeMag does not use or disclose sensitive personal information beyond the purposes described in this policy.

9.4 Changes to this policy

Material changes will be posted on this page with an updated effective date. Continued use of the Service after the changes take effect constitutes acceptance of the modified policy.

9.5 Contact

Bakersfield Home Magazine
9731 Rosedale Highway
Bakersfield, California 93312
kevin@bakhomemag.com

9.6 Governing law

This policy is governed by the laws of the State of California, United States, without regard to its conflict-of-law principles.