Privacy Policy

Effective date: July 25, 2026 · Last updated: July 25, 2026

Main Street Lobby, Inc. ("Main Street Lobby," "we," "us," or "our") is a national, non-partisan 501(c)(4) social welfare organization incorporated in Georgia. This Privacy Policy explains what personal information we collect from members and site visitors, how we use it, and the choices you have. It forms part of our Terms of Service, which are governed by the laws of the State of Georgia. Our services are designed for and directed to residents of the United States.

Our commitment

Privacy-by-design is one of our founding commitments:

  • We collect only what we need to run your membership and organize collective advocacy.
  • We never sell your personal information, and we do not use it for advertising. We do not "sell" or "share" your personal information, or process it for "targeted advertising," as those terms are defined under applicable state privacy laws.
  • Poll and survey results are only ever published in aggregate. Your individual answers are never published, shared, or displayed to other members or the public — unless you expressly choose to share something through a feature we clearly label that way.
  • As a civic-advocacy organization, we treat our member and supporter lists as confidential and resist compelled disclosure to the extent the law allows.

Information we collect

Information you provide.

  • Account information: your name and email address (required), plus either a password (stored only as a secure hash by our authentication provider) or a sign-in identifier from a supported provider (currently Google) if you choose social sign-in. If you use social sign-in, that provider shares your basic profile with us (name, and email where available).
  • Your ZIP code (required), which lets us direct advocacy to your own representatives — federal, state, and local.
  • Optionally, your mobile phone number — used only for the texts you opt into.
  • Your answers to the member surveys.
  • Membership and payment records: your subscription status and transaction records from our payment processor, Stripe. Payment happens on Stripe's secure checkout page — we never see or store your full card number.
  • Consent records: when and where you accepted the terms and gave any text-message opt-in.

Information collected automatically. Like most websites, we and our service providers automatically receive certain technical data when you use the site: your IP address, browser and device information, and logs of requests to our servers. Our authentication provider logs sign-in events, and Stripe uses cookies and device signals during checkout to detect fraud. See "Cookies and similar technologies" below.

How we use your information

  • To operate your membership: sign-in, receipts, renewals, cancellation, and support.
  • To aggregate member priorities so that members' collective voice is visible.
  • To direct advocacy actions to your own representatives — federal, state, and local — using ZIP codes.
  • To send you communications you have opted into.
  • To keep the service secure: preventing fraud, debugging problems, and protecting accounts.
  • To meet the legal and tax obligations that apply to a 501(c)(4).

We do not use your information for advertising, we do not sell or rent it to anyone, and we do not use it to make automated decisions that produce legal or similarly significant effects about you.

Cookies and similar technologies

We do not use advertising cookies or trackers. We may use privacy-respecting analytics to understand how the site is used and improve it; we configure any such tools so they are not used to advertise to you. We use browser storage for a small number of jobs, such as keeping you signed in, remembering your progress through the join flow, and briefly caching member pages so they load quickly. Stripe sets cookies and collects device signals during checkout to prevent fraud. Some fonts and scripts on our pages are delivered by content-delivery networks, which receive your IP address in order to serve those files.

Because we do not sell or share personal information or use it for advertising, signals like "Do Not Track" and Global Privacy Control do not change how we treat you — every member gets the same protections by default.

Email and text messages

Email. We send account and membership email as needed — sign-in links, confirmations, and receipts. As a member, you will also receive advocacy updates and organizational news by email; you can opt out of those at any time using the unsubscribe link in every such message or by contacting us, and your account email will continue for as long as you have an account.

Text messages (SMS). You will only receive texts if you provide your mobile number and check the consent box. Texts cover member polls, actions, impact updates, and important membership notices. Message frequency varies. Message and data rates may apply. Reply STOP to cancel at any time, or HELP for help; you can also reach us at privacy@mainstreetlobby.com. Consent is not a condition of membership. We record when and where you gave consent. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

Aggregate-only publication

Member survey responses power our "What Members Say" insights and our public accountability work. These are always statistical aggregates (for example, "68% of members say this issue matters a lot in how they vote"). We do not publish, share, or display any individual member's responses — not to other members, not to the public — unless you expressly choose to share something publicly through a feature we clearly label that way. Before publication, aggregate reports are reviewed to make sure they cannot identify individuals, and we do not publish results for groups so small that they could. We maintain aggregate data in de-identified form and will not attempt to re-identify it.

Service providers

A small number of companies process member data on our behalf. Each processes your data only to provide its service to us, under that provider's standard terms and data-processing agreement:

  • Stripe — payments (stripe.com/privacy)
  • Supabase — secure database and authentication (supabase.com/privacy)
  • Netlify — website hosting (netlify.com/privacy)
  • Resend — delivery of account emails, such as sign-in links and confirmations (resend.com/legal/privacy-policy)
  • Google — sign-in, if you choose it (policies.google.com/privacy)

We store member data in the United States. Some of these providers may process limited data through their own global infrastructure or sub-processors; wherever your information is processed, it remains protected under this policy.

Before we first send bulk advocacy email or text messages, we will add any additional providers that deliver them. A current list of our service providers is available on request.

When we may disclose information

We may disclose personal information if required by valid legal process, or where necessary to protect the rights, safety, or property of our members, the public, or Main Street Lobby.

Membership in a civic organization is sensitive. If we receive a government or third-party demand for member information, we will require valid legal process, assert the legal protections available to membership organizations against compelled disclosure, and — where the law allows — notify affected members before we respond. If Main Street Lobby is ever reorganized or merged, member data remains protected under this policy.

Your choices and rights

  • Cancel your membership at any time in the billing portal.
  • Opt out of texts by replying STOP, and out of non-essential email using the unsubscribe link.
  • Request access to, correction of, or deletion of your personal information by emailing privacy@mainstreetlobby.com or writing to us at the address below. We extend these rights to all members, whatever state you live in. You may use an authorized agent to make a request; we may ask the agent for proof that you authorized them.

We verify requests through your member account (or equivalent proof for former members) and respond within 45 days, and we may extend by an additional 45 days where the law permits, telling you why. We will never treat you differently for exercising your rights. If we decline a request — for example, where the law requires us to keep certain tax records — we will explain why, and you may appeal by replying to our decision. Depending on where you live, state privacy laws (such as those in California, Colorado, and other states) may give you additional rights; requests under those laws go through the same contact.

Security and retention

Access to member records is restricted to authorized personnel and service providers who need it to operate the service — for things like support, billing, security, and data integrity. All traffic is encrypted in transit, and database access is controlled server-side: member records are never exposed directly to the browser. If a security incident affects your personal information, we will act promptly to investigate and contain it and will notify you and any regulators as required by applicable law.

We keep information only as long as it is needed:

  • Financial and transaction records — generally seven years, or longer where the law requires.
  • Consent records — while you are a member, plus any legally required period.
  • Survey answers — retained to power our aggregate insights; deleted or anonymized if you ask us to delete your information.
  • Server and security logs — short, rotating retention.

After that, records are deleted or anonymized, unless the law requires us to keep them longer — for example, records subject to a legal hold in connection with a legal proceeding or investigation. Because your account is identified only by the details you give us, when we delete your information we remove those identifiers (such as your name, email address, phone number, and ZIP codes); anything that remains — such as survey responses that feed our aggregates — is then held under a random internal ID that cannot be linked back to you. The one exception is the transaction records we must keep for tax (described above), which we delete when that retention period ends.

Children

Main Street Lobby is for adults. We do not knowingly collect personal information from anyone under 18, and we delete any such information we learn we have collected.

Changes and contact

If we change this policy, we will post the updated version here with a new "last updated" date, and we will notify members of material changes by email and/or a prominent notice on the site. Questions or privacy requests: email us at privacy@mainstreetlobby.com or write to: Main Street Lobby, Inc., 8735 Dunwoody Place #13390, Atlanta, GA 30350.