Privacy Policy
PHX Beyond Binary
Effective Date: October 8, 2025
Last Updated: January 15, 2025
1. Introduction
Welcome to PHX Beyond Binary. We are committed to protecting your privacy and handling your personal information with care, especially given the sensitive nature of our community and the data we collect.
This Privacy Policy explains:
What information we collect and why
How we use and protect your information
Your rights regarding your data
How we handle sensitive information about gender identity and LGBTQ+ status
Our security practices and commitments
By using our website or services, you consent to the data practices described in this Privacy Policy. If you do not agree with our practices, please do not use our website or provide us with your information.
2. Who We Are
PHX Beyond Binary is a grassroots initiative planning to create a trans-centered hackerspace, makerspace, and community space in Phoenix, Arizona. We are currently in the planning and validation phase.
Resource Transparency:
PHX Beyond Binary is currently operated by a single founder. We want to be upfront about what this means:
Responses to inquiries may take longer than a large organization
We're building systems and processes as we grow
We prioritize security for sensitive community data above all else
We're committed to transparency about our capabilities and limitations
We believe in being honest about our scale so you can make informed decisions about sharing information with us.
Contact Information:
Website: https://phxbeyondbinary.com
Email: hello@phxbeyondbinary.com
Responsible Party: Quinn Penney, Founder
3. Information We Collect
3.1 Information You Provide Directly
We collect information that you voluntarily provide to us through various means including surveys, feedback forms, email signups, and other community engagement tools. The specific information we collect may include:
Contact Information
Email addresses (may be required or optional depending on the feature)
Names (typically optional)
Timestamps indicating when you provided information
Community Feedback and Research Data
When you participate in surveys, feedback forms, or community input mechanisms, we may collect:
Required Information:
Your level of interest in our services
Geographic location (general region only - e.g., "North Phoenix area")
Which services or activities you would use
Other essential feedback needed to validate and plan our services
Optional Information:
What aspects of our planned space are most important to you
Barriers you face in accessing existing tech or community spaces
Your willingness or ability to pay membership fees
Open-ended responses about:
What would help you feel comfortable participating
Your tech interests, skills, or experience level
Concerns or questions you have
Any additional information you wish to share
Your relationship to the LGBTQ+ community (e.g., trans/non-binary community member, LGBQ+ ally, general ally, or curious visitor)
Important Note on Sensitive Information:
Information about your relationship to the LGBTQ+ community may reveal your gender identity, sexual orientation, or community affiliation. We recognize this as sensitive personal information that requires special care and strong security protections. See Section 5 for details on how we protect sensitive community data.
Future Data Collection
As we grow and add services, we may collect additional types of information such as:
Membership applications and account information
Payment and billing information (when we begin accepting memberships)
Project descriptions and technical work
Forum or community platform posts
Event registration information
Usage data from physical space or technical infrastructure
We will update this Privacy Policy and notify you before collecting significantly new types of information.
3.2 Automatically Collected Information
When you visit our website, we automatically collect:
Technical Information: IP address, browser type and version, device type, operating system
Usage Information: Pages visited, time spent on pages, links clicked, referring website
Performance Data: Page load times, errors, and other diagnostic information
This information is collected through:
Vercel Analytics: Website traffic and performance monitoring
Vercel Speed Insights: Performance optimization data
3.3 Session Recording and User Experience Analytics
We use LogRocket, a session recording service, to understand how visitors interact with our website and identify where improvements can be made. LogRocket records sessions including:
Mouse movements, clicks, scrolling, and page navigation
Pages visited and time spent on each page
Browser console logs and JavaScript errors
Network requests (excluding form submissions)
Device and browser information
IP addresses
A persistent tracking identifier stored in your browser's localStorage to recognize returning visitors
Privacy Protection:
All form inputs are automatically blocked — We cannot see what you type in email or survey fields
Form submission data is excluded — When you submit forms, that data goes directly to our database and is not captured in session recordings
No personally identifiable information collected — We don't link recordings to your name or email address
30-day retention — Recordings are automatically deleted after 30 days
What "Anonymous" Means:
While we don't collect your name or email in session recordings, LogRocket can identify returning visitors through a combination of your IP address, device fingerprinting, and a persistent identifier we store in your browser. This allows us to see patterns in user behavior over time (e.g., "this visitor came back 3 times before signing up"), but we cannot identify who you are personally unless you provide that information separately.
Purpose: Session recordings help us identify where visitors experience confusion, technical issues, or difficulty navigating so we can improve the website for everyone.
Data Location: Session data is stored by LogRocket, Inc. in the United States using Google Cloud Platform infrastructure.
LogRocket Privacy Policy: https://logrocket.com/privacy
3.4 Cookies and Tracking Technologies
Cookies: We do not currently use cookies for tracking user behavior beyond what is necessary for our third-party analytics services. Our third-party service providers (Vercel, LogRocket) may use cookies and similar technologies.
Browser localStorage: We store a persistent tracking identifier in your browser's localStorage to recognize returning visitors across sessions. This identifier helps us understand user journey patterns (e.g., how many visits before conversion) but is not linked to your personal identity. You can clear this by clearing your browser's local storage or site data.
Third-Party Privacy Policies:
LogRocket: https://logrocket.com/privacy
Future Use: If we implement additional cookies or tracking in the future, we will update this policy and may provide you with options to manage your cookie preferences.
3.5 Information We Do NOT Collect
We do not knowingly collect:
Information from individuals under 18 years of age
Financial information (credit card numbers, bank account details) — we are not currently processing payments
Government-issued identification numbers (Social Security numbers, driver's license numbers)
Health information (unless you voluntarily share it in open-text survey responses)
Precise geolocation data
4. How We Use Your Information
4.1 Primary Uses
We use your information to:
Communications and Updates:
Send you information, updates, and newsletters you've requested
Notify you of events, programming, and opportunities to participate
Provide information about how to get involved with PHX Beyond Binary
Respond to your inquiries and feedback
Research and Planning:
Understand community needs and interest in our planned services
Validate the viability and sustainability of this project
Make data-driven decisions about programming, location, pricing, facilities, and services
Identify barriers and concerns we need to address
Build a clear picture of who would benefit from this space
Website Operations:
Understand how people use our website
Improve website performance and user experience
Identify and resolve technical issues
Optimize content, design, and navigation
Future Service Delivery:
When we launch membership services and physical space operations, we will use information to:
Manage memberships and access
Process payments and billing
Provide technical infrastructure and maker resources
Organize events and programming
Maintain safety and security
4.2 Aggregated and Anonymized Data
We may create aggregated, anonymized, or de-identified data from the information we collect. This means removing any information that could identify you personally. We may use and share this anonymized data for:
Publishing reports on community needs and interest
Grant applications and fundraising materials
Presenting to potential partners or sponsors
Public communication about our research and findings
Example: "75% of survey respondents indicated interest in server resources" (aggregate data, no individual identification)
4.3 Communication
We may use your contact information to:
Send you information you requested or signed up for
Respond to your inquiries, feedback, and support requests
Provide updates about PHX Beyond Binary's development and launch
Notify you of events, programs, and opportunities
Send important administrative or policy updates
Communicate about your membership (when applicable)
We will never:
Sell or rent your contact information to third parties
Send you unsolicited commercial messages or spam
Share your information with advertisers or marketers
Use your information for any purpose you didn't consent to
You can always opt-out of promotional communications while still receiving essential service-related messages (see Section 7.4).
4.4 Legal Compliance
We may use or disclose your information as required to:
Comply with applicable laws, regulations, or legal processes
Respond to lawful requests from government authorities
Protect our rights, property, or safety, or that of our community members
Enforce our Terms of Service
Investigate and prevent fraud, security issues, or illegal activity
5. How We Protect Sensitive Information
5.1 Recognizing Sensitivity
We recognize that information about gender identity, sexual orientation, and LGBTQ+ community affiliation is highly sensitive, especially in the current political climate. A data breach could expose vulnerable individuals to harm, discrimination, or harassment.
5.2 Special Protections
For sensitive community data, we:
Use encryption in transit (HTTPS/TLS) for all data transmission
Use encryption at rest for data stored in our database
Strictly limit access — Currently, only the founder has access to personal data. As we grow, access will be limited to essential personnel only, all of whom will sign confidentiality agreements
Follow security best practices for our database and hosting infrastructure
Monitor for security issues and apply updates promptly
Train any future staff or volunteers on data handling and confidentiality
Follow the principle of data minimization — we only collect what we truly need
Resource Reality:
As a small grassroots operation, we cannot afford enterprise-level security audits or dedicated security staff. However, we implement industry-standard protections appropriate to our scale and continuously educate ourselves on security best practices. We use reputable service providers (Vercel, secure database hosting) that maintain professional security standards.
5.3 Open-Text Responses and Free-Form Feedback
We recognize that when you provide open-ended feedback through surveys, contact forms, or other input mechanisms, your responses may contain:
Personal stories of discrimination or harassment
Mental health concerns (anxiety, depression, isolation)
Financial hardship information
Safety concerns
Details about personal circumstances or challenges
Other sensitive personal information
We handle these with special care:
All open-text responses are stored securely with the same protections as other sensitive data
Access is limited to a small number of trusted individuals with a legitimate need to review feedback
We do not quote or share identifying personal stories without explicit consent
We may identify general themes from responses but never in a way that could identify you
We treat all personal disclosures with confidentiality and respect
5.4 Anonymization for Public Use
When we share information publicly (in reports, presentations, or communications), we:
Remove all personally identifying information
Aggregate data so individuals cannot be identified
Avoid sharing unique combinations of characteristics that could reveal identity
Ask for explicit consent before sharing any identifiable personal stories or testimonials
6. How We Share Your Information
6.1 We Do NOT Sell Your Data
We will never sell, rent, or trade your personal information to third parties. Your data is not a commodity.
6.2 Service Providers
We share information with trusted service providers who help us operate our website and services:
Current Service Providers:
Vercel: Website hosting and analytics (https://vercel.com/legal/privacy-policy)
LogRocket: Anonymous session recording and user experience analytics (https://logrocket.com/privacy)
Database Hosting Provider: Stores our survey responses and email signups securely
Resend: Email service provider for sending updates to subscribers (https://resend.com/legal/privacy-policy)
These service providers:
Are contractually obligated to protect your data
May only use your data to provide services to us
Are not permitted to use your data for their own purposes
Are selected based on their security practices and reputation
6.3 Legal Requirements
We may disclose your information if required by law or in response to:
Court orders or subpoenas
Law enforcement requests
Legal proceedings or government investigations
Protection of our rights or safety of our community
If we receive a legal request for your information, we will:
Carefully review the request to ensure it is valid and necessary
Disclose only the specific information legally required
Notify you of the request unless prohibited by law or court order
Given the sensitivity of our community data, we take our responsibility to protect your information seriously and will carefully scrutinize any requests we receive.
6.4 Business Transfers
If PHX Beyond Binary is involved in a merger, acquisition, sale of assets, or dissolution, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website of any such change and provide you with choices regarding your data.
6.5 With Your Consent
We may share your information in other situations with your explicit consent. For example:
Featuring your testimonial or story (with your approval)
Connecting you with other community members (with mutual consent)
Sharing your project or work with proper attribution
7. Your Rights and Choices
7.1 Access Your Information
You have the right to request a copy of the personal information we hold about you. Contact us at hello@phxbeyondbinary.com and we will provide:
Any contact information we have for you
Your survey or feedback responses
Your account information (when applicable)
Any other personal data we have associated with you
Response Time: We will respond to your request within a reasonable timeframe, typically within 30-45 days. As a small operation, complex requests may take longer, but we will acknowledge receipt of your request promptly and provide a timeline estimate.
Format: We will provide your information in a practical format (such as PDF, spreadsheet, or text file). While we may not have automated export systems, we will ensure you receive all the information we hold about you.
7.2 Correct Your Information
If information we have about you is inaccurate or incomplete, you may request corrections. Contact us at hello@phxbeyondbinary.com with the corrected information.
Response Time: We will update your information within a reasonable timeframe, typically within 30-45 days of receiving your request with the correct information.
7.3 Delete Your Information
You have the right to request deletion of your personal information. Contact us at hello@phxbeyondbinary.com and we will:
Delete your contact information from our mailing lists
Delete your feedback and survey responses
Remove your account information (if applicable)
Delete all personal information from our active database
Exceptions:
We may retain aggregated, anonymized data that cannot identify you
We may retain information necessary for legal compliance or dispute resolution
We may retain information for a limited period in backup systems before permanent deletion occurs
Response Time: We will complete deletion within a reasonable timeframe, typically within 30-45 days of your request.
7.4 Opt-Out of Communications
You may opt-out of email communications at any time by:
Clicking the "unsubscribe" link in any email we send you
Contacting us at hello@phxbeyondbinary.com
Replying to any email with "UNSUBSCRIBE"
We will process your opt-out as soon as reasonably possible, typically within a few business days. For immediate effect, you can also mark our emails as spam in your email client.
Note: Even if you opt-out of marketing emails, we may still send you important transactional or administrative messages (such as responses to your inquiries or important policy updates).
7.5 Data Portability
Upon request, we can provide your information in a structured, commonly used, machine-readable format (such as CSV or JSON) so you can transfer it to another service.
7.6 Object to Processing
If you believe we are processing your information inappropriately or unlawfully, you may object. Contact us at hello@phxbeyondbinary.com with your concerns and we will review our practices.
8. Data Retention
8.1 How Long We Keep Your Data
Contact Information: We retain contact information (such as email addresses) until you unsubscribe, request deletion, or we determine the list is no longer needed (e.g., if the project does not launch).
Feedback and Research Data: We retain survey responses and feedback indefinitely for research and planning purposes unless you request deletion. We may create anonymized versions of data before deletion to preserve aggregate insights while removing your personal information.
Account Data (Future): When we offer membership accounts, we will retain account information for as long as your account is active, plus a reasonable period afterward for record-keeping purposes.
Website Analytics: Third-party analytics providers (such as Vercel) retain analytics data according to their own retention policies, which we do not control.
Transactional Records: We may retain financial and transactional records for longer periods as required by tax laws and accounting standards.
8.2 When We Close Down
If PHX Beyond Binary ceases operations, we will:
Notify all contacts via email
Provide at least 30 days notice when possible for data requests
Delete all personal information except what's legally required to retain
Retain only anonymized aggregate data for archival purposes
You may request deletion of your data at any time, regardless of project status (see Section 7.3).
9. Security Measures
9.1 Technical Security
We implement industry-standard security measures:
Encryption in Transit: All data transmitted to/from our website uses HTTPS/TLS encryption
Encryption at Rest: Sensitive data in our database is encrypted when stored
Access Controls: Only authorized personnel have access to personal information
Secure Authentication: Strong passwords and multi-factor authentication for admin access
Regular Security Updates: Software and systems are kept up-to-date with security patches
Database Security: PostgreSQL database with proper access controls and security configurations
9.2 Organizational Security
Limited Access: Only the founder and trusted volunteers (when added) have access to personal data
Confidentiality Training: Anyone with data access is trained on privacy and confidentiality
Need-to-Know Basis: Access to data is granted only when necessary for specific purposes
No Public Sharing: Personal data is never shared publicly or posted online
Incident Response Plan: Procedures are in place to respond to security breaches
9.3 Content Moderation Security
Our automated content filtering system helps protect the community by:
Screening user-submitted content for hate speech, slurs, harassment, and harmful content
Blocking inappropriate submissions from entering our database
Providing generic error messages that don't expose security details or create opportunities for circumvention
This filtering applies to surveys, feedback forms, and other user input mechanisms to maintain a safe and respectful community environment.
9.4 Limitations and Breach Response
No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security. You acknowledge and accept this risk when providing information to us.
As a small operation, we cannot provide:
24/7 security monitoring
Dedicated security staff
Enterprise-level security audits
Immediate breach detection and response
What we do provide:
Industry-standard security practices appropriate to our scale
Reputable, professionally-managed hosting and database services
Encryption for data in transit and at rest
Prompt action when security issues are discovered
If a data breach occurs, we will:
Investigate the breach as quickly as possible
Notify affected individuals promptly and as required by applicable law (which may range from 72 hours to 30 days depending on jurisdiction and severity)
Provide information about what data was affected
Take steps to prevent future breaches
Cooperate with law enforcement if appropriate
Our commitment: We will act quickly and transparently if a breach occurs, within the constraints of our resources.
10. Third-Party Services
10.1 Vercel Analytics and Speed Insights
Our website uses Vercel Analytics and Vercel Speed Insights for performance monitoring and traffic analysis. These services may collect:
IP addresses
Browser information
Page views and interactions
Performance metrics
Privacy Policy: https://vercel.com/legal/privacy-policy
Vercel's data collection is governed by their privacy policy. We have chosen Vercel because they have strong privacy practices and do not sell user data.
10.2 Database and Infrastructure Services
We use third-party database hosting and infrastructure services to store and process information you provide. These providers:
Are bound by strict data processing agreements
Use encryption and security best practices
Are carefully selected based on their security and privacy standards
May be located in the United States or other jurisdictions
10.3 Future Third-Party Services
As PHX Beyond Binary grows, we may integrate additional third-party services such as:
Email marketing platforms (for newsletters and updates)
Payment processors (for membership fees and donations)
Event management tools (for registrations and ticketing)
Communication platforms (for community forums or chat)
Accounting and bookkeeping software
Other services necessary for operations
Before integrating any new service that handles personal information, we will:
Carefully vet the provider's security and privacy practices
Ensure they offer strong data protection
Review their privacy policies and terms of service
Update this Privacy Policy to disclose the new service
Only choose providers that align with our values and commitment to protecting our community
You will always know which third parties have access to your information.
10.4 External Links
Our website may contain links to other websites. We are not responsible for the privacy practices of external websites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Children's Privacy
11.1 Age Restriction
PHX Beyond Binary is intended for individuals 18 years of age or older only. We do not knowingly collect information from individuals under 18.
11.2 COPPA Compliance
Our services are not directed at children under 13, and we do not knowingly collect personal information from children under 13. If we discover we have collected information from a child under 13, we will delete it immediately.
11.3 Parental Notice
If you are a parent or guardian and believe your child under 18 has provided us with personal information, please contact us immediately at hello@phxbeyondbinary.com so we can delete it.
12. International Users and Data Transfers
12.1 United States Operations
PHX Beyond Binary operates in the United States (specifically Arizona). Your information will be collected, processed, and stored in the United States.
12.2 GDPR (European Union)
If you are accessing our website from the European Union, you may have additional rights under the General Data Protection Regulation (GDPR), including:
Right to access your data
Right to rectification (correction)
Right to erasure ("right to be forgotten")
Right to restrict processing
Right to data portability
Right to object to processing
Right to withdraw consent
Right to lodge a complaint with a supervisory authority
Legal Basis for Processing:
We process your data based on:
Consent: You provide information voluntarily through our forms
Legitimate Interests: Understanding community needs and operating our website
To exercise your GDPR rights, contact us at hello@phxbeyondbinary.com.
12.3 Other Jurisdictions
Users from other countries may have privacy rights under their local laws. We will comply with applicable data protection laws to the extent they apply to our operations.
13. California Privacy Rights
13.1 CCPA Compliance
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights:
Right to Know: You may request information about the personal information we collect, use, disclose, and sell (we do not sell data).
Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
Right to Opt-Out: You have the right to opt-out of the sale of personal information (we do not sell data, so this does not apply).
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
13.2 Information We Collect (CCPA Categories)
Identifiers: Email addresses, IP addresses
Personal Information: Name (optional), survey responses
Protected Classifications: Gender identity and sexual orientation information (inferred from community relationship question)
Internet Activity: Website usage and browsing data
Geolocation: General region (Phoenix area), not precise location
13.3 Exercising Your Rights
California residents may exercise these rights by contacting us at hello@phxbeyondbinary.com. We will verify your identity and respond within 45 days.
14. Changes to This Privacy Policy
14.1 How We Update This Policy
We may update this Privacy Policy from time to time as our practices evolve, new services are added, or laws change. When we make changes:
We will update the "Last Updated" date at the top of this document
For material changes (significant changes to how we use or share your data), we will:
Send email notification to subscribers
Post a prominent notice on our website
Provide at least 30 days' notice before changes take effect
For non-material changes (minor clarifications, formatting, contact information updates), we will:
Update the "Last Updated" date
Post the updated policy on our website
14.2 Your Continued Use
Your continued use of our website or services after changes to this Privacy Policy constitutes acceptance of the updated policy.
If you do not agree with changes, you must stop using our website and may request deletion of your information.
14.3 Reviewing This Policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
15. Your Consent
15.1 Providing Consent
By using our website, submitting information through forms, or signing up for email updates, you consent to:
Our collection and use of your information as described in this Privacy Policy
Our sharing of information with service providers as described
Our use of cookies and tracking technologies
Transfer of your data to the United States
15.2 Withdrawing Consent
You may withdraw your consent at any time by:
Requesting deletion of your information (see Section 7.3)
Unsubscribing from email communications (see Section 7.4)
Stopping use of our website
Withdrawing consent does not affect the lawfulness of processing based on consent before withdrawal.
16. Our Commitment Despite Limited Resources
PHX Beyond Binary is a grassroots project operated by a single founder. We want to be transparent about what this means:
What We Can Promise:
✅ Your sensitive community data will be protected with encryption and strict access controls
✅ We will never sell your data or use it for purposes you didn't consent to
✅ We will respond to your privacy requests and inquiries
✅ We will be transparent about how we use and protect your information
✅ We will comply with applicable privacy laws
✅ We will act promptly if a security issue arises
What We Cannot Promise:
❌ Enterprise-level response times (we'll do our best!)
❌ Immediate responses to non-urgent requests
❌ Automated data export systems
❌ Dedicated security or privacy staff
❌ 24/7 monitoring or support
Why This Matters: We believe in being honest about our capabilities. We'd rather under-promise and over-deliver than make commitments we might not be able to keep, while ensuring your sensitive information is truly protected.
As We Grow: As PHX Beyond Binary develops and potentially secures funding, we will improve our capabilities and update this policy accordingly. For now, we operate with integrity within our means.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For Privacy-Specific Inquiries:
Subject Line: Please use "Privacy Request" in your email subject line
Include: Your email address and specific request (access, deletion, correction, etc.)
Response Time: We aim to respond within 30-45 days as required by law
For Data Breach Notifications:
If you believe there has been unauthorized access to your information, please contact us immediately at hello@phxbeyondbinary.com with "URGENT: Security Concern" in the subject line.
Response Time Expectations:
As a solo founder operation, please understand:
General Inquiries: We aim to respond within 5-7 business days
Privacy Requests: We aim to respond within 30-45 days as required by law
Security Concerns: We prioritize these and respond as quickly as possible
Simple Questions: May receive faster responses
We appreciate your patience and understanding. All requests are handled personally by the founder to ensure your privacy is protected.
18. Acknowledgment and Agreement
BY USING OUR WEBSITE OR SERVICES, YOU ACKNOWLEDGE THAT:
You have read and understood this Privacy Policy
You consent to our collection, use, and sharing of your information as described
You understand the sensitive nature of the information you may provide
You accept the security measures we have in place, while understanding no system is 100% secure
You are at least 18 years of age
You have the right to access, correct, and delete your information
You can withdraw consent at any time by ceasing use of our website
Thank you for trusting PHX Beyond Binary with your information. We take your privacy seriously and are committed to protecting our community.