Privacy Policy
Effective date: March 12, 2026
bigbear.news ("we," "us," or "our") operates the website at bigbear.news. This Privacy Policy explains what personal information we collect, how we use it, and your rights under California law.
1. Information We Collect
Account Data
When you sign in or create an account, we collect your email address. We use passwordless magic-link authentication through Supabase. A display name is generated from your email and can be changed in your settings.
Newsletter Subscription
If you subscribe to our newsletter, we collect your email address. We use double opt-in confirmation — you must click a link in your email to activate your subscription. You can unsubscribe at any time via the link in every newsletter.
Payment Data
Subscription payments are processed by Stripe. We never see or store your credit card number. We store only a Stripe customer identifier to link your account to your subscription.
Usage Data
When you click an advertisement or scan a QR code on the site, we record a one-way hash of your IP address (salted SHA-256, truncated), your browser's user-agent string, the referring page, and any UTM campaign parameters. We never store raw IP addresses for these purposes.
User-Generated Content
If you post in the community forum, submit events, claim a business listing, or upload ad banner images, that content is stored in our database. Forum posts and display names are publicly visible.
Bot Protection
We use Cloudflare Turnstile on our login and newsletter forms to prevent automated abuse. This sends your IP address to Cloudflare for verification and may set a cookie on your device.
Analytics
We use Vercel Analytics and Speed Insights to understand aggregate page views and site performance. These tools do not use cookies, do not track individual users, and do not collect personal identifiers.
Rate Limiting
To prevent abuse, we temporarily store IP addresses or user identifiers in a rate-limiting service (Upstash Redis). These keys automatically expire within minutes.
2. How We Use Your Information
- Provide, maintain, and improve the site
- Send our newsletter (only after you confirm your subscription)
- Process subscription payments
- Measure ad performance with aggregate click and impression counts
- Prevent abuse and enforce our terms
- Moderate user-generated content
3. Third-Party Services
We share information with the following service providers to operate the site:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Auth, database, storage | Account data, content |
| Stripe | Payment processing | Email, payment details |
| Resend | Email delivery | Recipient email, email content |
| Cloudflare | Bot protection | IP address, challenge token |
| Vercel | Hosting, analytics | Anonymous page views, web vitals |
| Upstash | Rate limiting | IP or user ID (ephemeral) |
4. Cookies
- Authentication cookies — Supabase sets session cookies (named
sb-*-auth-token) when you sign in. These are essential for keeping you logged in and cannot be opted out of. - Cloudflare Turnstile — may set a cookie on login and newsletter pages for bot detection.
- We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
5. Data Retention
- Account data — retained until you delete your account. To request account deletion, email privacy@bigbear.news. We will delete your account and associated personal data within 30 days. Forum posts will be anonymized (author removed) but content remains visible per our Terms of Service.
- Newsletter subscriptions — retained until you unsubscribe. We keep a record that you unsubscribed to honor your preference.
- Ad click and QR scan records — retained for aggregate analytics.
- Forum content — soft-deleted when you remove a post. If you delete your account, your posts are anonymized (author removed) but the content remains visible.
- Rate-limit keys — automatically expire within minutes.
6. Your California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights:
- Right to Know — you can request what personal information we have collected about you.
- Right to Delete — you can request that we delete your personal information.
- Right to Opt-Out of Sale — we do not sell or share your personal information with third parties for advertising or marketing purposes.
- Right to Non-Discrimination — we will not treat you differently for exercising your privacy rights.
To exercise any of these rights, email us at privacy@bigbear.news. We will respond within 45 days.
If we become aware of a data breach that affects your personal information, we will notify you via email within 72 hours and provide details about what information was involved and steps you can take to protect yourself, in accordance with California Civil Code § 1798.82.
7. We Do Not Sell Your Personal Information
bigbear.news does not sell, rent, or share your personal information with third parties for their marketing purposes. Aggregate, de-identified ad performance metrics (impressions and clicks) shown to advertisers do not include personal information.
8. Children's Privacy
bigbear.news is intended for users age 16 and older. We do not knowingly collect personal information from children under 16. If you believe we have collected data from a child, please contact us at privacy@bigbear.news and we will promptly delete it.
9. Third-Party Content
We aggregate publicly available information from external sources, including event listings, local news, road conditions, weather, and lake levels. We are not responsible for the accuracy of third-party content. Sources are attributed where applicable.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via our newsletter. We review and update this policy at least once per year.
Questions? Contact us at privacy@bigbear.news.