Privacy Policy
Version 2.0 · Effective July 31, 2026
Who we are
GMBC LLC, New Mexico, USA, operates gmbc.marketing and is the controller of the personal information described in this policy. gmbc.marketing is our only website and [email protected] is our only contact address.
Information we collect
- Account details — your first and last name, email address and the password hash for your customer portal login.
- Membership details — the exact Facebook display name you give us so that we can verify and manage your membership, and which communities you subscribe to. We do not collect or require your Facebook password, and we do not ask for a Facebook profile URL.
- Billing records — subscription status, billing dates, amounts charged, refunds, and the identifiers our payment provider returns to us (a provider-issued customer or vault reference, the card brand and the last four digits). We never receive or store your full card number, expiry or security code.
- Support correspondence — the messages you send to our support address and our replies.
- Operational and audit records — server and application logs, security events, and an audit trail of administrative actions taken on your subscription, which may include IP address, timestamps and user agent.
How we use information
We use your information to create and operate your account, take payment and manage renewals, verify your Facebook display name and manage your membership, send transactional email about your subscription, answer support requests, keep security and audit records, and meet our legal, tax and accounting obligations. We do not sell your personal information and we do not share it for cross-context behavioural advertising.
Payment processing
Payments are handled by a third-party payment provider. Depending on which provider is active when you subscribe, that provider is either NMI or Stripe, and your subscription stays with the provider it was created on for its lifetime. Card details are entered into payment fields or payment pages hosted by that provider and are not transmitted to, processed by, or stored on GMBC systems. GMBC stores only a provider-issued reference token plus the card brand and last four digits returned by the provider for display.
The active provider processes your payment details under its own privacy policy and compliance programme, and may use them to detect and prevent fraud. GMBC does not claim any particular completed PCI DSS assessment on this page.
Who we share information with
We share the minimum necessary personal information with service providers that operate the service on our behalf:
- Our payment provider (NMI or Stripe, whichever processed your subscription) for payment, renewal, refund and dispute handling.
- Our transactional email provider, to deliver subscription and support email.
- Our cloud hosting and database provider, to run and back up the service.
We may also disclose information where required by law, to enforce our Terms of Service, to investigate fraud or abuse, or as part of a merger, acquisition or sale of assets, in which case we will notify you.
International transfers
We are based in the United States and our service providers process data in the United States. If you are located outside the United States, your information is transferred to and processed in the United States under the safeguards offered by the relevant provider.
Cookies
We use strictly necessary cookies to keep you signed in to your customer portal and to protect against cross-site request forgery. We do not use advertising cookies or third-party behavioural tracking. Payment provider pages you are redirected to may set their own cookies under their own policies.
Retention
We retain account, membership and support records for as long as your account exists, and after cancellation for as long as needed to resolve disputes, enforce our agreements and meet legal, tax and accounting obligations. Billing, refund and dispute records held by our payment provider are retained and deleted according to that provider’s own retention configuration and policy, which we do not override.
Security
We use TLS for data in transit, hashed passwords, encrypted storage for sensitive configuration, access controls on administrative functions, and audit logging of administrative actions. No system is perfectly secure, and we cannot guarantee absolute security.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. To make a request, email [email protected] from the address on your subscription. We will verify your identity before acting and we will not discriminate against you for exercising a right. Some records must be kept to meet legal and accounting obligations even after a deletion request.
Children
The service is not directed to anyone under 18 and we do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.
Facebook and Meta
GMBC LLC is an independent company. It is not affiliated with, endorsed by, sponsored by, or in any way officially connected to Meta Platforms, Inc. Facebook is a trademark of Meta Platforms, Inc. Your use of Facebook remains governed by Facebook’s own terms and policies.
Information you post inside a Facebook community is handled by Meta under Meta’s own privacy policy, not this one.
Changes to this policy
When we update this policy we publish a new version number and effective date at the top of this page. Material changes are also communicated by email to subscribers with an active membership.
Contact
GMBC LLC, New Mexico, USA. Privacy questions and requests: [email protected].