PRIVACY & COMMUNICATIONS POLICY · EFFECTIVE SEPTEMBER 10, 2026
Your privacy.
Clear information.
How Blue Bench Media approaches personal information, lead-generation data, consumer choices, and responsible marketing communications.
Email info@bluebenchmedia.com, call 786-353-5286, or visit Your Privacy Choices. You do not need an account. Please identify the website or interaction involved if you know it.
TCPA & marketing consent ↓ · State privacy rights ↓ · Data sharing ↓ · Contact details ↓
1. Who we are and what this policy covers
Blue Bench Media LLC is a founder-operated digital marketing and lead-generation business. Brendan, the founder, is responsible for privacy and security oversight. This policy covers our corporate website, trust center, business inquiries, and the privacy requirements we establish for lead-generation services.
Specific campaigns can have different information flows. A campaign’s collection notice must identify its actual practices, recipients, and choices. When this policy describes a campaign practice conditionally, that does not mean every campaign uses that practice. Separate notices and contractual instructions apply where we act on behalf of another business. Contact us to identify the notice or organization responsible for a particular interaction.
2. Information we receive and its sources
The information involved depends on how you interact with us:
- Business and contact information: your name, email, telephone number, company, website, and the content of an inquiry you send by email, phone, or mail.
- Technical information: IP address, requested webpage, connection and device information needed by hosting services to deliver and protect the site.
- Lead or service-request information, where collected in a campaign: contact details, state or ZIP code, requested product or service, and the relevant answers you provide. The collection form must describe the fields needed for that request.
- Consent and transaction evidence, where applicable: the disclosure shown, its version, affirmative action, collection time, source URL, recipient scope, referral identifier, and delivery outcome. Limited technical evidence may be associated with the record where necessary and disclosed.
- Privacy and security request information: the details needed to locate an interaction, respond, verify identity when appropriate, and record the action taken.
Sources may include you directly, your device, a disclosed campaign or referral partner, and a contracted buyer returning transaction or reporting information. A transaction identifier can still be personal information if it is linkable to a person. Public availability alone does not authorize unrestricted use.
This corporate website and trust center do not contain quote-application forms, advertising pixels, optional cookies, or third-party analytics. Contact links open your email or telephone application; they do not submit a request automatically.
3. Why information is used
Information is used as relevant to respond to inquiries; discuss or deliver contracted services; facilitate a consumer’s disclosed request; document consent and delivery; reconcile transactions; assess campaign operation; prevent fraud and misuse; handle privacy requests; investigate security concerns; and meet applicable obligations.
Our data-handling standard requires collection to be limited to a defined purpose. A new, incompatible use requires an appropriate review and any necessary notice or permission. Submitting a service inquiry is not blanket permission for unrelated marketing, unrestricted resale, or model training.
5. TCPA, calls, texts, and consent
Visiting this website, reading this policy, accepting website terms, or sending a business inquiry does not by itself provide prior express written consent for automated marketing calls or texts. Any legally required consent must be obtained in the relevant interaction.
For campaigns requiring written consent, our standard requires a clear disclosure of the authorized seller, the telephone number, marketing purpose, applicable calling or messaging technology, and an affirmative signing action. Consent must not be made a condition of purchase. Applicable state laws and sector-specific rules may impose additional requirements.
Consent evidence must reflect what the consumer actually saw and agreed to, including the version and time. It must not be reconstructed from a later version of the page. A consent certificate or delivery timestamp is supporting evidence, not an automatic guarantee that outreach is lawful. Buyers must assess the permission required for their actual contact method.
Our full Consent & Communications Standard explains the campaign requirements and current regulatory context. The governing federal rule is 47 CFR § 64.1200.
6. Withdrawing consent and stopping marketing
You can communicate a clear withdrawal through a reasonable method. Examples include replying STOP to a marketing text where supported, telling the caller to stop, using the sender’s designated opt-out route, or contacting Blue Bench Media by the email or phone listed here. You do not need to use legal terminology or provide a reason.
Our standard requires prompt suppression in the systems we control and coordination with relevant recipients where required. Applicable TCPA withdrawals must be honored within a reasonable period not exceeding ten business days, or sooner when another applicable requirement controls. A request must not be used as an opportunity for another marketing message.
If the communication came from another business, we will assess our involvement and the appropriate recipient. Contacting Blue Bench Media does not automatically change every unrelated company’s systems. Minimal suppression information may be retained so an opt-out is not accidentally reversed.
7. Do Not Call and commercial email
The responsible caller must apply national, state, and company-specific Do Not Call requirements, assess any exception, and respect applicable calling times, frequency restrictions, and other state rules. Rapid delivery of a lead does not remove those responsibilities. Consumers may register at donotcall.gov and may also make a company-specific stop-contact request.
Covered commercial emails must identify the sender accurately, avoid deceptive subjects, include required sender and postal information, and provide an easy unsubscribe method. Our standard requires applicable email opt-outs to be honored within ten business days, with the mechanism remaining available for at least 30 days after sending. Essential nonmarketing correspondence may still be necessary to address your request or relationship.
See the FTC’s CAN-SPAM guidance and our communications standard.
8. Real-time lead integrations and partner information
When a contracted flow delivers information in real time, our standard requires a defined freshness limit, authenticated encrypted transport, minimized payloads, duplicate controls, bounded retries, and a record of the recipient and delivery result. Partial pre-bid information must still be assessed for identifiability. A rejected or old record must not be relabeled as a fresh consumer request.
Partner-supplied information must be used only for the agreed service and permitted purposes. Contracts should specify data roles, fields, authorized recipients, retention, security responsibilities, privacy-request cooperation, and incident notice. We do not publish a universal data-flow or latency guarantee for every integration. See the Lead Data Handling Standard.
9. Retention and deletion
Retention is based on the information category, the purpose for which it is needed, contractual requirements, applicable recordkeeping duties, and legal claims or holds. Lead payloads, contact correspondence, transaction records, consent evidence, suppression records, and backups can have different retention requirements.
Our standard requires an integration-specific retention schedule, restricted access, deletion or irreversible anonymization of unneeded records, and defined backup expiry. Where the FTC telemarketing recordkeeping rule applies, required records must be retained for five years. That requirement does not justify keeping every item of consumer data indefinitely. See 16 CFR § 310.5.
A deletion request may be subject to a lawful exception. We will explain the applicable reason and restrict retained information to the necessary purpose. Ask us about the retention applicable to your particular record.
10. State privacy rights
Depending on applicable law and the processing involved, rights may include access to information and its sources or recipients; correction; deletion; a portable copy; opting out of sale, sharing, targeted advertising, or certain profiling; limiting certain sensitive-data uses; and appealing a decision. These rights can differ by state and are subject to lawful exceptions.
California consumers may exercise applicable CCPA/CPRA rights through the contact routes below. For covered requests to know, delete, or correct, the standard is acknowledgment within ten business days and a substantive response within 45 calendar days. Any permitted extension must be explained. Applicable sale/sharing opt-outs and sensitive-information limitation requests must be acted on as soon as feasible, no later than 15 business days. Other request types and states may have different deadlines.
We do not require an account to submit a request. Access, deletion, and correction may require proportionate verification to protect against improper disclosure; sale/sharing opt-outs must not be conditioned on a verified consumer request. An authorized agent may act for you, subject to appropriate proof of authority where permitted. We do not discriminate unlawfully for exercising an applicable right.
For an appeal, contact us with “Privacy Appeal” in the subject or explain that you are appealing by phone. We will apply the relevant appeal process and deadline. You may also contact your state attorney general or privacy regulator. See California Privacy Protection Agency guidance.
11. Cookies, browser signals, and advertising choices
The corporate site and trust center use no optional cookies, advertising tags, or third-party analytics. They have no sale/sharing or targeted-advertising feature to switch on. The trust-center choices page can display a Global Privacy Control signal detected in your browser; this does not locate or delete existing lead records or change another site.
Where a separate covered campaign uses advertising or tracking technology, its own notice must explain those practices, and required recognized opt-out signals must affect the actual processing. A banner alone does not implement suppression. For records from another interaction, use our privacy-request channels and identify the site if known.
12. Sensitive data, health, finance, and children
Please do not send Social Security numbers, payment credentials, government identity documents, medical records, or other unnecessary sensitive information through general email. Our standard requires an additional review before a campaign collects sensitive information, including any necessary consent, authorization, collection notice, and processing restrictions.
Health-related campaigns require assessment of applicable state consumer-health laws and any HIPAA role; not every health inquiry falls under HIPAA. Financial campaigns require assessment of financial-privacy and safeguards obligations. Medicare marketing has separate CMS requirements. This general policy is not a substitute for a required consumer-health notice, authorization, or sector-specific disclosure.
Our corporate services and lead-campaign standard are intended for adults. We do not knowingly seek children’s information through this corporate site. If you believe information from a child was provided, contact us for assessment and appropriate action. Our standard prohibits knowingly selling or sharing minors’ information without the authorization required by applicable law.
13. Security, access, and service providers
Our Information Security Standard sets requirements for individually assigned accounts, least privilege, MFA, device encryption, malware protection, patching, encrypted transfer and appropriate storage protection, controlled changes, vulnerability management, training, vendor review, and recovery planning. Implementation evidence must be assessed for the systems involved; publishing a policy does not establish a completed audit.
This corporate website and trust center are static pages served through AWS. Their S3 content origin is private and served through CloudFront over HTTPS. Providers handling other information must be reviewed for the relevant purpose, access, contractual restrictions, and data locations. No transmission or system can promise absolute security.
14. Artificial intelligence
Blue Bench Media uses AI-assisted tools for creative development, software development, and internal productivity. Our policy prohibits putting partner confidential information, consumer PII, credentials, or production lead records into an AI service without specific authorization and appropriate contractual and technical safeguards. This also covers automated access to files, logs, and integrations. Human review is required for externally used output.
Use of AI in a future consumer-facing interaction or materially different processing requires its own assessment and any applicable notice and choices. This policy does not authorize using consumer information to train models.
15. International access and data-broker rules
Service providers, storage, backup, support, and administrative access may involve locations outside your state or country, including Canadian access where applicable. US hosting does not alone establish US-only processing. Any location commitment must be supported by an assessment of the actual engagement and applicable cross-border requirements.
Whether a business is a data broker depends on its activities and relationships. Our standard requires assessment of applicable registration and deletion-platform duties before covered activities. This page does not claim that Blue Bench Media is registered or exempt. California consumers can learn about the state’s deletion platform at DROP.
16. Security incidents and inquiries
Report suspected exposure or unauthorized access to info@bluebenchmedia.com or call 786-353-5286. Include the affected service and a concise description; do not include passwords or complete consumer records in ordinary email.
Our response standard covers triage, containment, evidence preservation, investigation, recovery, and required notification. Affected partner notices must follow the signed agreement, including a 48-hour requirement where agreed, or a shorter controlling deadline. Consumer and regulator notification obligations are assessed separately under applicable law.
17. Contact the privacy and security lead
Brendan, Founder — Privacy and Security Lead
Blue Bench Media LLC
1902 Thomes Avenue, Unit 202A
Cheyenne, Wyoming 82001
United States
Email: info@bluebenchmedia.com
Phone: 786-353-5286
Use “Privacy Request,” “Privacy Appeal,” or “Security Incident” in your subject when helpful; a request is not invalid merely because a different subject is used. Include only the information reasonably needed to identify the relevant interaction. Visit our contact page or privacy choices page for additional guidance.
18. Policy updates and further documentation
This policy was published September 10, 2026. We will update the effective date when it materially changes and provide additional notice where required. Changes do not retroactively create consent for a new purpose. The policy is to be reviewed at least annually and after material changes to data practices or requirements.
Our Trust Center contains the related security, communications, and data-handling standards and a primary-source reference library. Those documents describe requirements and scoped facts; they do not represent SOC 2 attestation, ISO 27001 certification, or a completed legal assessment of every campaign.