Phoenix Forum

Privacy Policy

Privacy Policy for Phoenix Forum

Last updated: August 17, 2026

This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. We have written it to describe what our systems actually do rather than in general terms, so that you can rely on it.


1. Who We Are and What This Policy Covers

Phoenix Forum runs small, vetted peer groups for founders and business owners in recovery. This site, phoenixforum.net, is operated by Sober Founders Inc, the entity responsible for the personal information described in this policy.

This policy covers this website, our application and sign up forms, our email and text messages, our online meetings and events, and the member systems we operate. It does not cover other companies’ websites or services that we link to, which have their own policies.


2. Information We Collect

Information you give us

  • Contact and application details: your first and last name, email address, phone number, company name, role, and annual revenue.
  • Recovery information: your sobriety date, or how long you have been sober. See the section on sensitive information below.
  • Anything else you write to us: notes, messages, application answers, survey and feedback responses, referrals you send us, and support requests.
  • Member profile information: what you choose to put on your member profile, which can include a photo, a short bio, your business, your city, and links you add.
  • Payment details: handled by our payment processors. See the payments section below.

Information we collect automatically

  • Site usage: the pages you view, the page or ad you arrived from, campaign tags in the link you clicked, your approximate location based on your IP address, and your browser and device type.
  • IP address: recorded with page views and form submissions for security and fraud prevention. We do not display it or use it to build an advertising profile.
  • Email activity: whether an email we sent was opened and which links in it you clicked. Open tracking uses a small invisible image, and because many mail apps load images automatically it is only an approximate signal.
  • Attendance: whether you registered for and attended a group, meeting, or event.
  • Cookies and similar technologies: described in full in the cookies section below.

Information from other sources

  • Advertising and social platforms: when you submit a lead form inside Facebook or Instagram, Meta passes us the details you entered.
  • Calendar and meeting tools: when you book a call with us, our scheduling, calendar, and meeting tools tell us that the meeting happened and who attended.
  • Payment and donation processors: confirmation of your payment or donation, and the limited details described in the payments section.
  • Email verification: we check that an address is deliverable before we send to it, which helps us avoid sending to a mistyped address.
  • Publicly available business information: for outreach to prospective members, we may use business contact details that are publicly listed or supplied by business data providers.

3. Sensitive and Health Related Information

Because of what we do, some of what you tell us is sensitive. Your sobriety date, the fact that you are in recovery, and anything you share about your recovery are treated as sensitive personal information under California law and as consumer health data under Washington’s My Health My Data Act and Nevada’s SB 370. Under the GDPR this is a special category of data concerning health.

Our commitments on this information are specific:

  • We collect it only because you choose to give it to us on an application or in conversation with us. We use it to decide fit for our groups and to support you as a member, and, for your sobriety date specifically, to show years sober on your member profile if you keep that visible, as described in the member directory section below.
  • We never sell it, and we never share it with advertising platforms. It is not included in any conversion event we send to Meta or Google.
  • We do not use or disclose it for any purpose other than the ones described in this policy, and we do not infer characteristics about you from it.
  • Access to your recovery details, such as application notes and anything you tell us in conversation, is limited to the small number of people who run our programs. The one exception is your sobriety date and years sober: those are part of your member profile, shown by default to other signed in members, and yours to hide at any time from your profile settings.
  • You can ask us to delete it at any time using the contact details at the end of this policy, and you can withdraw your consent to our processing of it at any time.

We are not a healthcare provider, a treatment program, or a covered entity under HIPAA, and nothing we do is medical treatment or medical advice. That means HIPAA does not apply to the information you give us, which is exactly why we set out the commitments above.


4. How We Use Your Information

  1. To review your application and decide whether Phoenix Forum is a fit for you.
  2. To communicate with you about your application, your membership, meetings, and events, including reminders and follow ups.
  3. To run our programs: scheduling, registration, attendance, and member support.
  4. To operate member features such as the member directory, the member map, and member to member introductions. Directory listing itself is a standard part of membership, not a separate opt-in; the individual fields shown on your card are yours to control (see below).
  5. To send you newsletters and other marketing, which you can stop at any time.
  6. To measure and improve our website, our content, and our advertising, including which ads and pages lead to applications.
  7. To take payments and, where relevant, to process and acknowledge donations.
  8. To keep our systems secure, prevent fraud and abuse, and diagnose faults.
  9. To meet our legal, tax, and accounting obligations.

Automated processing. We use automated scoring to prioritize which enquiries our team follows up on first, and we use AI tools to draft messages and summarize conversations. These are aids for our team. A human decides every application outcome, and no decision that affects you is made by automated means alone.


5. Our Legal Bases for Using Your Information

If you are in the UK, the European Economic Area, or Switzerland, we rely on the following legal bases under the GDPR:

  • Consent: for marketing emails and text messages, for non-essential cookies and advertising technologies, and for any information about your recovery. You can withdraw consent at any time, which does not affect anything we did before you withdrew it.
  • Performance of a contract: to provide membership and the services you signed up for, and to take payment for them.
  • Legitimate interests: to run and improve our programs, to keep our systems secure, to measure our website and advertising, and to contact business people about a program that is relevant to them. We balance these interests against your rights, and you can object at any time.
  • Legal obligation: to keep financial records and to respond to lawful requests.

6. Cookies, Analytics, and Advertising Technologies

We use cookies and similar technologies both to run the site and to measure and advertise it. These are the ones in use on this site:

  • Google Analytics 4 (Google): measures traffic, page views, and how people move through the site.
  • Microsoft Clarity (Microsoft): records how visitors interact with pages, including mouse movement, scrolling, clicks, and session replays, so we can see where a page is confusing. Clarity masks text input by default, so it is not meant to capture what you type into a form.
  • Meta Pixel and the Meta Conversions API (Meta, the company behind Facebook and Instagram): present on our advertising landing pages. It measures which ads led to an application. The Conversions API sends the same conversion events from our servers rather than your browser, and can include a hashed version of your email address or phone number so Meta can match the event to an account.
  • Our own first-party analytics: a cookie named sf_vid that we set ourselves. It records the pages you view, the site you arrived from, and any campaign tags in the link. This data stays with us.

Some of these are set by other companies, which means those companies receive information about your visit and may use it for their own purposes, including advertising. Their handling of it is governed by their own privacy policies.

Global Privacy Control and Do Not Track. Our own first-party analytics honors both signals automatically: if your browser sends a Global Privacy Control or Do Not Track signal, we do not set the sf_vid cookie and we do not record your visit. The Google and Meta tags described above are not yet wired to read a Global Privacy Control signal automatically, so turning one on does not by itself stop them; see the section on selling and sharing below for how to opt out of that sharing today.

Your browser controls. You can block or delete cookies in your browser settings. Essential parts of the site will still work, though some features may not behave as expected.


7. Email and Text Messages

Email. We send transactional email about your application, membership, meetings, and payments, and we send marketing email such as newsletters and program announcements. Every marketing email has an unsubscribe link, and unsubscribing stops marketing email without stopping the transactional messages you need in order to use what you signed up for. We record opens and link clicks as described above.

Text messages. We send text messages only to a number that has given consent to receive them, and our system refuses to send to a number with no recorded consent. Reply STOP to any message to opt out, or HELP for help. Message and data rates may apply, and message frequency varies.

We do not share mobile phone numbers or text messaging consent with any third party for their own marketing or promotional purposes. Phone numbers are shared only with the messaging provider that delivers our messages, and only so that the message reaches you.


8. Meetings, Recordings, and AI Assistance

Our groups, interviews, and calls run on video conferencing. Some calls, in particular sales and interview calls, are recorded and automatically transcribed and summarized by a meeting assistant, which writes a summary and a link to the recording into our contact records. When a call is being recorded you will be told at the start of it, and you can ask us not to record.

We use AI services from OpenAI, Anthropic, and Google to draft messages, summarize conversations, and analyze our own program data. These providers act on our instructions as service providers. We do not permit them to use your information to train their models.


9. Payments

Payments are processed by Stripe. Your card number is entered directly with the processor and never reaches our servers. We receive and store a record of the payment, which includes the amount, date, status, the last four digits of the card, and the billing name and email.


10. Who We Share Information With

We do not sell your personal information for money. We share it in these situations only:

  • Service providers that run our systems on our behalf, under contracts that limit them to our instructions. These currently include HubSpot (contact database), Supabase and Vercel (our database, application, and hosting), Resend (email delivery), Mailchimp (mailing lists), Telnyx (text messages), Stripe (payments), Zoom and Fathom (meetings, recording, and notes), Google and Microsoft (calendar, email, and workplace tools), OpenAI, Anthropic, and Google (AI features), RabbitSign (electronic signatures), and Sentry (error monitoring).
  • Advertising and analytics platforms, specifically Google and Meta, as described in the cookies section and in the next section.
  • Other members, through your member directory profile, visible only to other signed in members. Business, industry, location, hobbies and links, and your sobriety date and years sober are shown by default because that shared context is part of a peer recovery community; you can hide any of these fields at any time from your profile settings. Email and phone number are hidden by default and are shown only if you turn them on, except that members of your own Phoenix Forum cohort automatically see each other’s email and phone number as part of running the group, with no opt-out for that case. Your revenue and your original application answers are never shown to other members.
  • Professional advisors such as our accountants and lawyers, where they need it to advise us.
  • Legal and safety: where we are required to by law or legal process, or where we believe in good faith that disclosure is necessary to prevent serious harm to someone.
  • A change of organization: if our programs are transferred to or merged with another organization, your information may transfer with them, subject to this policy.

Newsletter sponsors pay to have their message included in an email we send. They do not receive your email address or any other personal information from us.


11. Selling and Sharing of Personal Information

We do not sell your personal information for money, and we have not done so in the last twelve months.

We do share some personal information for what California law calls cross context behavioral advertising. When you visit this site, the Google and Meta technologies described above receive identifiers such as cookie identifiers, device and usage information, and, for conversion events, a hashed version of your email address or phone number. Those companies may use it to target advertising. California law counts this as “sharing” and gives you the right to stop it whether or not any money changes hands, and several other state laws call the same activity “targeted advertising.”

Categories shared in the last twelve months: identifiers (such as cookie and device identifiers, and hashed email address or phone number), internet and network activity (such as pages viewed and referring pages), and inferences drawn about which products you may be interested in. Recipients are Google and Meta.

We never share sensitive personal information, including anything about your recovery, with advertising platforms, and we do not use sensitive personal information to infer characteristics about you. We do not knowingly sell or share the personal information of anyone under 16.

How to opt out of sharing for advertising

  1. Email us. Write to [email protected] with the subject “Do Not Sell or Share My Personal Information” and we will apply the opt out to your records. This is the reliable way to opt out today.
  2. Turn on Global Privacy Control. We honor it automatically for our own first-party analytics (see the cookies section above). We have not yet wired the Google and Meta advertising tags to read it automatically, so turning it on by itself does not stop those tags; email us as well until that changes.
  3. Use your browser and platform controls. Blocking cookies in your browser, and using the ad settings offered by Google and Meta, also limits what those companies receive.

We will not treat you differently for exercising any of these rights.


12. How Long We Keep Information

  • Applicants who do not join: kept while we may still be in conversation with you, then deleted or anonymized when the enquiry is clearly closed.
  • Members and former members: kept for the duration of your membership and afterwards for as long as we need it for our records and legal obligations.
  • Marketing contacts: kept until you unsubscribe or ask us to delete you. An unsubscribe or opt out record itself is kept indefinitely, because that is how we make sure we do not contact you again.
  • Payment records: kept for as long as tax and accounting rules require.
  • Website analytics: page views we cannot connect to a person are deleted after 90 days, together with the record of the browser that made them. Page views we can connect to you are kept with your contact record for as long as we keep that record, and are deleted when it is. The first-party sf_vid cookie expires on its own two years after your first visit.
  • Meeting recordings and notes: kept while they are useful to support you, and deleted on request.

If you want to know the retention period that applies to a specific piece of information about you, ask us and we will tell you.


13. How We Protect Information

  • Information is encrypted in transit and encrypted at rest by our database and hosting providers.
  • Access is limited to the people who need it to run our programs, and is controlled by individual accounts rather than shared logins.
  • Two factor authentication is enabled on our systems where the provider supports it.
  • Member facing systems apply row level access rules so that one member cannot read another member’s records.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and the relevant regulators where the law requires it.


14. Your Privacy Rights

Depending on where you live, some or all of the following rights apply to you. We honor all of them for everyone, wherever you are, except where the law requires us to keep something.

  • Know and access: ask what personal information we hold about you, where we got it, why we use it, and who we share it with, and get a copy.
  • Correct: ask us to fix information that is wrong or incomplete.
  • Delete: ask us to delete your personal information.
  • Portability: get a copy in a machine readable format, or ask us to send it to another provider.
  • Opt out of sharing for advertising, as described in the section above.
  • Limit the use of sensitive personal information: we already limit it to the purposes described in this policy and do not use it for advertising or profiling.
  • Withdraw consent at any time, including consent to marketing and consent to our use of your recovery information.
  • Object to or restrict processing that we carry out on the basis of legitimate interests.
  • Non discrimination: we will not deny you service, charge you a different price, or give you a lower level of service because you exercised a privacy right.

How to exercise your rights

Email [email protected] and tell us what you want to do. We will verify your identity, usually by confirming you control the email address we hold for you, and we may ask for more detail if the request is broad. We respond within 45 days for requests under United States state laws, extendable by another 45 days if we tell you why, and within one month for requests under the GDPR.

Authorized agents. You may use an authorized agent to make a request. We will ask the agent for written permission from you and will still verify your identity directly.

Appeals. If we refuse your request, you can appeal by replying to our decision with the word “appeal.” We will review it and respond in writing with our reasons. If we deny the appeal you may contact your state attorney general.

Complaints. If you are in the UK, the European Economic Area, or Switzerland, you also have the right to complain to your local data protection authority. We would rather you told us first so we can put it right.


15. Your Choices at a Glance

  • Stop marketing emails: click unsubscribe in any marketing email, or email us.
  • Stop text messages: reply STOP to any message.
  • Stop advertising sharing: email us as described above; we apply the opt out by hand today, since Global Privacy Control alone does not yet stop the Google and Meta tags.
  • Stop our first-party analytics: turn on Global Privacy Control or Do Not Track and we will not record your visit.
  • Decline call recording: tell us at the start of the call.
  • Control what other members see: edit or hide your member profile at any time.
  • Delete everything: email us and ask.

16. International Data Transfers

We are based in the United States and our systems are hosted there, so if you are outside the United States your personal information is transferred to and processed in the United States, which has different data protection laws from your own country. Where we transfer personal information out of the UK, the European Economic Area, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum in our contracts with our providers. You can ask us for a copy of the safeguards that apply.


17. Children’s Privacy

Our programs are for adults in business, and this site and our services are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, email us and we will delete it.


18. Additional Disclosures for Specific States

California

The categories of personal information we have collected in the last twelve months, using the categories named in the California Consumer Privacy Act, are: identifiers; customer records information such as name, phone number, and financial information; commercial information; internet and network activity; approximate geolocation; audio and visual information in the form of call recordings; professional and employment information; inferences; and sensitive personal information, specifically health related information about your recovery. We collect these from you, from your use of our site, and from the third party sources named earlier. We use and disclose them for the business purposes described in this policy, and we share the limited categories named in the selling and sharing section with Google and Meta for advertising. We disclose personal information to the service providers named above for business purposes.

Washington and Nevada consumer health data

Information about your recovery is consumer health data under Washington’s My Health My Data Act and Nevada’s SB 370. The section on sensitive and health related information above serves as our consumer health data notice: it states what we collect, why, who we share it with, which is no one for advertising, and how to exercise your rights. Washington residents have the right to confirm whether we collect, share, or sell their consumer health data, to access it, to withdraw consent to its collection and sharing, and to have it deleted, including deletion by our service providers. We do not sell consumer health data, and we have never done so. To exercise any of these rights, email [email protected].

Other states

Residents of Colorado, Connecticut, Delaware, Florida, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising and profiling. Exercise them the same way, by emailing [email protected]. We do not sell personal data as those laws define it, and we do not engage in profiling that produces legal or similarly significant effects.


19. Changes to This Policy

We update this policy when our practices or the law change. The date at the top shows when it last changed. If a change materially affects how we use information we already hold about you, we will tell you by email or with a notice on the site before it takes effect.


20. Contact Us

For any question about this policy, or to exercise any right described in it, contact us:

Phoenix Forum
Operated by Sober Founders Inc
Email: [email protected]