PRIVACY POLICY
Effective Date: May 30, 2026
1. Introduction
This website, thespotnashua.com (the "Site"), is operated by Oryx Technologies LLC ("Oryx Tech," "we," "us," or "our") on behalf of The Spot Kava Bar & Music ("The Spot"), located at 217 Main Street, Nashua, NH 03060. Oryx Tech is the data controller for personal information collected through the Site. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
By using the Site, you agree to the practices described in this policy. If you do not agree, please do not use the Site.
2. Information We Collect
We only collect personal information that you voluntarily provide, or that is automatically generated by your use of the Site.
2.1 Information you give us
- Newsletter signup (footer signup and popup signup, both site-wide): your email address.
- Contact form (on the Contact page): your first name, last name, email address, subject line, and message.
- Booking request form (on the Book Your Band page): your first name, last name, email address, and the date and time slot you select for a possible performance.
2.2 Information collected automatically
- Privacy-friendly analytics via Plausible Analytics. Plausible does not use cookies and does not track visitors across sites. It records aggregate page views, referrer, browser, device type, country, and entry/exit pages. No personal identifiers are collected and no data is sold or shared with third parties.
- Server logs (held briefly by our hosting providers): IP address, user agent, and request timing, used to detect abuse, debug errors, and protect the Site.
3. How We Use Your Information
- To respond to inquiries you submit through the Contact form.
- To review, accept, or decline booking requests you submit through the Book Your Band form, and to follow up with you about scheduling.
- To send the newsletter you subscribed to (events, specials, new releases). Every newsletter email includes a one-click unsubscribe link.
- To improve the Site (page performance, content quality) based on aggregate, non-identifying analytics.
- To protect the Site and users against spam, abuse, and security incidents.
We do not sell or rent your personal information. We do not share it with advertisers or data brokers. We do not use your personal information for cross-context behavioral advertising.
4. Legal Bases (where applicable)
For visitors in jurisdictions that require a legal basis (e.g., GDPR), we rely on: (a) your consent (newsletter signups), (b) the steps necessary to respond to your request (contact and booking forms), and (c) our legitimate interest in operating and securing the Site (server logs, privacy-friendly analytics).
5. Third-Party Services
The Site uses the following third-party providers, each of which processes limited data on our behalf:
- Website Upgrader Pro (operated by Oryx Technologies LLC) at websiteupgraderpro.com. Receives and stores newsletter signups, contact submissions, and booking requests in a Postgres database hosted on Railway. Required to operate the Site's forms.
- Resend at resend.com/legal/privacy-policy. Sends transactional and newsletter email from our platform.
- Cloudflare Pages at cloudflare.com/privacypolicy. Static hosting and CDN for the Site.
- Railway at railway.com/legal/privacy. Hosting for the backend database and application that powers the Site's forms.
- Plausible Analytics at plausible.io/privacy. Cookieless, privacy-friendly traffic analytics.
- Google Maps at policies.google.com/privacy. Provides the embedded location map on the Home and Contact pages. The map loads only when scrolled into view.
We do not use Stripe, Meta Pixel, Google Analytics, Google Tag Manager, or any advertising network on the Site.
6. Cookies and Tracking Technologies
The Site itself does not set tracking cookies. Plausible Analytics is cookieless by design. Our forms use the browser's sessionStorage to remember whether you dismissed the newsletter popup or floating bar during the current visit, which is cleared automatically when you close the browser. The embedded Google Maps iframe (loaded only after you scroll to the map) may set cookies under Google's policy linked above.
7. Your Privacy Rights
Depending on where you live, you may have the right to: (a) know what personal information we hold about you, (b) request a copy or deletion of that information, (c) correct inaccurate information, (d) opt out of any sale or sharing of your personal information (we do not sell or share for cross-context behavioral advertising), and (e) not be discriminated against for exercising these rights.
California residents have these rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA. New Hampshire residents have similar rights under the New Hampshire Data Privacy Act (NH SB 255), which takes effect January 1, 2025. EU/UK residents have rights under the GDPR/UK GDPR.
To exercise any of these rights, email [email protected] with the subject line "Privacy Request" and the request you'd like us to act on. We will verify your identity (by replying to the email on file) and respond within 45 days.
8. Newsletter and Email
When you submit our footer signup, popup, or booking form, you are opting in to occasional emails from The Spot about events, specials, and new menu items. Every email includes a one-click unsubscribe link in the footer. You can also unsubscribe by emailing [email protected] with "Unsubscribe" in the subject. We honor unsubscribe requests within 10 business days, as required by the federal CAN-SPAM Act.
9. Data Retention
- Newsletter subscribers: kept until you unsubscribe, then deleted from active sending lists within 10 business days.
- Contact submissions: retained up to 24 months from last activity, then deleted, unless we need to keep them longer to resolve a dispute or comply with law.
- Booking requests: retained up to 24 months after the requested performance date, for scheduling, payment, and tax records, then deleted.
- Server logs: retained up to 30 days for abuse detection, then rotated.
10. Children's Privacy
The Spot is an all-ages, alcohol-free venue, but the Site is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided personal information through our forms, email [email protected] and we will delete it. This complies with the federal Children's Online Privacy Protection Act (COPPA).
11. Security
We use industry-standard safeguards to protect your information: HTTPS/TLS in transit, encrypted storage at rest, access controls, honeypot anti-spam on every form, and per-tenant API key rotation. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your own email account secure.
12. Breach Notification
If a security breach affecting your personal information occurs, we will notify affected individuals without unreasonable delay, consistent with New Hampshire RSA 359-C:20 and any other applicable state breach-notification laws. We will also notify the New Hampshire Attorney General when required by law.
13. International Users
The Site is operated from the United States. If you access it from outside the U.S., your information will be transferred to and processed in the U.S., which may have different data-protection laws than your jurisdiction. By using the Site, you consent to that transfer.
14. Do Not Track
The Site does not track users across other sites and does not respond to "Do Not Track" browser signals because there is no industry consensus on how to interpret them. Plausible Analytics, our only analytics provider, is cookieless and does not perform cross-site tracking.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The "Effective Date" at the top will always reflect the latest revision. For material changes, we will give reasonable prior notice on the Site or by email.
16. Contact Us
For privacy questions, requests, or complaints, contact:
Oryx Technologies LLC (operator of thespotnashua.com)
Attn: Privacy
33 Clementi Ln, Methuen, MA 01844
Email: [email protected]
For in-person venue questions (hours, events, lost-and-found):
The Spot Kava Bar & Music
217 Main Street, Nashua, NH 03060
Phone: (603) 718-4732
