YourTech IT LLC
Privacy Notice
This notice applies to information submitted through the National FBA Business Directory's current public forms, including forms on its regional directory sites. The directory is operated by YourTech IT LLC.
Last updated: September 1, 2026
Information you may submit
Public forms may collect names, email addresses, telephone numbers, business and business-contact information, verification information or supporting materials, correction requests, and general contact messages.
If you create a public member account, the authentication provider processes your email address and credentials, while the directory stores a stable provider user identifier, a basic display name, account status, account timestamps, and your private selections of saved public businesses. The directory does not store your password, password-reset token, or session token in its member profile records.
How submitted information is used
Submitted information may be used to review business recommendations, assess directory eligibility, communicate about submissions, questions, or corrections, publish approved business information, and maintain administrative and audit records necessary to operate the directory.
Member account information is used to authenticate you, operate account settings, enforce account status, protect the service, and let you retain and manage a private saved-business list. Authentication emails may be sent for account confirmation, recovery, security verification, and email-address changes.
Public business information
Approved business information may be published publicly. Information submitted as a business's public contact information may appear on a published listing.
Directory-integrity reports
The Report a Directory Concern service accepts a short description, the public directory target you select, and one optional HTTPS reference with a short explanation of its relevance. It does not accept file uploads. The directory does not fetch, preview, unfurl, scrape, scan, or send that reference to an artificial-intelligence service. The server creates a limited snapshot using allowlisted public target fields.
The server derives whether a reporter is Anonymous, an authenticated Member, an active business manager for the target business, or an authorized directory administrator. Reporter identity is not shown to the public, a Business, a Business manager, or another Member. Directory investigators may see authenticated attribution when operationally necessary. Anonymous reports do not collect an email address. Raw IP addresses, full user-agent strings, Turnstile tokens, cookies, authentication tokens, and plaintext receipt tokens are not stored in Integrity records.
For abuse prevention, the application transiently uses the request network address and stores only domain-separated keyed HMAC values. Anonymous source HMACs expire within 30 days. Accepted reports receive a random receipt token; only its SHA-256 hash is stored. Anonymous receipt access expires no later than 180 days after case closure. Report text, public snapshots, external references, clarification, and investigation notes are deleted or irreversibly scrubbed 365 days after closure. Minimal case, disposition, and event records are deleted after 730 days. A time-limited retention hold may delay cleanup for an active investigation, privacy/security incident, or legal or regulatory requirement.
A report is an allegation for human review, not proof. It does not automatically change a listing, verification, claim, review, media, membership, billing, or submission record. Anonymous status shows only Received, Under review, or Closed and a generic outcome. Authenticated Members may see only reports they personally submitted. Integrity operational reporting excludes reporter identity, complaint text, public accusation rankings, and paid-tier comparisons.
Sensitive or unnecessary information
Do not submit highly sensitive personal information that is unnecessary for directory review.
Optional first-party directory analytics
If you allow Analytics, the directory may record first-party events that describe how its public pages, search and controlled filters, business profiles, and business-contact links are used. Records may include the directory site and route type, a safe business, category, state, operating-model or service-area reference, result counts, a coarse device class, and a referring hostname or conservatively limited campaign label. Reporting timestamps and day boundaries use UTC.
The browser does not send raw search text. It sends only whether a query was present, a query-length bucket, controlled filter values, and the number of results. Full referring URLs are not retained. The analytics system does not store raw IP addresses, full user-agent strings, precise visitor location, advertising identifiers, or browser fingerprints, and it does not send visitor data to advertising networks.
After consent, the browser creates a random identifier in session storage for the current browser tab. When optional session measurement is enabled, the server stores only an HMAC digest of that random value; it is not derived from IP address, device, fonts, screen, or browser properties. Withdrawing Analytics removes the tab identifier and stops future analytics requests. Previously accepted raw events remain only until their configured retention date.
The server may use a complete network address transiently to enforce abuse limits, but persists only a short-lived keyed HMAC rate-limit value that is separate from analytics reports. Raw analytics events default to 30 days of retention. Non-identifying UTC daily aggregates default to 790 days so longer trends do not require indefinite raw-event storage. These periods are configurable and may be shortened through controlled operations.
Aggregate operational reporting may also count authoritative account, saved-business, claim, review, and business-response records. Those counts do not copy member email, profile content, claim evidence, review text, or other member PII into generic analytics. Traffic collected after activation is kept distinct from historical domain activity; earlier traffic is not invented or backfilled.
Separately, an existing billing feature maintains identity-free daily interaction totals for business owners. Consented profile, website, and phone events may update those billing aggregates after the privacy-aware event is accepted. Intentional use of a paid-profile call-to-action, offer, or video redirect may also increment its daily business total without setting a visitor identifier. These billing totals do not expose visitor identity and are not used for advertising or ranking.
Visitor-requested external services
Public directory data and forms use same-origin requests. If you submit a question to Freedmen's conversational assistant, the question and limited recent conversation context are sent to the directory's server, which may use OpenAI to generate a source-grounded answer. The local FAQ search does not require OpenAI, and the conversation is not saved in browser storage by this site.
Business directions and external website links contact the selected provider only after you choose the link. The directory does not embed those third-party services.
Questions and corrections
For privacy questions, please contact the directory. To report inaccurate published information or another directory-integrity concern, use the private Report a Directory Concern service.
