Privacy Policy

Version 1.0. Last updated 30 August 2026.

Next Coast Brokerage is a division of Next Coast Media and Marketing Services LLC ("we"), the company responsible for your data under this policy. It applies to nextcoastbrokerage.com: reading the site and sending us a message through the contact form. Cookies and everything else stored in your browser are listed by name in the cookie policy.

Questions and requests about your data: [email protected].

What we collect, and when

Reading the site

Reading the site tells us nothing about you. We run no analytics and no advertising tools. Our hosting provider keeps standard server logs, including IP addresses, for security and to keep the site running; we do not use them to identify visitors.

Sending us a message

When you use the contact form we keep what you typed: your name, email address, company (if you give it), the topic you chose, your message, and the time it was sent. The form is protected against bots by Cloudflare Turnstile, which checks the browser invisibly. We do not store your IP address with your message; a short-lived, scrambled count of submissions per connection protects the form from floods and is discarded within hours.

Your message is stored in our records and emailed to the advisory team, who reply to you from our own email. Everything you tell us is treated as a confidential enquiry. If the conversation develops into an engagement, a written confidentiality agreement governs it from then on.

Why we are allowed to do this

WhatBasis
Answering your message and following up on your enquirySteps taken at your request before any engagement
Security and bot protection on the form and the siteOur legitimate interest in keeping the site running and safe
Keeping records of an engagementLegal obligation, where one applies

Who handles your data for us

We use these companies to run the site and reach you. Each one processes data on our instructions under its own data-processing terms. Where data leaves the United Kingdom or European Economic Area, the transfer rests on the standard contractual clauses approved by the European Commission and the UK addendum to them.

CompanyWhat forWhere
CloudflareHosting, bot protection on the form, and the storage behind the form and the cookie-consent recordUnited States, with edge locations worldwide
ResendDelivers the email that tells our team you wroteUnited States
Google WorkspaceOur email and document storageUnited States

We do not sell personal data, and we do not share it with data brokers, advertising networks, or anyone outside the company. We disclose it only to the companies above, to a buyer or successor if the business changes hands (you would be told), and where the law requires.

How long we keep it

DataKept for
Contact messagesTwo years after the last contact with you, unless a business relationship continues
Cookie-consent recordsThree years from the choice, as evidence that consent was given
Server logs held by our hosting providerThe short period set by the provider's own retention policy

Your rights

Wherever you live, you can ask us what we hold about you, ask for it to be corrected or deleted, ask for a copy in a portable format, object to processing based on our legitimate interests, and withdraw any consent you have given (the cookie settings in the footer do this without asking us). Readers in the United Kingdom and European Economic Area have these rights under the GDPR; readers in California have equivalent rights under the CCPA, including the right to know what we collect and the right not to be treated differently for exercising them. We do not sell or share personal information as California law defines those terms, so there is nothing to opt out of on that front.

To use a right, email [email protected] from the address you wrote to us from, or tell us enough to find you. We answer within one month. If you have never written to us, we hold nothing that identifies you.

If you are unhappy with our answer, you can complain to the data-protection authority where you live; in the UK that is the Information Commissioner's Office, and in the EU your national authority.

Children

Our readers are business owners and executives; nothing here is aimed at children. We do not knowingly collect data from anyone under 16; if you think we have, tell us and we will delete it.

Security

Everything travels encrypted (HTTPS). Access to messages is limited to the people who need it to answer you, and every provider above holds its own security certifications. No system is perfect; if a breach ever affects your data we will tell you and the relevant authority as the law requires.

Changes

When our practices change, this page changes and the date at the top moves.