Who we are
BetaNYC is a civic organization dedicated to improving lives in New York through civic design, technology, and data. We ask government to be open about how it works, and we hold our own websites to the same standard. This page says plainly what we collect, why, and what choices you have.
What this policy covers
This policy applies to www.beta.nyc, every subdomain of beta.nyc, betanyc.us, and betanyc.org. It also covers the newsletter signups, event registrations, and donations we run through outside services, the platforms where our community gathers, and the tools we keep our records in. Those services and platforms have their own privacy policies, and we link to them below.
What we collect and why
Visiting our sites
We use Google Analytics, loaded through Google Tag Manager, to see how the site is used: which pages people visit, the approximate location a visit comes from (based on IP address), and the kind of device and browser in use. We read these reports in aggregate to decide what to improve. Google’s privacy policy covers how Google handles this data.
Leaving a comment
If you leave a comment, we collect what you type into the comment form, plus your IP address and browser user-agent string to help detect spam, and comments may be checked by an automated spam-detection service. A hashed version of your email address, not the address itself, may be sent to Gravatar, a profile-picture service run by Automattic, to check whether you have a profile there; Automattic’s privacy policy covers that service. If you opt in, cookies will remember your name, email, and website so you do not have to retype them next time. Comments and their metadata stay on the site indefinitely, so we can recognize your follow-up comments and approve them instead of holding them in moderation.
Subscribing to the newsletter
When you sign up for our weekly newsletter, your name and email address go to Mailchimp, the service that delivers it, under Mailchimp’s privacy policy (Mailchimp is an Intuit company, so that link opens Intuit’s privacy statement). Every issue includes an unsubscribe link.
Mailchimp records whether you open an issue and which links you click, and it associates that with your subscription. We use it to understand which stories are useful and to stop sending to addresses that have gone dead. Blocking remote images in your mail client stops the open tracking. Clicking a link in the email is recorded either way, because the link routes through Mailchimp on its way to the destination. You can always paste a story’s address into your browser instead.
Registering for an event
We use Eventbrite and Ti.to for event registration, and Sched for the schedule at NYC School of Data. Your name, email address, and whatever else the form asks for are collected on those platforms under Eventbrite’s privacy policy, Ti.to’s privacy policy, and Sched’s privacy policy. Online events and office hours run on Zoom; joining one is governed by Zoom’s privacy statement.
Registrations and attendance from those platforms are copied into CiviCRM, our own database, so our record of who has taken part is not scattered across services we may stop using. That includes past events: we are bringing our event history since 2019 into one place. For online events, that record is the list of who joined, which Zoom gives us as the host.
Donating
Donations run through Donorbox, a service embedded on our donate page; PayPal appears as a payment option inside it. Your payment details go directly to Donorbox and its payment processors, under Donorbox’s privacy policy. We never receive or store full card numbers. We keep donation records for as long as accounting and tax rules require.
Emailing us
If you email us, whether privacy@beta.nyc or a staff member directly, we receive whatever you choose to include in your message.
Where our community gathers
Our community meets on platforms we do not run. Joining one means that platform processes your data under its own policy; each platform name below links to that policy.
- Slack (slack.beta.nyc), which is closing on October 16, 2026 — see “Retiring our Slack workspace” below
- Discord, home of our BetaBuilders community
- Meetup (meetup.com/betanyc)
- GitHub (github.com/BetaNYC), where our public repositories, issues, and contributions live
- Reddit (r/PublicInterestNYC)
- YouTube, our video channel, which runs under Google’s privacy policy
Retiring our Slack workspace
Our Slack workspace goes read-only on September 28, 2026 and closes on October 16, 2026. Three things worth saying plainly.
As the operator of that workspace, we can see the name and email address of everyone who joined it. That is true of any Slack workspace and always has been. We use it to run the workspace.
When the workspace closes, we are keeping a record of who was part of this community — name and email address — in CiviCRM, the database described above. We do that so our understanding of who this community is survives the platforms we use to reach it. We are not adding you to our newsletter because of it. If you hear from us, it is because of something you did — you subscribed, gave, registered, or wrote to us — or because of a role you hold with BetaNYC, as staff, board, associate board, or a fellow. Not because you were in Slack. You can ask us to delete that record at any time; see “Your rights.” Announcements about the closure will be posted in Slack itself, where you already are.
We are on Slack’s free plan, which shows only recent history and deletes older messages on its own schedule. Most of what was posted there over eleven years is already gone, and it went before we decided to close the workspace. We are preserving what remains of the public channels. We cannot recover direct messages, and we will not be able to retrieve them for you after the workspace closes.
Getting into BetaBuilders on Discord
Parts of our Discord are open only to current members. To let you in, we have to connect the person in our records to the account you use on Discord.
Here is how that works. We email you a one-time link. You follow it and sign in to Discord, which tells us your Discord account ID and nothing else. We store that ID on your record in CiviCRM. From then on, the record that says you gave or attended is the same record that says which Discord account is yours.
A program we run checks that record and sets your access. A qualifying donation or event opens the member areas for ninety days, and they close again if nothing renews it. That check runs on our own server at bot.beta.nyc, which receives a message from Donorbox when a donation comes in and from Ti.to when someone registers for an event.
You can ask us to remove the Discord ID from your record at any time. Doing so ends your access to the member areas and changes nothing else.
What is watched in BetaBuilders
Discord processes everything posted in BetaBuilders under its own privacy policy. Two things in it are worth knowing. Discord scans content across its service for illegal and harmful material, and it says it does not read direct messages between adults unless something is reported. Discord may also keep messages posted in server channels for 180 days to two years after you delete them, to train its detection systems; that is Discord’s retention, not ours.
We have turned on Discord’s server safety features. Every message in a text channel is checked before it posts against Discord’s lists for slurs, sexual language, severe profanity, spam, and messages with more than eight mentions. Every image is scanned for explicit content; images only, not video. A message that trips a filter is never posted; you see a notice that only you can see, and Discord sends the blocked text, your name, and the channel to a private channel that only staff can read, so a person can review the decision. We keep those alerts while they are relevant to the work. Members with the Administrator or Manage Server permission are exempt from the filters by Discord’s design.
We run two bots in BetaBuilders. The first, described above, connects your Discord account to your record and sets your access; it reads no messages. The second is Rosie, the robot, which staff run to post announcements, polls, and digests, and to help staff moderate. Every action Rosie takes that affects a person is reviewed and approved by a staff member first; she never acts on a person on her own, and she cannot change roles or server settings.
Rosie does not read or reply to messages on her own. She receives the text of a message only when someone mentions her by name. Those messages, the replies around them, and any reply a staff member sends through her are copied to a staff channel and kept in a private record on BetaNYC systems that only the staff who moderate the server can read, so a person can see it and answer, and so we can look back at what people asked. We keep that record indefinitely and review it every year. A daily summary with counts and links, and no message text, goes to staff. Rosie also receives, for every message in the channels she is in, the kind of information any bot on Discord receives: who posted, where, and when. She does not keep it. Neither bot reads direct messages. What Rosie can and cannot do is pinned in the server’s welcome channel, and our AI Policy sets out the rules we hold every bot to.
Staff can read any channel they are in, as on any Discord server. We do not read direct messages and cannot.
Questions about any of this go to #help-desk in the server or to any staff member. A concern about how a bot behaved goes to saferspaces@beta.nyc under the Code of Conduct.
Our social media accounts
We post on Bluesky, LinkedIn, Facebook, Instagram, Threads, and Mastodon (@betanyc@urbanists.social). We review engagement on those posts (likes, shares, replies, and follows) to understand what interests our community. We see only what each platform shows any account holder, and that activity is governed by each platform’s own privacy policy.
The tools we work in
Behind the scenes, we work in Google Workspace (email, documents, and forms) and keep contact, event, and program records in Airtable. Both process that information for us under their policies: Google’s privacy policy and Airtable’s privacy policy.
We also keep our membership, donation, and event records in CiviCRM, an open-source constituent database at betanyc.civicrm.org. We run it on CiviCRM Spark, the hosting service offered by the CiviCRM project, which processes that information for us under CiviCRM’s privacy policy. This is where a donation or an event registration becomes a record we can recognize you by, and it is what tells us whether your BetaBuilders membership is current.
When someone is asked to leave
Rarely, we ask someone to stop taking part in BetaNYC. When that happens we keep a record of the decision, including the person’s name and the reason for it, so the decision holds everywhere we gather rather than only in the room where it was made. That decision is made under our Code of Conduct, which sets out how it is reached and how to appeal it. That record does not stop our newsletter reaching you.
Our Mailchimp newsletter list and our CiviCRM records are separate systems, and information moves in one direction only: from Mailchimp into CiviCRM. If you unsubscribe, that is recorded in CiviCRM as well, so the newsletter does not find its way back to you from somewhere else. Unsubscribing from the newsletter stops the newsletter. It does not stop other mail you asked for, such as a receipt or a note to donors. Those are separate choices, and you can make each one separately. If you are a subscriber, we keep a record of that so we know you are part of this community. Nothing moves the other way: giving or attending does not subscribe you to the newsletter, and we do not add anyone to the newsletter from our records.
What we don’t do
- We do not run ads, and no advertising network operates on our sites.
- We do not sell or rent personal information, to anyone, for any purpose.
- We do not track you beyond what is described on this page.
- The only automatic decisions we make are the spam screening on comments and the Discord access check described above, which reads your record to decide whether the member areas are open to you. A person can always review either one; email privacy@beta.nyc.
- Beyond the services named above, we do not share personal information with anyone unless the law requires it.
If we ever receive a government or legal demand for personal information, we will disclose only what the law actually requires, and we will tell the affected person unless the law forbids us from doing so.
Cookies
Our sites set a small number of cookies: the cookies Google Analytics uses to tell returning visitors apart, and the optional cookies that remember your details when you comment. Embedded content from other sites may set its own, covered next. You can block or delete cookies in your browser settings.
Embedded content from other sites
Pages here sometimes embed videos, maps, social media posts, and similar content from other websites. An embed behaves as if you had visited the other site directly: it may set cookies and track your interaction with it, under that site’s own privacy policy.
How long we keep things
- Comments and their metadata: indefinitely.
- Donation records: as long as accounting and tax rules require.
- The newsletter list: until you unsubscribe. Unsubscribed addresses stay on a do-not-mail record so the newsletter cannot reach you again by mistake, unless you ask us to delete you entirely (see “Your rights”).
- Newsletter open and click records: while you are subscribed.
- Ordinary email: no fixed schedule; we keep correspondence while it is relevant to the work.
- Contact, event, and program records, including a Discord account ID and a record of Slack membership: no fixed schedule; we keep them while they are relevant to the work.
- A child’s registration details: no longer than we need to run and account for the program.
- Messages that mention our Discord bot, and the replies around them: kept indefinitely for staff review, and reviewed every year. You can ask us to delete yours; see “Your rights.”
- Alerts from Discord’s safety filters, which carry the blocked text, the author, and the channel: no fixed schedule; we keep them while they are relevant to the work, like other moderation records.
Your rights
You can ask to see the personal information we hold about you, correct it, receive a copy to take elsewhere, or have it deleted. Email privacy@beta.nyc and we will respond. One caveat, stated plainly: records we are required to keep for accounting, legal, or security reasons, such as donation records, stay on file even when a deletion request covers everything else. If that applies to your request, we will tell you.
Children’s privacy
Our websites are written for a general audience, and we do not knowingly collect personal information from children under 13 through them.
Some of our programs are for young people, and we offer childcare at events such as NYC School of Data and CityCamp. Childcare is run for us by a licensed childcare provider. A parent or guardian registers a child through Ti.to or by email, giving only what is needed to care for the child safely, and the provider may collect a little more at the door under its own practices.
We use this only to run that day’s care or program. It never goes into our membership database, it is not linked to any other record, and we do not use it to contact anyone afterward. What we keep in our own records is a count, not a child’s details, and we keep a child’s registration details no longer than we need to run and account for the program.
Changes to this policy
When we change this policy, we will post the new version on this page, update the “Last revised” date below, and add a short note of what changed significantly. A change in what we collect will appear here before it appears in practice.
Questions
Questions, corrections, and requests about your information go to privacy@beta.nyc. A person reads that inbox. If the answer you get does not settle the matter, you can raise it with our executive director, Noel Hidalgo, through the same address.
What changed on September 9, 2026. We added a section on what is watched in the BetaBuilders Discord, all of it already true and not yet written down: that Discord scans content under its own policy and keeps deleted server messages for a period it sets; that we have turned on Discord’s filters, which check every message and image before it posts and send blocked text to a staff-only channel; that staff can read any channel they are in and nobody reads direct messages; and the bot our staff run there, Rosie, the robot: what she does, that a person approves every action she takes that affects someone, that messages which mention her are copied to a staff channel and kept for staff review, and that she receives who-posted-where information for messages she cannot read. We added the mention record and the filter alerts to “How long we keep things.”
What changed on July 20, 2026. We described several things that were already true and not yet written down, and one that is about to be. Already true: how members connect a Discord account to their record to get into BetaBuilders, and that a program of ours reads that record to set access; that registrations and attendance from our event platforms are copied into CiviCRM; that we keep a record when someone is asked to leave under our Code of Conduct; that we offer childcare at some events and what happens to a child’s registration; that CiviCRM Spark hosts our database; that Sched runs the School of Data schedule; and the open and click tracking Mailchimp performs on the newsletter. About to be true: information will move from Mailchimp into CiviCRM, one direction only, so an unsubscribe is honored everywhere. That last change has not happened yet. We are describing it here first, which is the order we promised. We also corrected an earlier line that read as though unsubscribing from the newsletter stopped all our mail; it stops the newsletter, and other mail you asked for is a separate choice.
What changed on July 19, 2026. We added CiviCRM, the database where we keep membership, donation, and event records. It was in use and was not named here; that was a gap on our part. We also said that our Mailchimp newsletter list and our CiviCRM records are separate (superseded July 20; see above). And we added a section on retiring our Slack workspace, covering what we can see as its operator, what we are keeping when it closes and why, what has already been lost to Slack’s own deletion schedule, and how to ask us to delete your record.
This policy is adapted in part from NTEN’s Sample Privacy Policy (2021), with thanks. We license it under Creative Commons Attribution-ShareAlike 4.0: if your organization needs a privacy policy, you are welcome to copy this one, adapt it, and share what works.
Last revised: September 9, 2026