Privacy Policy

Effective August 25, 2026 · Last updated August 25, 2026

This policy explains what personal information the California Fresh Farmers Market Association collects through its vendor and event platform, how we use it, who we share it with, and the choices you have. We do not sell your personal information. If anything here is unclear, email vendors@cffma.com.

1. Who We Are and What This Policy Covers

The California Fresh Farmers Market Association (“CFFMA,” the “Association,” “we,” “us,” or “our”) operates farmers markets and community events in California and provides an online platform for vendors, sponsors, market hosts, staff, and customers to apply, register, communicate, schedule, and pay (the “Platform”).

This Privacy Policy explains what personal information we collect through the Platform and our related websites, emails, text messages, and phone lines, how we use it, when we share it, and the choices and rights you have. It applies to everyone who uses the Platform: vendor applicants and members, their sub-users and staff, sponsors and sponsorship contacts, market hosts and property partners, CFFMA employees and contractors, and members of the public who register for events, upload event photos, or view a shared gallery or proposal.

It does not cover the independent practices of vendors, sponsors, or other third parties who may collect information from you directly (for example, a vendor’s own point-of-sale system or website), or third-party sites we link to. Their handling of your information is governed by their own policies.

2. Information We Collect

Information you give us

  • Account information. First and last name, email address, phone number, password (stored only as a salted hash), profile photo, and — where you choose to enable it — two-factor authentication settings. Staff accounts may also include date of birth (used for internal birthday recognition; you may omit the year).
  • Vendor and membership application information. Business name and legal entity details, business and mailing addresses, contact people, product and menu descriptions, booth and equipment needs, and the compliance documents we are required to collect or verify — for example certificates of insurance, CDFA grower or producer certifications, county health permits, seller’s permits, business licenses, and county vendor applications.
  • Membership agreement and e-signature records. The version of the agreement you signed, your typed or drawn signature, the date and time of signing, and the IP address and browser used to sign, which together form the audit trail that makes the signature enforceable.
  • Payment and financial information. Billing contact and address, invoices, fees, credits, balances, and payment history. We do not collect or store full payment card numbers or bank account credentials — card and ACH details are collected and stored by our payment processor, Stripe, and we receive only limited identifiers such as the card brand, last four digits, expiration date, and the result of a charge.
  • Sales reporting. Gross sales figures you report for an event, any screenshots or register reports you upload to support them, and sales data imported from a point-of-sale system you connect (Square, Toast, Clover, or Shopify).
  • Employment and scheduling information (CFFMA staff and contractors only). Shifts, clock-in and clock-out times, timecards, pay rate and employee classification, time-off requests and balances, shift trades, and notes on time entries.
  • Communications and content. Messages you send through the Platform’s inbox, team chat, and campaign tools; email and text message exchanges with us; voicemails and phone calls with our business lines; support requests; photos and files you upload, including event photos, artwork, menu images, and documents.
  • Event and public registration information. Details you submit when registering for or requesting participation in an event, or when using a shared link to upload photos or view a gallery or proposal.

Information we collect automatically

  • Device and log data. IP address, browser type and user agent, pages and screens viewed, referring pages, timestamps, and error and diagnostic logs.
  • Usage and funnel analytics. Events such as starting a sign-up, completing an application, opening an emailed or texted link, viewing a shared proposal page, and downloading a photo from a gallery — recorded so we can measure whether the Platform works and where people get stuck.
  • Cookies and similar technologies. Described in Section 6 below.
  • Location at clock-in and clock-out (CFFMA staff and contractors only). If you clock in or out from the Platform’s time clock, we record the geographic coordinates reported by your device at that moment to confirm the entry was made at the worksite. We do not track your location at any other time, and we do not track your device in the background.
  • Call recordings and transcripts. Some calls to or from CFFMA business lines are recorded and transcribed for recordkeeping, quality, and follow-up. When a call is recorded you will be notified at the start of the call and may ask that recording stop or decline to continue.

Information we receive from others

  • Sign-in providers. If you sign in with Google, we receive your name, email address, and profile image from Google. We never receive your Google password.
  • Connected accounts you authorize. Google Drive and Gmail (when you connect them to import files or route mail), your point-of-sale provider, Eventbrite, Meta, and partner event systems. We receive only what the connection’s permissions allow, and only for as long as you keep it connected.
  • Payment and verification providers. Stripe (charge and payout status, disputes), Twilio (delivery and verification status), and Cloudflare Turnstile (a pass/fail signal that a form submission is human).
  • Market hosts, sponsors, and referrals. Contact details for a business or person submitted by a host property, sponsor, event partner, or an existing vendor who refers you.

3. How We Use Information

We use personal information to:

  • create and secure your account, verify your email address and phone number, and authenticate you;
  • review, approve, and administer vendor applications, memberships, event assignments, booth placement, and attendance;
  • verify insurance, permits, and certifications and meet our obligations to health departments, county agricultural commissioners, host properties, and insurers;
  • invoice and collect participation fees, membership dues, and other charges, process payments and refunds, reconcile balances, and maintain financial records;
  • operate events — schedule staff, publish maps and lineups, produce artwork and menus, and coordinate day-of logistics;
  • send you operational messages by email, text message, push notification, and phone about applications, events, schedules, invoices, and account security;
  • send marketing and community announcements about upcoming markets and opportunities, subject to your opt-out rights;
  • provide support, investigate issues, and maintain audit logs of significant actions taken in the Platform;
  • improve the Platform, analyze usage, and develop new features;
  • promote our markets and vendors, including publishing vendor business profiles, event photos, and press materials as described in Section 5;
  • detect, prevent, and respond to fraud, abuse, security incidents, and violations of our rules; and
  • comply with law, respond to lawful requests, and establish or defend legal claims.

We do not use the personal information of vendor applicants or members for any purpose that is materially different from the purposes described here without telling you first.

4. AI-Assisted Features

Parts of the Platform are assisted by artificial intelligence. AI assistants help draft and triage messages, summarize threads, transcribe voicemails and calls, generate event artwork and menu imagery, answer questions from our internal knowledge base, and suggest next steps on tasks. To do this, the relevant content — for example the text of a message thread, a call recording, a document you uploaded, or your account name and role — is sent to our AI service providers for processing.

  • We use business-tier AI services whose terms provide that content submitted through their APIs is not used to train their general models.
  • AI output can be wrong. A person reviews AI-drafted communications and AI-suggested decisions before they have any effect on your application, membership, billing, or employment. We do not make decisions that produce legal or similarly significant effects about you by automated means alone.
  • Please do not paste information into the Platform’s AI features that you would not want processed by a third-party service — for example, government identification numbers or financial account credentials.

5. Information That Is Public or Shared by Design

Some information you provide is meant to be seen by others. Please keep this in mind when deciding what to submit:

  • Vendor profiles. When your vendor profile is published, your business name, description, product categories, logo and photos, social links, and the markets you attend are publicly visible on the Platform and may be syndicated to cffma.com and partner event listings. Your personal contact details are not published unless you put them in a public field.
  • Event photos and galleries. Photos taken or uploaded at our events may be used in event recaps, galleries, social posts, and press materials. Gallery links can be shared by anyone who has them.
  • Shared links. Sales-reporting links, proposal links, photo-upload links, and gallery links are authorized by the token in the URL rather than by a login. Anyone with the link can use it for as long as it is valid, so treat those links as confidential.
  • Within your organization. If you are a sub-user on a vendor account, the account owner can see the applications, events, invoices, sales reports, and messages associated with that account, including activity you perform.
  • Team chat and internal messaging. Messages in shared channels are visible to other members of that channel and to administrators, and are retained in our records.

6. Cookies and Tracking Technologies

We use a small number of cookies and similar technologies:

  • Strictly necessary. Session and authentication cookies that keep you signed in, and security cookies used by our bot protection (Cloudflare Turnstile). The Platform does not work without these.
  • Analytics. Google Tag Manager and the analytics tags we deploy through it, which measure page views, sign-up funnel steps, and feature usage.
  • Advertising. On our public marketing pages we may use advertising tags (including Meta) to measure campaigns and reach people who have shown interest in our markets.

Most browsers let you block or delete cookies, and mobile operating systems offer advertising controls. We honor the Global Privacy Control (GPC) signal as a valid request to opt out of the sharing of personal information for cross-context behavioral advertising for the browser that sends it.

7. How We Share Information

We share personal information only as described below. We never sell it for money.

  • Service providers. Companies that run parts of the Platform on our behalf under contracts that limit them to our instructions: Amazon Web Services (hosting and file storage), Stripe (payments), Twilio (text messages, voice, and phone verification), SendGrid (email), Google (sign-in, Drive, Gmail, and mapping and AI services), Cloudflare (bot protection), Mapbox (maps), Anthropic and other AI providers (AI features), Voyage AI (search indexing), and ElevenLabs (voice synthesis).
  • Host properties, market partners, and regulators. When a market requires it, we share the vendor roster and compliance status — business name, contact person, products, insurance and permit status — with the host property, the venue, county health and agricultural authorities, and our insurers.
  • Event and listing partners. Published event and vendor listing details shared with platforms such as Webflow, Eventbrite, Street Feasts, and social channels.
  • Advertising platforms. We may provide hashed contact identifiers (such as an email address converted to an irreversible hash) to Meta to build custom or lookalike audiences for our market promotions. Under California law this may count as “sharing” personal information for cross-context behavioral advertising, and you can opt out at any time (see Section 9).
  • Professional advisors. Accountants, auditors, insurers, and attorneys, under duties of confidentiality.
  • Legal and safety. When we believe disclosure is required by law, subpoena, or court order, or is reasonably necessary to protect the rights, property, or safety of CFFMA, our vendors, our staff, or the public.
  • Business transfers. In connection with a merger, reorganization, financing, or transfer of all or part of our operations, subject to this Policy continuing to apply to the transferred information.
  • With your direction. Anywhere else you ask us to send it.

8. Retention and Security

We keep personal information for as long as your account is active and afterward for as long as we need it for the purposes described in this Policy. In practice that means:

  • Financial and tax records (invoices, payments, sales reports) — at least seven years, as required for tax and audit purposes;
  • Membership agreements and signature audit trails — for the life of the membership plus the applicable limitations period;
  • Insurance and permit documents — for the policy or permit period plus the period during which a claim could be brought;
  • Employment and time records — for the periods required by California and federal wage-and-hour law;
  • Messages, call recordings, and transcripts — generally up to three years, unless a longer period is needed for a dispute or investigation;
  • Server and analytics logs — generally up to twenty-four months.

We protect information with encryption in transit, encryption of stored files and access tokens, hashed passwords, role-based access controls, optional two-factor authentication, bot protection on public forms, audit logging of significant actions, and time-limited tokens for shared links. No system is perfectly secure; you are responsible for keeping your password and any shared links confidential and for telling us promptly if you believe your account has been compromised.

9. Your Choices and Privacy Rights

Choices available to everyone

  • Account information. You can review and update most of your information in your profile and vendor settings.
  • Email. Use the unsubscribe link in any marketing email. Operational messages about your account, applications, events, and billing will continue.
  • Text messages. Reply STOP to any message to stop texts from that number, or HELP for help. Message and data rates may apply.
  • Connected accounts. Disconnect Google Drive, Gmail, a point-of-sale provider, or another integration at any time from your settings.
  • Deletion. You can ask us to close your account and delete your information, subject to the records we must keep as described above.

California residents

Under the California Consumer Privacy Act, as amended by the CPRA, you have the right to know the categories and specific pieces of personal information we collect and the categories of sources, purposes, and recipients; the right to delete personal information we hold about you; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right not to receive discriminatory treatment for exercising these rights.

The categories of personal information we have collected in the past twelve months are identifiers; customer records and financial information; commercial information; internet and network activity; geolocation data (staff clock-in and clock-out only); audio and visual information (call recordings, voicemails, photos); professional and employment information; and inferences drawn from the above. We have not sold personal information for money in the past twelve months. We may have shared hashed contact identifiers for cross-context behavioral advertising as described in Section 7. We do not knowingly sell or share the personal information of anyone under 16.

The only sensitive personal information we collect is precise geolocation at staff clock-in and clock-out and, where you enable it, two-factor authentication credentials. We use these only to provide the service they belong to and never to infer characteristics about you, so the “limit the use of sensitive personal information” right does not restrict any additional use.

To exercise a right, email vendors@cffma.com or call (559) 540-8359 with the subject “Privacy Request.” We will verify your request against information we already hold — typically the email address and phone number on your account — and respond within 45 days, extending once by another 45 days if needed. An authorized agent may submit a request with written permission signed by you. Employees and job applicants have these rights as to their employment-related information as well.

10. Children’s Privacy

The Platform is intended for adults. We do not knowingly collect personal information from children under 13, and accounts may not be created by anyone under 18. Minors may appear in event photographs taken in public market settings; if you are a parent or guardian and want a photo of your child removed, email vendors@cffma.com and we will remove it from our galleries and marketing materials.

11. Where We Operate

CFFMA operates in California and the Platform is hosted in the United States. If you access it from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your country.

12. Changes to This Policy

We may update this Policy as the Platform and our practices change. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will give notice through the Platform or by email before the change takes effect. Continuing to use the Platform after a change takes effect means you accept the updated Policy.

13. Contact Us

Questions, concerns, or privacy requests can go to our team at:

California Fresh Farmers Market Association
8839 N Cedar Ave #385, Fresno, CA 93720
Email: vendors@cffma.com
Phone: (559) 540-8359
Web: www.cffma.com
If you have a concern about how we handled your information, please contact us first — we would like the chance to fix it. California residents may also contact the California Privacy Protection Agency or the California Attorney General’s Office.