Privacy policy
Last updated 4 October 2026
What Town Square collects when you use it, who can see it, and how to have it removed. Written to describe what the site actually does, in plain English.
Who this is about
Town Square is the member area of H7 Network. This policy explains what we collect when you use it, who can see it, and what you can do about it.
If anything here is unclear, or you want to know what we hold about you, email clayton@h7network.com.
What we collect
Your sign-in details. Your email address and password are handled by Google Firebase Authentication. We never see your password, and your email address is kept there, not on your member profile, so other members never see it.
Your profile — whatever you choose to put in it:
- Your name, headline, three-word introduction and about text
- Your industry, and whether you have said you are a military veteran
- Your location and time zone
- The markets you serve and the spheres you can introduce people into
- Links you add, such as your website, LinkedIn or booking page
- A profile picture and banner image, if you upload them
What you do here. Posts, asks and offers, comments, reactions, poll votes, recognitions you give, introductions you make or confirm, people you save to My Connections and any private notes you write about them, direct messages, meeting RSVPs, pods you join, marketplace listings, a storefront page if you make one, and your progress through the training. In an H7X pod: the pod's chat, its introductions ledger and workbook, and your own private notes.
Getting in. H7 keeps a list of its members' email addresses and whether each is a paying or complimentary member, so that when you confirm your email address here we can let you straight in. We record that you confirmed it. If you ask to be let in instead, we keep your name, your sign-in email, any other email address you give us and your note.
Your profile from the previous Town Square. When H7 moved from its old platform, it exported what members had on their profiles there (about text, three-word introduction, industry, location, time zone and markets). We keep that copy only to offer it back to you once, and delete it as soon as you answer.
Storefront enquiries. If someone uses the contact form on a member's public storefront page, we keep the name, email address, phone number (optional) and message they send. To stop the form being used for spam, we also count how many messages come from each network address in an hour; we keep only a scrambled form of the address, never the address itself, and the count for that hour.
Connection forms. If you fill in a connection form after a meeting — including as a visitor with no account — we collect the name, email address, phone number and LinkedIn you enter, along with your takeaway and the action you commit to.
Feedback and test runs. Anything you send through the feedback button, and your answers if you take part in a pre-launch test run, including the browser and device details that run records.
Ordinary technical information. Our host keeps standard server logs of requests, as any website does.
How the site is used. Which pages are visited, how quickly they load, errors the site runs into, and when someone uses a feature such as making an ask, giving a recognition or making an introduction. We link this to your account by its internal ID, not your name or email address. We do not record your screen, your clicks or what you type.
What we do not collect
We do not ask for or store health information, government identifiers, or card details. When payments are switched on, card details will be handled entirely by a payment provider and will not pass through us.
We do not run advertising trackers, and we do not sell your information or share it with data brokers.
Who can see what
Other members can see your profile in the member directory (including the veteran star, if you choose it), and anything you post, comment, react to or recognise. Assume anything you post is visible to every member.
Poll votes are not anonymous: other members can see which option you chose. The poll says so before you vote.
Your member record also notes whether you are a paying or complimentary member. We do not show that to other members, but it sits on the same record as your profile, so a technically minded member could read it. We plan to move it somewhere only H7 staff can see.
In an H7X pod, the chat, the introductions ledger and the workbook are visible to that pod's members. H7 admins can also see a pod's ledger and workbook, but not its chat unless they are in the pod. Your private notes in a pod are yours alone.
If you publish a storefront, that page is public: anyone with the link can see it, without signing in. Messages sent through its contact form go only to you.
Only you can see the people you have saved to My Connections and the notes you keep on them, and your notifications.
Only you and the person you are writing to can see a direct message. Nobody at H7 can read it from inside Town Square — not admins, not moderators, not the owner. The server refuses the request, and we have automated tests that fail if anyone ever changes that.
There is one exception, and only you or the person you are writing to can trigger it. If someone is being inappropriate, either of you can bring a named moderator into that one conversation from the “Get help” button in the thread. They can then read that conversation — all of it, including the messages already there, and anything sent afterwards. It applies to that conversation and no other, both of you are told at the top of the thread who was brought in and by whom, and it cannot be reversed once done.
The limit of that, stated plainly: messages are not end-to-end encrypted, so whoever administers the underlying database could read what is stored there, as is true of any hosted service that isn't encrypted end to end. Access to it is restricted to the people who run the platform, it is not used to browse conversations, and we would only look where a member reported abuse or the law required it. The “Get help” button above exists so that reporting abuse does not need that access at all.
Only H7 staff can see feedback you submit, connection form submissions, test-run answers, your training progress, requests to be let in, H7's member list, the copy of your old profile (which you can see too, once your email is confirmed), and the log of administrative changes. Direct messages are not on that list, on purpose — a moderator reaches one only when a participant hands it to them.
Nobody outside H7 sees any of it, apart from the services listed below that run the site for us, and a storefront page you choose to publish. The member directory is not public and is not published anywhere.
Cookies and what is kept on your device
We use browser storage for things the site needs to work, not for tracking:
- Your sign-in session, so you stay signed in
- Whether you chose light or dark mode
- How you have arranged and collapsed the sidebar
- Whether you have seen the welcome tour and the latest What's new
- Which messages you have already read on this device
- A random analytics identifier, so we can tell one visitor's visits apart from another's (PostHog, below)
There are no advertising or cross-site tracking cookies. Since 1 October 2026 we use product analytics to understand which features get used and where the site goes wrong; it is described under "What we collect" and "Who else handles it".
Who else handles it
We use a small number of services to run the site. They process information on our behalf and are not permitted to use it for their own purposes:
- Google Firebase — sign-in, the member database, and image storage (United States)
- Vercel — hosting and delivery (United States)
- HighLevel (GoHighLevel), through H7's own account — sends Town Square's emails, such as the link to confirm your email address and the notes that tell H7 admins someone has joined or asked to be let in. To email you, HighLevel needs you as a contact, so your email address is added as a contact in H7's HighLevel account, where H7 keeps its contacts, and the emails it sends are kept there (United States)
- Discord — alerts to H7 staff when someone signs up, asks to be let in or sends feedback, with that person's name, email address and message (United States)
- PostHog — product analytics and error reports: pages visited, load times, errors, and feature use, linked to your account's internal ID, not your name or email address (United States)
- A payment provider — card payments, once payments are switched on. Card details go to them, never to us
While the migration from the previous Town Square is under way, some information also exists in that older system, which is run by Mighty Networks.
How long we keep it, and how to have it removed
We keep your profile and what you have posted for as long as you are a member, so that the community's conversations stay intact.
There is no self-serve delete button yet — we are building one. Until it exists, email clayton@h7network.com and we will remove your account and your profile. Say if you also want your contact removed from H7's HighLevel account: that is a separate step, and we will do it.
One honest caveat about deletion: where you have posted something that others have replied to, we may keep the reply thread and remove your name from it, rather than delete other members' contributions along with yours.
How it is protected
The site is served over HTTPS, information is encrypted where it is stored, and access is enforced per record on the server — not merely hidden in the interface. Those rules are covered by an automated test suite that runs before every change goes live.
No system is perfectly secure, and we will not claim otherwise. If we ever discover a breach affecting your information, we will tell you.
Your choices
You can see and change most of what we hold about you at any time from your profile and settings pages. You can change your own email address and password.
For anything you cannot change yourself — including a copy of what we hold, or deletion — email clayton@h7network.com.
Age
Town Square is a professional network for adults in business. It is not intended for anyone under 18, and we do not knowingly collect information from children.
Changes to this policy
This is an interim policy while H7 Network finalises its formal version, and it will be updated. When the substance changes we will change the date at the top and note it in What's new inside the app.
Getting in touch
Questions about either document go to clayton@h7network.com.