Privacy Policy
Effective date: September 1, 2026·Version 2026-09-01
In plain English
This summary is provided for convenience only. The numbered sections below control if there is any difference between this summary and the full Privacy Policy.
- Most people who visit ffpvhub.com do not create an account. We do not currently use analytics, advertising cookies, retargeting pixels, or cross-site tracking.
- Vendors who apply to be listed provide business, contact, account, and subscription information. Vendors with accounts also have authentication and account activity information associated with them.
- Payment card and bank information is entered directly on Stripe’s hosted pages. Our website does not receive, transmit, or store card or bank account numbers.
- Vendor listing information is public by design. Published listings, images, offers, social links, and business contact information may be indexed, cached, or copied by search engines and other third parties.
- We do not sell or rent personal information or share personal information for cross-context behavioral advertising.
- Vendors can view and correct most listing and account information themselves. Some records, including our append-only account audit log and records that must be kept for legal, tax, accounting, security, or fraud-prevention purposes, may remain after an account or profile is deleted.
1. Scope and Who This Policy Applies To
This Privacy Policy explains how information is handled in connection with Florida First Premium Vendors, operating as part of Next Level Shows, through ffpvhub.com.
The legal entity responsible for operating the service is Next Level Shows.
Florida First Premium Vendors is based in Florida, United States. The service is intended for use in the United States and does not deliberately target residents of the European Union or United Kingdom.
The service is a public directory for vendors who exhibit at Next Level Shows events in Florida, including gun and knife, military, western, antique, and craft shows. Vendors may purchase subscriptions, maintain accounts, and manage their own public directory listings.
This Policy applies differently depending on how you interact with the service. We divide users into three groups:
- Public Visitors — people who browse the public directory without an account.
- Vendor Applicants — people who submit information to apply or sign up for a vendor listing.
- Vendors With an Account — vendors who have an active or existing account and can manage their listing.
Our Terms of Service separately govern use of the service, subscriptions, accounts, listings, and related contractual matters. This Privacy Policy should be read together with those Terms of Service.
2. Information We Collect
2.1 Public Visitors
Most visitors do not need an account, login, or other registration to browse the public directory.
For ordinary public visitors, we may have the following information:
- IP address;
- browser type;
- device type;
- operating system;
- referring page;
- request timestamps; and
- similar standard network and technical log information recorded through Cloudflare.
Cloudflare provides hosting, content delivery, network security, and tunnel services for the website. Technical log information is used for purposes such as security, abuse prevention, troubleshooting, and service performance.
The website also allows a visitor to choose a light or dark theme. That preference is stored in the visitor’s own browser using local storage. The theme preference is not transmitted to us and is not used to identify the visitor.
If a visitor emails us, we receive:
- the visitor’s email address;
- the contents of the message; and
- any information the visitor voluntarily includes.
We do not currently use analytics, advertising systems, cross-site tracking, retargeting pixels, or behavioral advertising technologies on the website.
2.2 Vendor Applicants
When someone applies or signs up to become a listed vendor, we collect information submitted through the signup process, including:
- business name;
- city;
- state;
- website, if provided;
- phone number, if provided;
- business contact email address;
- owner’s name;
- owner’s email address;
- password, if the applicant chooses to create one;
- selected subscription plan;
- selected event, where applicable to a single-show plan; and
- IP address used during signup.
Passwords are not stored in readable form. They are stored only as cryptographic hashes.
IP addresses associated with signup may be used for rate limiting, security, and abuse prevention.
Payment information is handled as described separately in Section 3.
2.3 Vendors With an Account
For vendors with an account, we may maintain all of the information described in Section 2.2, together with additional account information.
This may include:
- hashed session tokens;
- hashed single-use sign-in link tokens;
- token expiration times;
- an essential HTTP-only session cookie stored in the vendor’s browser;
- last sign-in time;
- email verification time;
- vendor listing content;
- uploaded logos, banners, gallery photographs, menu images, and other listing images;
- an append-only account audit log;
- rate-limiting records associated with email addresses and IP addresses; and
- subscription and payment records described in Section 3.
Single-use sign-in links expire after 15 minutes.
The account audit log records information such as:
- who performed an action;
- what was changed; and
- before-and-after values associated with the change.
The audit log is append-only. Existing audit records are not updated or deleted.
Vendor-uploaded images are stored and served using Cloudflare Images.
3. Payment Information
Vendor payments are processed through Stripe.
Payment card and bank information is entered directly into Stripe’s hosted checkout or billing interfaces.
Our website:
- does not display its own payment card entry field;
- does not receive card or bank account numbers;
- does not transmit card or bank account numbers; and
- does not store card or bank account numbers.
Stripe receives and processes payment information directly under Stripe’s own privacy practices.
We receive and store information needed to associate Stripe transactions and subscriptions with vendor accounts. This may include:
- a Stripe customer identifier;
- a Stripe subscription identifier;
- payment amount;
- currency;
- payment status;
- payment method type, such as “card” or “check”; and
- payment date.
Stripe also provides the hosted billing portal through which vendors may manage or cancel their subscriptions.
Stripe may send its own transaction or payment-related communications, such as payment receipts, according to Stripe’s services and policies.
4. Vendor Listing Content Is Public by Design
Vendor listings are intended to be publicly available on the internet.
Depending on what a vendor chooses to publish, publicly available listing information may include:
- business name;
- business description;
- logo;
- banner;
- gallery images;
- menu images;
- categories;
- tags;
- social media links;
- shows or events the vendor attends;
- published offers;
- promotional codes; and
- business contact information.
This information should not be treated as private or confidential.
When a vendor makes changes to published listing information through the vendor account, those changes may be published to the website immediately.
Public listing pages may be indexed by search engines. Search engines, archives, social media platforms, other websites, and other third parties may cache, copy, republish, or retain information after it has appeared publicly.
We cannot control copies retained independently by third parties.
Deleting information from our website therefore does not necessarily remove copies that have already been indexed, cached, downloaded, or copied elsewhere.
4.1 Account Information Is Different
Public listing information should not be confused with private account information.
Information such as the following is not intentionally published as part of a vendor’s public listing:
- owner’s private account email information;
- authentication credentials and tokens;
- session information;
- internal account activity records; and
- internal payment and subscription records.
5. How We Use Information
We use information according to the type of interaction involved.
5.1 Operating the Public Website
Technical information may be used to:
- deliver the website;
- protect the website and infrastructure;
- detect or limit abuse;
- enforce rate limits;
- troubleshoot errors;
- maintain network security; and
- support website performance.
5.2 Processing Vendor Applications
Vendor application information may be used to:
- create a vendor record;
- establish an account;
- associate a vendor with the selected subscription plan or event;
- prevent automated or abusive signup activity;
- communicate in connection with account access; and
- prepare the vendor’s directory listing.
5.3 Operating Vendor Accounts
Account information may be used to:
- authenticate vendors;
- send single-use sign-in links;
- maintain account sessions;
- verify email addresses;
- permit vendors to manage their listings;
- record account changes;
- provide security and fraud-prevention controls; and
- maintain records associated with vendor accounts.
The service currently sends account sign-in links. This Policy does not represent that we send newsletters or marketing emails.
5.4 Processing Subscriptions
Stripe-related information may be used to:
- associate payments with vendor accounts;
- identify subscription status;
- administer vendor plans;
- maintain financial records; and
- satisfy legal, accounting, and tax obligations.
5.5 Responding to Communications
If someone contacts us by email, we may use the information in that communication to review and respond to the request and maintain records associated with the communication.
6. Cookies and Local Storage
6.1 Vendor Session Cookie
When a vendor signs in, the service uses an essential HTTP-only session cookie.
This cookie is necessary to maintain an authenticated vendor session. It is not used for advertising or cross-site behavioral tracking.
Vendor sessions expire 14 days after sign-in.
Sessions do not automatically renew. A vendor must sign in again after the session expires.
6.2 Theme Preference
The website may store a light or dark theme preference using browser local storage.
That preference remains in the visitor’s browser. It is not transmitted to us and is not used to identify the visitor.
6.3 Cloudflare Security Cookies
Cloudflare may use cookies or similar technologies that are necessary to provide network security, protect the website from abuse, and operate its infrastructure.
6.4 No Analytics or Advertising Cookies
We do not currently use analytics cookies, advertising cookies, retargeting cookies, or cross-site behavioral tracking cookies.
Cloudflare analytics capabilities and Google Tag Manager are not currently used for website analytics or tracking.
If we introduce analytics, advertising technology, or a new category of tracking in the future, this Privacy Policy must be updated before that technology is enabled as described in Section 14.
7. Third-Party Services
We rely on a limited number of third-party providers to operate the service.
7.1 Stripe
Stripe provides:
- hosted checkout;
- payment processing;
- subscription processing; and
- the hosted billing portal used to manage or cancel subscriptions.
Stripe receives payment information directly and handles that information under its own privacy policy and practices.
7.2 Cloudflare
Cloudflare provides services including:
- hosting and infrastructure support;
- content delivery;
- network security;
- the tunnel used to serve the website;
- Cloudflare Images for storage and delivery of vendor-uploaded images; and
- Cloudflare Email Routing for the contact email address.
Cloudflare may process technical network information as necessary to provide those services.
7.3 Google
Google services are used for email delivery.
Outbound account-related emails, including sign-in links, are sent using Gmail’s SMTP service.
Inbound messages sent to our contact address are routed to and stored in a Google mailbox.
7.4 Vendor Websites and Social Media
Public vendor listings may contain links to vendor websites, social media accounts, or other external services.
Those websites and services are operated independently. Their collection and use of information are governed by their own privacy policies and practices, not this Privacy Policy.
8. How We Share Information
We do not sell or rent personal information.
We do not share personal information for cross-context behavioral advertising.
We may disclose information:
- to the service providers identified in Section 7 when necessary for them to provide services on our behalf;
- when required by law, court order, subpoena, or other valid legal process;
- when reasonably necessary to protect our rights, property, systems, users, or safety; or
- when reasonably necessary to investigate security issues, abuse, or suspected fraud.
Vendor listing information described in Section 4 is intentionally disclosed to the public because public publication is the purpose of the directory service.
Public listing information is different from non-public vendor account, authentication, and payment information.
9. Retention
We retain different types of information for different periods.
9.1 Sign-In Links
Single-use sign-in link tokens expire after 15 minutes.
They are designed for one-time use.
9.2 Vendor Sessions
Authenticated vendor sessions expire 14 days after sign-in.
Sessions do not automatically renew.
9.3 Rate-Limiting Information
Rate-limiting information is short-lived and maintained in hourly windows.
9.4 Technical Logs
Technical logs maintained by Cloudflare or other infrastructure providers are retained according to those providers’ standard practices and any applicable account configuration.
9.5 Vendor Account and Listing Information
Vendor account and listing information is generally retained while the account exists.
Some information may continue to be retained after an account is closed or deleted when necessary for legal, tax, accounting, fraud-prevention, security, or similar legitimate recordkeeping purposes.
9.6 Audit Log
The vendor account audit log is append-only and is not deleted.
A request to delete a vendor account may remove or de-identify applicable profile information and account details, but a tamper-evident record of account activity may remain for security, fraud-prevention, record integrity, and legal-compliance purposes.
We therefore do not promise complete erasure of every historical record associated with an account.
9.7 Uploaded Images
Deleting an uploaded image does not necessarily result in immediate removal of every copy.
An image is removed from underlying storage only when no other part of the listing continues to reference the same file.
Cloudflare or other content-delivery infrastructure may also temporarily retain cached copies after the underlying image has been removed.
Copies previously saved or cached by search engines or unrelated third parties are outside our control.
10. Security
We use technical and operational measures intended to protect account and personal information.
These measures include:
- HTTPS for network communications;
- cryptographic hashing of vendor passwords;
- cryptographic hashing of session tokens;
- cryptographic hashing of single-use sign-in tokens;
- HTTP-only session cookies;
- expiration of authentication credentials and sessions;
- rate limiting;
- account activity logging; and
- established infrastructure providers such as Cloudflare, Stripe, and Google.
No website, network, database, email account, or security system can be guaranteed to be completely secure.
10.1 Email Account Security Is Important
Vendors can access their accounts using single-use links delivered to their email address.
This means that a person who gains unauthorized access to a vendor’s email inbox may also be able to gain access to the vendor’s Florida First Premium Vendors account.
Vendors are responsible for taking reasonable steps to secure their email accounts, including the credentials and security controls provided by their email provider.
11. Privacy Rights and Requests
Depending on where a person lives and whether a particular privacy law applies, laws such as the California Consumer Privacy Act and privacy laws adopted by other U.S. states may provide certain rights concerning personal information.
We do not rely on a representation that every such law applies to our business.
Instead, we honor reasonable requests to exercise the rights described below regardless of whether a particular state privacy statute requires us to do so, subject to appropriate verification and legitimate retention requirements.
11.1 Access
You may ask us to provide information about personal information associated with you or your account.
11.2 Correction
You may ask us to correct inaccurate personal information.
Vendors can also view and correct most of their own account and listing information directly through their vendor account at any time.
This self-service ability is generally the fastest way to update vendor information.
11.3 Deletion
You may request deletion of applicable personal information.
Deletion is subject to the limitations described in this Policy.
In particular:
- the append-only audit log is retained;
- payment, subscription, tax, accounting, security, fraud-prevention, and legally required records may be retained;
- cached copies of images may temporarily remain;
- public information previously copied or indexed by unrelated third parties may remain outside our control; and
- an image may remain if another part of the vendor listing still references the same underlying file.
11.4 No Discrimination
We will not discriminate against a person because they submitted a privacy request or exercised a privacy right described in this Policy.
11.5 Verification
We may take reasonable steps to verify that a person making a privacy request is the person to whom the requested information relates or is otherwise authorized to act on that person’s behalf.
Privacy requests may be sent using the contact information in Section 15.
12. Children’s Privacy
The service is a general-audience business directory. It is not directed to children under 13.
We do not knowingly collect personal information from children under 13.
Vendor accounts are business accounts and must be established and managed by an adult.
Some vendors, products, services, or events listed in the directory may involve products or activities that are subject to age restrictions under applicable law. The presence of those listings does not mean that the account or directory service is intended for children.
If we learn that we have knowingly collected personal information from a child under 13 in circumstances where we should not have done so, we will take reasonable steps to address the information.
13. Do Not Track and Global Privacy Control
Some browsers and devices provide signals such as Do Not Track or Global Privacy Control.
At present, we do not use advertising tracking, cross-site behavioral tracking, retargeting pixels, or cross-context behavioral advertising.
We also do not sell personal information.
As a result, there is currently no advertising or cross-site tracking activity on the website for these signals to disable.
If our practices change in a way that makes such signals relevant, we will review how those signals should be handled and update this Privacy Policy as appropriate.
14. Changes to This Privacy Policy
We may update this Privacy Policy when the service, technology, legal requirements, or our information practices change.
The effective date and version number at the top of the Policy will identify the version currently in effect.
We will update this Privacy Policy before enabling analytics or introducing a new category of personal-information collection or tracking that is not described in the then-current Policy.
This includes enabling currently unused analytics capabilities such as Cloudflare analytics features or activating Google Tag Manager for tracking or analytics purposes.
Changes to this Privacy Policy do not replace or modify the separate Terms of Service except where expressly stated.
15. Contact and Privacy Requests
Questions or privacy requests may be sent to:
Florida First Premium Vendors
Operating as part of Next Level Shows
Privacy requests: [email protected]
General enquiries: [email protected]
When submitting a privacy request, please provide enough information for us to reasonably identify the relevant account or information.