Privacy / effective October 10, 2026
What does Bothell Lodge keep?
This privacy notice covers the Sons of Norway Bothell Lodge website, including its membership information, Norwegian cultural organization content, inquiry form and support chat. It is written for a person deciding whether to contact us, not for a data specialist. The site receives paid traffic from Google Ads, Microsoft Advertising and Meta Ads, so advertising identifiers and consent choices are part of this account.
Policy record
When did this notice take effect?
This notice took effect on October 10, 2026. It applies to the public website at bsofn.com and describes the information the site records through its present contact routes. It does not turn the website into a membership registration service. Registration continues at sofn.com.
Who is responsible?
Who operates this site?
The controller is Bsofn, trading at bsofn.com. The postal address is 23905 Bothell Everett Hwy, Bothell, Washington 98021, Bothell, Washington, United States. This is the local public contact for Sons of Norway Bothell Lodge in Bothell, Washington.
The site explains Sons of Norway membership in Bothell and points people to the external organization route. It does not collect a membership application, payment card or account password here.
What enters the system?
What do you keep?
An inquiry sent through the form contains the name, phone, email, address, kind of enquiry, message, requested specification and consent tick. The form also records the IP address, browser user-agent string, referring URL, the moment the form was rendered and the moment it was sent.
Support chat receives the conversation and optional name, phone, email and consent. A token is kept in the visitor’s browser so the conversation can be returned to. The browser stores the consent choice under site_consent_v2. Server and access logs contain technical request information. Advertising links can carry gclid, msclkid and fbclid. This site takes no account password, payment card or membership application.
Why is it used?
Why do you need it?
Name and contact details let the lodge reply to an inquiry. The message, kind and requested specification tell the operator what the question is about, without making a visitor repeat it. The address is handled when it is supplied in an inquiry and is not used to decide advertising eligibility.
Chat information keeps a support conversation coherent. IP address, user agent, referring URL and timestamps protect the service, diagnose delivery problems and show when a request was made. Consent records prove the choice that was made. Click identifiers help measure an ad visit. They do not create a promise of membership or any course result.
Why can this be done?
What is the legal basis for each use?
| Activity | Basis | What that means here |
|---|---|---|
| Replying to an inquiry | Consent and legitimate interest | You choose to send the form. Handling the request and keeping a reply route is a legitimate interest in operating the local contact service. |
| Support chat | Consent | The conversation is sent when you submit it and the consent line explains that it is handled to reply. |
| Security and logs | Legitimate interest | Limited technical records help protect the site and find faults. |
| Advertising measurement | Consent | Storage and the related consent signals remain denied until you allow storage. |
Which advertising traffic arrives?
What are click identifiers?
This live site receives traffic from Google Ads, Microsoft Advertising and Meta Ads. The source labels are google ads, microsoft advertising. Google Ads can attach gclid to a link, Microsoft Advertising can attach msclkid, and Meta Ads can attach fbclid where a campaign runs there. These values can arrive in the URL and may be used to measure an ad visit. The site does not claim that any platform reviewed, approved or verified it.
What choice controls storage?
How does consent mode v2 work?
Consent mode v2 holds ad_storage, ad_user_data, ad_personalization and analytics_storage denied until the visitor allows storage. When the visitor declines or later withdraws permission, all four signals are set back to denied. Reading the site is not blocked while that choice remains denied.
The non-blocking banner offers Allow and Decline. The Cookie choices control in the footer opens the same decision route after the first choice.
Who can receive it?
Who else sees it?
Google Ireland Ltd / Google LLC receives Google Ads consent signals and can handle the gclid attached to a click. Microsoft Ireland Operations Ltd handles Microsoft Advertising traffic and the msclkid; its privacy statement is at privacy.microsoft.com. Meta Platforms Ireland Ltd can handle Meta Ads traffic and fbclid where a campaign runs there.
The hosting provider serves this site and stores the inquiry database. The mail provider carries an inquiry notification to the operator’s inbox. Those service providers receive only what their service needs to perform that role.
Where can information travel?
Can data leave the United States?
Advertising, hosting and mail providers may process information outside the country where a visitor collected it, including through their own international systems. Where a transfer occurs, it is made under the provider’s applicable contractual safeguards, recognized transfer mechanism or other lawful protection. The operator does not promise that every provider stores information in one country.
How long is it kept?
When is information removed?
Enquiries and their email copies are kept for 36 months. Chat transcripts are kept for 12 months. Server and access logs are kept for 60 days. A record of a consent choice is kept for 12 months. These are the operating periods for the records described here; a legal hold or a necessary security investigation can require a record to remain until that task ends.
How is it protected?
What keeps an inquiry safe?
The site uses HTTPS in transit, access controls around the inquiry store, server-side validation, hidden honeypot fields and limited staff access. The form does not ask for a password, payment card or sensitive membership eligibility information. No online system is risk-free, so a visitor should not put confidential material in a public inquiry message.
For visitors in Europe
Which GDPR rights can I use?
Where the GDPR applies, you may ask for access, rectification, erasure, restriction, portability, objection, or withdrawal of consent. You may also ask what processing is taking place and challenge a use based on legitimate interest. The request route is set out below. It does not require you to create an account.
For United States visitors
What does US privacy law allow?
US state privacy law applies, including California’s CCPA and CPRA and other state laws in force where they apply. California visitors can ask for access, correction or deletion and can opt out of the sale or sharing of personal information. This site does not sell information or take payment, but the opt-out route remains available.
A browser preference
Do you honor Global Privacy Control?
Yes. The site honors global privacy control, including the Sec-GPC header, as an opt-out without asking again. Advertising-related consent signals remain denied after that opt-out.
Age and audience
Is this site for children?
This site is not directed to children and does not knowingly take data from children. It describes adult-oriented membership information and cultural activities. If a parent or guardian believes a child sent information, contact [email protected] so the operator can review the request.
If something feels wrong
Where can I complain?
You may complain to your state Attorney General. A California visitor may also contact the California Privacy Protection Agency. A visitor in Europe may complain to the data protection authority in the country where they live, work or believe an infringement occurred.
Your request route
How do I get it deleted?
Send a data request to [email protected], or write to 23905 Bothell Everett Hwy, Bothell, Washington 98021, Bothell, Washington, United States. Say whether you want access, correction, deletion, restriction, portability, objection or withdrawal of consent. Include enough detail for the operator to find the record, but do not send a password or payment information.
The operator answers a data request within 7 days. A request may need reasonable identity checking before records are disclosed or removed.
Keeping this current
How will a change be announced?
A changed notice is published on this privacy page with a new effective date at the top. A material change is explained in the page copy. The effective date for this version is October 10, 2026.
Human contact and access
How can I reach a person or request accessibility help?
Email [email protected] or call 425-485-9085. You may also write to 23905 Bothell Everett Hwy, Bothell, Washington 98021. Tell us what page or control needs attention and what format or assistance would let you use it. Accessibility requests are handled through the same human route as privacy requests.