Episode Show Notes
So here’s something that came up last week — a friend of mine who runs a licensed cultivation operation in the metro area asked me, point blank, what does CannaHubMN actually do with my information when I list my business there? And I realized I didn’t have a crisp answer.
That’s a fair question, and honestly it’s one more operators should be asking before they put their business information on any directory platform. The short answer is: the privacy policy is pretty transparent about it. But the details matter.
Right, and I think most people — myself included — scroll past the privacy policy like it’s a terms-of-service wall of text. But for a B2B platform serving licensed cannabis operators, there are some things in there that are actually worth understanding.
Completely agree. So let’s just walk through what’s actually in there, because it’s not that long and it covers some ground that’s relevant to how the platform works day to day.
Okay, so starting from the top — who is CannaHubMN, in terms of how they describe themselves in this policy?
They describe themselves as a business-to-business directory platform. The emphasis is on licensed cannabis operators and industry professionals in Minnesota. So this isn’t a consumer-facing review site. It’s built for the trade — cultivators, manufacturers, retailers, that kind of operator.
Which matters for the privacy conversation, because the people interacting with the platform are mostly professionals, not random consumers browsing around.
Exactly. And the data they’re collecting reflects that. It’s not a platform that’s trying to build a consumer profile on you. The collection is pretty functional.
Okay, so walk me through what they actually collect. Because I think people assume it’s everything.
So the main categories are comments and user submissions, uploaded media, and then cookies. Let’s take those one at a time. When someone leaves a comment or submits content, they collect what you enter in the form — name, email, whatever — plus your IP address and your browser’s user agent string.
The user agent string — that’s the thing that tells the site what browser and operating system you’re using?
Right. It’s not personally identifying on its own, but combined with an IP address, it helps with spam detection. That’s explicitly why they collect it.
Okay, and then there’s something in there about Gravatar? I had to read that twice.
Yeah, so Gravatar is a service — it’s been around forever — where you associate a profile image with your email address. What the policy says is that if you provide an email, an anonymized version of that email — a hash — might get sent to Gravatar to check whether you have a profile image set up there. If you do, that image could appear next to your comment.
So it’s not sending your actual email address to Gravatar.
Correct. It’s a one-way hash. Gravatar can’t reverse it back to your email. But it’s worth knowing that interaction happens, and the policy points people to Gravatar’s own privacy practices if they want to dig into that.
I appreciate that they flag it at all, honestly. A lot of platforms just don’t mention it.
It’s a transparency point, yeah. Small detail, but it’s the kind of thing that builds trust with an operator audience that’s already navigating a lot of regulatory scrutiny in their day-to-day business.
Okay, the uploaded media section — this one actually surprised me a little. Tell me about that.
So this is about image files. If you upload a photo to the site — say, a photo of your facility or your product line — that image file might contain embedded metadata. And one of the things that can be embedded is GPS location data. It’s called EXIF data.
Oh, like when you take a photo on your phone and it automatically tags where you were.
Exactly. Most people don’t think about it, but your phone is often embedding precise coordinates into every photo. The policy flags that other visitors could potentially download those files and extract that location information.
Which for a cannabis operator — I mean, the location of a cultivation facility is not something you necessarily want embedded in a publicly downloadable image file.
Right, and the policy recommends stripping that data before you upload. Most phones and computers have ways to do that. It’s a practical heads-up that I think a lot of operators would genuinely not think about.
That’s actually really useful. I’m going to tell my friend about that specifically.
It’s one of those things where the privacy policy is doing some real work, not just covering legal bases.
Alright, let’s talk cookies. Because I feel like this is where people’s eyes glaze over, but there’s actually some nuance here.
There is. So they break it into four scenarios. The first is comment convenience — if you leave a comment and opt in, your name, email, and website URL get saved in a cookie for up to a year so you don’t have to retype them next time.
Standard stuff.
Very standard. Second is a browser compatibility check — when you hit the login page, a temporary cookie gets set just to confirm your browser accepts cookies at all. No personal data, gone when you close the browser.
Okay, and then login sessions — that’s where it gets a little more layered.
A little bit, yeah. So when you log in, cookies maintain your session and your display preferences. Standard login cookies last two days. If you check ‘Remember Me,’ that extends to two weeks. And then screen option cookies — things like how you’ve configured your dashboard view — those can persist up to a year. When you log out, all the login cookies get cleared.
Wait, so if I don’t log out — if I just close the tab — those session cookies are still sitting there for two days?
On that device, yes. Which is pretty normal for any web platform. It’s not unusual behavior, but it’s worth being aware of if you’re logging into a shared computer or something.
Fair point. And the fourth cookie scenario?
Article editing. If you publish or edit a listing, a short-lived cookie records the ID of the content you edited. No personal data in it, expires after one day. It’s basically just a housekeeping cookie so the platform knows what you were working on.
Okay, so none of these are particularly alarming. They’re all functional.
They are. What I’d flag is the embedded third-party content section, because that’s where things get a little less predictable.
Yeah, talk about that.
So if a page on CannaHubMN has embedded content — a video, a map, an article from an external source — that content behaves as if you visited that third-party site directly. Those third parties can set their own cookies, collect their own data, deploy tracking technologies. The policy is clear that CannaHubMN doesn’t control what those third parties do.
And if you’re already logged into, say, a Google account or a social media platform, those embedded pieces can see that.
Exactly. That’s the specific scenario the policy calls out — if you’re logged into an account on a third-party platform and you encounter their embedded content on CannaHubMN, that platform can track your interaction.
Which is honestly true of pretty much every website that embeds external content. But it’s good that they say it out loud.
It is. And for operators who are privacy-conscious — and in the cannabis industry, there are a lot of reasons to be — it’s useful to know.
Let’s talk about data sharing, because I think that’s the question people really want answered. Does CannaHubMN sell data?
The policy is direct: no. They do not sell personal data. Full stop.
Okay, but there are some limited sharing scenarios.
Two of them. One is the spam detection service — visitor comments may get routed through an automated spam filter, which is a third-party service. The other is password resets — if you request a password reset, your IP address gets included in that reset email as a security measure.
The IP address in the reset email — I’ve actually never thought about why that happens. What’s the logic?
It’s so you can see whether the reset request came from a device or location you recognize. If you get a password reset email and the IP address in it is from somewhere you’ve never been, that’s a signal that someone else requested it.
Oh, that’s actually a smart security feature. I just never connected the dots on why it was there.
Most people don’t. It looks like noise in the email but it’s doing real work.
Alright, data retention. How long does CannaHubMN hold onto your information?
So comments and their metadata — indefinitely. The reasoning they give is that it lets them process follow-up comments without holding everything in a moderation queue. Which makes operational sense, but it does mean that comment data doesn’t age out.
That’s the part where I’d push back a little — indefinitely is a long time.
It is. And I think for most users it’s not a practical concern, but it’s worth knowing. For registered users — people with actual accounts — the retention is tied to account activity. As long as your account is active, they keep your profile information.
And if you close your account?
That’s where the data rights section comes in. Registered users can request deletion of their personal data. They can also request an exported copy of everything the platform holds on them.
Which is your right under a lot of privacy frameworks now — the right to access and the right to erasure.
Right. The policy acknowledges those rights explicitly. The one carve-out is data they’re required to retain for administrative, legal, or security purposes — they can’t delete that even if you ask.
Which is standard. You can’t ask a platform to delete a record that’s tied to a legal obligation.
Correct. And the process for making a data request is to contact them through the site. They don’t have a separate form or portal called out — just the general contact information.
One thing I noticed — there’s a line about registered users being able to update their own profile information, but not their username. Why is that?
Usernames tend to be used as internal identifiers — they’re often tied to comment records, post history, that kind of thing. Changing them can create data integrity problems on the back end. It’s a pretty common restriction across platforms.
So pick your username carefully, basically.
Basically, yeah. If you’re setting up a business account for your operation, use something that represents the business, not something you’re going to want to change in six months.
Practical advice. Okay, the section on where data is processed — what does that actually mean for operators?
It means that data submitted through the platform — particularly comments — may be processed by third-party services, specifically for spam detection and security. Those services have their own privacy policies. The platform encourages users to review those, though it doesn’t name the specific services in the policy itself.
Which is a little vague, honestly. If I’m an operator and I want to know exactly which third-party services are touching my data, that section doesn’t fully answer it.
That’s a fair critique. The policy is transparent about the fact that third parties are involved, but it doesn’t enumerate them. For most operators that’s probably fine. For someone with very specific data sovereignty concerns, they might want to reach out directly to ask.
And the platform does have contact information available on the site for exactly that kind of question.
Right. The policy says as much — questions about the policy can be directed through the contact information on the site.
Last piece — policy updates. How does CannaHubMN handle changes to this policy?
The standard approach: they post the revised policy on the same page, and continued use of the platform after an update constitutes acceptance of the new terms. They don’t commit to proactive notification — like an email alert — when the policy changes.
Which means if you’re a registered user and you care about this stuff, you’d need to check back periodically on your own.
That’s the practical implication, yes. It’s not unusual for a platform of this size, but it does put the monitoring burden on the user.
I think the broader takeaway here — and this is something I’d say to any operator thinking about listing on a Minnesota cannabis directory — is that reading the privacy policy isn’t paranoia. It’s just due diligence.
Completely agree. And in this case, the policy is actually readable. It’s not buried in legalese. The sections are short, the language is plain. An operator can get through it in five minutes and have a clear picture of what’s happening with their data.
Which is more than you can say for a lot of platforms in a lot of industries.
True. And for an industry that’s operating under as much regulatory scrutiny as Minnesota cannabis right now, having a directory platform that’s upfront about its data practices is not a small thing. Operators are already managing compliance on multiple fronts. The last thing they need is a data surprise from a tool they’re using to grow their business.
And the fact that they’re not selling data — that’s the one I’d lead with if someone asked me to summarize the whole policy in one sentence.
That’s the right instinct. The platform collects what it needs to function, uses it for operational purposes, doesn’t monetize it through data sales, and gives registered users meaningful control over their own information. That’s a reasonable baseline.
And the EXIF data thing — I’m still thinking about that. I genuinely did not know that was a consideration when uploading images to a directory listing.
It’s one of those details that sounds technical but has real practical implications. Especially for operators who might be uploading photos of spaces or equipment that they’d prefer not to have geographically indexed by anyone who downloads the file.
Strip your metadata before you upload. That’s the actionable line from this whole conversation.
That and: know what your username is going to be before you register, because you’re not changing it later.
Related reading: Terms and Conditions · Minnesota cannabis business directory · get listed in our directory