1. Information We Collect
1.1 Information You Provide Directly
When you interact with our website, consultation forms, or client portal, we may collect the following categories of personal information.
- Contact Information: Full name, email address, phone number
- Business Information: Company name, job title, industry, company size
- Account Credentials: Information used to create and manage your client portal account (managed through Clerk authentication)
- Consultation Form Submissions: Project descriptions, service inquiries, and any details you voluntarily provide
- File Uploads: Documents, images, or other files you submit through our consultation forms or client portal
- Payment Information: Billing address and payment method details (processed securely by Stripe; we do not store full credit card numbers on our servers)
- Communications: Emails, messages, and other correspondence you send to us
- Job Applicant Information: When you apply for a role or internship through our careers page, we collect your name, contact details, location, work authorization and sponsorship needs, years of experience, availability, compensation expectations, how you heard about us, and the résumé, cover letter, and links you submit
1.2 Information Collected Automatically
When you visit our website, certain information is collected automatically through cookies and similar technologies.
- Device and Browser Information: IP address, browser type and version, operating system, device type
- Usage Data: Pages visited, time spent on pages, click patterns, referring URLs, and navigation paths
- Analytics Data: Aggregated behavioral data collected through Google Analytics 4 (GA4), including session duration, page views, bounce rate, and user demographics
- Authentication Data: Login timestamps, session tokens, and authentication events processed by Clerk
2. How We Use Your Information
We use the information we collect for the following purposes.
- Service Delivery: To provide, manage, and improve our consulting services
- Account Management: To create and maintain your client portal account, authenticate your identity, and manage access permissions
- Communication: To respond to inquiries, send project updates, deliver invoices, and provide service-related notifications via email (sent through Resend/Amazon SES)
- Payment Processing: To process payments, issue refunds, and manage billing through Stripe
- Analytics and Improvement: To analyze website usage patterns through Google Analytics 4, improve our website experience, and optimize our services
- Recruiting and Hiring: To evaluate job and internship applications, communicate with applicants about current and future roles, and manage our hiring process; we keep applicant information confidential and retain it only as long as needed for recruiting
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
- Security: To detect, prevent, and address fraud, unauthorized access, and other security issues
3. Third-Party Service Providers
We work with trusted third-party service providers who process personal information on our behalf. Each provider is contractually obligated to protect your data and use it only for the purposes we specify.
| Provider | Purpose | Data Processed |
|---|---|---|
| Clerk | Authentication & user management | Name, email, login credentials, session data |
| Stripe | Payment processing | Billing info, payment method, transaction history |
| Resend / Amazon SES | Email delivery | Email address, name, email content |
| Google Analytics (GA4) | Website analytics | IP address (anonymized), usage data, device info |
| Vercel | Application hosting & edge security for the portal | Request metadata, IP address, and any data submitted through the portal |
| TiDB Cloud | Database hosting | All portal records described in this policy, encrypted at rest |
| Cloudflare | DNS and edge delivery/security for the marketing site | Request metadata and IP address |
| Slack | Internal operational alerts | Summary notifications (e.g. that an application or inquiry was received) |
| Vercel Blob | Encrypted storage for discovery interview recordings | The video and audio you record during a discovery session |
| Anthropic | Website assistant, and the written summary of a discovery interview | Your questions to the assistant, and your interview captions. Anthropic does not train its models on data sent through its API |
| LinkedIn (Insight Tag & Conversions API) | Advertising measurement and retargeting | Pages visited, device and browser info, IP address, and a one-way hashed email address when you submit a quote request |
| Calendly | Scheduling consultations | Name, email, and the meeting details you enter when booking |
| Cloudflare Turnstile | Spam and bot protection on our forms | Browser signals and IP address used to confirm a submission comes from a person |
Links to each provider's privacy policy, Clerk, Stripe, Resend, Google, Vercel, Anthropic, TiDB/PingCAP, Cloudflare, Slack.
3a. Discovery Interview Recordings
If we invite you into a discovery session, you may record short video answers to a set of questions on your own time. We ask for your permission to record separately from the mutual NDA, because the NDA protects what you tell us and does not by itself authorize a recording.
- What is captured: your camera and microphone only. Your screen is never recorded.
- Captions: where your browser supports it, your answers are transcribed on your own device so we can send you a written summary. Browsers without that feature record video only.
- Storage: recordings are stored encrypted with Vercel. They are never published, never used for advertising, and never used to train any AI model.
- Access: limited to Malcolm J. Henry and, where a specialist is brought onto your engagement, that specialist. Everyone with access is bound by the mutual NDA.
- Deletion: recordings are deleted 6 months after your interview, and sooner on request through our support page.
- Optional: recording is entirely your choice. If you would rather not be recorded, tell us through our support page and we will arrange a normal call instead.
4. Cookies and Tracking Technologies
4.1 Types of Cookies We Use
- Essential Cookies: Required for the website and client portal to function properly, including authentication session cookies set by Clerk
- Analytics Cookies: Used by Google Analytics 4 to collect aggregated usage data and help us understand how visitors interact with our website
- Functional Cookies: Used to remember your preferences and settings across sessions
- Advertising Cookies: Set by the LinkedIn Insight Tag to measure our LinkedIn campaigns and show relevant ads to people who have visited our website. You can opt out in your LinkedIn ad settings
4.2 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies may prevent you from using certain features of our website, including the client portal. You may also opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.
5. Data Retention
We keep personal information only as long as we have a business or legal reason, then delete or minimize it. A daily automated process enforces the schedule below, and we log what it removes. Our internal Data Retention & Management Policy governs this program.
- Job Applicant Files: Résumés and cover-letter files are deleted 12 months after you apply
- Job Applications: The remaining application details are deleted 24 months after you apply
- Consultation and Contact Inquiries: Deleted 24 months after submission
- Quote Requests: Scoping answers, the banded estimate, and contact details from the quote survey are deleted 24 months after submission; any brief or deck you attach has its file bytes deleted after 12 months
- Discovery Interview Recordings: Deleted 6 months after your interview, or sooner on request
- Discovery Session Records: Interview transcripts, written summaries, and the NDA and recording-consent evidence are deleted 24 months after the session opens
- Newsletter Subscribers: Kept until you unsubscribe; unsubscribed addresses are kept on a suppression list so we do not email you again
- Client and Team Accounts and Documents: Kept for the duration of the relationship and as required for legal, tax, and audit purposes
- Payment and Financial Records: Kept up to 7 years for tax and accounting compliance (card numbers are held only by Stripe, never by us)
- Security and Operational Logs: Purged on a rolling 90-day basis once resolved or expired
- Website Analytics: Retained per Google Analytics' settings (default 14 months); proposal-view analytics are deleted after 12 months
- Network Specialist and Company Profiles: Account profiles and posted needs are kept for the duration of your network membership or relationship, and removed on an account-deletion request
- Engagement Verifications: Background checks are run by our provider (Gusto); we keep only the status and a provider reference, never the report contents, and only for the duration of the relationship
- Network Match Analytics: Match scores linking specialists to company needs are deleted 12 months after they are created
- Support Tickets: Deleted 24 months after the ticket is resolved or closed
- Engagement Requests: Declined requests are deleted 24 months after that decision; accepted requests are kept for the duration of the relationship
- Investor Bids: Bids we pass on are deleted 24 months after that decision; accepted bids are kept with the investment records
- Internal Action Items: Task records our team uses to track requests are deleted 90 days after they are resolved
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include the following.
- Encryption of data in transit using modern TLS, with HTTPS enforced everywhere and HTTP Strict Transport Security (HSTS)
- DNSSEC on our primary domain to protect against DNS spoofing, and a Content-Security-Policy on the portal to limit code execution
- Secure authentication and session management through Clerk, with two-factor authentication enforced on our hosting account
- Bot-abuse protection on public forms and per-IP rate limiting to deter automated attacks
- PCI-DSS compliant payment processing through Stripe; we never store full card numbers
- Encryption of data at rest at our database provider, and role-based access controls that limit client and applicant data to authorized administrators
- Automated deletion of data past its retention window, and a documented incident-response process
While we take reasonable precautions to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information.
- Access: Request a copy of the personal information we hold about you
- Correction: Request that we correct inaccurate or incomplete personal information
- Deletion: Request that we delete your personal information, subject to legal retention requirements
- Portability: Request a copy of your data in a structured, machine-readable format
- Opt-Out of Marketing: Unsubscribe from marketing emails at any time using the link provided in each email
- Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time
To exercise any of these rights, submit a request through our support page under the Security or privacy category (or use the contact information in Section 11 below). We verify your identity and aim to respond within the timeframe required by applicable law. We honor deletion requests unless a legal obligation, such as tax recordkeeping, requires us to retain specific information.
8. State-Specific Privacy Rights
8.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete your information, the right to opt out of the "sale" or "sharing" of personal information, and the right to non-discrimination for exercising your rights. We do not sell your personal information.
8.2 Georgia Residents
As a business based in Atlanta, Georgia, we comply with all applicable Georgia state privacy regulations. While Georgia does not currently have a comprehensive consumer privacy law equivalent to the CCPA, we extend the same rights and protections described in this policy to all users regardless of location.
8.3 Other U.S. State Privacy Laws
We are committed to complying with applicable state privacy laws, including those in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states with consumer privacy legislation. If you are a resident of a state with specific privacy rights, please contact us to exercise those rights.
9. Children's Privacy
Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately so we can delete that information.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you via email or through a notice on our website.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us.
Malcolm Jermaine Henry Consulting, LLC
Atlanta, Georgia
Support malcolmjhenry.com/support
Website malcolmjhenry.com