Privacy Policy

Last updated July 1, 2026

This Privacy Policy explains how ConsultingOS (“we,” “us”) collects, uses, shares, and protects information when you use the Service. When our business customers use ConsultingOS to manage their own members, we act as a processor on their behalf, and their privacy practices govern that data.

1. Information we collect

Account information

When staff accounts are created, we collect names, email addresses, roles, and a securely hashed password. We record sign-in activity such as last login time.

Customer Data you provide

Our business customers enter or import data about their members and operations — for example member names, emails, program tiers, membership status, billing arrangements, notes, engagement events, products, and payment plans. This is entered by the customer and processed on their behalf.

Payment and billing data

When a customer connects their own Stripe account, we synchronize billing metadata such as transaction amounts, statuses, and subscription state. Full payment card numbers are handled by Stripe and are never stored by us.

Lead / opt-in data

If you submit a form on our website (for example, the website-optimization opt-in), we collect the details you provide, such as name, email, phone, business name, and website URL.

Usage and cookies

We use a single, essential session cookie to keep you signed in. It is set to be secure, HTTP-only, and same-site. We do not use third-party advertising or cross-site tracking cookies.

2. How we use information

  • To provide, operate, secure, and improve the Service.
  • To authenticate users and protect against fraud and abuse (including rate-limiting sign-in attempts).
  • To synchronize and reconcile billing data from connected services like Stripe.
  • To generate reports and, where enabled, AI-assisted suggestions.
  • To communicate with you about the Service, including password resets and important notices.
  • To comply with legal obligations and enforce our Terms.

3. How we share information

We do not sell personal information. We share information only as needed to run the Service:

  • Service providers (sub-processors) that host and power the Service — for example Vercel (hosting), Neon (database), Stripe (payments), GoHighLevel (CRM, if you connect it), Anthropic (AI features, if used), and Resend (transactional email, if enabled).
  • Business customers: member data is accessible to the customer organization that owns it and its authorized staff.
  • Legal and safety: when required by law, or to protect the rights, property, or safety of users and the public.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

4. Security

We take security seriously and apply industry-standard safeguards, including:

  • Encryption in transit (HTTPS/TLS) and encryption at rest for sensitive stored secrets such as connected Stripe and GoHighLevel keys.
  • Passwords stored using a strong one-way hashing algorithm (scrypt) — never in plain text.
  • Signed, HTTP-only session cookies and verification of payment webhooks.
  • Access controls that limit staff to only the sections their role permits.

No method of transmission or storage is 100% secure, but we work to protect your information.

5. Data retention

We retain information for as long as needed to provide the Service and for legitimate business or legal purposes. Business customers control the retention and deletion of their members’ data within the Service. On account termination, we may delete or de-identify data after a reasonable period, subject to legal requirements.

6. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. If your data was provided to us by a business customer, please direct your request to that business; we will assist them as their processor. Otherwise, contact us at tom@tomleonardis.com.

7. Children’s privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

8. International users

We operate in the United States, and information may be processed there. If you access the Service from outside the U.S., you understand your information may be transferred to and processed in the U.S.

9. Changes to this Policy

We may update this Policy from time to time. We will update the “last updated” date above and, for material changes, provide additional notice where appropriate.

10. Contact

Questions about this Policy or your data? Contact us at tom@tomleonardis.com.