Privacy

Privacy Notice

Effective August 26, 2026

This Privacy Notice explains how OpTheory (“OpTheory,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit tryoptheory.com or another OpTheory website that links to this Notice, submit an inquiry or application, communicate with us, or interact with our pre-engagement processes (collectively, the “Services”).

Information handled during a paid consulting engagement may also be governed by the applicable Master Services Agreement or Consulting Agreement, Statement of Work, and related client instructions. If those documents impose stricter requirements for engagement information, those stricter requirements control.

1. Information we collect

Information you provide

We may collect information that you voluntarily provide, including:

  • contact information, such as your name, email address, telephone number, location, and preferred contact method;
  • professional and business information, such as your role, business name, website, business stage, industry, team size, products or services, and operating goals;
  • application, qualification, and intake information concerning your business model, customer journey, systems, workflows, technology, data practices, vendors, challenges, priorities, timing, budget readiness, and desired scope;
  • communications and records of correspondence, meetings, feedback, and support requests;
  • proposal, contract, billing, and transaction-related information, although payment-card or bank-account details are generally processed directly by payment providers rather than stored by OpTheory; and
  • documents, links, or other materials you choose to provide through an approved client workflow.

Information collected automatically

When you visit the Site, we and our hosting or security providers may automatically receive technical information such as your Internet Protocol address, browser type, device type, operating system, referring page, pages requested, timestamps, approximate location derived from an IP address, and security or diagnostic logs.

Information from third parties

We may receive information from service providers you use to interact with us, referral sources, publicly available business sources, and organizations or representatives authorized to communicate with us on your behalf.

2. How we use information

We may use personal information to:

  • operate, maintain, secure, troubleshoot, and improve the Site and our business operations;
  • respond to inquiries and evaluate whether a prospective engagement is a fit;
  • conduct qualification, scope potential work, prepare proposals, and administer onboarding;
  • communicate about applications, meetings, agreements, payments, services, and requested information;
  • provide and manage contracted consulting services;
  • maintain business, contractual, financial, security, and compliance records;
  • detect, investigate, and prevent fraud, abuse, security incidents, and unlawful activity;
  • protect our rights, systems, users, clients, and third parties;
  • comply with law, legal process, and enforceable governmental requests; and
  • create aggregated or de-identified information that does not reasonably identify an individual.

3. How we disclose information

We may disclose personal information in the following circumstances:

  • Service providers. To providers that support hosting, security, forms, email, file storage, scheduling, videoconferencing, electronic signatures, invoicing, payment processing, analytics, and other business functions.
  • Professional advisers. To attorneys, accountants, insurers, auditors, or other advisers when reasonably necessary.
  • Legal and safety purposes. When reasonably necessary to comply with law or legal process; protect rights, safety, property, or security; investigate fraud or abuse; or enforce agreements.
  • Business transactions. In connection with a financing, reorganization, merger, acquisition, sale, transfer, or similar transaction involving all or part of the business, subject to appropriate confidentiality protections where applicable.
  • At your direction or with your consent. When you request, authorize, or consent to a disclosure.

OpTheory does not sell personal information for money. OpTheory does not use or disclose personal information for cross-context behavioral advertising or targeted advertising. If those practices change, we will update this Notice and provide any choices required by law before beginning them.

4. Google Forms and other third-party services

OpTheory currently uses Google Forms and related Google services for qualification and intake workflows. When you use a Google-hosted form, Google may process technical and account-related information under its own privacy terms. Your responses are also made available to OpTheory for the purposes described in this Notice.

The Site is hosted through Cloudflare, which may process network, device, security, and request information to deliver and protect the Site. Other third-party tools used for scheduling, meetings, signatures, payments, or file exchange process information under their own privacy notices and contractual terms.

5. Cookies, analytics, and similar technologies

Our hosting and security providers may use cookies, logs, or similar technologies that are necessary to deliver, secure, and diagnose the Site. OpTheory does not currently use advertising cookies or targeted-advertising trackers on the Site.

If OpTheory adds nonessential analytics or advertising technologies, this Notice and any required consent mechanism will be updated before or when those technologies are activated.

6. Sensitive information and credentials

Do not submit passwords, API keys, authentication codes, banking credentials, government identification numbers, medical information, or other highly sensitive information through public forms or ordinary email. If system access or sensitive materials are needed for an engagement, OpTheory will establish a separate method appropriate to the circumstances.

7. Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Notice, including evaluating and administering potential or active engagements, maintaining business and contractual records, resolving disputes, enforcing agreements, meeting legal obligations, and protecting against fraud or security threats. Retention periods vary based on the type of information, the relationship, legal requirements, and operational need.

We may retain aggregated or de-identified information that does not reasonably identify an individual.

8. Data security

We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. No transmission or storage system is completely secure, and we cannot guarantee absolute security.

9. Your choices and privacy requests

You may request access to, correction of, or deletion of personal information that OpTheory maintains about you. You may also ask us to stop particular communications or object to certain processing. Depending on your location and applicable law, you may have additional rights, including rights relating to portability, consent, targeted advertising, sale of personal information, or profiling.

To submit a request, email optheoryconsulting@gmail.com with the subject line “Privacy Request.” We may need to verify your identity and authority before completing a request. We may deny or limit a request where permitted by law, including when information must be retained for legal, security, contractual, or recordkeeping purposes.

OpTheory will not discriminate against you for exercising a privacy right provided by applicable law. If applicable law provides a right to appeal a decision on your request, you may submit an appeal using the same email address with the subject line “Privacy Appeal.”

10. International visitors

OpTheory is based in the United States. If you access the Services from another country, your information may be transferred to, stored in, and processed in the United States and other locations where our service providers operate. Those locations may have data-protection laws different from the laws where you live.

11. Children’s privacy

The Services are intended for adults and business users and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can review and delete it as appropriate.

12. Third-party links

The Site may link to websites or services that OpTheory does not control. This Notice does not govern those third parties, and we encourage you to review their privacy notices before providing information.

13. Changes to this Notice

We may update this Notice periodically. The updated version will be posted on this page with a revised effective date. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent when required by law.

14. Contact

Questions or requests concerning this Notice or OpTheory’s privacy practices may be sent to optheoryconsulting@gmail.com.