Effective date: August 1, 2026. This policy supersedes the version dated January 1, 2026.
1. Who we are
Hinson Consulting Group, LLC (“HCG,” “we,” “us”) is a business systems and digital experience consultancy based in Richmond, Virginia, United States. HCG designs and implements connected business systems spanning strategy, websites, AI visibility, workflow automation, data architecture, CRM, reporting, client portals, custom applications, and governed AI, including the CREVOX capability ecosystem.
For privacy questions or requests, contact hello@hinsonconsultinggroup.com.
2. What this policy covers
This policy describes how HCG collects, uses, shares, and protects personal information through:
- this website (hinsonconsultinggroup.com) and its forms, assessments, and APIs;
- client-facing applications, portals, and dashboards that HCG builds or operates for clients;
- integrations HCG configures between client systems and third-party platforms, including Intuit QuickBooks, CRM platforms, e-commerce systems, and data services; and
- business communications with prospects, clients, and vendors.
Where HCG processes data inside a client’s systems as part of a consulting engagement, HCG acts as a service provider or processor on the client’s behalf: the client’s own privacy policy and the engagement agreement govern that data, client-owned data remains the property of the client or applicable data owner, and this policy applies only to what HCG itself controls.
3. Information we collect
Information you provide
- Contact and assessment forms: name, business email, company or organization, the need you select, your description of the business problem, the systems involved, and timing. If you complete the readiness assessment or FAQ pathway before submitting, your answers accompany the submission.
- Business communications: information you share by email or in meetings, proposals, and engagement work.
Information collected automatically
- Server logs: IP address, browser type, requested pages, referring page, and timestamps, retained for security, capacity, and diagnostics.
- Session data: a session cookie used solely to protect form submissions against forgery (CSRF), and a browser session flag that prevents the homepage entrance animation from repeating. Neither is used for tracking.
This website does not run third-party analytics, advertising pixels, social-media trackers, or cross-site tracking of any kind.
Information from integrations you authorize
When an engagement involves connecting a platform you control — for example Intuit QuickBooks, a CRM, or an e-commerce system — HCG accesses only the data scopes you or your organization authorize, through the platform’s official authorization flow (such as OAuth). See Section 7.
4. How we use information
- Responding to inquiries and assessment requests, and recommending a starting path;
- delivering, configuring, securing, and supporting consulting engagements, applications, portals, and integrations;
- operating, securing, and improving this website;
- sending administrative or service communications you request;
- meeting legal, tax, accounting, and contractual obligations; and
- establishing, exercising, or defending legal claims.
HCG does not sell personal information, does not share personal information with third parties for their own marketing, and does not use personal information for cross-context behavioral advertising.
5. Cookies and similar technologies
This website uses one strictly necessary session cookie (CSRF protection on the contact form, HttpOnly, SameSite=Lax) and one sessionStorage flag (entrance-animation control). No consent banner is displayed because no optional, analytical, or advertising cookies exist to consent to. Because we do not sell or share personal information for targeted advertising, browser opt-out preference signals such as Global Privacy Control do not change how this site treats your data — there is nothing to opt out of; we honor the spirit of such signals by default.
6. AI systems and automated processing
HCG uses AI systems in its own operations and builds governed AI capabilities for clients. Our commitments:
- Disclosure: where an HCG-operated experience has you interacting directly with an AI system (for example a chatbot or AI assistant), that will be clearly disclosed at the start of the interaction, consistent with the EU AI Act’s transparency obligations (Article 50, applicable from August 2, 2026) and the Colorado Artificial Intelligence Act’s disclosure requirements (effective January 1, 2027). This website currently contains no such conversational AI features.
- Human accountability: AI-supported work product is subject to human review, client approval, and professional judgment. HCG does not use AI to make consequential decisions about individuals — such as employment, credit, housing, or insurance decisions — without human review.
- No training on your data: HCG does not use client data, lead submissions, or connected-platform data to train public AI models, and does not permit its AI vendors to do so, unless expressly authorized in writing by the data owner.
- Governed configurations: AI capabilities HCG builds (including CREVOX capabilities) are designed around approved sources of truth, defined data boundaries, validation, logging, and human decision gates.
7. Intuit QuickBooks and other connected-platform data
Some HCG engagements and custom applications connect to Intuit QuickBooks or similar platforms holding financial and business records. For any such connection:
- access occurs only after you or your organization authorizes it through the platform’s official authorization flow, and only for the scopes required by the agreed work;
- data retrieved from the platform is used solely to deliver the agreed services — such as integration, automation, migration, reconciliation, or reporting — and never for HCG’s own marketing, resale, profiling, or model training;
- HCG maintains data-handling standards at least as restrictive as Intuit’s own privacy statement, as Intuit’s developer terms require;
- credentials and tokens are stored using platform-approved methods, are never placed in source control, and are revocable by you at any time from the platform’s own connection settings; and
- when an engagement ends or you disconnect the app, HCG deletes or returns platform data in its possession, except where retention is required by law or the engagement agreement.
8. When we share information
HCG shares personal information only with:
- Infrastructure and service providers acting on our instructions — website hosting, transactional email delivery (currently Mailgun, for sending form-submission notifications), and professional services such as accounting or legal counsel;
- parties you direct us to work with, such as your own team or vendors within an engagement;
- authorities or litigants where legally required, in response to lawful process, or to protect rights, safety, or the integrity of our services; and
- a successor entity in a merger, acquisition, or asset sale, subject to this policy’s commitments.
9. Data retention
Form submissions are retained while relevant to evaluating or serving the inquiry and for reasonable business-record periods afterward. Server logs are retained on a rolling basis for security and diagnostics. Engagement records are retained per the engagement agreement and legal requirements. When retention ends, data is deleted or de-identified.
10. Security
HCG applies access controls, authentication, permission management, encrypted transport (HTTPS), secure hosting practices, secrets management, monitoring, logging, backups, timely system updates, and administrative review. No method of transmission or storage is perfectly secure; if a breach affecting your personal information occurs, HCG will notify affected parties and regulators as applicable law requires. Please do not submit passwords, credentials, protected health information, or regulated personal data through the website contact form.
11. Your privacy rights
Depending on where you live, you may have statutory rights over your personal information — including under the comprehensive privacy laws now in effect in twenty U.S. states (among them California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Indiana, Kentucky, and Rhode Island) and, for visitors from the EEA or UK, the GDPR and UK GDPR. HCG extends the following rights to everyone, regardless of residence:
- Access: confirm whether we process your personal information and receive a copy;
- Correction: correct inaccurate personal information;
- Deletion: request deletion of personal information we hold about you;
- Portability: receive your provided data in a portable format;
- Objection / restriction: object to or restrict processing where the law provides;
- Communication preferences: opt out of non-essential communications at any time via the unsubscribe link or by contacting us.
To exercise any right, email hello@hinsonconsultinggroup.com. We will verify the request using the information associated with your records, respond within the time required by applicable law (generally 45 days or less), and will not discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our decision; we will respond to appeals within the statutory period, and you may also contact your state attorney general or supervisory authority. We do not sell personal data or process it for targeted advertising, so no opt-out of sale/sharing is required.
12. Children
This website and HCG’s services are business-to-business and are not directed to children under 16. HCG does not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will delete it.
13. International visitors and data transfers
HCG operates from the United States, and information is processed on servers in the United States. If you access the website from outside the U.S., you understand your information will be transferred to and processed in the U.S. For EEA/UK individuals, HCG relies on your consent, contract performance, or legitimate interests as lawful bases, and applies appropriate safeguards with its service providers.
14. Regulatory change and updates to this policy
Privacy and AI law is changing quickly: additional U.S. state privacy laws and amendments take effect through 2026 and 2027, the Colorado AI Act’s disclosure regime becomes effective January 1, 2027, and EU AI Act obligations phase in through 2027. HCG reviews this policy against new requirements as they take effect and updates it as needed. Material changes will be reflected in a revised effective date at the top of this page; significant changes affecting active clients will be communicated directly. Continued use of the website after an update constitutes acceptance of the revised policy.
15. Contact
Hinson Consulting Group, LLC
Richmond, Virginia, United States
hello@hinsonconsultinggroup.com