Henry Street Advisors LLC ("we," "us," "our") operates henrystreetadvisors.com and the client portal at /clients/. This policy explains what we collect, how we use it, and how we protect it.

We wrote this ourselves, in plain language, because a privacy policy nobody can read is not much of a policy. If anything here is unclear, get in touch.

Information we collect

Information you provide

  • Contact form: your name, email, company, phone (optional), the situation you describe, and an optional revenue band. We store this for up to 90 days (so a delivery failure doesn't lose it) and email it to us; it is not used for anything beyond responding to you.
  • Client portal: if you are a client, we store your email address, display name, a hashed password (we never store your actual password — see Data security below), your role, which engagement your account belongs to, and basic account activity (created/updated/last-login timestamps).
  • Private engagement pages: some pages exist only for one specific client engagement, reachable by a unique, unpublished link rather than site navigation — for example, a document or content review page. If you submit anything through one of these pages, we store what you submit (such as your name and your decisions or comments) for as long as needed to support that engagement, using the same security practices described in this policy.

Information collected automatically

  • Analytics: we use Google Analytics to understand how visitors use the site (pages visited, session duration, device type, approximate location). See Google's own policy, linked below, for exactly what it collects.
  • IP address: Cloudflare, our hosting provider, processes IP addresses as part of standard web hosting.
  • Theme preference: whether you're viewing the site in light or dark mode is saved in your browser's local storage, not a cookie, and never leaves your device.
  • Cookies: see Cookies below.

How we use your information

  • Respond to your inquiry and, if you become a client, deliver the engagement
  • Send service-related communications
  • Monitor and improve the site
  • Prevent abuse and keep the portal secure

We do not sell your information. We do not use it for targeted advertising.

The client portal, and embedded LinkedIn content

The client portal shows each client their own content review data, and nothing else — a session is scoped to one engagement, checked on every request. Some engagement views embed a public LinkedIn post directly from linkedin.com, using LinkedIn's own official embed, so you can review it in place. That embed is only visible to the client it belongs to, never on the public site, and loading it is subject to LinkedIn's Privacy Policy, not ours.

Third-party services

Each of the following receives only the data necessary for its function:

  • Cloudflare (hosting, CDN, data storage): Privacy Policy
  • Google Analytics (site analytics): Privacy Policy
  • Resend (email delivery): Privacy Policy
  • Telegram (internal failure alerts only): if anything goes wrong while we're recording or emailing a form submission on this site (the contact form, or a private engagement page), we get an alert on our own Telegram so we can follow up — sometimes with the submitted details attached, sometimes just a notice that something needs attention. This does not happen on a normal, successful submission: Privacy Policy
  • LinkedIn (embedded content inside the client portal, described above): Privacy Policy

Cookies

  • Session cookie (__hsa_session): set only when you sign in to the client portal. Expires after 24 hours, is HttpOnly and Secure (no script can read it; it only travels over an encrypted connection), and is SameSite=Lax (not sent along with cross-site subrequests like forms or embeds on other sites, though it is sent when you click a direct link to the portal).
  • Google Analytics cookies: distinguish users and sessions. See Google's cookie policy.

We do not use advertising cookies or cross-site tracking cookies. We do not currently respond to Do-Not-Track browser signals.

Data security

  • All data is transmitted over HTTPS
  • Passwords are hashed with PBKDF2 (100,000 iterations, unique salts)
  • Authentication cookies are HttpOnly and Secure
  • Rate limiting is in place on the portal sign-in

No method of storage or transmission is 100% secure. We take reasonable measures; we can't guarantee absolute security.

Data retention

  • Contact form submissions: retained up to 90 days as a delivery-failure backup, then handled per the inquiry
  • Client portal accounts: retained until we delete the account
  • Analytics data: retained per Google Analytics' default settings

Your rights

You may request access to, correction of, or deletion of the personal information we hold about you, or opt out of any communications from us. Send the request through our contact form and we'll respond within 30 days.

Children's privacy

This site is for business professionals and isn't directed at anyone under 13. We don't knowingly collect information from children under 13; if we learn we have, we'll delete it.

Changes to this policy

We may update this policy as our practices change. The "Last updated" date above reflects the most recent revision.

Contact us

Questions about this policy, or about data we hold on you, go through our contact form. It reaches us directly.