Privacy Policy

What we collect, why we have it, and what you can ask us to do with it.

Effective 10 August 2026

We are a small advisory firm, not an advertising business. We collect what we need to run engagements and to answer people who contact us, we use Google Analytics to see which pages get read, and we do not sell personal information.

Who we are

Future State Advisors, LLC (“Future State Advisors”, “we”, “us”) provides fractional technology leadership to growing companies. Our registered address is 5799 S. Main Street #1051, Clarkston, MI 48347. This policy covers this website, the client workspace you sign in to, and the personal information we handle in the course of an engagement.

If you have a question about anything here, write to privacy@futurestateadvisors.com and a person will answer.

Two different roles, and why it matters to you

We handle personal information in two capacities, and your rights differ depending on which one applies.

  • As a controller. For visitors to this site, people who contact us, and our own business records, we decide what is collected and why. This policy describes those decisions.
  • As a processor. For material inside a client workspace, the client company decides what goes in and what it is used for. We act on their instructions under the engagement agreement. If you are an employee of a client and want to know why your name appears on a risk register, your employer is the right first place to ask, though we will help.

What we collect

Information you give us. Your name, email address, company, and whatever you write in the contact form or a booking request. If you become a client, the names and email addresses of the people in your organisation who need access to the workspace.

Engagement material. What a client uploads or records during an engagement: contracts, invoices and spend exports, system inventories, policy documents, assessment answers, and the registers we build from them. This routinely contains the names and job titles of a client’s own staff and the names of their suppliers.

Billing information. If you pay by card, Stripe collects and holds the card details. We receive a record that a payment succeeded, not the card number.

Technical information. Our host records the usual server log data for security and reliability: IP address, browser type, the pages requested, and the time of the request. We also use Google Analytics, described in its own section below.

Sign-in logs are handled differently

Part of an assessment can involve reviewing an identity provider’s sign-in export. Those files are unusually sensitive: they show who logged in, from where, and when.

They are never uploaded. The file is read and aggregated inside the advisor’s browser, and only the derived figures leave the machine, such as how many accounts were never challenged for a second factor and how many sign-ins came from an unexpected country. A short fingerprint of the file is stored so we can tell one export from another. The raw log does not reach our servers or any of the companies listed below.

How we use it

  • To answer enquiries and arrange introductory calls.
  • To carry out the work a client has engaged us for, including producing assessments, registers, reviews, and reports.
  • To administer accounts and access to the workspace.
  • To invoice and collect fees.
  • To keep the service secure, diagnose faults, and prevent abuse.
  • To meet our legal, tax, and professional obligations.

We do not sell personal information for money, and we do not use client engagement material to market to anybody. Some state privacy laws define “sharing” broadly enough to cover analytics, which is why analytics here is off unless you switch it on, and switching it back off takes one click from any page.

Where AI may be used

Some engagements use AI assistance to draft analysis from assessment responses and from text extracted out of evidence documents. Whether it is used at all, and on what, is decided in the individual client agreement rather than by us unilaterally.

Where it is used, we work with commercial providers under terms that exclude the material from being used to train their models, and a person reviews and edits every analysis before it becomes a deliverable. Nothing goes to a model without an advisor starting it. If you would prefer that no part of your engagement involves AI assistance, say so and we will run it manually.

Google Analytics

We use Google Analytics to understand which pages of this site get read and how people arrive at them. It sets cookies that count visits and distinguish a returning visitor from a new one, and it collects your approximate location, device and browser type, and the pages you viewed.

We use it to write a better website, not to build a profile of you. We do not upload customer lists to it, and nothing inside a client workspace is measured by it.

It is off until you turn it on. The tag is not requested from Google, and no analytics cookie exists, unless you accept the banner shown on your first visit. If you accept and later change your mind, the Cookie settings link in the footer of any page forgets the answer and deletes the cookies. Declining costs you nothing: every part of this site and the workspace works the same either way. The cookie policy names the cookies involved.

Who else processes it

We keep the list of companies that process data on our behalf deliberately short. Each is bound by a data processing agreement, and none of them are advertising businesses.

Cloudflare, Inc.
What they do for usHosting, content delivery, and bot protection for this site and the client workspace.
What they seeIP addresses and request metadata in transit; page content at the edge.
WhereUnited States and global edge network
Supabase, Inc.
What they do for usDatabase, file storage, and authentication for the client workspace.
What they seeAccount records, engagement records, uploaded evidence, and documents we issue.
WhereUnited States
Stripe, Inc.
What they do for usPayment processing for the assessment fee and any retainer charged to a card.
What they seeBilling contact and payment details, which are collected by Stripe rather than by us.
WhereUnited States
Google LLC
What they do for usGoogle Analytics, which tells us which pages of this site people read.
What they seePage views, approximate location, device and browser type, and a randomly assigned visitor identifier.
WhereUnited States
AI model providers
What they do for usWhere an engagement uses AI assistance, a commercial model provider drafts analysis for an advisor to review.
What they seeAssessment responses and extracted document text, and only where the client agreement permits it.
WhereUnited States. The specific provider is named in the client agreement and available on request.
Cal.com, Inc.
What they do for usScheduling, if you book an intro call through the link on this site.
What they seeName, email, and anything you type into the booking form. Governed by Cal.com's own policy.
WhereUnited States

We will also disclose information where the law requires it, to our professional advisers under confidentiality, and to a buyer if the business is ever sold, in which case we would tell affected clients first.

International transfers

We are based in the United States and the providers above process data there. If you are in the UK or EEA, transfers rely on the Standard Contractual Clauses or an equivalent approved mechanism, together with the technical measures described below.

How long we keep it

  • Enquiries that do not become engagements: up to two years, then deleted.
  • Client workspaces: for the life of the engagement and for seven years afterwards, unless the client asks us to delete sooner, which we will do except where we are required to retain something.
  • Financial records: seven years, because tax law requires it.
  • Server logs: a rolling short retention window set by our host, measured in days, not years.

A client can ask for an export of everything in their workspace at any time, during or after an engagement.

How we protect it

  • Every workspace is isolated at the database level, so one client's records cannot be read from another client's session.
  • Access to client material is limited to the advisors working on that engagement.
  • Data is encrypted in transit and at rest by our infrastructure providers.
  • Card details never touch our systems; Stripe handles them.
  • Sign-in log files are processed in the browser and never uploaded, as described above.

No system is perfect. If we become aware of a breach affecting your personal information we will notify you and any regulator as the law requires, without undue delay.

Your rights

Depending on where you live you may have the right to ask us for a copy of your personal information, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent. If you are a California resident you also have the right to know what we collect and to opt out of sale or sharing, though we do neither.

Exercise any of these by writing to privacy@futurestateadvisors.com. We will not treat you differently for asking. We will respond within the time the applicable law allows, usually a month. If the request concerns material in a client workspace, we will refer it to that client, since it is their decision to make.

If you are unhappy with how we have handled a request, you can complain to your data protection authority.

Cookies

We use a small number of cookies: some are necessary to sign you in, some remember a preference you set, and the Google Analytics ones described above count visits. There is no advertising or retargeting on this site. The cookie policy lists every one by name.

Children

This is a service for businesses. It is not directed at children and we do not knowingly collect information from anyone under 16. If you believe we have, tell us and we will delete it.

Changes to this policy

We will update this page when our practices change and move the effective date at the top. If a change materially affects how we handle personal information, we will tell clients directly rather than relying on you noticing.

Contact

Future State Advisors, LLC, 5799 S. Main Street #1051, Clarkston, MI 48347. Privacy questions: privacy@futurestateadvisors.com. Anything else: hello@futurestateadvisors.com. This policy is governed by the laws of Michigan.