Privacy Policy
Last updated: October 5, 2026
1. Introduction
Vertex Business Solutions ("VX," "Vertex Apps," "we," "us," or "our") operates ConsultBase (myconsultbase.com), a client portal and business management platform for independent consultants. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
It covers two groups of people: consultants and firms who hold a ConsultBase account ("you"), and the people our users work with — their clients and prospects — when they open a client portal or a shared proposal, book a meeting, pay an invoice, or sign a document through ConsultBase. Section 2.4 explains how we handle information about those clients.
By using ConsultBase, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password (stored only in hashed form), business name
- Profile Information: Business details, contact preferences, branding settings
- Client Data: Information about your clients that you choose to store (names, emails, engagement details) — see Section 2.4
- Financial Information: Invoice details and payment records. Payments are processed by Stripe; we never receive full card numbers
- Communications: Messages exchanged through the platform, support requests
- Connected Calendars and Meetings: If you connect Google Calendar or Microsoft Outlook, the events on those calendars; if you connect Zoom, what is needed to create and manage meeting links (see Sections 4.4 and 4.5)
- AI Requests: What you ask Ivy or another AI feature, and the records it needs to answer (see Section 4.1)
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken within the platform, and the page that referred you. We use PostHog for product analytics.
- Session Recordings:On our public website and inside the ConsultBase app, PostHog records how pages are used — clicks, scrolling, page changes, the text on the page, and technical errors — so we can see where people get stuck and fix problems. What you type into form fields is masked and not recorded. We do not record sessions on the pages your clients see (client portals, shared proposals, booking pages, and file links). Recordings are deleted after 30 days.
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP address, access times, referring URLs
Client portal, proposal, invitation, and file links work like keys. We remove the key from page addresses before they reach any analytics provider.
2.3 Free Tools (No Account Required)
We offer free tools that do not require an account, such as the Statement of Work generator at myconsultbase.com/tools/sow-generator. The document you create is generated entirely in your browser, and you can download it without giving us any information. To make these tools more useful, we may also collect:
- Draft content: If you choose to save your work to create an account, or ask us to email a copy to you, the content you entered into the tool (for example, the parties, scope, and terms of a statement of work) is stored as a draft so it can be carried into your new account or sent to you.
- Email address:Only if you provide it through an optional field (for example, the “email me a copy” option). It is never required to use the tool.
- Hashed IP address: We store a one-way cryptographic hash (SHA-256) of your IP address — not the address itself — solely to de-duplicate anonymous usage analytics for the tool. The hash cannot be reversed to recover your IP and is not used to identify you.
If you never create an account, a saved draft is automatically deleted after 180 days (see Section 5).
2.4 Information About Our Users' Clients
Consultants use ConsultBase to work with their own clients. If a consultant has invited you to a client portal, sent you a proposal or invoice, or shared a booking page or file with you through ConsultBase, we handle the following on that consultant's behalf:
- Contact and project details: What the consultant records about you, and what you send them — messages, files, and booking details.
- Signing records: When you sign a document, the name you type, the date and time, and your IP address, kept with the signed document as a record of how it was signed.
- Payment details: Payments go to the consultant through Stripe, and we never receive your full card number. If you save a card for future payments, we keep its brand, last four digits, and expiry date, plus a record of your authorization (time, IP address, and browser).
- Portal activity: When a portal was last opened and how many times it has been opened.
- Page views: Limited usage events with the access key removed from the page address. We do not record sessions on these pages.
The consultant decides what information to collect about you and how to use it, and their own privacy notice applies to that. To see, correct, or delete your information, contact the consultant directly — we will help them respond. If you cannot reach them, email us at support@myconsultbase.com.
2.5 Cookies and Similar Technologies
- Essential: Cookies set by our authentication provider (Supabase) keep you signed in, and Cloudflare Turnstile protects sign-up, sign-in, and password reset from bots. Sign-in does not work without them.
- Analytics: PostHog uses a first-party cookie and your browser's local storage to recognize a returning browser. On our public website only, Google Analytics sets its own cookies to measure visits. Ahrefs Web Analytics and Vercel Web Analytics count page views without cookies.
- Sign-up attribution: A first-party cookie (
cb_signup_ref) remembers for 30 days which website or campaign brought you to us, so we can tell which channels lead to sign-ups. - Settings: Your browser's local storage keeps small settings, such as choices you make in the app.
We do not use advertising cookies or advertising pixels (such as those from Meta or LinkedIn). You can block or delete cookies in your browser settings, but blocking essential cookies prevents sign-in. To opt out of Google Analytics, use Google's opt-out browser add-on.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve ConsultBase
- Provide the AI features you ask for, such as answers from Ivy, drafts, summaries, and clause reviews (see Section 4.1)
- Process transactions and send related information (invoices, receipts, payment confirmations)
- Send administrative messages, updates, and security alerts
- Respond to your comments, questions, and support requests
- Understand how ConsultBase is used and find and fix problems, including through analytics and session recordings (Section 2.2)
- Measure which websites and campaigns bring us visitors and sign-ups
- Detect, prevent, and address technical issues, abuse, and fraudulent activity
- Comply with legal obligations
We do not sell personal information, and we do not use your content or your clients' information for advertising.
4. Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
4.1 Service Providers
We use these companies to run ConsultBase. Each receives only what it needs to provide its service to us:
- Supabase: Database hosting, authentication, and file storage
- Vercel: Application hosting and Vercel Web Analytics (cookieless page counts)
- Stripe: Subscription billing, and payments from your clients through Stripe connected accounts
- Resend: Email delivery
- Anthropic:The AI model behind Ivy and ConsultBase's other AI features. When you use one, your request and the records needed to answer it — which can include information about your clients and your calendar — are sent to Anthropic to generate the response. Under Anthropic's commercial terms, this content is not used to train Anthropic's models, and it is kept only for a limited period (longer only where the law requires it or to enforce Anthropic's usage policies).
- PostHog: Product analytics, session recordings, and error tracking
- Google: Google Analytics on our public website, and Google Workspace for our own email
- Ahrefs: Cookieless analytics on our public website
- Cloudflare: Bot protection (Turnstile) on sign-up, sign-in, and password reset
4.2 Legal Requirements
We may disclose information if required by law, subpoena, or other legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.3 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your information.
4.4 Google API User Data
When you connect your Google account to ConsultBase (Settings → Calendar Integrations → Connect Google Calendar), ConsultBase requests OAuth access to the following Google APIs:
- Google Calendar events on your own calendar (read and write):to display your existing events in the ConsultBase Calendar view alongside ConsultBase-native bookings and engagement milestones; to add the events ConsultBase creates for you — bookings made through your public booking page, and meetings you schedule in ConsultBase, including Google Meet links — to your Google Calendar; and to update or remove those events when they are rescheduled or cancelled in ConsultBase (including when you ask Ivy to do it). ConsultBase works only with your primary calendar, not with calendars other people own or share with you.
- Google Calendar free/busy:to check when you're busy, so your public booking page doesn't offer times you're already committed. This returns busy time ranges only, not event details.
- Google account email and profile: to identify and display the connected Google account in your settings.
ConsultBase's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the features described above.
- We do not use Google user data for advertising or marketing.
- We do not transfer or sell Google user data to third parties, except as necessary to provide or improve user-facing features: storing event metadata in our database hosted by Supabase (bound by Data Processing Agreements limiting use to providing infrastructure services), and, when you ask Ivy about your schedule, sending the relevant event details (such as titles, times, and descriptions) to our AI provider, Anthropic, solely to generate Ivy's reply.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or machine learning models, and our AI provider does not use it to train its models.
- Humans (including ConsultBase staff) do not read your Google user data, except (a) with your explicit consent for specific support requests, (b) for security purposes (e.g., investigating suspected abuse), (c) to comply with applicable law, or (d) where data has been aggregated and anonymized for internal operations.
You can revoke ConsultBase's access to your Google account at any time via Settings → Calendar Integrations → Disconnect, or directly at https://myaccount.google.com/permissions. Disconnecting in Settings also removes the events ConsultBase imported from your Google Calendar; nothing in Google Calendar itself is deleted. If you revoke access from your Google Account instead, ConsultBase can no longer fetch new data, and events already imported stay in your ConsultBase account until you disconnect in Settings or delete them.
4.5 Integrations and Apps You Connect
Each of these starts only when you set it up, and you can disconnect it at any time in Settings:
- Microsoft Outlook calendar: to show your Outlook events in ConsultBase and add bookings to your Outlook calendar. Disconnecting removes the Outlook events ConsultBase imported.
- Zoom: to create and manage meeting links for your bookings.
- AI apps (Claude, ChatGPT, Cursor, and others) through our MCP connector:a connected app can read your ConsultBase data — clients, engagements, milestones, and invoices — and, with your confirmation, make the changes you ask for. That app's own terms and privacy policy apply to what it receives.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide you services.
Account Deletion: When you delete your account, your data is removed from our active database. For fraud prevention and chargeback protection purposes, we retain minimal account information (email, subscription history, account dates, and usage summary) for 180 days after deletion. This archived data is automatically purged after the retention period.
Client Data:When you delete a client, we permanently delete that client's record and everything attached to it — engagements, invoices, payments, proposals, messages, documents, milestones, and updates — from our active database. Calendar events, bookings, and time entries not attached to one of the client's engagements stay in your account, no longer linked to the client; you can delete them separately.
Free Tool Drafts: Drafts created with our free, no-account tools (see Section 2.3) that are never claimed by creating an account are automatically and permanently purged 180 days after creation. Once a draft is claimed into an account, it becomes part of your account data and follows the account retention terms above.
Analytics:Session recordings are deleted after 30 days. Other analytics data is kept under our analytics providers' retention settings.
Backups: Deleted information can remain in encrypted backups for a limited time, until those backups are replaced.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication with password hashing
- Row-level security policies for database access
- Regular security reviews and updates
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Client portal, proposal, invitation, and file links work like keys: anyone who has one can open what it points to. Share them only with the intended person. If one reaches the wrong person, contact us and we will replace it.
7. Your Rights and Choices
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Update or correct inaccurate information via your account settings
- Deletion: Delete your account and associated data through Settings → Delete Account
- Export: Request an export of your data
- Opt-out: Unsubscribe from marketing communications (transactional emails cannot be opted out)
To exercise these rights, contact us at support@myconsultbase.com.
If you are a client of a ConsultBase user, see Section 2.4. Depending on where you live, you may have additional rights under local law; contact us and we will respond as that law requires.
7.1 Do Not Track
Some browsers send a "Do Not Track" signal. There is no common standard for responding to it, so ConsultBase does not change what it collects when it receives one. We do not use advertising cookies or pixels. Google Analytics on our public website may collect information about your visits over time, and Google may combine it with information from other websites that use its services, under Google's own privacy policy; you can opt out as described in Section 2.5.
8. Children's Privacy
ConsultBase is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@myconsultbase.com.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. Our service providers operate globally, and by using ConsultBase, you consent to the transfer of your information to facilities in the United States and other countries.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of ConsultBase after changes constitutes acceptance of the updated policy.
For material changes, we will also make reasonable efforts to tell account holders by email or in the app.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: support@myconsultbase.com
This Privacy Policy is effective as of December 13, 2025 and was last updated on September 30, 2026.