What we collect, and what we do with it.
We collect what the work needs and nothing for resale. There is no analytics on this site, no advertising, and no tracking of any kind. This page says what is actually held, by whom, and for how long.
Last updated
Who we are
This site is operated by Salto Strategic Advisors, LLC, a limited liability company formed in North Carolina. We are an advisory firm. We are not a software company, and there is no product here to subscribe to.
Two people run it, Nichole and Steve DiPippo, and the work is remote. There is no office to visit and no third party answering for us.
The short version
- This site runs no analytics, no advertising and no tracking. Loading any public page makes no request to any third party.
- One cookie exists, and only after a client signs in to the portal. It holds a signed session and nothing else.
- If you fill in the contact form we get your name, email, company and message, by email. Nothing is stored in a database.
- If you become a client, the documents you upload are deleted sixty days after delivery, and sooner on request (contract §§7.3, 7.5).
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
If you only read the site
Nothing is collected beyond what any web server writes down to serve a page: the request, the time, the address it came from, and the browser that asked. Our host keeps those logs to run the service and to stop abuse. We do not build a profile from them, and we cannot: there is no analytics on this site to join them to.
Fonts and images are served from this domain, not from a font or media network, so reading a page does not tell anyone else that you read it.
If you use the contact form
The form asks for your name, your email, your company (optional) and a message. It is delivered to our inbox as an email through our email provider, and your address is set as the reply-to so a reply comes from a person. It is not written to a database and it is not added to a mailing list. There is no mailing list.
We keep the enquiry in the inbox for as long as we would keep any business correspondence, and you can ask us to delete it.
The form has one hidden field that people never see and automated submitters fill in. If it is filled, we discard the message. It collects nothing about you.
If you become a client
This is where the real data is, and it is governed by the engagement agreement you sign rather than by this page. The agreement is the operative document; this section summarises it and does not change it.
What we hold:
- Your account: the name and email address you sign in with, and which client organisation you belong to.
- The documents you upload for the audit: books, owner statements, bookings, and whatever else the domain you bought needs. These are financial records and are treated as confidential information under §8.
- Your answers to the intake questions.
- The findings we produce, and our own analysis and working materials underneath them.
- Ordinary business records: the deal, the contract, invoices.
Where it lives: your documents and findings are held in a Google Shared Drive under our workspace; your account and the state of your engagement are in a Postgres database; the deal record is in our CRM. Each of those is named below.
How long we keep it
The windows below are the ones in the engagement agreement, not a policy invented for this page.
| What | How long | Clause |
|---|---|---|
| Your portal, and everything downloadable from it | Sixty days from the delivery date. We send a reminder before it closes. | §§7.1, 7.2 |
| The source documents you uploaded | Deleted at the end of those sixty days. Keep your own copies. | §7.3 |
| Earlier deletion, if you ask in writing | Within thirty days, except anything we are required to keep by law. | §7.5 |
| The findings, and our analysis and working materials | Kept after that date, so we can advise you later and measure against the baseline. Confidentiality still applies. | §§7.4, 8 |
| Confidentiality obligations | Three years from the delivery date, and indefinitely for anything that is a trade secret. | §8.4 |
| A contact-form enquiry | Held as ordinary correspondence. Ask and we delete it. | No clause; this page is the whole of it |
Who else touches it
We use other companies to run the service. Each one is listed because this application actually calls it, and each is bound to us by its own terms. We do not sell personal information to anyone, and none of these is an advertising network.
| Who | What for | What they see |
|---|---|---|
| Vercel | Hosting and delivery of this site | Server logs: request, time, IP address, browser |
| Neon | The portal database | Portal accounts and engagement state |
| Resend | Sending email: contact enquiries, sign-in links, portal notices | The sender, the recipient and the contents of that email |
| The Shared Drive your documents and findings are held in, and the tracking sheet | Client documents, intake answers and findings | |
| Zoho | Our CRM, holding the client and deal record | Client and contact details, engagement status |
| Our payment processor | The ACH bank debit for the fee (§3.3) | Payment details and the debit |
These companies are in the United States, and if you are writing to us from outside it your information will be processed there.
Automated processing and AI
We use software systems, including artificial-intelligence systems, to organise and analyse the materials a client provides. A client consents to that processing in the engagement agreement (§9.1).
Those systems support the work; they do not decide it. No findings go to a client without a Salto principal reading them, and the firm remains responsible for the findings under the agreement (§9.2). Nothing on this site makes an automated decision about you, and there is no profiling.
Whether we will name you
We may describe an engagement and what we found in our own materials in de-identified form, without naming the client and without figures specific enough to identify them (§10.1).
Naming a client, using their logo, quoting them, or citing their specific figures needs their separate written consent, given at the time (§10.2). A client can withdraw the de-identified permission at any time in writing, and we stop using the material going forward (§10.3).
What you can ask us to do
Whatever jurisdiction you are in, and whether or not the law where you live reaches a firm this size, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to send it somewhere else. Use the contact form or reply to any thread you have with us. We will not treat you differently for asking, and we do not charge for it.
We will acknowledge a request within ten business days and answer it within forty-five days. If it is genuinely complicated we may take up to forty-five more, and we will tell you that inside the first forty-five rather than go quiet. If we cannot do what you asked, we will say which part and why.
We may need to check you are who you say you are before we hand over or delete anything, which for a client usually means the email address on your engagement. You can use an authorised agent; we will ask for something showing you authorised them.
One limit, stated plainly: where you are a client, some of what we hold is our own work product and some we may be required to keep. Deleting your uploaded documents is straightforward and covered above. Unpicking a finding from our analysis is not, and we will tell you which is which rather than promise both.
If you are in California: we do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to offer. You have the rights to know, delete, correct, and to non-discrimination, and we handle a request the same way whoever asks. Because we operate entirely online and deal with you directly, an emailed request or one through the form is the method we offer.
If you are in the UK or the EEA: our basis for handling an enquiry is our legitimate interest in answering it, and for client work it is the performance of our contract with you. You have the rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your supervisory authority. We have not appointed an Article 27 representative, and we say so rather than imply one.
The categories, by their statutory names
Prose is easier to read and categories are easier to check, so both are here. Nothing in this table is sold, and nothing is shared for advertising.
| Category | What that means here | Why we have it |
|---|---|---|
| Identifiers | Your name, email address, company name. For a client, the email you sign in with. | To answer you, and to let you into your own portal |
| Commercial information | The engagement you bought, the fee, the invoice, the deal record. | To do the work and keep our books |
| Internet or network activity | Server logs from our host: the request, the time, the address it came from, the browser. No browsing history, because there is nothing here to build one with. | To run the site and stop abuse |
| Professional or employment information | What you tell us about your business, your team and your week, in an enquiry or in the intake. | It is the subject of the work |
| Audio or visual | Screen recordings and calls, where a client makes them as part of an engagement. Never from this website. | To write down how your business actually runs |
| Sensitive personal information | None. We do not ask for or want a government ID, a financial account number, precise location, health information, or anything about race, religion, union membership or sexual orientation. If a document you send happens to contain one, tell us and we will remove it. | Not collected |
| Inferences or a profile | None. We do not profile visitors and there is no analytics here to profile with. | Not collected |
When your documents contain other people
A P&L has staff in it. Owner statements have owners. A booking export has guests. When you send us those, we are handling other people's information on your behalf rather than collecting it for ourselves, and the commitments below are how we treat it.
- We use it only to do the engagement you bought. Not to build a product, not to train anything of our own, not for anything else.
- We do not sell it and we do not share it for advertising. Nobody gets it because they paid for it.
- The companies listed above are the only ones that touch it, each for the one job named, and each bound to us by its own terms.
- It goes on the same clock as everything else: the source documents you uploaded are deleted sixty days after delivery, or within thirty days of your written request, whichever comes first (§§7.3, 7.5).
- If someone in one of those documents makes a request to us about their own information, we will point them to you, because it is your relationship and your record, and we will help you answer it.
If your own obligations need this as a signed data-processing agreement rather than as a published commitment, ask and we will put one in place for your engagement. Some clients need that and most do not, so we do it on request rather than send everybody a document.
Security, and its limits
The portal is served over HTTPS only. Sign-in is by a one-time link rather than a password you have to remember. The session cookie is signed, is not readable by JavaScript, and expires after thirty minutes of inactivity rather than at the end of the day, because the portal holds P&Ls and owner statements.
No system is perfect and we are not going to claim ours is. If we find that your information has been exposed we will tell you without undue delay, and we will tell you what we know at the time rather than wait until the picture is complete. Deliberately no fixed number of hours here: the notification deadlines that apply depend on what was exposed and where you are, and a number invented for this page would be either wrong or a promise to miss.
What reduces the blast radius is holding less. Your documents are gone sixty days after delivery, we have never held a password of yours because sign-in is a one-time link, and there is no analytics database to lose.
Children
This is a service sold to businesses. It is not directed at children and we do not knowingly collect anything from anyone under 16. If we learn that we have, we delete it.
Changes to this page
If we change it we move the date at the top. This version is dated 17 September 2026. Where this page and a signed engagement agreement disagree, the agreement governs.
If something on this page contradicts an agreement you have signed with us, the agreement governs. Tell us, because one of the two is wrong and we want to know which.
Ask us about it