Last updated: April 18, 2026 · This Privacy Policy describes how Vantage Point Strategy Group LLC collects, uses, and protects information you provide when using our services.
The short version: We collect only what we need to deliver our services. We never sell your data. We never share it with advertisers. Employee data you upload stays yours and is deleted after your engagement ends.
1. Who We Are
Vantage Point Strategy Group LLC ("VPSG," "we," "us," or "our") is a strategic advisory and technology firm based in Oklahoma City, Oklahoma. We operate the VPSG Benefits Reconciliation Intelligence™ (BRI™) platform, the VPSG Client Portal, and related services. Our EIN is 41-4595360 and we can be reached at admin@vantagepointstrategygroup.com.
2. Information We Collect
Information you provide directly:
- Account registration information (name, email, company, job title)
- Payment information (processed by Stripe — VPSG does not store card numbers)
- Risk Assessment and organizational assessment responses
- Employee data files uploaded to the BRI™ platform (payroll, enrollment, carrier, invoice data)
- Communications sent to VPSG via email or platform messaging
- Consultation scheduling information (via Cal.com)
Information collected automatically:
- Browser type, device type, and operating system
- Pages visited and time spent on our website
- IP address and general geographic region
- Authentication logs and session data
3. How We Use Your Information
VPSG uses information collected for the following purposes:
- Delivering the services you have requested or purchased
- Processing payments and managing your account
- Running diagnostic analyses on uploaded data files
- Generating and delivering Risk Assessment reports
- Scheduling and conducting advisory consultations
- Communicating with you about your account, services, and results
- Improving our products and services using aggregated, anonymized data
- Complying with applicable legal obligations
We do not use your information for advertising, marketing profiling, or sale to third parties.
4. Employee Data — Special Handling
When you upload employee benefits data, payroll records, or enrollment files to the BRI™ platform, that data is treated with heightened care:
- Employee data is processed solely to perform the diagnostic analysis you requested
- Employee data is never shared with third parties for any purpose
- Employee data is never used to train AI models or build third-party products
- Raw uploaded files are deleted within thirty (30) days of engagement completion
- Diagnostic results are retained for ninety (90) days for your download access, then deleted
If you upload data that may constitute Protected Health Information (PHI) under HIPAA, you are required to execute a Business Associate Agreement (BAA) with VPSG prior to upload.
5. Information Sharing
VPSG does not sell, rent, or trade your personal information. We share information only in the following limited circumstances:
- Service providers: We use trusted third-party providers to operate our platform, including Supabase (database), Netlify (hosting), Stripe (payments), Google (email), and Cal.com (scheduling). Each is bound by confidentiality and data protection obligations
- Legal requirements: We may disclose information if required by law, court order, or government authority
- Business transfers: In the event of a merger or acquisition, information may be transferred as part of the transaction, subject to equivalent privacy protections
- With your consent: We may share information in other circumstances with your explicit written consent
6. Data Security
VPSG implements commercially reasonable technical and organizational security measures to protect your information, including:
- Encrypted data transmission (TLS/HTTPS) for all platform communications
- Encrypted data storage through Supabase infrastructure
- Role-based access controls limiting data access to authorized personnel
- Authentication requirements for all portal access
- Regular review of security practices and third-party integrations
No security system is impenetrable. In the event of a data breach affecting your information, we will notify you as required by applicable law.
7. Cookies and Tracking
Our website uses minimal cookies necessary for authentication and session management. We do not use advertising cookies, tracking pixels, or behavioral profiling technologies. We use basic analytics to understand how our website is used in aggregate. You can disable cookies in your browser settings, though this may affect functionality of the client portal.
8. Data Retention
We retain information for as long as necessary to provide our services and comply with legal obligations:
- Account information: retained for the duration of your account plus 2 years
- Uploaded employee data files: deleted within 30 days of engagement completion
- Diagnostic results and reports: retained 90 days post-engagement for download, then deleted
- Payment records: retained as required by applicable tax and financial regulations
- Communications: retained for the duration of the business relationship plus 3 years
9. Your Rights
You have the following rights with respect to your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information, subject to legal retention requirements
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain processing activities
To exercise any of these rights, contact us at admin@vantagepointstrategygroup.com. We will respond within thirty (30) days.
10. Children's Privacy
VPSG services are intended for business use by adults. We do not knowingly collect personal information from individuals under 18 years of age. If you believe a minor has provided information to VPSG, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. Your continued use of VPSG services following notice of changes constitutes acceptance of the updated policy.
12. Contact Us