Privacy Policy

Last updated: [DATE]

CMI Consulting, a division of Carolina Management Institute, LLC ("CMI," "we," "us," or "our"), respects your privacy. This policy explains what information we collect through carolinamanagementinstitute.com and our CMI Insider membership service (together, the "Service"), how we use it, and the choices and rights available to you.

1. Information We Collect

Information you provide directly:

  • Contact form submissions: name, email, organization, role, and your message
  • Newsletter signup: email address
  • Membership account: name, email, organization, and a password (stored as a one-way cryptographic hash — we cannot see or recover your actual password)
  • Any correspondence you send us directly

Information collected automatically:

  • Standard web server logs (IP address, browser type, pages visited, timestamps) for security and rate-limiting purposes
  • If analytics are enabled on this site, aggregated, privacy-focused usage analytics (see Section 6)

Information we do not collect:

  • Payment card information — see Section 2
  • Protected health information (PHI). This Service is a marketing and membership-content site for a consulting practice; it is not a healthcare service, and you should not submit PHI through the contact form or any part of this Service.

2. Payment Information

CMI Consulting does not collect, transmit, process, or store payment card information on our own servers. Membership payments are processed entirely by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you subscribe, you enter your card details directly on Stripe's secure, hosted checkout page. We receive only a subscription status, a Stripe customer reference ID, and billing metadata (such as your plan and renewal date) — never your card number, expiration date, or security code. Stripe's own privacy policy governs its handling of your payment information; see stripe.com/privacy.

3. How We Use Information

  • To respond to contact form inquiries and provide requested information about our consulting services
  • To create and administer your CMI Insider membership account, including authenticating your login and delivering member-only content
  • To process membership payments (via Stripe) and communicate about your subscription, including renewal, payment failure, and cancellation notices
  • To send you the newsletter or member communications you've opted into, and to let you unsubscribe at any time
  • To maintain the security, integrity, and proper functioning of the Service, including rate-limiting abusive requests and detecting fraud
  • To comply with legal obligations

We do not sell your personal information, and we do not use it to serve third-party advertising.

4. How We Share Information

We share information only with service providers who help us operate the Service, under obligations to protect it:

  • Stripe — payment processing (see Section 2)
  • Microsoft 365 — email delivery, to send transactional and requested communications
  • Hosting and infrastructure providers — to run the Service (currently a DigitalOcean droplet)
  • AI service providers (Anthropic, OpenAI, or Grok, depending on current configuration) — used internally by CMI staff for operational drafting and review; member or visitor personal information is not intentionally submitted to these providers as part of normal Service operation
  • Analytics providers, if enabled — see Section 6

We may also disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of CMI, our users, or the public. If CMI is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy's protections.

5. Data Retention

  • Contact form submissions are retained for up to 24 months, or until you request deletion, whichever comes first
  • Membership account data is retained for as long as your account is active, plus a reasonable period afterward to comply with legal, tax, and accounting obligations
  • If you delete your membership account, we anonymize your account record (email, name, and organization are removed) rather than deleting billing history outright, to preserve accounting integrity — see Section 8 for how to request deletion
  • Server logs are retained for a limited period for security purposes and then automatically purged

6. Cookies & Analytics

This Service uses essential cookies required for the site to function — specifically, secure session cookies that keep you logged in to your member or admin account. These are not used for advertising or cross-site tracking.

If privacy-focused analytics (such as Plausible) are enabled, they collect aggregated, anonymized usage statistics (e.g., page views, referrers) without using cookies or collecting personally identifiable information, and without tracking you across other websites. We do not currently use advertising cookies, and we do not serve third-party ads.

7. Security

We use reasonable administrative, technical, and physical safeguards designed to protect your information, including encrypted transmission (HTTPS/TLS) across the Service, encryption of sensitive configuration values at rest, hashed (not reversibly stored) passwords, and rate limiting on authentication and form-submission endpoints. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your Rights & Choices

Depending on your state of residence, you may have some or all of the following rights regarding your personal information — rights broadly available under the comprehensive consumer privacy laws now enacted in more than twenty US states (including California, Virginia, Colorado, Connecticut, and others):

  • Access — request a copy of the personal information we hold about you
  • Correction — request that we correct inaccurate information
  • Deletion — request that we delete your personal information, subject to legal retention exceptions
  • Portability — request your information in a portable format
  • Opt-out of sale/targeted advertising — not applicable in practice, as we do not sell personal information or use it for targeted advertising
  • Non-discrimination — we will not deny you service or charge you differently for exercising these rights

Members can self-service most of these rights directly: update your name/organization from your member dashboard, and delete your account (which cancels any active subscription and anonymizes your account) from the same dashboard. For any other request, or if you are not a member, contact us using the information in Section 12. We will verify your identity before fulfilling a request and will respond within the timeframe required by applicable law (generally 45 days, extendable once by an additional 45 days for complex requests).

California residents: you may also designate an authorized agent to make a request on your behalf, and you have the right to appeal a denied request.

9. Children's Privacy

This Service is intended for business professionals and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

10. International Visitors

This Service is operated in the United States and intended primarily for a US audience. If you access the Service from outside the United States, your information will be processed in the United States, which may have different data protection laws than your home jurisdiction. We do not specifically target or offer services to individuals in the European Economic Area, UK, or Switzerland; if you are located in one of those regions and have concerns about GDPR-specific rights, please contact us directly.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above; for significant changes, we may provide additional notice (such as a notification to members). Continued use of the Service after an update constitutes acceptance of the revised policy.

12. Contact

Questions about this policy, or requests to exercise your privacy rights, can be sent to dshearer@carolinamanagementinstitute.com.