Skip to content
Tidebreak Advisory

Tidebreak Advisory · Privacy Policy

Effective date: 2026-06-17

Last updated: 2026-08-21

Tidebreak Advisory, LLC, a New Hampshire single-member limited liability company ("Tidebreak," "we," "us," "our"), values the privacy of visitors to our website and the firms that engage our services. This Privacy Policy explains what information we collect through our website, how we use it, who we share it with, and the rights you have regarding that information.

This policy covers our public website only. It does not govern information we collect or process under a signed engagement letter with a client; that information is handled under the engagement letter's confidentiality and data-handling terms.

Information we collect

Information you provide to us.

When you contact us through the website, schedule a call through our scheduling tool, subscribe to an email update, or request a trust-artifact download (for example, a framework crosswalk or sample report), you may provide information that can include your name, work email address, firm name, role, and any optional message. We collect only what you choose to give us.

Information collected automatically.

When you visit the website, our hosting provider (Vercel) and our analytics tools log basic technical information including IP address (or a truncated version of it), browser type, device type, referring URL, pages visited, and session timestamps. We use Vercel Web Analytics and Vercel Speed Insights, which are cookieless, and Google Analytics 4, which uses cookies, to understand site traffic and page performance in aggregate and to operate and secure the website.

Cookies and similar technologies.

We use a small number of cookies to operate the website and to measure how it is used. Essential cookies are necessary for the website to function. Analytics cookies, set by Google Analytics and Microsoft Clarity, help us understand how the site is used; they are not used to build advertising profiles. You can control cookies through your browser settings, and you can turn off our analytics and session replay tools for this browser using the opt-out link below. Disabling essential cookies may affect site functionality.

Session replay and heatmaps (Microsoft Clarity).

We use Microsoft Clarity to understand how visitors use and interact with the website through behavioral metrics, heatmaps, and session replay. Clarity records mouse movement, clicks, scrolling, and page navigation so we can see which parts of a page are read, skipped, or cause confusion, and uses first- and third-party cookies and similar technologies to recognize repeat visits. We use this information only to improve the website and its content and for security purposes; we do not use it for advertising. Clarity is configured to mask the text you type into forms by default, and we do not collect passwords, payment details, or other sensitive information on the website. Recordings are stored and processed by Microsoft on its own infrastructure and are accessible to Tidebreak and to Microsoft as our service provider; we do not share them with anyone else. For more information about how Microsoft collects and uses your data, see the Microsoft Privacy Statement linked below.

Opting out of analytics and session replay.

You can turn off Google Analytics and Microsoft Clarity for this browser at any time. Following the opt-out link sets a cookie that tells the website not to load either tool; it does not affect the cookieless Vercel measurements or the essential cookies the site needs to function. The opt-out lasts one year or until you clear cookies, and you can reverse it with the opt-in link.

What we do not collect through the website.

We do not collect payment information on the website. We do not collect health information, financial account information, Social Security numbers, government identifiers, or other sensitive personal information through the website. We do not use automated decision-making or profiling in any way that produces a legal or similarly significant effect.

How we use information

We use information you provide and information collected automatically to:

  • respond to inquiries and requests for information, including scheduling scoping conversations;
  • deliver materials you request, including trust-artifact downloads and email updates you have subscribed to;
  • operate, secure, improve, and analyze use of the website;
  • comply with legal obligations and enforce our Terms of Use.

We do not use information collected through the website for any purpose that is materially different from the purposes described in this policy without notifying you first.

What we do not do with your information

  • We do not sell or rent your personal information.
  • We do not share your personal information with third parties for their own direct marketing purposes.
  • We do not use your personal information to train or fine-tune artificial intelligence or machine learning models.
  • We do not share information submitted through the website with any managed service provider, IT vendor, or other organization that Tidebreak may assess in a client engagement.

How we share information

We share information only with the following categories of recipients:

  • Service providers that support our operations. These include our website hosting provider (Vercel), our website analytics and session replay providers (Vercel, Google, and Microsoft), our email service provider, our scheduling tool provider, and our email marketing provider (if you have subscribed). These providers access information only as needed to perform services for us and are contractually required to protect it.
  • Professional advisors. We may share information with our accountants, attorneys, and insurers on a need-to-know basis, subject to professional duties of confidentiality.
  • Legal and compliance. We may disclose information if required by law, legal process, or legitimate government request, or to protect the rights, property, or safety of Tidebreak, our clients, or the public.
  • Business transfers. If Tidebreak is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.

A current list of service provider categories is available on request to the contact below.

How long we keep information

We retain information only as long as reasonably needed for the purposes described above. Inquiry submissions and scheduling records are retained for up to twenty-four months after the last contact unless you ask us to delete them sooner. Email subscribers' information is retained until you unsubscribe or we stop using the list. Analytics data is retained in aggregate for up to twenty-six months.

Information collected under a signed engagement letter is retained according to the engagement letter's terms, not this policy. Under our Ongoing Oversight retainer, standing access terms and retention are governed by the engagement letter's scope rider.

Your privacy rights

All visitors.

You may contact us using the information in Section 11 to ask what personal information we hold about you, to ask us to correct or delete it, or to unsubscribe from any list you have joined. We will acknowledge your request promptly and respond within the timeframe required by applicable law (typically within thirty to forty-five days).

California residents (CCPA and CPRA).

If you are a California resident, you have the rights listed below with respect to personal information we have collected about you.

  • Right to know the categories and specific pieces of personal information we have collected, the categories of sources, the purposes for collection, and the categories of recipients with whom we have shared personal information.
  • Right to delete personal information we have collected from you, subject to limited exceptions provided under law.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing of personal information. Tidebreak does not sell or share personal information as those terms are defined in the CCPA and CPRA.
  • Right to limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information through the website.
  • Right to non-discrimination for exercising any of these rights.
  • Authorized agent. You may designate an authorized agent to make a request on your behalf by providing us with written authorization and sufficient information to verify the agent's authority.

To exercise any of these rights, contact us using the information in Section 11 and include "California privacy request" in the subject line. We will verify your identity using information you have previously provided to us or other reasonable means, and respond within the timeframe required by law.

Categories of personal information collected in the past twelve months.

Identifiers (such as name, email address, and IP address); commercial information (such as professional role and firm name); internet or other electronic network activity (aggregate site usage); and inferences reasonably drawn from the above for operation of the website. We have not sold or shared personal information for cross-context behavioral advertising purposes.

Do Not Track signals

Some web browsers transmit "Do Not Track" signals. Because there is no industry-wide consensus on how to interpret these signals, Tidebreak does not currently respond to them. Tidebreak does honor opt-out mechanisms available through specific services where offered.

Children

The website is not directed to children under sixteen, and we do not knowingly collect personal information from children under sixteen. If you believe we have collected information from a child under sixteen, please contact us and we will take steps to delete it.

Third-party websites and services

The website contains links to third-party websites and services, including LinkedIn and our scheduling tool provider. This Privacy Policy does not apply to those third-party sites and services, each of which has its own privacy policy. We encourage you to review the privacy practices of any third-party site before providing information.

Security

We use reasonable administrative, technical, and physical safeguards designed to protect information collected through the website against unauthorized access, disclosure, alteration, or destruction. No method of internet transmission or electronic storage is fully secure, and we do not guarantee absolute security. You can contact us at any time to ask about specific safeguards in place.

Security practices described on the website in connection with our assessment services (for example, encryption of engagement evidence, role-limited access, and return-or-destruction at engagement close-out) are described in the applicable engagement letter and are not promises made through this website.

Contact us

Tidebreak Advisory LLC

Privacy inquiries: privacy@tidebreakadvisory.com

Mailing address: 285 Union St, Portsmouth, NH 03801

For California-specific requests, please include "California privacy request" in the subject line.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service offerings, or applicable law. The "Effective date" at the top indicates when the current version took effect. We encourage you to review this policy periodically. For material changes, we will post a notice on the website and, where required by law, provide additional notice.