Privacy Policy
How NaviStrat collects, uses, and protects visitor information — and the rights you have over your data.
Last updated: July 2026
This Privacy Policy explains what information NaviStrat Consulting & Advisory Solutions Inc. (“NaviStrat”, “we”, “us”) collects when you visit our website and use our tools, why we collect it, how long we keep it, and the choices and rights you have. By using our site you agree to the practices described here.
1. Information We Collect
Information you provide directly: your name, email address, company, job title, and any details you submit through our forms (resource downloads, newsletter signup, treasury assessment, ROI calculator, demo requests, and contact forms).
Information collected automatically when you visit our site, only after you grant consent via our cookie banner:
- Pages you view and the order in which you view them, plus approximate time spent on each page.
- An anonymous, randomly-generated visitor identifier stored in your browser's localStorage, which lets us recognise the same browser across visits (not across devices).
- A per-tab session identifier stored in sessionStorage.
- Approximate location (country, region, city) derived from your IP address.
- Reverse-IP organisation lookup — we infer a company/organisation name from your IP address to understand whether visits originate from corporate networks (a business signal). This is not a precise identification of you personally.
- Device, browser, and operating system type derived from your user-agent string.
- Viewport size, browser locale, language, and timezone.
- Scroll depth and referrer/landing page for engagement analysis.
- UTM campaign parameters if you arrived via a marketing link.
We do not use advertising or cross-site tracking cookies. We do not sell your personal information.
2. Why We Collect It (Lawful Basis)
We process this information under the following lawful bases:
- Consent (GDPR Art. 6(1)(a) / ePrivacy) — for the non-essential analytics and localStorage tracking described above. You may withdraw consent at any time via the cookie banner or by clearing the
ns_consententry in your browser storage. - Contract / steps to a contract (GDPR Art. 6(1)(b)) — for information you submit to request a demo, assessment, or consulting engagement.
- Legitimate interests (GDPR Art. 6(1)(f)) — for aggregated, anonymised analytics that help us improve our content and tools, and for B2B account identification where you have not opted out.
- Legal obligation (GDPR Art. 6(1)(c)) — where we are required to retain records for tax, accounting, or regulatory purposes.
3. Cookies & Local Storage
We use browser localStorage (not HTTP cookies) for the identifiers described above. These are only set after you click “Accept analytics” on our consent banner. If you “Decline”, no analytics tracking occurs and no non-essential storage is written. Essential functionality (such as your dark-mode preference) may be stored regardless of consent.
4. Data Retention
We keep visitor analytics data only as long as necessary:
- Anonymous page-view records and visitor profiles are automatically deleted after a maximum of 13 months from the date of collection/last activity, via a scheduled retention process.
- Lead and enquiry records you submit (assessments, ROI calculations, demo requests) are retained for the duration of our business relationship plus the period required by applicable tax and records-retention laws (typically up to 7 years), after which they are deleted or anonymised.
- Subscriber emails are retained until you unsubscribe; you may unsubscribe at any time via the link in any email.
- Financial account data (Plaid-connected account balances, holdings, and transaction data) is retained only while your accounts are actively linked to the platform. When you disconnect a linked account or request deletion, the associated Plaid access token is revoked and all stored financial data (holdings, positions, balances, and credentials) is permanently deleted from our systems within 30 days. Plaid access tokens and broker API credentials are stored as restricted, encrypted fields and are never displayed in full — only masked representations (last four characters) are shown in the interface.
If you reside in a jurisdiction with a shorter statutory maximum, the shorter period applies.
5. How We Protect Your Data
Data is transmitted over encrypted (HTTPS/TLS 1.2+) connections and stored on cloud infrastructure with AES-256 encryption at rest. Access to personal and financial data is restricted to authorised personnel on a need-to-know basis, enforced through role-based access controls (RBAC). Consumer financial data retrieved through integrations such as Plaid — including access tokens, account balances, and portfolio holdings — is encrypted at rest and never exposed to the client-side application. Sensitive credentials are masked in all interface displays. Multi-factor authentication (MFA) is enforced for all administrative accounts with access to systems processing consumer financial data. Despite these measures, no method of transmission or storage is 100% secure.
6. Third Parties & International Transfers
We use the following service providers who may process data on our behalf:
- ip-api.com — converts your IP address into approximate location and organisation name. See ip-api.com's privacy notice.
- Our hosting and platform provider — for application hosting, database, and authentication.
If you access our site from the European Economic Area, UK, or other regions with data-protection laws that differ from those in the United States, please note that your data may be transferred to and processed in the US. We take steps to ensure such transfers use appropriate safeguards.
7. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data (“right to be forgotten”).
- Restrict or object to the processing of your data.
- Data portability — receive your data in a structured, machine-readable format.
- Opt out of the “sale” or “sharing” of personal information (CCPA/CPRA). We do not sell your data.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Delete financial account data — you may disconnect any linked brokerage or financial account at any time. Upon disconnection, your Plaid access token is immediately revoked and all associated financial data (balances, holdings, positions, and stored credentials) is permanently deleted from our systems within 30 days. You may also request complete deletion of all financial data by emailing us at the address below.
To exercise any of these rights, email us at the address below. We will respond within the timeframes required by applicable law (generally 30 days).
8. Contact & Complaints
For privacy questions, data-subject requests, or to lodge a complaint, contact us at info@navistrat.com. If you are in the EU/UK, you also have the right to complain to your local data-protection authority. We aim to resolve concerns directly before that becomes necessary.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. We encourage you to review this page periodically.
By using our website, you acknowledge that you have read and understood this Privacy Policy.
Back to home