VECTOR HOLDING GROUP | Privacy Policy
1. Introduction and Scope
Vector Holding Group, a dba of Vector Consultants, LLC (“VHG,” “Vector,” “we,” “us,” or “our”), a state of California registered company, respects your privacy and is committed to protecting the personal information we collect. This Privacy Policy explains what personal information we collect, why we collect it, how we protect it — including when you email us or communicate with us by SMS text message — and what choices and rights you have.
This Policy applies to personal information we collect through VectorHoldingGroup.com, our client-facing communications, and our recruiting process. Section 11 addresses how it applies to employees and contractors specifically. It does not apply to third-party websites or services we do not control, even if linked from our site.
2. Personal Information We Collect
Depending on how you interact with us, we may collect the following categories of personal information:
• Identifiers: name, email address, phone number, mailing address, IP address, online identifiers.
• Commercial/Business Information: services purchased, order history, billing and payment information (processed by our payment processor — we do not store full card numbers).
• Communications: the content of emails, SMS messages, and other messages you send us, and related metadata (timestamps, delivery status).
• Website Usage Data: pages visited, referring URLs, browser/device type, and similar analytics data collected through cookies or similar technologies.
• Employment Application Data: resume/CV, cover letter, work history, references, and interview notes, if you apply for a role with us.
• Employment/Engagement Data: for employees and contractors — see Section 11.
We do not knowingly collect Social Security numbers, government ID numbers, or financial account credentials through our website. Do not send this information to us by email or SMS (see Section 6).
3. How We Use Personal Information
• To provide, operate, and improve our services and respond to inquiries.
• To process transactions and send related confirmations, receipts, and service notices.
• To communicate with you about your account, project, or engagement with us.
• To evaluate job applications and communicate with candidates.
• To maintain the security and integrity of our systems and comply with legal obligations.
• To improve our website through aggregated, de-identified analytics.
We do not sell or share personal information with third parties for cross-context behavioral advertising, and we do not use third-party advertising trackers (such as ad pixels) that would trigger a “sale” or “share” under the CCPA/CPRA. If this changes, we will update this Policy and provide a “Do Not Sell or Share My Personal Information” mechanism before doing so.
4. Sources of Personal Information
• Directly from you — forms, email, phone, SMS, or in-person conversations.
• Automatically — through cookies and standard web server logs when you visit our site.
• From service providers who perform functions on our behalf (e.g., email delivery, SMS delivery, payment processing, hosting).
5. Disclosure of Personal Information
We disclose personal information only to:
• Service providers bound by written agreements who process data solely on our behalf (e.g., our email platform, SMS/text messaging provider, hosting provider, payment processor) and only to the extent needed to provide their service.
• Legal and safety purposes — to comply with a subpoena, court order, or other legal process, or to protect the rights, property, or safety of VHG, our workforce, or the public.
• Business transfers — in connection with a merger, financing, or acquisition, subject to standard confidentiality protections.
We do not sell personal information and have not done so in the preceding 12 months.
6. How We Protect Personal Information Sent by Email
• Encryption in transit: Our mail systems use TLS (Transport Layer Security) encryption to protect messages while they travel between mail servers, when the receiving server also supports TLS.
• Access controls: Mailboxes are protected by unique, complex passwords and multi-factor authentication (MFA) in accordance with our internal Password Protection Policy, and access is limited to personnel who need it to do their jobs.
• Phishing and malware screening: Inbound email is screened for malicious attachments and links, and staff complete periodic security-awareness training.
• Retention and deletion: Email containing personal information is retained only as long as necessary for the purpose it was collected, consistent with our internal Data Retention Policy, and is then securely deleted.
• What we ask of you: Standard email is not encrypted end-to-end by default. Please do not email us your Social Security number, bank account or card numbers, passwords, or other highly sensitive information. If you need to send sensitive documents, contact us first and we will provide a secure upload option.
7. How We Protect Personal Information Sent or Received by SMS Text Message
Nature of our texting program: VHG uses SMS text messages for operational and transactional purposes only — for example, appointment reminders, account or service notices, and verification codes. We do not send marketing or promotional text messages, and we do not sell, rent, or share your mobile phone number with third parties for their own marketing purposes.
• Consent: We text you only if you have provided your mobile number to us for that purpose (for example, at intake or account setup). Your consent to receive operational texts is not shared with unaffiliated third parties.
• Message frequency and cost: Message frequency varies based on your engagement with our services. Message and data rates may apply, per your mobile carrier's plan.
• Opt-out: Reply STOP to any text to opt out at any time; we will process opt-outs within 10 business days, and in practice, in real time wherever our platform allows. Reply HELP for assistance, or contact us using the information in Section 16. We treat any reasonable, clearly expressed request to stop texting you — by any channel — as a valid opt-out, not only the word “STOP.”
• Security of the SMS channel: We work only with SMS providers that are registered under the wireless carriers' 10DLC/campaign-registry framework and that contractually commit to CTIA Messaging Principles and Best Practices. Consent records (who, when, and how you opted in) are retained for at least four years to document compliance with the Telephone Consumer Protection Act (TCPA).
• What we ask of you: SMS is not an encrypted channel. Please do not text us your Social Security number, full card number, or passwords.
8. Data Security — General Practices
Beyond the email- and SMS-specific measures above, we apply layered safeguards across all systems that store personal information, consistent with our internal Acceptable Use, Password Protection, BYOD, and Remote Working policies:
• Passwords meeting minimum complexity standards, changed on a regular cycle, and never shared.
• Encryption of data at rest on company-managed devices and cloud storage where technically supported.
• Role-based access controls limiting data access to personnel who need it.
• Anti-virus/anti-malware protection and timely security patching.
• A documented incident response process, including a designated point of contact for suspected data security incidents.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to using industry-standard safeguards and to notifying affected individuals and any legally required regulators without unreasonable delay if a breach affecting personal information occurs.
9. Data Retention
We retain personal information only as long as reasonably necessary for the purpose it was collected, to provide you services, and to meet our legal, accounting, or reporting obligations, consistent with our internal Data Retention Policy. Retention periods differ by data type — for example, employment, tax, and wage-related records are retained for the periods required by California and federal law (which, for several waeg and personnel record categories, is a minimum of three to four years, not 30 days), while general inquiry correspondence is retained for a shorter period. Specific retention periods are available on request.
10. Job Applicants
If you apply for a position with VHG, we collect the application materials you submit (resume, cover letter, references, interview notes) to evaluate your candidacy. This data is shared only with VHG personnel involved in the hiring decision and is not sold or used for unrelated marketing purposes. Recruitment data for unsuccessful candidates is retained only for the period necessary to close out the recruitment process and defend against potential claims, then securely deleted.
11. Employees and 1099 Contractors
If you are a VHG employee or contractor, this Policy covers information we collect through our public website and general business communications with you. Personal information we collect and use specifically in the employment or engagement relationship — such as payroll, benefits, performance, and personnel records — is governed by our internal HR and personnel policies and applicable California and federal employment law, and is made available to you separately at onboarding. Under California law, workers are entitled to the same categories of CCPA rights described in Section 13 with respect to HR-related personal information, subject to employment-law exceptions.
12. Cookies and Website Analytics
Our website may use first-party cookies and similar technologies necessary for the site to function, and limited analytics cookies to understand aggregate site usage. We do not use these technologies for cross-site advertising tracking. You can control cookies through your browser settings; disabling them may affect site functionality.
13. Your California Privacy Rights
Regardless of whether VHG is required to comply with the CCPA/CPRA, we voluntarily extend the following rights to California residents whose personal information we hold:
• Right to Know what personal information we have collected, used, and disclosed about you.
• Right to Delete personal information we have collected from you, subject to certain legal exceptions.
• Right to Correct inaccurate personal information.
• Right to Opt Out of the sale or sharing of personal information (we do not currently sell or share, so there is nothing to opt out of today).
• Right to Non-Discrimination for exercising any of these rights.
To exercise any of these rights, contact us using the information in Section 16. We will verify your identity before fulfilling a request and will respond within 45 days (extendable by an additional 45 days for complex requests, with notice to you).
14. Children's Privacy
Our website and services are directed to businesses and adults. We do not knowingly collect personal information from children under 16. If we learn we have inadvertently collected such information, we will delete it promptly.
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. The “Effective Date” at the top of this Policy indicates when it was last revised. Material changes will be posted on this page; we encourage you to review it periodically.
16. Contact Us
If you have questions about this Policy, want to exercise a privacy right, or want to report a suspected data security incident involving your personal information, contact us at: