Privacy
Policy.
Last Updated 9th September 2026.
Ash Vos Brand Consulting (“we,” “us,” “our”) provides fractional brand strategy and marketing consulting services, primarily to premium and luxury hospitality and consumer brands. This Privacy Policy explains what personal information we collect through ashvos.com and in the course of client engagements, how we use and store it, who we share it with, and the choices and rights available to you.
This policy applies to website visitors, newsletter subscribers, prospective clients who make an enquiry, and current and former clients. It does not apply to the internal employees or contractors of client organisations, whose data is governed by their own employer's policies unless we are engaged to process it directly on the client's behalf.
A note on scope: we are an Australian-based consulting practice serving clients internationally. We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and we extend comparable rights, on request, to visitors and clients located in the EU/UK (GDPR) or elsewhere with equivalent protections.
Information We Collect
Information you provide to us
Contact details submitted via website forms (Squarespace) — name, email address, company or brand name, and any message content. Newsletter and lead magnet sign-ups — name and email address, collected and managed through our email marketing platform. Meeting bookings — name, email address, and time zone, collected through our scheduling tool (Calendly) when you book a Strategy session or discovery call. Billing and payment details — name, billing address, and payment information, processed through our payment processor (Stripe). We do not store full card numbers ourselves. Engagement materials — information you share with us directly during a Strategy, Marketing, or Retainer engagement, including business documents, brand assets, and communications by email or in working sessions.
Information collected automatically
Website usage data — pages visited, referral source, device and browser type, and approximate location, collected via Squarespace's built-in analytics and Google Analytics (or a comparable analytics tool). Cookies and similar technologies — used to operate the website, remember preferences, and understand aggregate visitor behaviour. See Section 4 (Cookies & Analytics) below.
Information from third parties
Where relevant to an engagement, we may receive information about a client's business — for example, performance data shared by a client's internal team, agency, or platform (such as a booking engine or CRM) — solely for the purpose of delivering the agreed services.
How We Use Information
We use personal information to:
Respond to enquiries and schedule consultations. Deliver Strategy, Marketing, and Retainer services under an active engagement. Send newsletters, resources, and occasional marketing communications, where you have opted in or where permitted by law, with the ability to unsubscribe at any time. Process invoices and payments. Maintain internal business records, including client history and correspondence. Understand website performance and improve our content and services. Meet legal, accounting, and regulatory obligations. We do not use client or prospect information to train third-party AI models beyond the ordinary operation of the tools listed in Section 3, and we do not sell personal information to third parties.
Third-Party Service Providers
We rely on a small number of third-party platforms to operate the practice. Each acts as a data processor on our behalf and maintains its own privacy and security standards. Current providers include: Squarespace — website hosting, forms, and on-site analytics. Email marketing platform (e.g. Mailchimp, Flodesk, or ConvertKit) — newsletter and lead magnet delivery. Calendly — meeting scheduling. Stripe — payment processing. Google Analytics (or comparable) — aggregate website traffic and behaviour reporting.
These providers may process data outside Australia, including in the United States. Where this occurs, we rely on the provider's own compliance frameworks (such as standard contractual clauses or equivalent safeguards) and select providers with appropriate security and privacy commitments. We periodically review this list as tools change; the current list is always reflected in this policy.
Cookies & Analytics
ashvos.com uses cookies and similar technologies to operate core site functionality and to understand how visitors use the site in aggregate. This includes essential cookies (required for the site to function) and analytics cookies (Google Analytics or comparable), which we use to see which content and pages are most useful. You can control or disable cookies through your browser settings; disabling non-essential cookies will not affect your ability to browse the site or submit enquiries.
Confidential Client Business Data
During Strategy, Marketing, and Retainer engagements, clients often share commercially sensitive information beyond ordinary contact details — for example, direct and OTA booking data, revenue and pricing information, marketing performance figures, internal strategy documents, and brand assets. We treat this material as strictly confidential, distinct from general website and marketing data, and it is handled as follows: Used only for the purpose of the engagement it was provided for, and not shared with other clients or used in case studies, testimonials, or marketing materials without explicit written permission. Stored in access-controlled systems, limited to Ash Vos and any contractor or sub-processor directly supporting the engagement under an equivalent confidentiality obligation. Retained only for as long as needed to deliver the engagement and to meet record-keeping obligations (see Section 7), after which it is securely deleted or returned on request. Never used to train third-party AI tools in a way that would expose it outside the engagement; where AI-assisted tools are used in strategy or analysis work, client-identifying and commercially sensitive details are handled in line with the tool provider's business/no-training terms. Confidentiality obligations regarding client business data are also typically set out in the engagement agreement or statement of work, which takes precedence over this policy in the event of any inconsistency.
Data Storage & Security
Personal and business information is stored using the platforms listed in Section 3, together with encrypted cloud storage and email systems used to manage the practice. We apply reasonable technical and organisational measures — including access controls, password protection, and limiting access to information on a need-to-know basis — to protect information against loss, misuse, and unauthorised access. No method of transmission or storage is completely secure, and while we take reasonable steps to protect personal information, we cannot guarantee absolute security.
Data Retention
Enquiry and prospect data: retained for up to 24 months from last contact, or deleted sooner on request. Newsletter subscribers: retained until you unsubscribe or request deletion. Client records and engagement materials: retained for the duration of the engagement plus a period required for accounting, tax, and legal record-keeping (generally up to 7 years in Australia). Billing records: retained as required by Australian tax law. Where retention is no longer required, information is securely deleted or de-identified.
Disclosure of Information
We do not sell personal information. We disclose information only: To the third-party service providers listed in Section 3, to the extent necessary to operate those services. To professional advisers (such as an accountant or lawyer) where reasonably necessary. Where required by law, regulation, or a valid legal process. In connection with a sale, transfer, or restructure of the business, subject to equivalent confidentiality protections.
Your Rights & Choices
Depending on your location, you may have the right to access, correct, or request deletion of your personal information, to object to or restrict certain processing, to withdraw consent to marketing communications at any time (via the unsubscribe link in any email or by contacting us directly), and to lodge a complaint with a relevant regulator — in Australia, the Office of the Australian Information Commissioner (OAIC); in the EU/UK, your local data protection authority. To exercise any of these rights, contact us using the details in the Contact Us section of this policy. We will respond within a reasonable timeframe and in line with applicable law.
International Visitors & Clients
Ash Vos Brand Consulting is based in Australia and works with clients internationally, particularly in luxury hospitality. If you are located outside Australia, your information may be transferred to and processed in Australia and in the countries where our service providers operate (see Section 3). By engaging with us or using this website, you acknowledge this cross-border handling of information, carried out consistently with the protections described in this policy.
Children's Privacy
This website and our services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
Contact Us
For questions about this policy, or to exercise any privacy right described above, contact:
Ash Vos Brand Consulting a@ashvos.com with ‘Privacy Policy’ in the subject title.
Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, tools, or legal requirements. The “Last updated” date at the top of this page reflects the most recent revision. Material changes affecting how client engagement data is handled will be communicated directly to active clients.
Contact
a@ashvos.com

