Privacy policy

Last updated August 2026.

Privacy is not a compliance exercise in this business. Owners tell us things their own employees do not know. This is what we do with what you send us.

What we collect

  • What you type into a form. Name, email, phone, company, and whatever you choose to tell us about the business or your search.
  • Valuation and readiness inputs. The figures and answers you enter, and the result they produced.
  • NDA acceptances. Your name, typed signature, the date and time, your IP address and a hash of the exact agreement text.
  • First-party analytics. Pages viewed and the order you viewed them in, the referring source, device and browser type, and a random visitor identifier stored in a cookie.
  • Your IP address, and the city and state it resolves to. We keep this so an inquiry can be understood in context — which part of the country it came from, and which pages led to it. The address is looked up once against an IP geolocation service and the result is cached on our own server. There is no Google Analytics, no advertising pixel and no third-party tracker on this site.

Why we collect it

  • To answer your inquiry and provide the advisory service you asked for.
  • To qualify buyers before releasing confidential information about a seller's business.
  • To keep a record of confidentiality agreements that were accepted.
  • To understand which pages help people, so we write more of what does.

What we never do

  • We never sell your data.
  • We never share it with foreign entities.
  • We never use it for unsolicited marketing.
  • We never contact your employees, customers, suppliers or competitors.

Who else sees it

Only the people at this practice who need to, and — where you have asked for an introduction — the specific professional you asked to be introduced to. A referral is never made without telling you.

Where a form submission's country of origin is checked, that lookup sends the requesting IP address to an IP geolocation provider and nothing else. The result is cached on our own server.

Where it lives, and for how long

On our own server, transmitted over HTTPS. Inquiries and NDA records are retained while a relationship is active and for the period our professional obligations require afterwards. Analytics — including IP addresses and the locations resolved from them — and abuse logs are deleted on a rolling basis, and can be cleared at any time on request.

Your choices

  • Ask us what we hold about you.
  • Ask us to correct it.
  • Ask us to delete it — we will, except where a record of an accepted confidentiality agreement must be retained.
  • Ask us to stop contacting you, and we stop.

Email steve@dykstraconsulting.com and say what you would like.

Cookies

Two: a session cookie so forms work, and a first-party analytics cookie holding a random identifier. Neither follows you to other sites. There are no advertising or cross-site cookies.

Security

HTTPS in transit, password hashing for the internal console, rate limiting and lockout on repeated failed sign-ins, and a layered spam defence on public forms. No system is perfect; if you believe something is wrong, tell us and we will look immediately.