Privacy Policy
Last updated August 11, 2026
Boundary HR is a solo HR-consulting practice. This policy explains what information the site and the client portal collect, why, where it is stored, and how to have it deleted. It is written to be read, not to be survived.
The short version
- No advertising trackers, no third-party cookies, and no profile of you built anywhere. Page analytics is cookieless and never runs on your private client links. Fonts are served from this site, not from Google.
- Information is collected only when you type it into a form or upload a document.
- Nothing is sold, rented, or shared for marketing.
- Payment card details are never entered on this site and are never seen by Boundary HR.
- Documents uploaded during onboarding are deleted when the engagement closes, and sooner on request.
What is collected
When you request a quote. The quote form collects your name, email address, company name, employee count, the states you operate in, and anything you write in the message field. This is used to prepare a quote and follow up with you.
When you become a client. The onboarding form collects business details needed for the engagement and lets you upload existing HR documents — handbooks, offer letters, policies, and similar files. What you upload is your choice. Please do not upload employee Social Security numbers, medical records, or I-9 forms unless we have specifically discussed it; a redacted sample is almost always enough for a compliance review.
Automatically. Cloudflare, which hosts this site, processes standard request information such as IP address for security, abuse prevention, and rate limiting. The quote endpoint keeps a short-lived per-IP counter to prevent spam submissions.
Page analytics. The public marketing pages use Cloudflare Web Analytics to count page views and see which pages people find useful. It is cookieless, it does not fingerprint your device, it does not follow you to other websites, and it does not build a profile of you. It is deliberately not loaded on the private client pages — onboarding forms, deliverable downloads, and report links — so that the secret link you were sent is never shared with an analytics service. There is no advertising technology anywhere on this site.
How it is used
To prepare quotes, deliver the work you engaged Boundary HR to do, communicate with you about it, send invoices, and meet record-keeping obligations. It is not used to build advertising profiles and is not shared with anyone for their own marketing.
Quote submissions are also reviewed in aggregate — which packages get requested, typical company size, which states come up most — to understand demand and shape the services offered. That is counting, not profiling: it uses only what people typed into the quote form, and nothing from it is sold, shared, or used to target anyone.
Where it is stored
Form submissions and client records are stored using Cloudflare's data services. Uploaded documents are stored in private Cloudflare object storage that is not publicly reachable — files are served only through an authenticated administrative endpoint.
Access to the administrative dashboard is restricted by Cloudflare Access and requires a Google sign-in on an explicitly allowed account. In practice one person — Harrison Larsen — has access.
Secret links instead of client accounts
Clients are not asked to create accounts or passwords. Instead, onboarding forms, deliverable downloads, and online reports are reached through long, unguessable links unique to you. Holding the link is what grants access, so treat those links like passwords: don't post them publicly or forward them to anyone who shouldn't see the contents. These pages ask search engines not to index them and are configured not to leak the link address to other sites.
If a link is ever exposed, tell me and I will revoke it and issue a new one.
Service providers
A small number of vendors process information on Boundary HR's behalf:
- Cloudflare — website hosting, data storage, file storage, administrative access control, and cookieless page analytics on the public marketing pages.
- Square — invoicing and payment processing. When you pay an invoice you enter your card or bank details on Square's own secure page. Those details are never entered on this site and Boundary HR never receives or stores them.
- Microsoft 365 — business email and scheduling.
- Calendly — booking intro calls. The scheduling page is Calendly's own site, opened in a new tab; no Calendly code runs on boundaryhr.com. If you book a call, the name and email you give Calendly are held by them under their privacy policy. This is being replaced by Microsoft Bookings.
- Resend — automated transactional email, such as an onboarding invitation or a notice that your deliverable is ready.
Each is used for that purpose only. Information is not sold or shared for anyone else's marketing.
How long it is kept
Uploaded documents are deleted at the close of the engagement. Closing out an engagement permanently removes the files you uploaded and disables your onboarding link. You can ask for this sooner at any point after delivery.
Client records and delivered work — the report and documents produced for you, plus basic engagement details — are retained afterward so that your deliverables remain available and for tax and business records.
Quote submissions that never become engagements are kept while they are still a live prospect and deleted on request.
Your choices
Write to [email protected] to ask what is held about you, correct it, have uploaded documents deleted, have a quote submission deleted, or have an access link revoked. There is no form to fill in and no charge. Depending on where you live you may have additional rights under state privacy law; those requests are honored regardless of whether the law strictly applies.
Requests to delete records needed for tax or legal obligations may be limited to what can lawfully be removed, and I will say so plainly rather than quietly declining.
Security, stated honestly
Uploaded files are kept in private storage, the administrative area sits behind an identity-provider login, client-facing links are long random values, and state-changing administrative actions are protected against cross-site request forgery. No system is perfectly secure, and this one is run by a single practitioner rather than a security team. If you become aware of a vulnerability, please report it to [email protected].
Business contacts, not consumers
This site serves businesses. It is not directed to children, and information about children is not knowingly collected.
Changes
If this policy changes materially, the date at the top will be updated and current clients will be told directly rather than left to notice.
Contact
Boundary HR · [email protected]
Boundary HR is not a law firm and nothing on this site is legal advice.