Privacy policy
The Management Sherpa Privacy Policy
Effective date: August 25, 2026
Last updated: August 25, 2026
The Management Sherpa ("The Management Sherpa," "TMS," "we," "us," or "our") respects your privacy and is committed to handling personal information responsibly, transparently, and securely.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit the-management-sherpa.com or themanagementsherpa.com, create an account, purchase a product or service, subscribe to communications, participate in a course, bootcamp, coaching or consulting engagement, complete an assessment, attend an event, or otherwise interact with us (collectively, the "Services").
This policy applies when The Management Sherpa acts as the business or controller responsible for deciding how and why personal information is used. When we process information for an organizational client under that client's instructions, the client may be the controller or business and its privacy notice may also apply.
1. Who We Are
The Management Sherpa provides leadership development, sales enablement, organizational development, coaching, consulting, assessments, learning programs, memberships, books, digital content, and related services.
You may contact us at:
Email: info@themanagementsherpa.com
United States: 6338 Snider Road, #76, Mason, Ohio 45040, United States
United Kingdom: 124 City Road, #2268, London EC1V 2NX, United Kingdom
Telephone: +1 513 828 9352 or +44 0203 929 2030
2. Personal Information We Collect
The information we collect depends on how you interact with us.
Information you provide directly
We may collect:
-
Identity and contact information, such as your name, email address, telephone number, billing and shipping address, employer, job title, and professional profile information.
-
Account information, such as login credentials, account preferences, membership status, course enrollment, progress, and completion records.
-
Transaction information, such as products or services purchased, order history, payment status, billing details, and tax-related information. Payment card data is generally collected and processed by our payment providers rather than stored directly by us.
-
Program and service information, such as event registrations, course responses, assignments, survey answers, goals, action plans, coaching notes, communications, and feedback.
-
Assessment information, such as responses to leadership, sales, team, personality, strengths, 360-degree, or other professional assessments and the reports or insights generated from them.
-
Communications, including information you provide through contact forms, email, telephone, virtual meetings, customer support, testimonials, reviews, and social media interactions.
-
Marketing preferences, including newsletter subscriptions and communication choices.
-
Job or contractor information, if you apply to work with us.
Please avoid providing sensitive personal information unless it is necessary for a specific service and we have asked you to provide it. Coaching conversations and assessment responses may reveal sensitive information. We will process such information only when appropriate safeguards and a valid legal basis are in place.
Information collected automatically
When you use our websites or digital services, we and our service providers may automatically collect:
-
IP address and approximate location;
-
browser, device, and operating-system information;
-
cookie identifiers and similar online identifiers;
-
pages viewed, links clicked, referring pages, session activity, and timestamps;
-
shopping-cart, checkout, account, and site-performance information; and
-
information about how you interact with our emails and advertisements, where permitted.
Information received from other sources
We may receive information from:
-
your employer, sponsor, manager, or another organization that enrolls you in a program or purchases services for you;
-
assessment, learning-management, event, video-conferencing, scheduling, customer-relationship-management, and payment providers;
-
business partners, referral sources, publicly available professional sources, and social media platforms; and
-
Shopify and other providers that support our website, commerce, analytics, and advertising functions.
If an organizational client provides information about you, that organization is responsible for having authority to provide it and for giving any notice required by law.
3. How and Why We Use Personal Information
We may use personal information to:
-
provide, personalize, administer, and support the Services;
-
create and manage accounts, memberships, purchases, course access, and certifications;
-
process orders, payments, refunds, shipping, and tax obligations;
-
deliver coaching, consulting, assessments, learning programs, reports, and events;
-
communicate with you about services, appointments, transactions, support requests, and program participation;
-
send newsletters, invitations, educational content, and promotional communications in accordance with your choices and applicable law;
-
understand how our Services are used, improve content and functionality, and develop new offerings;
-
measure marketing effectiveness and, where permitted, personalize advertising;
-
protect our users, systems, business, and rights; prevent fraud or misuse; and maintain security;
-
comply with legal, accounting, tax, contractual, and regulatory obligations; and
-
establish, exercise, or defend legal claims.
We may aggregate or de-identify information so that it can no longer reasonably identify an individual. We may use and disclose properly aggregated or de-identified information for research, benchmarking, service improvement, and business analysis, subject to applicable law. We will not attempt to re-identify information that applicable law requires us to maintain in de-identified form.
4. Legal Bases for UK and European Processing
Where UK or European data protection law applies, we rely on one or more of the following legal bases:
-
Contract: processing is necessary to enter into or perform a contract with you, including providing purchased products, programs, memberships, coaching, or support.
-
Legitimate interests: processing is necessary for our legitimate business interests, such as operating and improving our Services, communicating with organizational clients, protecting security, preventing fraud, and limited business-to-business marketing, provided those interests are not overridden by your rights and interests.
-
Consent: you have consented to a particular use, such as certain marketing, non-essential cookies, testimonials, recordings, or processing of particular sensitive information. You may withdraw consent at any time, without affecting prior lawful processing.
-
Legal obligation: processing is necessary to comply with applicable law, regulation, court order, tax, accounting, or other legal requirements.
-
Vital interests or public task: in the uncommon situation in which one of these bases applies.
Where we process special-category data, we will also identify an additional condition required by applicable law, such as explicit consent or the establishment, exercise, or defense of legal claims.
5. Assessments, Coaching, and Employer-Sponsored Programs
Our professional-development services may involve information that deserves particular care.
-
We use assessment responses, coaching information, course activity, and related information to deliver the relevant service, create reports, support development, and evaluate program effectiveness.
-
Before an employer-sponsored engagement, we aim to clarify what information will be shared with the sponsoring organization. Depending on the engagement, this may include participation, completion, aggregate trends, agreed goals, or assessment reports.
-
We do not represent coaching as legally privileged or as medical or mental-health treatment. We may disclose information when required by law or when reasonably necessary to address a serious threat to health or safety.
-
We do not use assessment or coaching information to make solely automated decisions that produce legal or similarly significant effects unless we provide any notice, safeguards, and choices required by law.
Engagement-specific terms, consent forms, or notices may supplement this policy. If those materials conflict with this policy regarding an engagement, the more specific terms will govern to the extent permitted by law.
6. Cookies and Similar Technologies
We use cookies, pixels, local storage, and similar technologies to operate the website, remember preferences, understand site use, protect transactions, and support marketing.
These technologies may include:
-
Strictly necessary technologies required for security, checkout, account access, and core site functions;
-
Functional technologies that remember choices and enhance features;
-
Analytics technologies that help us understand traffic and improve performance; and
-
Advertising technologies that may measure campaigns or personalize advertising across websites or services.
Where required, we ask for consent before using non-essential cookies. You can use our cookie preference tool to accept, reject, or change your choices. You may also adjust browser settings, although blocking necessary cookies may affect site functionality.
Where required by applicable law, we recognize supported browser-based opt-out preference signals, such as the Global Privacy Control, as a request to opt out of sale, sharing, or targeted advertising for the browser or device sending the signal.
For more detail about specific cookies, providers, purposes, and durations, please see our Cookie Policy or cookie preference tool.
7. How We Disclose Personal Information
We may disclose personal information to:
-
Service providers and processors that support website hosting, ecommerce, payments, order fulfillment, cloud storage, email, customer relationship management, analytics, advertising, scheduling, video conferencing, learning management, assessments, surveys, IT, security, and professional services. These providers may include Shopify and providers selected for a particular program or transaction.
-
Organizational clients and sponsors when they purchase or administer services for participants, subject to the engagement terms and notices described above.
-
Business partners and instructors when needed to deliver a co-sponsored event, course, assessment, or other requested service.
-
Professional advisers, such as attorneys, accountants, auditors, insurers, and consultants.
-
Government authorities or other parties when required by law or reasonably necessary to protect rights, safety, security, users, or the public; investigate fraud; enforce agreements; or respond to lawful process.
-
Parties to a business transaction, such as a merger, financing, reorganization, acquisition, or sale of assets, subject to appropriate confidentiality and legal safeguards.
-
Other parties at your direction or with your consent.
We do not sell personal information for money. Some privacy laws define "sale," "sharing," or "targeted advertising" broadly enough to include certain disclosures involving analytics or advertising technologies. If we engage in activity covered by those definitions, you may opt out through our cookie preference tool, a "Your Privacy Choices" link, a supported opt-out preference signal, or by contacting us.
We do not knowingly sell or share the personal information of anyone under 18 for targeted advertising.
8. International Data Transfers
We operate and use service providers in the United States, the United Kingdom, and other countries. As a result, personal information may be transferred to or accessed from a country whose laws provide a different level of protection.
Where UK or European law requires a transfer mechanism, we use appropriate safeguards, which may include an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another lawful mechanism. You may contact us for more information about relevant safeguards.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide Services, maintain business and tax records, resolve disputes, enforce agreements, protect security, and comply with law.
Retention depends on the nature and sensitivity of the information, the relationship, legal requirements, and the risk associated with continued retention. As a general framework:
-
transaction, tax, and core contract records are ordinarily retained for up to seven years after the relevant transaction or relationship, unless a different period is required;
-
account, course, membership, and customer-service records are ordinarily retained while the account or relationship is active and for a reasonable period afterward;
-
coaching notes, assessment data, recordings, and participant-level program records are retained according to the applicable engagement terms and are deleted or de-identified when no longer needed;
-
marketing contact information is retained until you unsubscribe, object, or we determine it is no longer current, with limited suppression records retained to honor your choice; and
-
cookie and analytics information is retained according to the settings disclosed in our cookie preference tool and the applicable provider's configuration.
We may retain information longer when required by law, reasonably necessary for a legal claim, or requested by you.
10. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, taking account of the nature of the information and the risks involved. These measures may include encryption in transit, access controls, provider due diligence, authentication, backups, and security monitoring.
No method of transmission or storage is completely secure. You are responsible for protecting your credentials and should notify us promptly if you believe your account or interaction with us has been compromised.
If a personal-data breach occurs, we will investigate and provide notices to individuals, clients, regulators, or other parties when required by applicable law.
11. Your Privacy Rights and Choices
Depending on where you live and subject to applicable exceptions, you may have the right to:
-
request access to or a copy of your personal information;
-
request correction of inaccurate information;
-
request deletion of personal information;
-
request restriction of or object to certain processing;
-
receive certain information in a portable format;
-
withdraw consent where processing relies on consent;
-
opt out of direct marketing;
-
opt out of sale, sharing, targeted advertising, or certain profiling;
-
limit certain uses or disclosures of sensitive personal information;
-
appeal our decision on a privacy request; and
-
receive equal service and pricing and not be discriminated against for exercising a privacy right.
You may exercise a right by emailing info@themanagementsherpa.com with the subject line Privacy Request, or by using any privacy request or preference tool made available on our website. Please describe your request and the jurisdiction in which you reside.
We may need to verify your identity before completing a request. Verification will be proportionate to the request and the sensitivity of the information involved. You may use an authorized agent where permitted by law; we may request proof of the agent's authority and, when lawful, direct identity confirmation from you.
We will respond within the time required by applicable law. If we deny a request, we will explain the basis for the decision and any available appeal process. To appeal, email us with the subject line Privacy Appeal. We will not discriminate against you for exercising a privacy right.
Marketing choices
You may unsubscribe from promotional email by using the unsubscribe link in the message or contacting us. We may still send non-promotional communications concerning transactions, accounts, programs, security, or our ongoing relationship with you.
UK and European complaints
If UK data protection law applies, you may complain to the UK Information Commissioner's Office at ico.org.uk. If European Economic Area law applies, you may complain to the data-protection authority where you live, work, or believe an infringement occurred. We encourage you to contact us first so we can try to address your concern.
12. U.S. State Privacy Disclosures
The categories of personal information we may collect are described in Section 2. The sources, purposes, and categories of recipients are described in Sections 2, 3, and 7. The applicable retention criteria are described in Section 9.
Depending on your state's law and whether that law applies to us, the information we collect may include identifiers, customer records, commercial information, internet or electronic-network activity, professional information, inferences, account credentials, payment-related information handled by payment providers, and information that may be treated as sensitive under applicable law.
We do not use or disclose sensitive personal information for purposes that require a right to limit under California law unless we provide the required notice and choice. We do not offer financial incentives in exchange for personal information unless we first provide the notice required by law.
California's "Shine the Light" law may permit California residents to request certain information about disclosures of personal information to third parties for their own direct-marketing purposes. You may submit such a request using the contact information in Section 16.
13. Children
Our Services are intended for adults and professional audiences. They are not directed to children under 13 in the United States or under the minimum age required for independent consent in another jurisdiction. We do not knowingly collect personal information from a child in violation of applicable law.
If a program is specifically designed for minors, we will use appropriate notices, permissions, contracts, and safeguards. If you believe a child has provided information improperly, please contact us so we can investigate and delete it where required.
14. Third-Party Sites and Services
Our Services may link to or integrate with third-party websites, social networks, applications, or services. Their privacy practices are governed by their own notices. We encourage you to review those notices before providing information.
15. Changes to This Policy
We may update this Privacy Policy to reflect changes in our Services, practices, technologies, or legal obligations. We will post the updated policy on this page and revise the "Last updated" date. If changes are material, we will provide additional notice when required by law, such as by email, account notice, or a prominent website message.
16. Contact Us
Questions, concerns, or privacy requests may be directed to:
The Management Sherpa
Email: info@themanagementsherpa.com
Subject line: Privacy Request
United States: 6338 Snider Road, #76, Mason, Ohio 45040, United States
United Kingdom: 124 City Road, #2268, London EC1V 2NX, United Kingdom
We will make reasonable efforts to address your inquiry promptly.
Publication and Governance Checklist (Do Not Publish as Part of the Policy)
Before publishing, The Management Sherpa should confirm and document the following:
-
Legal identity: Replace “The Management Sherpa” with the full legal name of the entity or entities acting as controller/business. Clarify whether the UK address is an establishment, affiliate, representative, or mailing address.
-
Data map: Inventory every form, checkout, CRM, email platform, LMS, assessment platform, coaching system, analytics tag, advertising pixel, scheduling tool, videoconferencing tool, cloud drive, and payment provider.
-
Cookie compliance: Configure a consent platform that blocks non-essential cookies before consent where UK/EU law applies. Publish a current cookie table and enable users to reopen preferences.
-
U.S. opt-outs: If advertising or analytics activity is legally considered sale, sharing, or targeted advertising, add a conspicuous “Your Privacy Choices” link and honor Global Privacy Control signals.
-
Marketing: Confirm consent and unsubscribe processes for email and text marketing under applicable U.S., UK, and European rules. Keep suppression records.
-
Client programs: Use written data-processing and confidentiality terms for employer-sponsored assessments, 360 feedback, coaching, and LMS programs. Tell participants exactly what individual-level information will be shared with sponsors.
-
Assessment vendors: Identify controller/processor roles, retention, sub-processors, international transfers, security controls, and deletion processes for each assessment platform.
-
Retention: Approve a written retention schedule with specific periods for coaching notes, 360 feedback, recordings, LMS activity, inactive accounts, prospects, contracts, tax records, and backups.
-
International transfers: Put appropriate contractual safeguards in place for transfers from the UK/EEA to the United States and complete transfer-risk assessments where required.
-
Privacy requests: Assign an owner, create an identity-verification process, log requests and deadlines, and prepare response and appeal templates.
-
Security and incidents: Maintain access controls, multi-factor authentication, vendor review, backup practices, an incident-response plan, and a jurisdiction-specific breach-notification matrix.
-
Contracts and notices: Align the policy with client contracts, coaching agreements, assessment consents, event releases, recording notices, terms of service, and internal practice.
-
Applicability review: Confirm which U.S. state comprehensive privacy laws apply based on revenue, data volume, business model, and jurisdiction-specific thresholds.
-
Children: Confirm whether any Ubuntu Leadership Academy or other youth-oriented activity shares systems or data with The Management Sherpa. If so, use a separate child-appropriate privacy process and do not rely on this general policy alone.
-
Annual review: Review the privacy policy, cookie inventory, vendor list, retention schedule, and data map at least annually and whenever practices materially change.
Legal review recommended: This draft is a governance-oriented starting point and should be reviewed by qualified privacy counsel before publication, particularly because The Management Sherpa operates across the United States and United Kingdom and may handle confidential coaching and assessment data.