Clemenza Law Group

    Privacy Policy

    Last updated August 19, 2026

    Most privacy policies are written to survive a deposition rather than to be read. This one is written to be read, and it is short because this website does not do much with your information.

    Where a comfortable phrase and an accurate one were available, the accurate one is below.

    Two different kinds of confidentiality

    One is the privacy of a website visitor, which is what this page governs. The other is the confidentiality a lawyer owes a client under Rule 1.6 of the New York Rules of Professional Conduct, which is a professional duty and is far stronger than anything a privacy policy can promise.

    Reading this site does not make you a client. Information you send through a form before we have run a conflicts check and both signed an engagement agreement is not protected by the attorney-client privilege. That is why the forms say so, and why we ask you to describe your situation in general terms until we have told you it is safe to do otherwise.

    What you give us

    Only what you type, and only on the pages that ask for it.

    Contact and intake forms
    Your name, email, phone, and whatever you choose to write in the message. The intake wizard also records which door you came through, so the first call starts further along.
    Consultation booking
    The same contact details, plus the time you choose.
    Mailing lists
    Your email address, and the date you subscribed. Every message carries an unsubscribe link that works on the first click.
    Payment
    Card numbers never reach us. Stripe collects them on its own systems; what comes back to us is the last four digits, the brand, and whether the charge succeeded.
    The client portal
    If you become a client, the portal holds your matter records, documents, messages, invoices, and signatures. That material is client information first and website data second, and it is handled under your engagement agreement and Rule 1.6.

    What your browser gives us

    Every web server records the request that reaches it: an IP address, the browser and operating system, the page asked for, and the time. Our host keeps those logs for operations and security. We do not use them to build a profile of you, and we do not combine them with anything else.

    The forms are checked by Cloudflare Turnstile, which decides whether a submission is coming from a person or a script. It sees the request; it does not see what you wrote.

    Analytics, and only if you say yes

    Google Analytics 4 and Microsoft Clarity load only after you press Accept on the cookie notice. Before that they are not on the page: not deferred, not anonymized, not present. Decline and nothing about the site changes except that we learn less.

    Two things are stored on your device regardless, because without them the site cannot do what you asked. One is your answer to the cookie notice, so we stop asking. The other, only if you sign in to the client portal, is the session that keeps you signed in.

    You can change your answer at any time from “Cookie preferences” at the foot of every page.

    Who else handles it

    A small firm runs on other people’s infrastructure. These are the companies that touch your information, and what each one does:

    Vercel
    Serves this website and keeps the request logs described above.
    Supabase
    The database, sign-in, and file storage behind the site and the client portal.
    Stripe
    Takes payments. Card details go to Stripe and stop there.
    Resend
    Sends the mail — confirmations, notifications, and the lists you asked to be on.
    Cloudflare
    Runs the Turnstile check on the forms.
    Google and Microsoft
    Analytics and session replay, and only after you have accepted.
    Plaid
    Connects the firm’s own attorney trust account to its reconciliation records. It is named here for completeness; it never touches a client’s bank account.

    Each is a vendor under contract to us. None of them is given your information for its own marketing. We do not sell personal information, which is a phrase with a specific legal meaning and carries no asterisk here.

    How long we keep it

    An inquiry that does not become an engagement is kept while it may still matter to a conflicts check, and then deleted. What survives is a conflicts record: names, dates, and the general subject. A firm keeps that permanently, because it is how it knows years later whose adversary it cannot become.

    Client files are kept for the period stated in your engagement agreement, and destroyed on the schedule that agreement sets.

    What you can ask for

    Write to us and ask what we hold, ask for a copy, ask us to correct it, or ask us to delete it. Two honest limits. We cannot delete what a court, a tax authority, or the Rules of Professional Conduct require us to keep. And we will confirm who you are before we act, because “delete my file” is exactly what someone else would say.

    If you are in the European Union, the United Kingdom, or California, the rights above are the ones those laws give you. We apply them to everyone rather than running two policies and hoping the right one is showing.

    Children

    This site is not intended for anyone under sixteen, and we do not knowingly collect information from them.

    Changes, and how you will know

    The date at the top of this page is the date it last changed in substance. If a change is material, it will be flagged on the site rather than slipped in under a new timestamp.

    Who to write to

    The Clemenza Law Group PLLC, 21 West End Avenue, Suite 3606, New York, NY 10023. info@clemenzalaw.com · (212) 365-4875. The firm is the controller of the information described on this page.