1. Introduction and who we are
This Privacy Policy explains how COMPANY_LEGAL_NAME_PLACEHOLDER, a limited liability company organized in the State of Texas, United States (“we,” “us,” “our,” or the “Company”), collects, uses, shares, and protects your personal information when you use The English Dojo and related services (the “Service”). We aim to collect as little as possible.
We offer the Service to users around the world. Depending on where you live, different privacy laws may give you specific rights, which are described in Section 9. For users in the European Economic Area (“EEA”), the United Kingdom, and Switzerland, we act as the “controller” of your personal data. If you have any questions, contact us using the details in Section 13.
2. Information we collect
Information you provide to us:
- Account details — your email address, and a name if you choose to provide one, from signing in with a one-time email link.
- Purchase information — a record of your transaction and the access you bought. Payment is handled by Stripe; we receive a confirmation and customer reference and never see or store your full card details.
- Communications — messages you send us, such as support requests or feedback.
Information collected automatically when you use the Service:
- Usage data — such as your IP address, browser and device type, and which lessons you have marked complete, so we can show your progress.
- Sign-in security logs — to protect your account, we record sign-in attempts (successful and failed), including the time, IP address, browser/device, and — where this feature is enabled — an approximate location derived from the IP address. We use this to detect and investigate suspicious account activity.
- An essential cookie — to keep you signed in (see Section 6).
- Analytics data — if you consent to analytics cookies, we receive aggregated statistics about how the Service is used (see Section 6). We do not collect this unless you opt in.
Information from third parties: limited transaction and fraud-prevention information from our payment processor.
3. How we use your information (and legal bases)
We use personal information to operate, secure, and improve the Service. Where the EU/UK GDPR applies, we rely on the legal bases noted below.
| Purpose | Legal basis (where the GDPR applies) |
|---|---|
| Create and manage your account and give you access to the course | Performance of our contract with you |
| Process your payment and prevent fraud | Contract; legal obligation; legitimate interests |
| Respond to your support requests | Contract; legitimate interests |
| Keep the Service secure, including sign-in security logging | Legitimate interests |
| Measure and improve the Service through analytics | Consent — set only if you opt in, and you can withdraw at any time |
| Send service emails (such as your sign-in link and receipts) | Performance of our contract with you |
| Send marketing emails, where you have opted in | Consent — you may withdraw it at any time |
| Comply with tax, accounting, and legal obligations | Legal obligation |
We do not sell your personal information. See Section 9 for how certain laws treat the “sale” or “sharing” of personal information and your related rights.
4. How we share information
We share personal information only as needed to run the Service, and never for others’ independent marketing. Our service providers are required to protect your information and to use it only to provide services to us:
- Stripe — payment processing and fraud prevention.
- Resend — transactional email, such as your sign-in link and receipts.
- Google Cloud — hosting, database, and file storage.
- Google Analytics — optional website analytics, provided by Google, used only if you consent to analytics cookies.
- An IP-geolocation provider — where enabled, to approximate the location of a sign-in attempt for the security logs described in Section 2.
We may also disclose information to professional advisors, to authorities where required by law or to protect rights, safety, and security, and to a successor entity in connection with a merger, acquisition, or sale of assets.
5. International data transfers
We are based in the United States, and our service providers may be located in the United States and other countries. If you are located outside the United States, your information will be transferred to and processed in countries whose data-protection laws may differ from those in your country. For transfers of EEA, UK, or Swiss personal data to countries not recognized as providing adequate protection, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant). You can request more detail using the contact in Section 13.
6. Cookies
We use a strictly necessary cookie to keep you signed in and secure your session; because it is essential to operate the Service, it does not require consent. With your consent, we also use Google Analytics cookies to understand how the Service is used so we can improve it — these are set only after you opt in through our cookie banner, and you can change or withdraw your choice at any time. We do not use advertising or marketing cookies. For the full list and how to manage your choices, see our Cookie Policy.
7. Data retention
We keep personal information for as long as your account is active and for as long as needed to provide the Service, and then for a reasonable period afterward to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. The sign-in security logs described in Section 2 are kept only for a limited retention period and are then automatically deleted.
8. How we protect information
We use reasonable technical and organizational measures designed to protect personal information, such as encryption in transit, access controls, and the use of reputable service providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your privacy rights
Depending on where you live, you may have some or all of the rights below. We will not discriminate against you for exercising them. To make a request, contact us as described in Section 13; we may need to verify your identity before responding.
EEA, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP). You have the rights to access your personal data; correct inaccurate data; request erasure; restrict or object to certain processing; data portability; and, where processing is based on consent, withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local data-protection supervisory authority.
California (CCPA / CPRA) and other U.S. state laws. You have the rights to know what personal information we collect and how we use and disclose it; access, correct, and delete your information; and opt out of the “sale” or “sharing” of personal information and certain targeted advertising. We do not sell your personal information for money. To the extent our use of analytics cookies is treated as “sharing” for cross-context behavioral advertising under some U.S. state laws, you can opt out at any time by declining or withdrawing analytics consent through our cookie banner. Residents of other U.S. states with comprehensive privacy laws may have similar rights, which we honor where they apply to you.
Other regions. If you are in Canada, Brazil (LGPD), Australia, or another jurisdiction with applicable privacy laws, you may have rights to access, correct, and delete your personal information and to withdraw consent. Contact us and we will respond as required by the law that applies to you.
10. Marketing communications
Where we send marketing emails, you can opt out at any time using the unsubscribe link in the message or by contacting us. We will still send essential service-related messages, such as your sign-in link, receipts, or important account notices.
11. Children’s privacy
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children under the age set by applicable law (for example, under 16 in parts of the EEA, or under 13 in the United States under COPPA). If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after the changes take effect means you accept the updated policy.
13. How to contact us
For privacy questions or to exercise your rights, contact:
COMPANY_LEGAL_NAME_PLACEHOLDER
COMPANY_ADDRESS_PLACEHOLDER
Email: info@english-dojo.app