ClassSync Privacy Policy
Last updated: July 1, 2026 Effective date: July 1, 2026
1. Introduction
This Privacy Policy explains how ClassSync, Corp., 144 Firefly, Irvine, CA 92618 (“ClassSync,” “we,” “us”) collects, uses, shares, and protects personal information when you use our websites, applications, and services (the “Services”). It also describes your privacy rights and how to exercise them.
Our two roles. ClassSync plays two different roles depending on whose data is involved:
-
As a business (controller) for the information of Operators — the academies, coaches, schools, and organizations who use ClassSync to build and sell courses — and for visitors to our own sites.
-
As a service provider (processor) for the information about an Operator’s own Learners/customers that the Operator collects through the Services. In that case, the Operator is the business responsible for that data, decides how it is used, and must provide its own privacy notice. We process Learner data on the Operator’s behalf and under our agreement with them.
By using the Services, you acknowledge this Policy. If you do not agree, please do not use the Services.
2. Information We Collect
2.1 Information Operators and account holders provide. To register and use the Services, you provide your name and email address, along with a password for your account. That is the only personal information we ask you to provide. If you choose not to provide it, you will not be able to register or use certain features.
2.2 Payment information. All payments are processed by Stripe. When you or a Learner make a payment, your payment card and billing details are provided directly to Stripe and are handled under Stripe’s terms and privacy policy. We do not collect or store your payment card or billing information. We can view limited transaction records in our Stripe dashboard (such as the date, amount, card type, and last four digits of the card) to verify purchases, provide support, and manage access and refunds.
2.3 Learner information collected for Operators. To operate the Services, we store information about an Operator’s Learners so the Operator can offer and manage content — typically the Learner’s name and email address, and any additional information the Operator chooses to collect through optional custom checkout fields. Operators are responsible for the lawfulness of any information requested in those fields.
2.4 Usage and device information. Like nearly all online services, our servers automatically log limited technical information when you use the Services, such as IP address, browser and device type, operating system, and time-and-date stamps, which we use for security, troubleshooting, and operating the Services. We do not use third-party analytics or tracking services. Under California law, some of this information (for example, IP address) is “personal information.”
2.5 Sensitive personal information. We do not seek to collect sensitive personal information beyond what is necessary to provide the Services (for example, account login credentials). Under California’s updated rules, personal information of anyone under 16 is treated as sensitive personal information. We handle it accordingly and do not use it for purposes beyond providing and securing the Services without appropriate consent.
2.6 Notice at collection. This Policy, together with any notice presented at the point of collection, serves as our notice at or before the point of collection under California law: it identifies the categories of personal information we collect (Sections 2.1–2.5), the purposes for which we use them (Section 4), whether we sell or share them (we do not — Section 5), and our retention approach (Section 8).
3. Sources of Information
We collect information directly from you; automatically through your use of the Services (server logs and essential cookies); from Operators (about their Learners); and from our payment processor, Stripe.
4. How We Use Information
We use personal information to: provide, operate, secure, and improve the Services; create and manage accounts; process payments and provide access to content; authenticate users and prevent fraud and abuse; provide customer and technical support; send transactional and account communications; send marketing communications where permitted (with opt-out); comply with legal obligations; and enforce our Terms. We limit our collection, use, and retention of personal information to what is reasonably necessary and proportionate for these purposes.
5. How We Share Information
We do not rent or sell your personal information. We share it only as follows:
-
Service providers. With vendors who perform services for us — payment processing (Stripe), hosting, email delivery, and support — under contracts that limit their use of the information to providing those services.
-
Operators. Learner information is made available to the relevant Operator so they can manage their content and customers.
-
Legal and safety. When required by law, legal process, or to protect the rights, safety, or property of ClassSync, our users, or the public.
-
Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
No sale or sharing for cross-context behavioral advertising. We do not “sell” personal information or “share” it for cross-context behavioral advertising as those terms are defined under California law. We never sell or share the personal information of Learners under 16.
6. Cookies and Tracking
We use only essential cookies — those strictly necessary for the Services to function, such as login, session, security (including Stripe’s fraud-prevention cookies at checkout), and preference cookies. We do not use analytics, advertising, or tracking cookies. For details, see our Cookie Statement. You can control cookies through your browser; because our cookies are essential, disabling them may prevent sign-in or purchases. We honor recognized opt-out preference signals (such as Global Privacy Control) as required by law.
7. Children Under 13
The Services are a general-audience service and are not directed to children under 13. We do not knowingly collect personal information from anyone under 13, and Operators are prohibited from using the Services to enroll or collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly and may suspend the associated accounts. If you believe a child under 13 has provided personal information through the Services, please contact us at [email protected]. Learners aged 13–17 may use the Services only with the involvement and permission of a parent, legal guardian, or authorizing school, as described in our Terms of Use; Operators enrolling minors are responsible for any consents required by applicable law (including FERPA, where applicable).
8. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we remove associated personal data within 30 days, except for limited information we must retain for legal, tax, security, or backup purposes, which we delete on a rolling basis. We do not retain children’s personal information indefinitely.
Data breach notification. If a security incident affecting your personal information occurs, we will notify affected individuals and regulators as required by applicable law, including California Civil Code § 1798.82.
9. Your California Privacy Rights
If you are a California resident, you have the following rights, subject to legal exceptions:
-
Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it.
-
Delete personal information we collected from you.
-
Correct inaccurate personal information.
-
Opt out of any “sale” or “sharing” of personal information (note: we do not sell or share, as described in Section 5).
-
Limit the use and disclosure of sensitive personal information to what is necessary to provide the Services.
-
Non-discrimination for exercising your rights.
How to exercise. Submit a request by email to [email protected] or by mail to ClassSync, Corp., 144 Firefly, Irvine, CA 92618. We will verify your identity before responding and will respond within the timeframes required by law. A right-to-know request is not limited to the preceding 12 months: you may request personal information collected before that period (for information collected on or after January 1, 2022) where we still retain it. You may use an authorized agent to submit a request on your behalf with proper authorization. If we deny a request, you may appeal by contacting [email protected].
“Shine the Light” (Civil Code § 1798.83). California residents may request information about disclosure of personal information to third parties for those parties’ direct-marketing purposes. We do not disclose personal information to third parties for their direct-marketing purposes.
10. Other U.S. State Privacy Rights
Residents of other U.S. states with comprehensive privacy laws may have similar rights (to access, correct, delete, and opt out of certain processing). To exercise them, contact us using the details in Section 16, and we will honor rights that apply to you under your state’s law.
11. International Users and Data Transfers
The Services are operated from the United States, and your information will be processed in the United States and other locations that may not offer the same level of data protection as your home country. By using the Services, you understand your information may be transferred and processed there. If you are in the EEA or UK, you may have rights under the GDPR or UK GDPR, including access, correction, deletion, and objection; contact us to exercise them.
12. Operator Responsibilities
If you are an Operator, you are responsible for maintaining your own privacy policy that complies with the laws applicable to your business, for the lawfulness of any information you collect from your Learners (including through optional custom fields), and for obtaining any required consents (including parental or school consent for minors). You can access and delete your Learners’ data through the Services’ delete function. We recommend you consult legal counsel to protect your customers’ privacy.
13. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS), encryption of stored data where appropriate, hashing of passwords (so they are not stored in readable form and can be reset but not retrieved), access controls, and monitoring for suspicious activity. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please help protect your account by using a strong, unique password and keeping your credentials confidential.
14. Communications
When you register or transact through the Services, we may send you transactional and account communications (welcome and account information, security and product updates, and changes to our Terms or this Policy). These are part of the Service and are not marketing. We may also send marketing communications about features and offers; you can opt out of marketing at any time using the unsubscribe link or by contacting us — opting out of marketing does not stop essential transactional messages. We do not send marketing communications to Learners known to be children.
15. Changes to This Policy
We may update this Policy. If we make material changes, we will provide notice — for example, by email to registered users or a notice in the Services — before the changes take effect where required, and update the “Last updated” date. Please review it periodically.
16. Contact Us
Questions or privacy requests: [email protected] · ClassSync, Corp., 144 Firefly, Irvine, CA 92618.