← The Course Closer

DRAFT — not legal advice, have a lawyer or a service like Termly/Rocket Lawyer review before publishing.

Privacy Policy

The Course Closer Operated by [YOUR BUSINESS ENTITY NAME] Website: thecoursecloser.com Contact: [INSERT SUPPORT EMAIL] Last updated: [INSERT PUBLISH DATE]

This Privacy Policy explains what information we collect when you visit thecoursecloser.com, join our waitlist/email list, or purchase The Course Closer, how we use it, and what rights you have over it. "We," "us," and "our" refer to [YOUR BUSINESS ENTITY NAME].

We do not operate our own payment system and we do not store passwords. Payments are handled entirely by Stripe's hosted checkout, and account access is granted through a one-time email link rather than a password you set with us.


1. What We Collect

Information you provide directly:

  • Email address (when you join our waitlist, subscribe to our list, or purchase the Course). Your email is also your login identity.
  • Purchase information (which tier you bought, purchase date) — held in our Stripe account, described below
  • Any information you send us directly, e.g., in a refund request or support email (such as worksheet responses you choose to share)

Information we do NOT collect or store:

  • Full payment card numbers, CVV, or bank details. These are entered on Stripe's own hosted checkout page and go straight to Stripe. They never touch our website. We can see only limited transaction metadata (e.g., last 4 digits, purchase amount) in our Stripe dashboard, as needed to process orders, refunds, and support requests.
  • Passwords. We do not use passwords at all. Access is granted through a time-limited link sent to your email address, so there is no password of yours for us to store or lose.

Information collected automatically:

  • A single essential cookie that keeps you logged in after you use your access link. It contains a signed token, not your personal details.
  • [NEEDS REVIEW: If you add analytics or advertising pixels (e.g., Google Analytics, Meta Pixel), name them here before publishing. As built, the site ships with none.]

2. How We Use Your Information

We use the information collected to:

  • Deliver the Course and process your purchase, access, and any refund requests
  • Send you transactional emails (purchase receipts, access links, support replies)
  • Send you marketing emails if you've opted in — waitlist nurture sequences, new content, launch announcements, and offers related to The Course Closer
  • Improve our sales page, course content, and marketing based on aggregate (non-identifying) behavior patterns
  • Prevent fraud and enforce our Terms of Service (e.g., investigating chargebacks or access-sharing violations)
  • Comply with legal, tax, and accounting obligations related to processing payments

We do not sell your personal information to third parties.


3. Who We Share Data With (Third-Party Processors)

We use the following third-party services to run this business. Each processes certain personal data on our behalf, governed by their own privacy policies:

ProviderWhat they handleTheir privacy policy
StripePayment processing, card data, transaction records, fraud prevention, and the record of who has purchasedhttps://stripe.com/privacy
[HOSTING PROVIDER, e.g. Vercel]Website hosting and server logs[INSERT LINK]
[EMAIL PROVIDER, e.g. Resend]Sending access links, receipts, and marketing emails[INSERT LINK]

[NEEDS REVIEW: confirm these match the providers you actually sign up with, and add a row for any analytics or ad pixel you enable.]

We do not share your personal information with any other third party except:

  • As required by law, subpoena, or legal process
  • To protect our rights, safety, or property, or that of our customers
  • In connection with a sale, merger, or transfer of the business (in which case affected users would be notified)

4. Cookies

As built, our website sets exactly one cookie:

  • An essential login cookie — set only after you use an access link, so you stay logged in between visits. It holds a signed token, not your personal details, and is required for the course area to work.

We do not currently use analytics, advertising, or tracking cookies, so no cookie consent banner is shown. You can control cookies through your browser settings at any time.

[NEEDS REVIEW: if you later add analytics or ad pixels, this section must be updated and a consent banner will likely be required for EU/UK visitors under GDPR.]


5. Data Retention

  • We retain purchase and transaction records for as long as required for accounting, tax, and legal purposes (typically at least [INSERT RETENTION PERIOD, e.g., 7 years] per standard business record-keeping practice — confirm with your accountant).
  • We retain email marketing data (name, email, engagement history) for as long as you remain subscribed. You can unsubscribe at any time (see Section 6).
  • Course access is derived from your Stripe purchase record rather than a separate account database, so it persists for as long as that purchase record is retained.

6. Your Rights and Choices

Depending on where you live, you may have rights under laws such as the EU/UK GDPR or U.S. state privacy laws (e.g., California's CCPA/CPRA). These can include the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your personal data ("right to be forgotten"), subject to our legal obligation to retain certain transaction/tax records
  • Opt out of marketing emails at any time via the unsubscribe link in any email, or by emailing us directly
  • Opt out of the sale of personal data — we do not sell personal data, so this does not apply, but you retain the right to ask
  • Data portability — request a copy of your data in a portable format

To exercise any of these rights, email us at [INSERT SUPPORT EMAIL]. We will respond within the time required by applicable law (commonly 30 days).

Because payment and purchase data live in Stripe's systems, some requests (e.g., full deletion of payment history) may require us to coordinate with Stripe, and some data may need to be retained regardless of a deletion request to comply with tax/accounting law. Note that deleting your purchase record also removes your access to the Course.


7. Children's Privacy

The Course is not directed at, marketed to, or intended for use by children. We do not knowingly collect personal information from anyone under 18. If we learn we've collected information from a child under 18, we will delete it.


8. International Visitors

Our business, and the third-party providers we use (Stripe, our hosting provider, and our email provider), may process and store data in the United States or other countries. By using our site or purchasing the Course, you understand your information may be transferred to and processed in a country different from your own, which may have different data protection laws than your home jurisdiction.


9. Data Security

We deliberately minimise what we hold. We do not store passwords, and card details are handled entirely by Stripe's PCI-compliant hosted checkout rather than passing through our site. The site is served over HTTPS with standard security headers, and access to the course area is granted by a signed, time-limited email link. We also apply account-level security practices on our end — such as two-factor authentication on our Stripe, hosting, domain, and email accounts. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.


10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page. Continued use of the site or Course after changes are posted constitutes acceptance of the updated policy.


11. Contact Us

Questions about this Privacy Policy or your data can be sent to: [INSERT SUPPORT EMAIL]

[NEEDS REVIEW: if you register a business entity with a mailing address, add it here — some laws (e.g., CCPA) expect a physical or registered contact address in addition to email. A registered-agent or virtual business address is the usual way to satisfy this without publishing a home address.]


This document is a draft template prepared for internal use and is not a substitute for legal advice. Have a licensed attorney, or a reputable legal-document service (e.g., Termly, Rocket Lawyer, TermsFeed), review this policy — particularly Sections 3, 6, and 8 — for compliance with GDPR, CCPA/CPRA, and any other regimes relevant to where your customers are located, before publishing it live or collecting emails against it.