Privacy Policy

Last updated: August 25, 2026

This policy explains what information TheCertCoach handles, why we use it, and the choices available to you. We aim to collect only what we need to operate and improve the site.

What We Collect

Account Data

When you create an account, we use Clerk for authentication and account management. Clerk handles your login credentials and stores information such as your email address, account identifier, and name if you provide one. We receive the account information needed to sign you in and provide the service, but we do not store your password.

Billing Data

If Stripe Checkout or the Stripe customer portal is enabled for your account and you choose to use it, Stripe receives your verified account email and the payment and billing information you submit on Stripe’s hosted pages. TheCertCoach does not receive or store your full payment-card number. We receive and retain the Stripe customer, Checkout, price, and subscription identifiers and the product, test-or-live mode, Checkout or subscription status, billing-period dates, cancellation state, and event timestamps needed to connect that billing relationship to your TheCertCoach account and determine access. Before completing an account-deletion request, we dispose of our open hosted Checkout sessions, immediately cancel any active individual subscription, revoke its access, and replace the raw account link in our live billing ledger with a pseudonymous identifier. We also retain a private pseudonymous billing-erasure marker outside the billing ledger so restoring an older ledger cannot recreate the deleted billing relationship. Refund decisions are handled separately from technical cancellation.

Email for Notifications

If you request sample lessons or join a newsletter or certification notification list, we store your email address, the list or request you selected, signup and delivery timestamps, delivery status, and subscription status on our server. We also store a one-way hash of a random unsubscribe token; we do not store the usable token itself. Postmark processes your email address and message details to deliver the email.

Support, Certification Requests, and Content Reports

If you use a signed-in form to contact support, request another certification, or report a content issue, we receive your account name and email address with the fields you submit. Depending on the form, those fields can include a subject, message, certification name, page path, module or item identifier, issue category, and your description of the concern. The site sends the submission to our support mailbox through Postmark; it is not added to an email subscription merely because you sent a form.

Please do not include passwords, sensitive personal information, or recalled questions from a live certification exam in a support or content report.

Study Progress

The site stores learning activity in your browser's localStorage. Depending on the feature you use, this can include completed and visited modules, practice-exam history, study schedules, Study Profile responses, confidence ratings, notes, bookmarks, module quiz results, and adaptive-study activity. This browser copy is not an automatic account backup.

If you are signed in, the site attempts to save selected progress fields in a private TheCertCoach learner record linked to your account so supported activity can be available on another device. Those fields include module completion and visit history, practice-exam history, study schedules, Study Profile and confidence data, objective-check evidence, and dashboard-tool records such as domain-practice and worksheet activity, CPE entries, and personal study-group plans. Text you enter into a synced worksheet, CPE entry, or study-group plan is included in that record. When this storage is first initialized, supported progress already held in your Clerk account metadata can be copied into the private record so it remains available; the older Clerk copy can remain there. A browser copy can remain even when an account update has not been confirmed. If the dashboard shows a sync warning, follow its retry guidance.

For each scored Decision Lab, TheCertCoach keeps a private server-side record linked to your account rather than adding the lab data to Clerk account metadata. The record contains cumulative counts of submitted attempts and attempts that met the practice benchmark. It retains only the latest attempt's submission identifier, rubric version, server submission time, and complete set of structured choice identifiers; the score and result are recalculated from those choices and the versioned rubric. To recognize a retry after a timeout, the record also keeps compact hashes derived from the submission identifier and structured response set for up to two attempts immediately before the latest one. These retry entries are not full historical attempt or score records, and older entries are replaced as new attempts are submitted. Draft choices, the generated artifact, and the optional private reflection are scoped to the signed-in account in that browser and are not synced. Module knowledge-check results, module notes, and bookmarks also remain in that browser and are not synced to your account.

Analytics

We use a cookieless ServiceAlert analytics service hosted at analytics.servicealert.ai. The analytics script can send the page path and title, referrer and campaign parameters, a random per-page session tag, browser and device categories, connection information made available by your browser, page-load and navigation timing, Core Web Vitals, and JavaScript error details such as the error message, source file, line number, and stack trace. The service honors the browser's Do Not Track setting. We do not use this analytics service for targeted advertising or cross-site advertising profiles.

Like any service reached over the internet, the analytics server may receive network request information such as your IP address and user-agent string as part of handling the request. We use the resulting information to understand site reliability, performance, referrals, and aggregate usage.

How We Use Your Data

  • To provide the service — your account lets you log in, track progress, and access content.
  • To send messages you requested — sample links, newsletter messages, certification updates, or other email you chose to receive.
  • To respond and maintain the material — support messages, certification requests, and content reports help us answer questions, investigate reported problems, and make supported corrections.
  • To sync selected progress across devices — so signed-in learners can continue supported activities on another browser or device.
  • To provide and manage paid access when enabled — so we can open Stripe’s hosted billing pages, reconcile subscription events, show billing status, and determine whether an account has full-catalog access.
  • To operate and improve the site — analytics, performance measurements, and error reports help us find broken pages and understand how the site is used.
  • To protect the service — request records and short-lived rate-limit data help us prevent abuse and investigate operational problems.

Third-Party Services

We use the following external services to operate the site:

  • Clerk — handles authentication and account management, including account identity and access-plan information. Their privacy policy applies to account data they store. Older supported progress fields can remain in Clerk metadata after the private learner record is initialized.
  • Postmark — delivers requested and subscription email, including support and content-report messages, and processes the recipient address and message-delivery data.
  • Stripe — hosts any enabled individual Checkout and billing-portal pages, processes the account email and payment or billing information submitted there, and sends customer and subscription status needed to operate paid access. Stripe’s privacy policy applies to the information Stripe handles.
  • ServiceAlert analytics — receives the analytics, performance, and error information described above.
  • Cloudflare — provides network delivery and security services and processes normal request information when traffic passes through its network.
  • Google Fonts and jsDelivr — serve font files and the Clerk browser library. When your browser requests those files, those providers receive normal network request information.

What We Don't Do

  • We don't sell your data to anyone.
  • We don't share your data with third parties for their own targeted advertising.
  • We don't run targeted ads.
  • We don't use analytics or advertising cookies.

Data Storage

Browser-only learning data and local browser copies remain in localStorage until you clear them or the browser removes them. Signing out does not erase those records or a pending sync: it switches the site to its signed-out guest view, and account-scoped data is shown again only to the matching account. Guest data can still be visible while the browser is signed out, so clear TheCertCoach site data before handing a shared device to someone else. Clearing site data does not delete fields already synced to your account. Selected synced learning data and private Decision Lab records remain on TheCertCoach's server for as long as needed to provide the account-based features and meet operational or legal needs. Older supported progress fields can also remain in Clerk metadata after migration. Email requests and subscription records are stored on our server. If you unsubscribe, we retain the subscription's opt-out status so that we can honor your request. Billing records are retained for as long as needed to provide account access and billing support and to meet security, accounting, tax, dispute, and other legal obligations. After account erasure, the minimum retained local billing record and private restore-safe marker can include an opaque account hash, a random pseudonymous subject, Stripe identifiers, selected test-or-live mode, terminal subscription facts, and security or event timestamps, but not the raw Clerk account identifier in the live billing linkage; Stripe retains information under its own policy. Support, certification-request, and content-report messages can remain in our support mailbox for as long as needed to respond, investigate the issue, make a correction, and keep appropriate operational or legal records.

Security

We use administrative, technical, and access controls intended to protect the information we handle. No internet service can guarantee absolute security, so please contact us if you believe your account or information has been compromised.

Your Choices

  • You can clear TheCertCoach site data through your browser to remove browser-only learning data, pending sync records, and local copies. Signing out alone preserves those account-scoped records and does not delete progress already synced to your account.
  • You can unsubscribe from a list using the visible link in a subscription email or your email provider's built-in unsubscribe control. The link contains an opaque token rather than your email address.
  • You can enable your browser's Do Not Track setting to prevent the ServiceAlert analytics script from sending analytics events.
  • You can ask us to delete your account or other information associated with your email address, subject to records we need to retain for security, accounting, tax, dispute, opt-out, or other legal purposes. Any active individual subscription is canceled before account deletion is completed.

Policy Changes

We may update this policy when the site or the services it relies on change. The date at the top shows when we last revised it.

Contact

Questions about any of this? Email us at hello@thecertcoach.com.