Privacy Policy
Last updated September 27, 2026
JoinCPR ("we", "us") provides software that training providers ("Businesses") use to schedule classes, register students, collect payments and issue certificates. This policy explains what personal information we handle, why, and the choices you have. It covers our own site and dashboard and the registration sites we host for Businesses.
Two roles
For Businesses that hold an account with us, we are the data controller for the account information described below.
For students who register for a class through a Business's site, the Business is the controller: it decides what to collect and how to use it, and it is your first point of contact for questions, corrections and deletion. We process student information on the Business's behalf to run the Service. If you contact us about student data we will pass the request to the Business unless we are required to act ourselves.
Information we collect
From Businesses
- Account details: business name, your name, email, password (stored hashed), phone, timezone, logo and branding.
- Billing: subscription status and invoice history. Card details are entered directly with Stripe; we store only a reference and the last four digits Stripe reports.
- Payment processor connections: identifiers and access tokens for the Stripe or Square account you connect, stored encrypted, so we can create charges and refunds on your behalf.
- Usage: sign-in times, actions taken in the dashboard (kept in an activity log), emails and SMS sent, and technical data such as IP address and browser.
From students (on behalf of a Business)
- Registration details: name, email, phone, answers to questions the Business asks, agreements the Business requires, and the class registered for.
- Payment details: amount, payment method type, card brand and last four digits, and payment or refund identifiers from the processor. Full card numbers are entered directly with Stripe or Square and never reach our servers.
- Training records: attendance, completion, certificates issued (number, dates, course) and keycodes assigned.
- Communications: emails and, where the Business enables it and you have not opted out, SMS reminders.
- Optional account: if you create a student login, your password is stored hashed.
How we use it
- To provide the Service: registration, payment processing, rosters, certificates, reminders, receipts and the student portal.
- To bill Businesses and to detect and prevent fraud or abuse.
- To support users and to send service messages (for example receipts, confirmations, billing and security notices). We do not send marketing to students.
- To keep the Service reliable and secure, including logs and backups.
- To meet legal obligations.
Who we share it with
- The Business a student registers with, which sees that student's registration, payment status and training records.
- Payment processors: Stripe and Square, under their own privacy policies.
- Service providers that host and operate the platform for us: cloud hosting (DigitalOcean), Cloudflare (DNS, TLS and security), an email delivery provider, and Twilio for SMS where enabled.
- Integrations a Business chooses to connect, such as Mailchimp, ActiveCampaign, GoHighLevel, Google Calendar or Microsoft Outlook. Data is sent to those services only when the Business enables the integration.
- Certificate verification: a certificate can be verified by anyone who has its number; the verification page shows the student's name, the course, and issue and expiry dates.
- Authorities where the law requires, and a successor in the event of a merger or sale, under this policy.
We do not sell personal information.
Cookies
We use cookies needed to keep you signed in and to protect forms from forgery. We do not use advertising cookies. Your browser can block cookies, but the dashboard and student portal need them to work.
Retention
Business account data is kept while the account is active and for a limited period after closure so it can be exported, then deleted except where we must keep records for tax or legal reasons. Student records are kept for as long as the Business keeps them; certificates are typically retained for the life of the certification and a reasonable period after. Email and activity logs are pruned automatically after one and two years respectively.
Security
Data is encrypted in transit (TLS) and sensitive credentials such as processor tokens are encrypted at rest. Access to production systems is restricted and logged. No system is perfectly secure; if we learn of a breach affecting your information we will notify affected Businesses without undue delay so they can inform their students.
Your choices and rights
- Students can view their registrations, receipts and certificates by creating a student login on the Business's site, can opt out of SMS by replying STOP, and can ask the Business to correct or delete their information.
- Businesses can edit their details in Settings, export their data at any time, disconnect integrations and processors, and close their account.
- Depending on where you live you may have rights to access, correct, delete or port your data, or to object to certain processing. Email us and we will respond within the time the law requires, or direct you to the responsible Business.
Children
The Service is intended for adults. Businesses that train minors are responsible for obtaining any consent their law requires before entering a minor's details. We do not knowingly collect information directly from children under 13.
Where data is processed
Our servers are in the United States. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.
Changes
We will post updates here with a new date and notify Businesses by email of material changes.
Contact
JoinCPR, [email protected], (855) 223-3496.