Privacy Policy

Last Updated: September 4, 2026

This Privacy Policy explains how CourseDeck (“CourseDeck,” “we,” “us,” or “our”) collects, uses, and processes personal data in connection with the CourseDeck website, platform, and related services (collectively, the “Service”).

This Privacy Policy is intended for a business-to-business (B2B) SaaS platform and should be read together with our Terms of Service and Data Processing Addendum (DPA).

1. Scope and Applicability

CourseDeck provides a SaaS platform to educational institutions and organizations (“Customers”).

CourseDeck does not offer the Service to students or minors as independent consumer customers. Certain Customer-configured enrollment pages, portals, or educational workflows may, however, be used by parents, guardians, adult learners, other authorized registrants, or students in connection with a Customer’s use of CourseDeck.

Depending on the context, CourseDeck acts either as:

  • a Data Processor (most commonly), or
  • an independent Data Controller for limited business-related and website data.

2. Roles Under Data Protection Law

2.1 Student and Educational Data

For student data and other data processed through Customer-configured workflows, including data relating to minors:

  • Customer (School / Institution) is the Data Controller.
  • CourseDeck is the Data Processor, acting on the Customer’s documented instructions.

Student data may be entered by the Customer or submitted by parents, guardians, adult learners, or other authorized registrants through enrollment and other workflows made available by the Customer.

The Customer determines the purposes for which student data is collected and used and is responsible for establishing an appropriate lawful basis and obtaining parental or guardian consent where required by applicable law.

CourseDeck processes such data on behalf of the relevant Customer.

2.2 Business and Website Data

For limited data such as:

  • website visitors,
  • trial sign-ups,
  • billing contacts,
  • marketing communications,

CourseDeck acts as an independent Data Controller.

3. Categories of Personal Data Processed

3.1 Identifiers

  • Name
  • Email address
  • Username
  • Organization or school name
  • IP address

3.2 Professional and Educational Information

  • Role or job title
  • Class or course information
  • Attendance records
  • Educational performance data

3.3 Student and Minor Data (Customer Data)

Student and minor data may include:

  • Student name and identifiers
  • Class enrollment and schedules
  • Attendance and progress records
  • Parent or guardian contact details
  • Date of birth or age-related information where required for enrollment
  • Health, medical, or other information submitted for the relevant Customer’s enrollment or service needs

Student data may be provided by Customers or submitted by parents, guardians, adult learners, or other authorized registrants through Customer-configured enrollment workflows.

Information submitted through enrollment may be stored in the Customer’s CourseDeck account as part of the student record. Authorized Customer users may review or update certain information, and existing student information may be reused for subsequent enrollments so that the same information does not need to be re-entered each time.

CourseDeck processes this data on behalf of and under the instructions of the relevant Customer.

3.4 Usage and Technical Data

  • Device and browser information
  • Log files and timestamps
  • Authentication and session data

3.5 Website, Analytics, and Advertising Measurement Data

Depending on the technologies you allow and the context in which you use the Service, we may process:

  • Website usage metrics
  • Page views and interaction data
  • Advertising performance and conversion measurement events, such as clicks on registration calls to action on our marketing website

On our marketing website, optional Google Analytics and Google Ads measurement technologies are loaded only after you make the corresponding choice through our Cookie Preferences controls.

Additional information about these technologies and how to manage your choices is available in our Cookie Policy.

4. Data Relating to Minors

CourseDeck is not a child-directed consumer service. The Service may nevertheless process personal data relating to minors when Customers, parents, guardians, or other authorized persons submit that information through Customer-configured enrollment, portal, or educational workflows.

The relevant Customer is responsible for:

  • determining the lawful basis for processing minors’ data,
  • providing any notices required by applicable law,
  • obtaining parental, guardian, or other authorization where required under COPPA, GDPR, UK GDPR, or other applicable laws,
  • configuring the Service appropriately for its users, and
  • responding to parental, student, or other data subject rights requests where the Customer acts as Data Controller.

CourseDeck processes student and minor data on behalf of the relevant Customer and does not use Customer student data for behavioral advertising or cross-context behavioral advertising.

Parents and guardians should normally contact the relevant school or organization regarding student data processed through that Customer’s CourseDeck account.

5. Legal Bases for Processing (GDPR / UK GDPR)

Where CourseDeck acts as a Data Processor, processing is based on the Customer’s lawful instructions.

Where CourseDeck acts as a Data Controller, processing may be based on:

  • Performance of a contract
  • Legitimate interests (e.g., service security, product analytics, and improvement where permitted)
  • Legal obligations
  • Consent, where required by law, including for optional Google Analytics and Google Ads measurement on our marketing website

The appropriate lawful basis for Customer-controlled student data is determined by the relevant Customer in accordance with applicable law.

6. Service Providers and Sub-Processors

CourseDeck uses third-party service providers and, where applicable, sub-processors to deliver, secure, support, and measure the Service.

Depending on the service and processing context, a provider may act as a sub-processor, an independent controller, or a Merchant of Record.

Current providers include:

ProviderPurpose
VercelHosting and infrastructure
NeonServerless PostgreSQL database
UploadThingFile and media storage
ResendTransactional email delivery
PostHogProduct analytics
Google AnalyticsWebsite usage analytics on the marketing website
Google AdsAdvertising performance and conversion measurement on the marketing website
Lemon SqueezyPayment processing and Merchant of Record

Where a provider acts as a sub-processor, CourseDeck requires appropriate data protection obligations consistent with this Privacy Policy and our DPA.

Providers acting in other roles may process personal data under their own applicable terms, privacy policies, and data processing arrangements.

7. Data Location and International Transfers

CourseDeck and its service providers may process personal data in the United States and other locations in which they operate, subject to applicable legal requirements.

Personal data may be accessed by authorized personnel and service providers where necessary to provide and support the Service.

Where required for applicable international transfers, CourseDeck and its relevant service providers rely on appropriate transfer mechanisms and contractual safeguards.

8. Data Retention

Personal data is retained:

  • for the duration of the Customer’s contractual relationship,
  • as required by applicable law, or
  • in accordance with Customer instructions.

Upon termination, data handling is governed by the Terms of Service and DPA.

9. Data Subject Rights

Depending on jurisdiction, individuals may have rights to:

  • access
  • rectification
  • erasure
  • restriction
  • objection
  • data portability

Requests relating to Customer-controlled student data should normally be submitted to the relevant Customer (school or organization) acting as Data Controller.

10. California Privacy Rights (CCPA / CPRA)

California residents may have rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA, including rights to:

  • know or access certain personal information,
  • correct inaccurate personal information,
  • delete certain personal information, subject to legal exceptions,
  • opt out of certain sale or sharing of personal information where applicable, and
  • limit certain uses of sensitive personal information where applicable.

CourseDeck uses personal information as described in this Privacy Policy, including limited Google Ads conversion measurement on our marketing website when enabled by the visitor.

CourseDeck does not use Customer student data for cross-context behavioral advertising.

Requests regarding personal data for which CourseDeck acts as an independent Data Controller may be submitted to support@mycoursedeck.com. Requests relating to Customer-controlled student data should normally be directed to the relevant Customer.

11. Security Measures

CourseDeck implements appropriate administrative, technical, and organizational measures designed to protect personal data. These measures may include:

  • Role-based and least-privilege access controls
  • Logical segregation of Customer data within multi-tenant environments
  • Secure transmission of data using industry-standard security protocols
  • Security logging and monitoring appropriate to the relevant systems and services
  • Security controls provided by our hosting, database, storage, and other infrastructure providers

No system is completely secure, but we take reasonable steps to protect personal data.

12. Updates to This Privacy Policy

We may update this Privacy Policy periodically. The “Last Updated” date above reflects the most recent version.

13. Contact Us

For questions or privacy-related requests, please contact:

Email: support@mycoursedeck.com