COCO SWANSON

Privacy Policy

Last updated: February 23, 2026

Data We Collect

Data CategoryWhat We CollectHow Long We Keep It
Account DataName, email, password (encrypted)Until account deletion + 30 days
Profile DataAvatar, timezone, bioUntil account deletion
Payment DataStripe customer ID (NOT card numbers)7 years (tax/accounting)
Transaction HistoryPurchases, amounts, dates7 years (tax/accounting)
Subscription DataPlan type, status, start/end dates7 years (tax/accounting)
Quiz ResponsesReadiness level, experience, challengesUntil account deletion
Content EngagementPages viewed, content played, progress2 years rolling
Community PostsForum topics, repliesUntil deleted by user or admin
Email PreferencesOpt-in/out status, email frequencyUntil account deletion
Session DataLogin timestamps, IP addresses, device info90 days
CookiesSession cookies, analytics cookies, preferencesSee Cookie Policy
Lab RegistrationsName, email, session registered for1 year after lab date
Support CommunicationsEmails, messages to support3 years

Data NOT Collected

  • Credit card numbers, CVVs, or bank account details (handled entirely by Stripe, never touches our server)
  • Social Security numbers
  • Health records or medical information
  • Biometric data

Third-Party Data Sharing

Third PartyData SharedPurpose
StripeName, email, payment intentPayment processing
SupabaseAll account and content dataDatabase hosting
ResendName, email, event typeTransactional email delivery
CloudflareIP address, request headersCDN and security
Bunny StreamVideo view events (anonymous)Video hosting and delivery
Google Analytics (GA4)Anonymized browsing behaviorWebsite analytics
CalendlyName, email, booking timeSession scheduling

Data is NOT sold. You do not sell, rent, or trade user personal data to any third party, ever.

User Rights

RightHow to Exercise
Right to know what data is collectedEmail request or Account Settings
Right to access/download your dataAccount Settings > "Download My Data"
Right to delete your dataAccount Settings > "Delete Account" or email request
Right to correct inaccurate dataAccount Settings (self-service) or email request
Right to data portabilitySame as access (data export)
Right to opt out of analyticsCookie banner settings
Right to opt out of marketing emailsUnsubscribe link in every email + Account Settings
Right to restrict processingEmail request
Right to object to processingEmail request

Response time: All requests fulfilled within 30 days (GDPR) / 45 days (CCPA).

Account Deletion Process

  1. 1.User requests deletion via Account Settings or email
  2. 2.Active subscriptions must be canceled first (commitment minimums still apply)
  3. 3.Account data deleted within 30 days
  4. 4.Transaction/payment records retained for 7 years (legal/tax requirement, disclosed to user)
  5. 5.Community forum posts anonymized (author changed to “Deleted User”) but content preserved for thread integrity
  6. 6.Deletion is irreversible. User is warned before confirmation.

Data Security Summary

  • All data encrypted in transit (TLS 1.3)
  • All data encrypted at rest (AES-256)
  • Passwords hashed with bcrypt (never stored in plain text)
  • Payment data handled by Stripe (PCI DSS Level 1 certified, never touches our server)
  • Admin access requires two-factor authentication
  • Security breach notification within 72 hours

Children's Privacy

The platform is not intended for children under 18. We do not knowingly collect personal information from minors. If a parent or guardian becomes aware that their child has provided personal information, they should contact you immediately. Any such data will be deleted within 48 hours.

International Data Transfers

User data may be transferred to and processed in the United States. For EU users, this transfer is protected by Standard Contractual Clauses where applicable, compliance certifications from our service providers, and user consent at signup.

Questions

If you have questions about this Privacy Policy, please reach out at hi@cocoswanson.com.