Privacy

Privacy policy

This policy describes what SureTrace Consulting & Training collects when you use this site, how that information is used, who it is shared with, and the choices you have. It is written in plain language; the formal language below matters because it is what controls if a question ever needs a definitive answer.

Effective date: July 25, 2026. Material changes are posted here with a new effective date and recorded in the version history of this file.

1 — Who we are

The operator, the contact channel, and the postal address that backs the policy

Operator
SureTrace Consulting & Training
The legal entity responsible for the information described below.

You can reach us at contact@suretraceutility.org or 513-346-8869. We respond to privacy requests — access, correction, deletion — inside 30 days. Use the same channel to opt out of any non-essential communication.

The principles below apply to every service tied to this domain: /contact, /contact/engagement, /contact/intake, the LMS at /training, and the Engagements reflective of the scope-boundary conversation described in our terms.

2 — What we collect

Information you give us, and information the site gathers by default

We collect what is needed to operate the service you used. The list below reflects what the published forms, account flows, and Stripe checkout actually capture today.

Contact form submissions
A short message, optional name, email, phone, and a one-line project topic.

Submitted via /contact through our hosted form. We use this to reply to your inquiry — nothing else.

Engagement inquiry submissions
Project type and a short scope outline.

Submitted via /contact/engagement. Used to scope the engagement and respond with the right tier shape.

Intake submissions
Full engagement scope — OSHA-aligned lead form, site footprint, standards in play.

Submitted via /contact/intake. Used to draft the scope-boundary agreement and prepare the field team.

Account data for LMS
Email and password hash (authentication is handled by our installed auth provider; passwords are stored hashed, never in plaintext).

Created when you sign up at /auth. Used to give you access to the LMS at /training and to keep your progress tied to your account.

LMS assessment & progress data
Quiz scores, completion state, and time on task for the cohorts and modules you enroll in.

Tied to your account. Used to issue enrollment and assessment confirmations and to award the certificates the program defines.

Standard server logs
IP address, user agent string, request path, request timestamp, and response status.

Captured by the infrastructure that hosts the site. Used to operate the service and to investigate abuse, errors, and security incidents.

We do not third-party analytics tools. If we ever add one — for example, a privacy- respecting first-party counter or a self-hosted event store — this section is where that change is documented before it ships.

3 — Payments

Stripe-hosted checkout, and what we receive when you enroll

Card data & billing
LMS Enroll checkout is handled by Stripe

Payment for LMS enrollments is processed through Stripe's hosted checkout. When you click Enroll, you are redirected to a Stripe domain; the card data you enter is captured and stored by Stripe and never touches our servers. We never see the card number, CVV, or expiration date.

  • We receive only: your billing email, the card brand, the last four digits, and the payment outcome (success, failure, refund).
  • We do not collect bank account numbers, social security numbers, or tax IDs through the public site.
  • Custom / on-site engagements are invoiced directly. Any payment details tied to an invoice are exchanged on a need-to-know basis.

Read Stripe's Privacy Policy for what they retain on their side: a Stripe-hosted subdomain captures the card data and keeps it under Stripe's own retention rules.

4 — How we use the data

Use it for the service you came for — nothing else

We use the data we collect to do the things you came here for:

  • Reply to inquiries and engagement requests; deliver the services you scoped.
  • Run the training you enrolled in and record your progress.
  • Send enrollment, assessment, and scope confirmations related to the service you used.
  • Meet legal and financial recordkeeping for invoiced work (tax, audit, contractual).
  • Protect the site and its users — investigate abuse, errors, and security incidents.

We do not perform automated profiling or ad targeting. We do not enrich your data with third-party databases or sell audience segments.

5 — Sharing

Only the vendors the service actually needs

Information is shared only as needed to run the service:

  • Stripe — payment processor for LMS enrollments.
  • Email service — sends confirmation and transactional messages you triggered.
  • Infrastructure providers — host the site and the database that backs it.

We do not sell, rent, or trade your information. Limited disclosure may occur if required by law or to prevent harm — and we will narrow the disclosure to what is legally required.

6 — Retention

How long each kind of record is held

  • Account data — kept for as long as the account is active. We delete on request, subject to legal hold windows.
  • Inquiry, contact-form, and intake rows — kept long enough to deliver the engagement, handle follow-ups, and meet bookkeeping obligations. Non-converting rows are automatically pruned after 24–36 months; invoiced engagements are kept longer.
  • LMS records — kept while your enrollment is active. Progress is archived on completion; on account deletion, the archive is removed.
  • Server logs — kept on a rolling window that matches operational needs (typically 30–90 days).
7 — Your choices & access

Request a copy, request a correction, request a deletion

Email contact@suretraceutility.org to ask for a copy of the data we hold on you, to ask for corrections, or to ask us to delete what we legally can. We respond within 30 days. If your request requires more time — for example, pulling records across multiple systems — we will tell you before the 30-day mark.

For LMS enrollments, you can also delete your account from the account settings page in the LMS; deletion removes your progress records and unenrolls you from any future-cohort notifications you opted into.

8 — Security

Reasonable measures, not a guarantee of perfection

Operational safeguards
  • HTTPS for every page and every form submission.
  • Server-side key handling via platform-managed environment variables; secrets are not committed to source.
  • Database queries are parameterised; they are not built by string concatenation.
  • Access to operational systems is limited to the team that needs it.

No security claim is absolute. The liability section of the Terms applies to security incidents as it applies to any other claim; a stronger posture reduces the probability of an incident but does not eliminate the underlying framework.

9 — Children's privacy

This site is not directed to children under 13

Under 13

This site is not directed to children under 13. Do not submit information on their behalf. If you believe information about a child under 13 has been collected through this site, contact us at contact@suretraceutility.org and we will remove it.

10 — Changes to this policy

How updates are published and versioned

Material changes are posted here with a new effective date. The version in source — and its git history — is the change record. Non-material changes (typo fixes, clarifications that do not change behavior) are folded in without a new effective date.

The version published at the time of your action (the form submission, the LMS enrollment, the Stripe checkout click-through) is the version that controls that action.

11 — Contact

Privacy questions, requests, and complaints

Reach us at contact@suretraceutility.org or 513-346-8869. We answer privacy questions, access requests, correction requests, and deletion requests within 30 days.

For the governing law and venue that cover disputes tied to this policy, see the Terms of Service.