Throughout this document, we may use certain words or phrases, and it is important that you understand the meaning of them. The following is a non-exhaustive list of definitions of words and phrases found in this document:
“App” refers to our Heights app, which provides a platform for creating and managing online education programs;
“Heights” refers to our company, known as “Velora Studios, LLC”; our Site; our Service; our App; or a combination of all or some of the preceding definitions, depending on the context in which the word is used;
“Service” refers to the services that we provide through our Site, including our Site itself, our education platform creation services, our App, and any other services we may provide online or offline;
“Site” refers to our website, www.heightsplatform.com;
“Subprocessor” refers to an entity which processes personal data on behalf of Heights so that we can provide our Service;
“User” refers to users of our App, and general visitors to our Site;
3. Information Collected
Whenever you visit our Site, we may collect non-identifying information from you, such as your IP address, referring URL, browser, operating system, cookie information, and Internet Service Provider. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, this information alone cannot usually be used to identify you.
4. Use of Your Information
We may use your information to:
- Enhance or improve User experience, our Site, or our Service.
- Process transactions.
- Send e-mails about our Site or respond to inquiries.
- Target advertisements that we believe may be of interest to you.
- Provide you with our Service (such as by storing data of courses and lessons you create on our servers so that you may access them using the App).
- Provide support to help you improve your program and or courses within them.
- Tracking behavior metrics for improvement of our Service. Please note that although we may track User behavior (e.g., last login date and percentage of lessons completed, last lesson views, numbers of students and courses in a program), we will not store and track sensitive payment information on our servers. Payment information is instead stored by a PCI compliant third party vendor (Stripe).
- If Heights merges with or is acquired by another company. Should this ever happen, we will notify you before any personal information is transferred and becomes subject to a different policy.
- Perform any other function that we believe in good faith is necessary to protect the security or proper functioning of our Site or Service.
5. Accessing, Editing, and Removing Your Information
Users may in some cases be able to review and edit the personal information they have provided to us by logging into your account on the Site and editing their account. Although most changes may occur immediately, information may still be stored in a web browser’s cache. We take no responsibility for stored information in your cache, or in other devices that may store information, and disclaim all liability of such. In addition, we may, from time to time, retain residual information about you in our backup and/or database.
|Operation Essential||These cookies are necessary for us to provide our Service. They help to recognize your account status, protect your account security, and remember your preferences.|
|Analytics||These cookies help us to maintain and continuously improve our Service. We use this type of cookie to help improve your experience using our Service.|
|Advertising||We use these cookies to serve advertisements that we believe may be relevant to your interests, and to measure the effectiveness of these advertisements. We also may use the information provided by this type of cookie for frequency capping purposes (ie: to ensure we are not serving the same advertisement to you too many times).|
Revoking permission of certain cookies that are not operation essential for us to provide our service:
Heights uses the Facebook Conversion Tracking Pixel, a service of Facebook, Inc. (https://www.facebook.com/policy.php). This cookie is an advertising type cookie which allows us to record the results of our advertisement performance for marketing purposes. You can revoke the permission for Facebook to track this at the following link: https://www.facebook.com/ads/website_custom_audiences/
Heights uses Google Analytics, a service of Google, Inc. (https://policies.google.com/privacy?hl=en) which allows us to track visits to our website and other browser data so that we can improve your experience. Our particular use of Google Analytics keeps your IP address anonymized before Google records it. This anonymized, or masked IP address, will not be connected to any other data on Google. This is an analytics type cookie. You can prevent analysis of your browser behavior across all websites using Google Analytics by installing this browser plugin: http://tools.google.com/dlpage/gaoptout. Google Analytics Advertising Features may also use anonymized insights into your device behaviors, and you can access and or delete such data via Google's "My Activity" page.
7. Third Party Websites
Heights may post links to third party websites on its Site. These third party websites are not screened for privacy or security issues by Heights, and you release us from any liability for the conduct of these third party websites.
8. Third Party Access to Your Information
Although you are entering into an Agreement with Heights to disclose your information to us, we do use third party individuals and organizations to assist us, including contractors, web hosts, and others.
Throughout the course of our provision of our Service to you, we may delegate our authority to collect, access, use, and disseminate your information. For example, our web host stores the information that you provide us, and we may hire outside contractors to perform maintenance or assist us in securing our website. A current list of vendors is available upon request.
Without limiting the generality of the foregoing, you authorize us to use the following third party services which may also store data about you:
|Amazon Web Services||Media files||Yes|
|CloudFlare||Media files||Yes||After trial or subscription ended|
|Google Analytics||Browser identifiers||Yes|
|Help Scout||Email, name|
|Help Scout||Browser identifiers|
|Heroku||Email, name||After trial or subscription ended|
|Heroku||Password||Bcrypt encryption||After trial or subscription ended|
|Heroku||Account data/media files||After trial or subscription ended|
|Scout APM||Operation heuristics||Yes|
|Stripe||Credit card data||PCI Compliant|
|Transloadit||Media files||Yes||Automatically after ~24 hours|
- Anonymized: Any data that could be used to identify the data subject is scrubbed, or a specific encryption policy is used in a case where data is not anonymized.
- Discarded: Data is destroyed automatically without requiring a request by data subject
- Archived: Data can only be accessed by Heights founder.
You authorize us to allow third party Site and App visitors to view and download data to their respective devices (not limited to mobile phones, tablets, laptops, computers), whether these third party visitors access this content via our Site, App or view and download this content via any mobile application which displays it. Without limiting generality, you understand that the ability of other parties to view information you save in our App and Site is a part of the Service we are providing to you.
9. Release of Your Information for Legal Purposes
At times it may become necessary, for legal purposes, to release your information in response to a request from a government agency or a private litigant. You agree that we may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of a civil action, criminal investigation, or other legal matter. In the event that we receive a subpoena affecting your privacy, unless we are legally prevented from it, we will notify you to give you an opportunity to file a motion to quash the subpoena, or we may attempt to quash it ourselves, but we are not obligated to do either. We may also proactively report you, and release your information to, third parties where we believe that it is prudent to do so for legal reasons, such as our belief that you have engaged in fraudulent activities. You release us from any damages that may arise from or relate to the release of your information to a request from law enforcement agencies or private litigants.
10. Commercial and Non-Commercial Communications
11. Security Measures
We take certain measures to enhance the security of our Site and Service, such as by using SSL Certificates. Your data is encrypted in transit between you and Heights for account and payment related pages. Should you be accessing our service through a custom domain (ie: a domain other than heightsplatform.com), ensure that the domain used to access our service also has HTTPS if you want your data to be encrypted throughout our entire App. We make routine, secure backups of your data, and we use multiple techniques to eliminate points of failure. We also conduct security reviews on our Service periodically and ensure that third party contractors and employees only have access to the information that is necessary for them to perform their job. However, we make no representations as to the security or privacy of your information. It is in our best interest to keep our website secure, but we recommend that you exercise precautions and use anti-virus software, firewalls, and other precautions such as not telling others your password to protect yourself from security threats. If you need to report an exploit, or you have noticed and incident with your account, please contact us at [email protected].
12. Security Breach Notifications
In the event that your private data are disclosed to unauthorized people (ie: hackers), Heights will send email notifications to all possibly affected parties. We may also make an announcement on our Site directly.
13. Deleted Data
We retain your personal information for the duration of our business relationship, and afterwards for as long as necessary for legitimate business purposes until you exercise your right to erase your personal information. When you request your account and personal information be deleted, we’ll ensure that nothing is stored on our servers past 30 days. Data that you choose to delete from your account while it is active will also be deleted within 30 days, though most data is deleted instantly.
14. GDPR Rights
The General Data Protection Regulation (“GDPR”) gives people under its protection certain rights with respect to their personal information collected by us on the Site. Accordingly, Heights recognizes and will comply with GDPR and those rights, except as limited by applicable law. The rights under GDPR include:
- Right to Be Informed. This is your right to know how we will process your data, who will process it, and where it might be located.
- Right to Access. This includes your right to access the personal information we gather about you, and your right to obtain information about the sharing, storage, security and processing of that information.
- Right to Rectification. This is your right to request correction errors and updating of incomplete information.
- Right to Erasure. This is your right to request, subject to certain limitations under applicable law, that your personal information be erased from our possession (also known as the "Right to deletion" or "Right to be forgotten"). However, if applicable law requires us to comply with your request to delete your information, fulfillment of your request may prevent you from using Heights services and may result in closing your account.
- Right to Restrict Processing. This is your right to request restriction of how and why your personal information is used or processed.
- Right to Object. This is your right, in certain situations, to object to how or why your personal information is processed.
- Right to Portability. This is your right to receive the personal information we have about you and the right to transmit it to another party.
- Right to not be subject to Automated Decision-Making. This is your right to object and prevent any decision that could have a legal, or similarly significant, effect on you from being made solely based on automated processes. This right is limited, if the decision is necessary for performance of any contract between you and us, is allowed by applicable European law, or is based on your explicit consent.
Many of these rights can be exercised by logging in to our App and directly updating or deleting your account data. If you have any questions about exercising these rights, please contact us at [email protected].
15. Your California Online Privacy Rights
Below are the rights you have, though these are not absolute. In certain cases we may decline your request as permitted by law.
- Information: You can request the following information about how we have collected and used your personal information during the past 12 months:
- The categories of personal information that we have collected.
- The categories of sources from which we collected personal information.
- The business purpose for collecting your personal information.
- The categories of third parties with whom we share personal information.
- Whether we have disclosed your personal information for a business purpose, and if so, the categories of personal information received by each category of third party recipient.
- Whether we’ve sold your personal information, and if so, the categories of personal information received by each category of third party recipient.
- Access: You may request a copy of the personal information that we have collected about you.
- Deletion: You may ask us to delete the personal information that we have collected from you.
- Nondiscrimination: You are entitled to exercise the above rights free from discrimination.
You may contact us at [email protected] with any questions or to exercise these rights listed above. We may require government identification to process your request and to confirm your residency.
Individuals under 13 years of age are not allowed to use our Service. If you become aware of a User who is under the required age to use our Service, please notify us immediately at [email protected] and provide us with full details as to why you believe they are below that age and we will address the issue. If you are a User who is reported in this manner, we may require you to provide suitable proof of age, such as a copy of government identification, in order to continue using our Site and/or Service.
17. International Transfer
Attn: Velora Studios, LLC
16192 Coastal Highway
Lewes, Delaware 19958
Last Modified: June 13, 2020