Skip to main content

Privacy Policy

Version 2026-07-16.d1
Updated July 16, 2026
DRAFT — not legally approved

Summary

  • Accounts are adult-owned. Children do not create their own accounts.
  • Child learner profiles are private by default.
  • We do not sell personal information.
  • We do not use child learner information for targeted advertising.
  • Parents control who can access a child learner profile.
  • Users may request access, correction, export, or deletion of their information.
  • Sensitive information is minimized; free-form medical text is not collected.

1. Scope

This policy describes how [LEGAL ENTITY NAME] collects, uses, and safeguards personal information through LearnToSwim.com, its mobile experiences, applications, and related services (the "Service").

2. Information we collect

A. Adult account information

  • Name, email, authentication data, account preferences, locale, and timezone.

B. Child learner-profile information

  • Preferred first name or nickname.
  • Age band (rather than a complete birth date).
  • Parent-selected goals.
  • Skill progress and comfort ratings.
  • Session history and instructor assessments.
  • Parent-authorized caregiver access.

We do not collect a child's home address, personal email, personal phone number, school, exact birth date, precise location, biometric identifiers, government identifiers, contacts, or unnecessary photos, videos, or audio recordings.

C. Adult learner information

  • Swimming experience, goals, comfort ratings, practice results, and optional accommodation preferences.

D. Instructor information

  • Profile, organization, teaching preferences, self-reported credentials, assigned learners and classes, and curriculum or lesson plans.

E. Transaction information

Subscription selection, billing status, and limited payment metadata received from [PAYMENT PROCESSOR]. We do not store full payment card numbers.

F. Device and usage information

  • IP address, browser, device type, operating system, app version, general usage events, and security and diagnostic logs.

G. Location information

  • Manually entered city or ZIP code. Approximate location only when requested for lesson discovery. Precise location only after separate opt-in, if ever introduced.

H. Communications

  • Support requests, safety reports, feedback, and email or notification preferences.

I. Optional sensitive information

Only structured, opt-in accommodation preferences described in the intake flow (for example: an individualized adaptation may be needed; a sensory or mobility consideration; a previous difficult water experience; a preference to discuss directly with an instructor; or "prefer not to answer"). We do not collect free-form medical histories in the initial release. If we later collect diagnoses, medical details, mental-health information, biometric information, disability details, or other consumer health data, a separate Consumer Health Data Privacy Notice and separate affirmative consent will apply.

3. Sources of information

  • Adult users, authorized caregivers, and authorized instructors.
  • User devices.
  • Payment processors and authentication providers.
  • Public provider information for directory listings.
  • Service providers acting on our documented instructions.

4. Purposes

  • Account creation and authentication.
  • Personalized learning plans and progress tracking.
  • Safety and prerequisite checks.
  • Caregiver and instructor sharing controlled by the responsible adult.
  • Customer support and billing.
  • Security, fraud prevention, and product improvement using minimized or aggregated data.
  • Legal compliance and provider-directory functionality.

5. Disclosures

Categories of recipients: hosting and database providers; authentication providers; payment processors; video and content-delivery providers; email and notification providers; analytics providers; customer-support providers; authorized caregivers; parent-authorized instructors; our professional advisers; government or legal recipients where legally required; and a successor in a merger or acquisition subject to continued privacy obligations. Specific service providers are listed in the [LIST OF SERVICE PROVIDER CATEGORIES] maintained by our operations team.

6. No sale or targeted advertising

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use child learner information for targeted advertising. If these practices ever change, we will update this policy, provide a notice at collection, offer applicable opt-out mechanisms, obtain separate parental consent where required, and complete internal legal and administrative review before activation.

7. Children's privacy

Only adults create accounts. Parents or guardians create and control child learner profiles. No child email or phone number is collected. Profiles are private. No public social features involving children exist on the Service. See the Children's Privacy Notice.

8. Consumer health and sensitive information

We minimize health information. Optional accommodation information is used only to provide the requested experience and is not used for advertising. See the Consumer Health Data Privacy Notice for the additional protections that apply if consumer health data is ever collected.

9. Cookies and analytics

We categorize cookies and similar technologies as strictly necessary, preference, analytics, or marketing. Marketing categories are disabled by default and are not permitted on child-facing experiences. Nonessential tracking does not load until your legally required choice has been honored. A preference center is available at Privacy Choices.

10. Data retention

Retention periods are set by data category in an operations-approved schedule: [DATA RETENTION SCHEDULE]. Unverified accounts, active accounts, learner profiles, assessment history, safety acknowledgements, support communications, transaction records, instructor records, deleted accounts, backups, and security logs each have their own period, recorded in the admin retention table and published here once approved.

11. Security

We use reasonable safeguards including encryption in transit, encryption at rest where appropriate, row-level access controls, least-privilege access, authentication protections, logging and monitoring, vendor review, secure deletion, and documented incident-response procedures. No system is 100% secure.

12. Your rights

The Privacy Center lets you access, correct, download, or delete your information; delete a learner profile; revoke caregiver or instructor access; withdraw optional consent; manage communications; and submit a privacy request without creating a new account.

13. California and other U.S. state privacy disclosures

Because the default is no sale and no cross-context behavioral advertising, we do not display a misleading opt-out control for conduct that does not occur. If any category changes or the company confirms applicability of a specific state law, this section will be activated with the required disclosures (categories collected, sources, business purposes, categories disclosed, retention criteria, and the rights of access, deletion, correction, portability, non-discrimination, appeal, authorized-agent submissions, and recognition of legally required opt-out preference signals). Draft status until reviewed by counsel.

14. International users

The Service is intended for users in the United States at initial launch. We do not claim GDPR compliance at this time.

15. Data breach and incident response

We provide notifications as required by applicable law. Specific timelines will be documented after operational and legal review.

16. Changes

Effective date: [EFFECTIVE DATE]. Last updated: [LAST UPDATED DATE]. Version history is maintained at legal history.

17. Contact

Privacy contact: [PRIVACY EMAIL]
Mailing address: [BUSINESS MAILING ADDRESS]

Submit a request or appeal at any time from Privacy Choices.