SkillFlow Hub is operated by The Prassas Group (“Prassas,” “we,” “us,” or “our”). This policy explains what personal information we collect, why we collect it, who we share it with, and the choices and rights you have - including under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and other US state privacy laws.
Effective date: July 2, 2026 · Last updated: July 2, 2026
This policy applies to skillflowhub.com and the SkillFlow Hub learning platform (the “Service”). Course content is delivered through our learning-experience provider, Reach360. A list of the service providers that process personal information on our behalf is on our Subprocessors page.
In short
Over the preceding 12 months we have collected the following categories of personal information (using the categories enumerated in the CCPA/CPRA). We collect this information directly from you, and automatically or from service providers as described in Section 2.
| CCPA category | Examples we collect | Collected? |
|---|---|---|
| Identifiers | Name, email address, account ID, IP address, and provider IDs (Stripe customer ID, Reach360 user ID). | Yes |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name and contact details tied to a purchase. Payment card details are entered on Stripe Checkout and never reach our servers. | Yes |
| Commercial information | Courses and plans purchased, enrollments, subscription status, and order history. | Yes |
| Internet or other network activity | Interactions with the Service, device/log data, and email delivery events (for the emails we send you). | Yes |
| Inferences | Course or topic interests inferred from your enrollments to recommend relevant learning. | Limited |
| Sensitive personal information; biometric, genetic, or neural data; precise geolocation; protected classifications; audio/visual data | We do not intentionally collect government identifiers, financial-account credentials, health, biometric, neural, or precise-geolocation data. | No |
We use personal information for the following purposes:
We disclose personal information to service providers and processors who act on our behalf under contract and only for the purposes above. Our current subprocessors - Supabase, Stripe, Reach360, Beehiiv, Resend, Vercel, and PostHog - are listed with the data each receives on our Subprocessors page. We may also disclose information to comply with law, respond to lawful requests, protect our rights and users’ safety, or in connection with a corporate transaction (in which case this policy will continue to apply to your information).
We do not sell your personal information for money or other valuable consideration, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We also do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use. Because we do not sell or share, we honor Global Privacy Control (GPC) and other opt-out preference signals as a valid opt-out to the extent required by law, and there is nothing you need to do to prevent the sale or sharing of your data. We have not sold or shared the personal information of consumers, including minors under 16, in the preceding 12 months.
We keep personal information for as long as your account is active and as needed to provide the Service, then only as long as necessary for the purposes described in this policy, to comply with our legal and tax obligations, resolve disputes, and enforce our agreements. Retention periods vary by record type - for example, order and payment records are kept longer to meet financial and tax requirements, while email delivery logs are purged on a shorter cycle. When information is no longer needed, we delete or de-identify it.
If you are a California resident, you have the following rights, subject to certain exceptions:
Submit a request any time through our privacy request form or by emailing info@prassasgroup.com. Logged-in learners can request a copy of their data, or delete their account directly, from the Privacy & data page in their account.
We will acknowledge your request and respond within the timeframes required by law (generally within 45 days, with one 45-day extension where reasonably necessary). To protect your information, we verify requests by matching the details you provide to information in our records; we may ask for additional information to confirm your identity. You may use an authorized agent to submit a request on your behalf, subject to proof of authorization and identity verification.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws (including Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Kentucky, Rhode Island, and others as those laws take effect) have similar rights, which may include the right to confirm and access their data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling. Where your state provides a right to appeal a decision on your request, you may appeal by replying to our decision or emailing info@prassasgroup.com. We do not engage in targeted advertising, sale of personal data, or profiling with legal or similarly significant effects, and we honor recognized universal opt-out mechanisms such as Global Privacy Control where required.
The Service is intended for a business and adult audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13, in line with the Children’s Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided us personal information, please contact us at info@prassasgroup.com and we will delete it. Consistent with California law, any personal information of a consumer we know to be under 16 is treated as sensitive personal information, and we do not sell or share the personal information of consumers under 16.
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, and row-level security in our database. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If a breach affects your information, we will notify you and applicable regulators as required by law.
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, where required, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
If you have questions about this policy or your personal information, contact us:
The Prassas Group
Attn: Privacy
The Prassas Group, New Jersey, USA (full postal address available on request)
Email: info@prassasgroup.com