Privacy Policy
Effective June 2, 2026
Timberline Coffee School ("Timberline", "we", "us", or "our") operates the Groundwork platform at groundwork.coffee. We are committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
1. Information We Collect
- Account information. When you create an account, we collect your name, email address, and password (hashed).
- Payment information. Payments are processed by Stripe. We do not store your full card number or CVV. We receive and retain a payment record including billing name, last 4 digits of the card, transaction ID, and subscription status from Stripe.
- Usage data. We collect information about how you use the Service, including lessons viewed, progress milestones, session timestamps, and feature interactions.
- Device and technical data. We automatically collect your IP address, browser type, operating system, and referring URLs when you visit the Service.
- Advertising and analytics identifiers. If you consent to analytics or marketing cookies, we and our advertising partners may set cookies and similar identifiers (such as the Meta Pixel and Google tags) to measure site usage and the performance of our ads. We do not set these until you have given consent.
- Communications. If you contact support or submit feedback, we retain those communications.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account.
- Process your subscription payments.
- Deliver and improve the Service and course content.
- Send transactional emails (receipts, password resets, account notices).
- Send marketing emails if you have opted in (you can opt out at any time).
- Measure and improve our advertising, where you have consented to marketing or analytics cookies.
- Detect and prevent fraud and abuse.
- Comply with legal obligations.
3. Legal Basis for Processing (EU/EEA/UK visitors)
For visitors in the European Economic Area (EEA) or United Kingdom (UK), applicable data-protection law requires us to state a legal basis for each processing activity. The relevant bases are:
| Processing activity | Legal basis |
|---|---|
| Creating and managing your account | Performance of contract -- Art. 6(1)(b) GDPR |
| Processing subscription payments | Performance of contract -- Art. 6(1)(b) GDPR |
| Sending transactional emails (receipts, resets, notices) | Performance of contract -- Art. 6(1)(b) GDPR |
| Delivering and improving the Service and course content | Legitimate interests -- Art. 6(1)(f) GDPR (our interest in providing a working, improving product) |
| Analytics cookies (e.g. Google Analytics 4) | Your consent -- Art. 6(1)(a) GDPR |
| Marketing / advertising cookies and CAPI (Meta, Google Ads) | Your consent -- Art. 6(1)(a) GDPR |
| Hashed-PII sharing with Meta / Google for ad measurement | Your consent -- Art. 6(1)(a) GDPR |
| Sending marketing emails | Your consent -- Art. 6(1)(a) GDPR |
| Fraud prevention and security | Legitimate interests -- Art. 6(1)(f) GDPR (our interest in protecting the Service and users) |
| Complying with legal obligations | Legal obligation -- Art. 6(1)(c) GDPR |
Where we rely on legitimate interests, you have the right to object to that processing (see Your Rights).
4. International Data Transfers (EU/EEA/UK visitors)
Timberline Coffee School is operated in the United States. When you use the Service, your personal data may be transferred to and processed in the United States.
We share certain data with the following US-based third parties and rely on the following transfer mechanisms for transfers from the EEA or UK:
| Recipient | Transfer mechanism |
|---|---|
| Meta Platforms, Inc. | EU-US Data Privacy Framework (adequacy decision -- Commission Implementing Decision 2023/1795); UK Extension to the DPF |
| Google LLC | EU-US Data Privacy Framework (adequacy decision -- Commission Implementing Decision 2023/1795); UK Extension to the DPF |
| Stripe, Inc. | Standard Contractual Clauses (SCCs) / EU-US DPF -- see stripe.com/legal/dpa |
| Supabase | Standard Contractual Clauses (SCCs) -- see supabase.com/privacy |
You may request a copy of the relevant transfer safeguards by contacting us at privacy@timberlinecoffeeschool.com.
5. Information We Share
We do not sell your personal information. We share it only as follows:
- Stripe-- to process and manage subscription payments. Stripe’s privacy policy is at stripe.com/privacy.
- Supabase -- our cloud database and authentication provider stores your account and usage data on our behalf.
- AI provider(s) -- certain features (such as personalized recommendations or interactive tools) may send anonymized or pseudonymized usage data to AI processing services. We do not send your name, email, or payment information to AI providers.
- Meta (Facebook).If you consent to marketing cookies, we use the Meta Pixel and the Meta Conversions API to measure the performance of our advertising. Any personal data we send to Meta through the Conversions API (such as email or phone) is SHA-256 hashed before it leaves our servers, so Meta does not receive it in readable form. Meta’s data policy is at facebook.com/privacy/policy.
- Google.If you consent to analytics or marketing cookies, we use Google Analytics 4 and Google Ads to understand site usage and measure ad performance. IP addresses are anonymized for analytics. Google’s privacy policy is at policies.google.com/privacy.
- Legal and safety. We may disclose information if required by law, court order, or to protect the rights and safety of Timberline, our users, or the public.
- Business transfers. If Timberline is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you in advance.
6. Data Retention
We retain your account information for as long as your account is active, plus up to 3 years after closure for legal and audit purposes. Payment records are retained as required by law (typically 7 years). You may request deletion at any time (see Your Rights below).
Analytics and advertising data is retained only with your consent. Google Analytics user and event data is retained for up to 14 months. Hashed identifiers sent to advertising partners are transmitted for measurement and are not stored by us in a separate profile. Meta and Google retain the data they receive according to their own retention policies. Your consent choice is stored for up to 12 months, after which we ask again.
7. Your Rights
Depending on where you live, you may have rights to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your information.
- Object to or restrict certain processing.
- Export your data in a portable format.
- Opt out of marketing emails at any time via the unsubscribe link or by contacting us.
To exercise any of these rights, email privacy@timberlinecoffeeschool.com. We will respond within 30 days.
EEA/UK visitors -- additional rights:
If you are located in the EEA or UK, you also have the right to:
- Lodge a complaint with your local data-protection supervisory authority. In the EU, you can find your authority at edpb.europa.eu/about-edpb/board/members_en. In the UK, the supervisory authority is the Information Commissioner’s Office (ico.org.uk).
- Withdraw consent at any time where we process your data on the basis of consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To withdraw cookie consent, use the Cookie Preferences link in the site footer, or clear the
gw_consentcookie in your browser settings. To withdraw marketing email consent, use the unsubscribe link in any marketing email or contact us.
8. Cookies and Your Choices
We group cookies and similar technologies into three categories:
- Necessary. Required to keep you logged in, remember your preferences, and secure the Service. These are always on and cannot be turned off.
- Analytics. Help us understand how the Service is used so we can improve it (for example, Google Analytics). Set only with your consent.
- Marketing. Let us measure the performance of our advertising (for example, the Meta Pixel, the Meta Conversions API, and Google Ads). Set only with your consent.
When you first visit, a banner lets you accept all cookies or choose necessary only. We do not load analytics or marketing cookies until you have made a choice and given consent. You can change your choice at any time by clicking the Cookie Preferences link in the site footer of any page, which will reopen the consent banner. You can also clear the gw_consent cookie in your browser settings, or contact us. Disabling necessary cookies through your browser may affect some Service features.
9. Security
We use industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
10. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 14 days before the changes take effect.
12. Contact
Timberline Coffee School
Email: privacy@timberlinecoffeeschool.com