JoinCPR JoinCPR

Privacy Policy

Last updated September 28, 2026

JoinCPR ("we", "us") provides software that training providers ("Businesses") use to schedule classes, register students, collect payments and issue certificates. This policy explains what personal information we handle, why, and the choices you have. It covers our own site and dashboard and the registration sites we host for Businesses.

Two roles

For Businesses that hold an account with us, we are the data controller for the account information described below.

For students who register for a class through a Business's site, the Business is the controller: it decides what to collect and how to use it, and it is your first point of contact for questions, corrections and deletion. We process student information on the Business's behalf to run the Service. If you contact us about student data we will pass the request to the Business unless we are required to act ourselves.

Information we collect

From Businesses

From students (on behalf of a Business)

How we use it

Who we share it with

We do not sell personal information.

Mobile numbers and SMS consent

We never share mobile information with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, sold, rented or transferred, and are not included in the data sent to integrations a Business connects; they are used only to send the class texts a student agreed to, on behalf of the Business they registered with.

Students receive texts only after ticking an unchecked-by-default consent box. Message frequency varies, typically one message per class registered. Message and data rates may apply. Reply STOP to any message to opt out or HELP for help. See our SMS Terms and Conditions.

Cookies

We use cookies needed to keep you signed in and to protect forms from forgery. We do not use advertising cookies. Your browser can block cookies, but the dashboard and student portal need them to work.

Retention

Business account data is kept while the account is active and for a limited period after closure so it can be exported, then deleted except where we must keep records for tax or legal reasons. Student records are kept for as long as the Business keeps them; certificates are typically retained for the life of the certification and a reasonable period after. Email and activity logs are pruned automatically after one and two years respectively.

Security

Data is encrypted in transit (TLS) and sensitive credentials such as processor tokens are encrypted at rest. Access to production systems is restricted and logged. No system is perfectly secure; if we learn of a breach affecting your information we will notify affected Businesses without undue delay so they can inform their students.

Your choices and rights

Children

The Service is intended for adults. Businesses that train minors are responsible for obtaining any consent their law requires before entering a minor's details. We do not knowingly collect information directly from children under 13.

Where data is processed

Our servers are in the United States. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.

Changes

We will post updates here with a new date and notify Businesses by email of material changes.

Contact

JoinCPR, [email protected], (855) 223-3496.