Privacy Policy
1. Who we are and how to contact us
Can't Stop the Growth ("CSTG", "we", "us") provides a workforce training platform for home-services contractors — HVAC, plumbing and electrical companies. This policy explains what personal information the CSTG platform at app.cstgtraining.com collects, how we use it, and the choices you have.
Legal entity: Cant Stop the Growth [CONFIRM FULL REGISTERED LEGAL NAME AND ENTITY TYPE, e.g. "Can't Stop the Growth, LLC"]
Address: 656 S. Graham Rd., Greenwood, IN 46143, United States
Email: danny@cantstopthegrowth.com
[DATA PROTECTION CONTACT / DPO, IF APPLICABLE]
2. Information we collect
Account data
Name, work email address, role or job title, team, and the company that provisioned the account. Accounts on CSTG are normally created by the company that subscribes to the platform.
Training activity
Course and learning-track enrollment, lesson and module progress, skill and certification status, event and cohort attendance, assessment and survey responses, coaching or one-on-one notes recorded by managers, and related timestamps.
Calendar data
If — and only if — a user chooses to connect a Google Calendar or Microsoft Outlook calendar, we access calendar event data as described in section 4.
Technical data
Log data needed to operate and secure the service: IP address, browser and device type, and timestamps of requests. We use only cookies necessary for authentication and session management. [CONFIRM WHETHER ANY ANALYTICS OR PRODUCT-USAGE TOOLING IS IN USE AND LIST IT HERE]
3. How we use information
- To provide the platform: authenticate users, deliver training content, record progress, and run events and cohorts.
- To let managers, training leads and owners at a user's own company see team progress and analytics.
- To create, update and synchronize CSTG training events on a user's connected calendar, where the user has enabled that.
- To send service communications — enrollment notices, event reminders, campaign and survey invitations, and account or security notices.
- To secure the service, prevent abuse, troubleshoot, and meet legal obligations.
We do not sell personal data. We do not use personal data or calendar data for advertising, and we do not use it to train generalized artificial-intelligence or machine-learning models. [CONFIRM LEGAL BASES IF YOU SERVE UK/EU USERS — e.g. contract, legitimate interests, consent for calendar connection]
4. Calendar data (Google Calendar and Microsoft Outlook)
What we access
Calendar events. When a user connects a calendar, CSTG uses the authorized calendar scopes to create, read, update and delete the calendar events that correspond to CSTG training sessions and live events the user is enrolled in. Where the connected calendar API requires access to the calendar as a whole in order to write and reconcile those events, CSTG's processing is limited to CSTG-created or CSTG-managed events; we do not read, store, index or analyze the content of unrelated events.
Why we access it
So that the training a user is enrolled in appears on the calendar they already use, and so that reschedules, cancellations and updates stay accurate in both places. Calendar connection is optional and the platform is fully usable without it.
Retention
We store the minimum needed to keep the two systems in sync: the identifier of the connected calendar, the identifiers of CSTG-created events, and sync state such as last-sync timestamps and change tokens. This data is deleted when the user disconnects the calendar or when the account is deleted, and in any case within [30] days of disconnection. [CONFIRM RETENTION WINDOW]
Tokens
OAuth access and refresh tokens are stored encrypted at rest and are used only to perform the calendar synchronization described above. They are never shared with third parties.
How to disconnect
A user can disconnect at any time in CSTG under account settings, which revokes the token and stops all sync. Access can also be revoked directly from the Google Account permissions page (myaccount.google.com/permissions) or from Microsoft account app permissions (account.live.com/consent/Manage).
Limited use
CSTG's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
CSTG's use and transfer of information received from Microsoft APIs, including the Microsoft Graph and Outlook calendar APIs, will adhere to the Microsoft APIs Terms of Use and the Microsoft Services Agreement, including their limited-use and data-handling requirements. Microsoft calendar data is used only to provide the calendar synchronization features described above and is never sold, transferred for advertising, or used for any unrelated purpose.
5. Data sharing
We share personal data only with service providers who process it on our behalf so we can run the platform, and only for that purpose:
- Cloud hosting and database infrastructure — [HOSTING PROVIDER]
- Transactional email delivery — [EMAIL PROVIDER]
- [ANY OTHER SUBPROCESSOR — e.g. error monitoring, video hosting]
We also share data with the company that provisioned a user's account — a user's employer can see that user's training activity and progress. We may disclose information if required by law or to protect the rights and safety of users and the service, and in connection with a merger or acquisition, in which case this policy continues to apply to the transferred data. We do not sell personal data or calendar data, and we do not share it with advertisers or data brokers.
6. Data retention and deletion
We keep account and training records for as long as the company's subscription is active and the account exists, and afterwards only as long as needed for legal, tax or dispute-resolution purposes. Calendar sync data follows the shorter retention described in section 4.
A user may request access to, correction of, or deletion of their personal data by emailing danny@cantstopthegrowth.com; where the account was provisioned by an employer, we will coordinate with that company's administrator. A company administrator may request deletion of the company workspace and all associated user data by the same address. We respond to verified requests within [30] days and delete data from live systems and from backups on our normal backup-expiry cycle of [BACKUP RETENTION PERIOD]. [CONFIRM STATE/REGIONAL PRIVACY RIGHTS LANGUAGE — e.g. GDPR, CCPA — IF APPLICABLE]
7. Security
Data is encrypted in transit with TLS and at rest, including OAuth tokens. Access to production systems is limited to authorized personnel, protected by individual accounts and multi-factor authentication, and logged. We review access periodically. No system can be guaranteed perfectly secure, but we work to protect data using measures appropriate to its sensitivity. [CONFIRM ANY CERTIFICATIONS OR AUDITS, e.g. SOC 2 — OMIT IF NONE]
8. Children
CSTG is a workplace training platform. It is not directed at, and we do not knowingly collect personal information from, anyone under 18 years of age. If we learn that we have collected such information, we will delete it.
9. Changes to this policy
We may update this policy as the platform changes. When we do, we will revise the effective date above and, for material changes, notify account administrators by email or through the platform before the change takes effect.
10. Contact
Questions about this policy or about your data: danny@cantstopthegrowth.com, or Can't Stop the Growth, 656 S. Graham Rd., Greenwood, IN 46143, United States.