HEIGHTS PRIVACY POLICY

We believe that privacy is important. As such, we only collect the information needed to conduct business and improve your experience. We will never sell your data and we will not share your data without your permission. Our Privacy Policy below, and our list of Subprocessors covers a list of the data we collect, how and why we use it, and where it is kept.

1. Introduction

Thank you for visiting our Site and/or using Heights, an app designed to allow you to build and manage your own online education program. This Privacy Policy, like our Terms of Service, is an integral part of using our service, and you must completely agree to it in order to use our website and service.

2. Definitions

Throughout this document, we may use certain words or phrases, and it is important that you understand the meaning of them. The following is a non-exhaustive list of definitions of words and phrases found in this document:

“App” refers to our Heights app, which provides a platform for creating and managing online education programs;

“Heights” refers to our company, known as “Velora Studios, LLC”; our Site; our Service; our App; or a combination of all or some of the preceding definitions, depending on the context in which the word is used;

“Privacy Policy” refers to this Privacy Policy;

“Service” refers to the services that we provide through our Site, including our Site itself, our education platform creation services, our App, and any other services we may provide online or offline;

“Site” refers to our website, www.heightsplatform.com;

“Subprocessor” refers to an entity which processes personal data on behalf of Heights so that we can provide our Service;

“User” refers to users of our App, and general visitors to our Site;

“You” refers to you, the person who is governed by this Privacy Policy.

3. Information Collected

Identifying Information

We collect certain personal information from you when you sign up to our Service that can be used to identify you, such as your name, e-mail address, credit card information, IP address, time zone information, password, and any other information that we may deem relevant to provide our Service to you. The information we collect from you, to the extent that it is private, is disclosed only in accordance with our Terms of Service and/or this Privacy Policy. We will never sell your personal info to third parties, and we won’t use your name or company in our marketing materials without your permission.

Non-Identifying Information

Whenever you visit our Site, we may collect non-identifying information from you, such as your IP address, referring URL, browser, operating system, cookie information, and Internet Service Provider. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, this information alone cannot usually be used to identify you.

4. Use of Your Information

We may use your information to:

  • Enhance or improve User experience, our Site, or our Service.
  • Process transactions.
  • Send e-mails about our Site or respond to inquiries.
  • Target advertisements that we believe may be of interest to you.
  • Provide you with our Service (such as by storing data of courses and lessons you create on our servers so that you may access them using the App).
  • Provide support to help you improve your program and or courses within them.
  • Tracking behavior metrics for improvement of our Service. Please note that although we may track User behavior (e.g., last login date and percentage of lessons completed, last lesson views, numbers of students and courses in a program), we will not store and track sensitive payment information on our servers. Payment information is instead stored by a PCI compliant third party vendor (Stripe).
  • If Heights merges with or is acquired by another company. Should this ever happen, we will notify you before any personal information is transferred and becomes subject to a different policy.
  • Perform any other function that we believe in good faith is necessary to protect the security or proper functioning of our Site or Service.

5. Accessing, Editing, and Removing Your Information

Users may in some cases be able to review and edit the personal information they have provided to us by logging into your account on the Site and editing their account. Although most changes may occur immediately, information may still be stored in a web browser’s cache. We take no responsibility for stored information in your cache, or in other devices that may store information, and disclaim all liability of such. In addition, we may, from time to time, retain residual information about you in our backup and/or database.

6. Cookies

We use cookies to create a session and remember a User as they use our Site, in order to distinguish them from other Users. We also use them to remember your preferences, compile statistical data about the usage of our Site, protect against malicious usage of our Site and optimize the speed of our Site. For this reason, it is necessary that you enable cookies in your browser in order to use our Service, and you hereby acknowledge that we have informed you of our use of cookies and that you consent to our use of cookies in relation to your computer system. There are four primary uses for different types of cookies we may use:

Cookie Type Purpose
Operation Essential These cookies are necessary for us to provide our Service. They help to recognize your account status, protect your account security, and remember your preferences.
Analytics These cookies help us to maintain and continuously improve our Service. We use this type of cookie to help improve your experience using our Service.
Advertising We use these cookies to serve advertisements that we believe may be relevant to your interests, and to measure the effectiveness of these advertisements. We also may use the information provided by this type of cookie for frequency capping purposes (ie: to ensure we are not serving the same advertisement to you too many times).
Third Party Subprocessors and other businesses we have contracted may use cookies for the same purposes as described above.

Revoking permission of certain cookies that are not operation essential for us to provide our service:

Heights uses the Facebook Conversion Tracking Pixel, a service of Facebook, Inc. (https://www.facebook.com/policy.php). This cookie is an advertising type cookie which allows us to record the results of our advertisement performance for marketing purposes. You can revoke the permission for Facebook to track this at the following link: https://www.facebook.com/ads/website_custom_audiences/

Heights uses Google Analytics, a service of Google, Inc. (https://policies.google.com/privacy?hl=en) which allows us to track visits to our website and other browser data so that we can improve your experience. Our particular use of Google Analytics keeps your IP address anonymized before Google records it. This anonymized, or masked IP address, will not be connected to any other data on Google. This is an analytics type cookie. You can prevent analysis of your browser behavior across all websites using Google Analytics by installing this browser plugin: http://tools.google.com/dlpage/gaoptout. Google Analytics Advertising Features may also use anonymized insights into your device behaviors, and you can access and or delete such data via Google's "My Activity" page.

7. Third Party Websites

Heights may post links to third party websites on its Site. These third party websites are not screened for privacy or security issues by Heights, and you release us from any liability for the conduct of these third party websites.

Please be aware that this Privacy Policy, and any other policies in place, in addition to any amendments, does not create rights enforceable by third parties or require disclosure of any personal information relating to members of the Service or Site. Heights bears no responsibility for the information collected or used by any advertiser or third party website. Please review the privacy policy and terms of service for each site you visit through third party links.

8. Third Party Access to Your Information

Although you are entering into an Agreement with Heights to disclose your information to us, we do use third party individuals and organizations to assist us, including contractors, web hosts, and others.

Throughout the course of our provision of our Service to you, we may delegate our authority to collect, access, use, and disseminate your information. For example, our web host stores the information that you provide us, and we may hire outside contractors to perform maintenance or assist us in securing our website. A current list of vendors is available upon request.

It is therefore necessary that you grant the third parties we may use in the course of our business the same rights that you afford us under this Privacy Policy. For this reason, you hereby agree that for every authorization which you grant to us in this Privacy Policy, you also grant to any third party that we may hire, contract, or otherwise retain the services of for the purpose of operating, maintaining, repairing, or otherwise improving or preserving our website or its underlying files or systems. You agree not to hold us liable for the actions of any of these third parties, even if we would normally be held vicariously liable for their actions, and that you must take legal action against them directly should they commit any tort or other actionable wrong against you.

Without limiting the generality of the foregoing, you authorize us to use the following third party services which may also store data about you:

Supplier Data Type Anonymized Discarded Archived
Airbrake Error logs
Algolia Search queries Yes Automatically after ~24 hours
Amazon Web Services Media files Yes
ActiveCampaign Email, name
ActiveCampaign Browser identifiers
CloudFlare Media files Yes After trial or subscription ended
Continually Email, name
Continually Browser identifiers
Google Analytics Browser identifiers Yes
Help Scout Email, name
Help Scout Browser identifiers
Heroku Email, name After trial or subscription ended
Heroku Password Bcrypt encryption After trial or subscription ended
Heroku Account data/media files After trial or subscription ended
Plerdy Browser identifiers Yes Automatically after 6 months
Posthog Account analytics Yes After trial or subscription ended
OpenAI Account data After trial or subscription ended
Scout APM Operation heuristics Yes
Segment Browser identifiers
Segment Email, name
Segment Account analytics
Sendgrid Email, name
Stripe Credit card data PCI Compliant
Transloadit Media files Yes Automatically after ~24 hours
  • Anonymized: Any data that could be used to identify the data subject is scrubbed, or a specific encryption policy is used in a case where data is not anonymized.
  • Discarded: Data is destroyed automatically without requiring a request by data subject
  • Archived: Data can only be accessed by Heights founder.

You authorize us to allow third party Site and App visitors to view and download data to their respective devices (not limited to mobile phones, tablets, laptops, computers), whether these third party visitors access this content via our Site, App or view and download this content via any mobile application which displays it. Without limiting generality, you understand that the ability of other parties to view information you save in our App and Site is a part of the Service we are providing to you.

9. Release of Your Information for Legal Purposes

At times it may become necessary, for legal purposes, to release your information in response to a request from a government agency or a private litigant. You agree that we may disclose your information to a third party where we believe, in good faith, that it is desirable to do so for the purposes of a civil action, criminal investigation, or other legal matter. In the event that we receive a subpoena affecting your privacy, unless we are legally prevented from it, we will notify you to give you an opportunity to file a motion to quash the subpoena, or we may attempt to quash it ourselves, but we are not obligated to do either. We may also proactively report you, and release your information to, third parties where we believe that it is prudent to do so for legal reasons, such as our belief that you have engaged in fraudulent activities. You release us from any damages that may arise from or relate to the release of your information to a request from law enforcement agencies or private litigants.

10. Commercial and Non-Commercial Communications

By providing information to the Site that forms the basis of communication with you, such as contact information, you waive all rights to file complaints concerning unsolicited email from Heights since, by providing such information, you agree to receive communication from us other anyone else covered under this Privacy Policy. However, you may unsubscribe from marketing communications by clicking on the unsubscribe links in our marketing emails, or by notifying Heights that you no longer wish to receive solicitations or information and we will remove you from the database. We may still send certain transactional emails required in order to provide you notice to important alerts regarding your account in our Service.

11. Security Measures

We take certain measures to enhance the security of our Site and Service, such as by using SSL Certificates. Your data is encrypted in transit between you and Heights for account and payment related pages. Should you be accessing our service through a custom domain (ie: a domain other than heightsplatform.com), ensure that the domain used to access our service also has HTTPS if you want your data to be encrypted throughout our entire App. We make routine, secure backups of your data, and we use multiple techniques to eliminate points of failure. We also conduct security reviews on our Service periodically and ensure that third party contractors and employees only have access to the information that is necessary for them to perform their job. However, we make no representations as to the security or privacy of your information. It is in our best interest to keep our website secure, but we recommend that you exercise precautions and use anti-virus software, firewalls, and other precautions such as not telling others your password to protect yourself from security threats. If you need to report an exploit, or you have noticed and incident with your account, please contact us at [email protected].

12. Security Breach Notifications

In the event that your private data are disclosed to unauthorized people (ie: hackers), Heights will send email notifications to all possibly affected parties. We may also make an announcement on our Site directly.

13. Deleted Data

We retain your personal information for the duration of our business relationship, and afterwards for as long as necessary for legitimate business purposes until you exercise your right to erase your personal information. When you request your account and personal information be deleted, we’ll ensure that nothing is stored on our servers past 30 days. Data that you choose to delete from your account while it is active will also be deleted within 30 days, though most data is deleted instantly.

14. GDPR Rights

The General Data Protection Regulation (“GDPR”) gives people under its protection certain rights with respect to their personal information collected by us on the Site. Accordingly, Heights recognizes and will comply with GDPR and those rights, except as limited by applicable law. The rights under GDPR include:

  • Right to Be Informed. This is your right to know how we will process your data, who will process it, and where it might be located.
  • Right to Access. This includes your right to access the personal information we gather about you, and your right to obtain information about the sharing, storage, security and processing of that information.
  • Right to Rectification. This is your right to request correction errors and updating of incomplete information.
  • Right to Erasure. This is your right to request, subject to certain limitations under applicable law, that your personal information be erased from our possession (also known as the "Right to deletion" or "Right to be forgotten"). However, if applicable law requires us to comply with your request to delete your information, fulfillment of your request may prevent you from using Heights services and may result in closing your account.
  • Right to Restrict Processing. This is your right to request restriction of how and why your personal information is used or processed.
  • Right to Object. This is your right, in certain situations, to object to how or why your personal information is processed.
  • Right to Portability. This is your right to receive the personal information we have about you and the right to transmit it to another party.
  • Right to not be subject to Automated Decision-Making. This is your right to object and prevent any decision that could have a legal, or similarly significant, effect on you from being made solely based on automated processes. This right is limited, if the decision is necessary for performance of any contract between you and us, is allowed by applicable European law, or is based on your explicit consent.

Many of these rights can be exercised by logging in to our App and directly updating or deleting your account data. If you have any questions about exercising these rights, please contact us at [email protected].

15. Your California Online Privacy Rights

This section pertains only to residents of California. Heights permits residents of California to use its services. Therefore, it is the intent of Heights to comply with the California Business and Professions Code §§ 22575-22579 and the California Consumer Privacy Act of 2018 (“CCPA”). If you are a California resident, you may request certain information regarding our disclosure of personal information to any third parties for their direct marketing purposes. Various provisions throughout this Privacy Policy address requirements of the Californian privacy statutes. In summary, you must presume that we collect electronic information from all visitors.

Below are the rights you have, though these are not absolute. In certain cases we may decline your request as permitted by law.

  • Information: You can request the following information about how we have collected and used your personal information during the past 12 months:
    • The categories of personal information that we have collected.
    • The categories of sources from which we collected personal information.
    • The business purpose for collecting your personal information.
    • The categories of third parties with whom we share personal information.
    • Whether we have disclosed your personal information for a business purpose, and if so, the categories of personal information received by each category of third party recipient.
    • Whether we’ve sold your personal information, and if so, the categories of personal information received by each category of third party recipient.
  • Access: You may request a copy of the personal information that we have collected about you.
  • Deletion: You may ask us to delete the personal information that we have collected from you.
  • Nondiscrimination: You are entitled to exercise the above rights free from discrimination.

You may contact us at [email protected] with any questions or to exercise these rights listed above. We may require government identification to process your request and to confirm your residency.

16. Minors

Individuals under 13 years of age are not allowed to use our Service. If you become aware of a User who is under the required age to use our Service, please notify us immediately at [email protected] and provide us with full details as to why you believe they are below that age and we will address the issue. If you are a User who is reported in this manner, we may require you to provide suitable proof of age, such as a copy of government identification, in order to continue using our Site and/or Service.

17. International Transfer

Your information may be transferred to - and maintained on - computers located outside of your state, province, country or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. Heights transfers Personal Information to the United States and to multiple third party Subprocessors (List of Subprocessors). We enter into GDPR-compliant data processing agreements with each of these Subprocessors. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

18. Amendments

Like our Terms of Service, we may amend this Privacy Policy from time to time. When we amend this Privacy Policy, we will update this page. We may send out an email notification to notify you if more significant changes are made. You must read this page each time you access our Site and Service and notify us at [email protected] with details sufficient to identify your account if you do not agree to the amendments, so that we may terminate your account. You may also contact us via mail with questions at:

Attn: Velora Studios, LLC
16192 Coastal Highway
Lewes, Delaware 19958
United States

Last Modified: May 25, 2024