BrightCourse Privacy Policy
Last updated: September 11, 2026
This Privacy Policy explains how BrightCourse collects, uses, protects, and discloses personal information, and how you can contact us about your privacy choices.
BrightCourse is a service of True to Life Productions, Inc.
919 S. Main Street
Snowflake, AZ 85937, United States
1-800-767-7258
This Policy applies to www.brightcourse.com and the BrightCourse account, lesson, training, and communication services that display or link to this Policy, including related interactions with our support team (the "Service"). In this Policy, "BrightCourse," "we," "us," and "our" refer to True to Life Productions, Inc. A separate privacy notice governs a product or service when that notice is provided.
Our Terms and Conditions also govern use of the Service. Applicable customer agreements, data processing agreements, and business associate agreements may impose additional privacy obligations. This Policy does not reduce protections required by those agreements or by applicable law.
Definitions
"Personal Information" means information that identifies, relates to, or can reasonably be linked to an individual. A "Customer" is an organization or individual that subscribes to the Service. A "Client" is an individual a Customer enrolls to receive lessons or other services. "Client Confidential Information" means personal information about Clients submitted to or generated through the Service on a Customer's behalf.
For our own account administration, billing, and business communications, we determine how Personal Information is used. For Client records that we handle at a Customer's direction, we generally act as a service provider or processor. The Customer is responsible for its own collection practices, required notices and consents, and use of Client records. This Policy does not replace the Customer's privacy notice.
Website Visitors
When you visit or use the Service, we collect technical and usage information, such as IP address, browser and device type, language preference, referring page, pages or features used, and the date and time of requests. Cookies and similar technologies can also supply identifiers and preference information. We treat this information as Personal Information when it can reasonably be linked to you or your device.
We use this information to operate the Service, maintain sessions and preferences, protect accounts, investigate errors and misuse, and understand how the Service is used. We disclose it only as described in this Policy. Any de-identified statistics are subject to the safeguards under Aggregated Statistics.
Customer Personal Information
We collect information you or your organization provide when requesting a trial, opening an account, purchasing a subscription, using training, or contacting us. This can include names, work contact details, organization and role, account credentials, billing details, transaction history, training participation and completion, support communications, and communication preferences.
We use Customer information to establish and manage accounts, provide training and completion records, process payments, answer questions, send service notices, improve the Service, and communicate about BrightCourse offerings, subject to your communication preferences and applicable law.
We disclose Customer Personal Information to employees and service providers that need it to operate the Service, including hosting and storage providers, payment processors, messaging and email providers, customer support providers, and providers that help us manage our own customer communications and marketing. Service providers acting on our behalf are required to protect the information and use it only for authorized services, subject to applicable law.
Where a Customer participates in a referral program, we may provide the relevant referral partner with Customer business contact and referral-attribution information needed to administer that referral. Where training reporting is part of the program, we may provide the Customer and relevant training provider with participant identity and completion information. These disclosures do not authorize disclosure of unrelated Client records or use of messaging opt-in information for a partner's own marketing.
We may disclose information to professional advisers or as required by law, a valid legal process, or a legally permitted response to fraud or a security incident. Disclosures of Client Confidential Information remain subject to the restrictions in the next section and any applicable agreement.
Client Confidential Information
Customers and Clients may provide Client names, phone numbers, email addresses, other identifiers, form responses, messages, and notes through the Service. We also process assigned lessons, viewing and completion activity, homework responses, communication delivery information, and related records generated through the features the Customer uses. These records may include sensitive information, such as information about pregnancy, health, family circumstances, or religious beliefs, if a Customer or Client supplies it or it is revealed by their use of lessons.
We use Client Confidential Information to provide the services the Customer requests, deliver lessons and communications, record participation and completion, report activity to the Customer, provide support, investigate service issues, and maintain security. We may also create de-identified aggregate statistics for service monitoring, subject to the safeguards below. These activities are the "Permitted Purpose."
We keep Client Confidential Information confidential and process it on the Customer's behalf for the Permitted Purpose, as authorized by the applicable customer agreement, or as required by law. As between BrightCourse and the Customer, the Customer retains its rights in these records, subject to each individual's privacy rights. We do not sell Client Confidential Information, use it for cross-context behavioral advertising, or disclose it to unrelated organizations for their own marketing.
Access is limited to the Customer's authorized users and our personnel, service providers, and professional advisers who need the information for the Permitted Purpose and are subject to confidentiality obligations. The Customer decides which of its staff may access Client records and which lessons and services to provide. We may also make a disclosure when legally required, subject to applicable restrictions and any required notice to the Customer.
Customers should submit only information needed for the services they use and must have authority to provide it. Where we process protected health information as a business associate under HIPAA, applicable HIPAA requirements and the relevant business associate agreement also govern that processing. This Policy does not replace a healthcare provider's notice of privacy practices.
An authorized Customer may request deletion of Client Confidential Information by contacting us. We will verify the request and delete the information, or return it when required by the applicable agreement, subject to applicable law and the limited retention exceptions described under Data Retention. A Client can contact the organization that enrolled them or contact us for help routing a request. We will coordinate with that organization when we process the records on its behalf.
If we become aware of unauthorized access to or disclosure of Client Confidential Information, we will notify the affected Customer without undue delay, take reasonable steps to contain and address the incident, and provide information needed to support the Customer's response. Any shorter notification deadline in applicable law or a binding agreement continues to apply.
Your Privacy Rights
Your rights depend on your location, the information involved, and whether the relevant law applies to our processing. Subject to applicable conditions and exceptions, you may have the rights described below. We will not unlawfully discriminate or retaliate against you for exercising them.
California residents. Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies, you may request access to the categories and specific pieces of Personal Information we hold about you, information about its sources, purposes, and disclosures, correction, or deletion. You may also have rights to opt out of a sale or sharing for cross-context behavioral advertising and to limit certain uses or disclosures of sensitive Personal Information.
Our handling of Client records is described under Client Confidential Information. Disclosures involving public website advertising or Customer referral programs can be treated as a sale or sharing under applicable law even without a cash payment. You may submit an applicable opt-out request using the contact details below; browser-based choices and preference signals are addressed under Cookies and Similar Technologies.
Other United States residents. Applicable state laws may provide rights to confirm processing, access information, obtain a portable copy, correct or delete information, withdraw consent, and opt out of sales, targeted advertising, or certain profiling used for decisions with legal or similarly significant effects. Where applicable law provides a right to appeal a denied request, contact us using the same channels and state that you are appealing. We will explain our decision and available complaint options.
European Economic Area, United Kingdom, and Switzerland. Where the relevant data protection law applies, you may have rights to access, correct, erase, restrict or object to processing, receive a portable copy, withdraw consent, and complain to your local data protection authority. Withdrawing consent does not affect processing that was lawful before withdrawal. For processing we control, the basis depends on the activity: contract performance for requested services, legal obligations for required records, legitimate interests for administration, support and security, and consent where required. Sensitive information requires an additional legal condition where applicable. For Client records processed on a Customer's instructions, the Customer is responsible for establishing the applicable legal basis.
BrightCourse is based in the United States, and information may be processed there. Privacy laws may differ from those where you live. Where a cross-border transfer is subject to legal restrictions, a lawful transfer basis and any required safeguards are necessary. Contact us for information about the locations and transfer arrangements applicable to your information.
To make a privacy request, email support@brightcourse.com, call 1-800-767-7258, or write to the address under Contact Us. Identify your request and, if relevant, the organization that enrolled you. We may request proportionate information to verify your identity or an authorized agent's authority. Do not send passwords, full payment card numbers, or unnecessary sensitive records. We will respond within the period required by applicable law and explain any permitted extension or refusal. Requests about records controlled by a Customer will be handled with that Customer as required by law.
Children and Teenagers
The Service is not directed to children under 13, and Customers must not enroll children under 13 or submit their Personal Information through the Service. We do not knowingly collect Personal Information online from children under 13. If you believe such information has been submitted, contact us so we can investigate and take steps to delete it as required by law.
Teenage Clients may receive lessons or services through a Customer. The Customer is responsible for any notices, permissions, and consent required for its services, including rules protecting a minor's ability to consent and confidentiality where applicable. We verify a parent's or guardian's authority before responding to a request for a minor's information. Customer account holders must meet the age requirements in our Terms and Conditions.
Data Retention
We retain Personal Information only for as long as reasonably necessary for the purposes described in this Policy. The period depends on the type of record, whether an account or service relationship remains active, the Customer's instructions and contract, applicable retention requirements, and a need to address security issues, disputes, or legal claims. Closing an account does not necessarily delete every record immediately.
Account and billing records may be retained after closure to complete transactions, meet tax and accounting obligations, and resolve disputes. Client records are retained for the Customer's authorized services and handled in accordance with its instructions, the applicable agreement, and law. Technical and security records are retained as needed to investigate errors, prevent misuse, and protect the Service. Consent and opt-out records may be retained to document and honor communication choices.
When information is no longer needed, we delete it or de-identify it where permitted. Information subject to a legal retention obligation or preservation requirement is retained only for that purpose and remains protected. Deleted information may remain temporarily in restricted backups until those backups expire through the regular backup cycle. If a backup is restored, applicable deletion requests must be reapplied. These exceptions do not permit routine reuse of deleted Client records or override stricter legal or contractual deletion requirements.
Security
We use reasonable administrative, technical, and physical safeguards designed to protect Personal Information. These include encrypted HTTPS/TLS connections for web access to the Service, account authentication, permissions that restrict access to authorized users, and limiting personnel access to those who need it for their duties. Users are responsible for protecting their credentials, managing authorized access, and promptly reporting suspected account misuse. No method of internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
Data Breach Notification
We investigate suspected security incidents and take reasonable steps to contain and address them. When a breach requires notice, we will notify the appropriate Customers, affected individuals, regulators, and other parties within the time and in the manner required by applicable law and our binding agreements. We will coordinate with the Customer when it is responsible for notifying its Clients. This provision also applies to Personal Information outside Client records and does not limit the Customer notification obligation described above.
Links to External Sites
The Service may link to third-party websites or services. When you follow a link or use an independently provided service, that provider's privacy notice explains its practices. Review that notice before submitting Personal Information.
We do not control independent third-party sites or their privacy practices. This does not remove our obligations for information we disclose to service providers acting on our behalf.
Aggregated Statistics
We may use or publish aggregate statistics about website use and Service performance only in a form that does not identify, and cannot reasonably be linked back to, an individual. We take reasonable steps to prevent re-identification, do not attempt to re-identify information we maintain as de-identified except as permitted by law to test the de-identification process, and require recipients of de-identified data to follow applicable restrictions.
Text and Email Communications
We process phone numbers, email addresses, message content, delivery information, and records of opt-in and opt-out choices to provide communications requested by Customers and users. We do not sell or share mobile numbers, email addresses, or messaging opt-in information with third parties or affiliates for their own marketing or promotional purposes. We may disclose the information to the organization that collected it and to service providers and carriers solely as needed to support the communication service, or when disclosure is required by law.
To stop texts, reply STOP to the number sending the messages. For help, reply HELP or contact us. You can unsubscribe from marketing emails using the instructions in the email or by contacting us. Opting out of marketing does not necessarily stop account, billing, or other nonmarketing notices permitted by law. A text opt-out does not itself delete Client records. Additional texting terms are available in our Short Code Usage Policy at https://brightcourse.com/short-code-usage-policy.
Cookies and Similar Technologies
We use cookies and similar technologies to maintain sign-in sessions, remember preferences, deliver requested features, and help protect the Service. A cookie is a small file stored by your browser. Related technologies, such as local storage and device identifiers, can help recognize a browser or device.
Our public website may also use analytics and marketing technologies to measure visits, understand interactions, and support advertising for BrightCourse. Depending on the tool, website identifiers and activity may be disclosed to analytics or advertising providers. These activities are distinct from our processing of Client Confidential Information to deliver lessons and communications and remain subject to applicable consent and opt-out requirements.
Where applicable law requires consent for a cookie or similar technology, we will obtain that consent before using it and provide a way to withdraw it. Continuing to browse does not, by itself, provide that consent. You can also use browser settings to block or delete cookies, although this may affect sign-in and other features. Browser cookie settings may not control every form of tracking. Contact us using the details below to ask about tracking choices or withdraw consent. We will honor legally recognized browser opt-out signals, such as Global Privacy Control, when required by applicable law.
Payments and Purchases
When you buy a subscription or product, we and our payment providers process the contact, billing, and payment information needed to complete the transaction, manage the subscription, maintain transaction records, and address billing inquiries or fraud. Information is disclosed only as described in this Policy and as necessary to process payment. You may decline to provide requested information, but we may be unable to complete the purchase or provide a feature that requires it.
Governing Law
This Policy is governed by Arizona law to the extent permitted by applicable law. Nothing in this Policy limits mandatory privacy protections, remedies, or rights available to you under the law that applies to you or to our processing.
Privacy Policy Changes
We may update this Policy to reflect changes in the Service, our practices, or legal requirements. We will post the revised Policy and update the date above. For material changes, we will provide additional notice and obtain consent when required by applicable law. Continued use of the Service does not replace any consent that the law requires.
Contact Us
For privacy questions or requests, contact:
True to Life Productions, Inc.
Attention: BrightCourse Privacy Requests
919 S. Main Street
Snowflake, AZ 85937, United States
Phone: 1-800-767-7258
Email: support@brightcourse.com