Legal

Privacy Policy

Effective date: June 17, 2026

1. Introduction

This Privacy Policy describes how OSHA Safety Training ("OSHA Safety Training," "Company," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit our website, create an account, purchase or take an online training course, request a certificate of completion, contact us, or otherwise interact with our products and services (collectively, the "Services").

By using the Services, you acknowledge that you have read and understand this Privacy Policy. This Policy is incorporated into and forms part of our Terms of Service.

Important. OSHA Safety Training is a private training company. We are not the U.S. Occupational Safety and Health Administration or any other government agency, and we are not affiliated with or endorsed by any government agency.

2. Information We Collect

We collect the following categories of personal information:

(a) Information you provide directly. Name, email address, postal address, phone number, employer name and contact, job title, the legal name to print on your certificate, account password (in hashed form), course enrollments, exam answers and scores, communications with our support team, testimonials, and any other information you choose to submit.

(b) Payment information. Billing address and payment-method details processed by our third-party payment processors. We do not store full payment-card numbers on our servers.

(c) Training and certification data. Course progress, time spent on each module, quiz and exam responses, pass/fail outcomes, attempts, certificate numbers, and issue/expiration dates.

(d) Automatically collected information. IP address, device and browser information, operating system, language, referring/exit pages, pages viewed, links clicked, session duration, approximate location derived from IP, and similar telemetry collected through cookies, log files, pixels, and similar technologies (see Section 7).

(e) Information from third parties. Information from employers that enroll you, single-sign-on or identity providers you use to authenticate, advertising and analytics partners, and publicly available sources.

We do not knowingly collect Social Security numbers, driver's-license numbers, precise geolocation, biometric identifiers, or information from children under 16. The Services are not directed to children under 16, and we ask that they not use the Services or provide personal information to us.

3. How We Use Personal Information

We use personal information to:

  • provide, operate, and maintain the Services and your account;
  • deliver training content, administer examinations, calculate scores, and issue, verify, and re-issue certificates of completion;
  • process payments, refunds, and chargebacks;
  • respond to inquiries, provide customer support, and send transactional communications (e.g., receipts, certificate emails, expiration reminders, policy updates, service notices);
  • share completion records with your employer or designated third party when you or your employer requests or authorizes it (for example, when your employer purchases training on your behalf);
  • detect, investigate, and prevent fraud, account sharing, certificate misuse, cheating, abuse, and security incidents;
  • analyze and improve the Services, develop new features, and conduct research and reporting;
  • send marketing communications about courses, promotions, and updates (you can opt out at any time);
  • comply with legal obligations, enforce our Terms, and protect the rights, property, or safety of OSHA Safety Training, our users, and others.

4. Legal Bases for Processing

Where required by law (for example, under GDPR or UK GDPR), we rely on the following legal bases: performance of a contract with you; compliance with a legal obligation; our legitimate interests in operating, securing, and improving the Services and preventing fraud; and your consent, where consent is required (for example, certain cookies and marketing). You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. How We Share Personal Information

We share personal information with the following categories of recipients:

(a) Employers and authorized purchasers. If your employer or another party purchases training for you, we may share your enrollment status, progress, scores, and certificate information with that party.

(b) Service providers. Vendors that help us operate the Services, including cloud hosting, payment processors, email and SMS providers, customer-support platforms, analytics, advertising, fraud-prevention, identity verification, and learning-management integrations. These providers are bound by contract to use personal information only as needed to perform services for us.

(c) Verification. When a certificate holder, employer, regulator, insurer, or auditor asks us to verify the validity of a certificate, we may confirm whether the certificate is valid and, if so, the name on it, the course, the issue date, and any expiration or revocation status.

(d) Legal and safety. Government authorities, courts, law enforcement, or other third parties when we believe disclosure is necessary or appropriate to comply with applicable law, legal process, or government requests; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of OSHA Safety Training, our users, or others.

(e) Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of the transaction.

(f) With your consent or at your direction.

We do not sell personal information for money. Some advertising and analytics cookies may constitute "sharing" or a "sale" of personal information under certain U.S. state privacy laws (such as California's CCPA/CPRA). See Section 9 for your rights and how to opt out.

6. Data Retention

We retain personal information for as long as needed to provide the Services, maintain training and certification records, comply with our legal, tax, accounting, and recordkeeping obligations, resolve disputes, and enforce our agreements. Because employers, regulators, insurers, and auditors may need to verify training records years after issuance, we generally retain training and certificate records for the longer of the certificate's stated validity period or the applicable statute of limitations, and may retain them indefinitely in de-identified or aggregated form.

7. Cookies and Similar Technologies

We and our service providers use cookies, pixels, local storage, SDKs, and similar technologies to operate the Services, remember your preferences, authenticate you, measure performance, analyze usage, prevent fraud, and (where permitted) deliver advertising. You can usually control cookies through your browser settings; blocking some cookies may impair certain features of the Services. Where required, we present a cookie banner that allows you to manage non-essential cookies.

We honor Global Privacy Control (GPC) signals as a request to opt out of "sale" or "sharing" of personal information for cross-context behavioral advertising, where applicable.

8. Security

We use administrative, technical, and physical safeguards designed to protect personal information against loss, theft, misuse, and unauthorized access, disclosure, alteration, or destruction. These measures include encryption in transit, access controls, and vendor due diligence. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials.

9. Your Privacy Rights

Depending on where you live, you may have the following rights with respect to personal information we hold about you:

  • access, correct, update, or delete your personal information;
  • obtain a portable copy of your personal information;
  • opt out of the "sale" or "sharing" of personal information and of targeted advertising;
  • limit the use of sensitive personal information (where applicable);
  • opt out of marketing communications;
  • withdraw consent where processing is based on consent;
  • appeal a denial of a privacy request, where required by law;
  • lodge a complaint with a supervisory authority (EEA, UK) or your state attorney general.

To exercise these rights, contact us at the address in Section 14. We will verify your request using account details and may decline requests where permitted by law. You may designate an authorized agent to make a request on your behalf, subject to verification. We will not discriminate against you for exercising your privacy rights.

Training records and certificates. Even where you request deletion, we may retain certificate-validity records as needed to honor employer, regulator, auditor, and insurer verification requests, to comply with our legal obligations, and to preserve the integrity of training records. Where possible, we will de-identify or restrict access to such records following a deletion request.

10. U.S. State-Specific Disclosures

California (CCPA/CPRA). In the past 12 months we have collected the categories of personal information listed in Section 2 from the sources described there, used them for the purposes in Section 3, and disclosed them to the categories of recipients listed in Section 5. We do not knowingly sell or share the personal information of consumers under 16. To exercise CCPA rights, including the right to opt out of sale/sharing or to limit use of sensitive personal information, contact us as described in Section 14 or use any "Your Privacy Choices" link we provide.

Other states. Residents of states such as Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Jersey, and others with comprehensive privacy laws have similar rights to access, correct, delete, and obtain copies of personal information, to opt out of targeted advertising, "sale," and certain profiling, and to appeal denials. We process these requests consistent with applicable law.

11. International Users and Data Transfers

The Services are operated from the United States. If you access the Services from outside the United States, your personal information will be transferred to, stored, and processed in the United States and other countries that may have data protection laws different from those in your country. Where required, we use appropriate safeguards such as Standard Contractual Clauses to transfer personal information from the EEA, UK, or Switzerland to the United States.

12. Third-Party Sites and Services

The Services may contain links to or integrations with third-party websites, applications, and services. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy notices of any third party you interact with.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Effective date" above and may provide additional notice (such as an email or in-product notice). Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.

14. Contact Us

For privacy questions or to exercise your rights, contact:

OSHA Safety Training
Attn: Privacy
Email: support@example.com