Privacy Policy
1. This static storefront is designed to minimize data collection
This static storefront is designed to minimize data collection. The cart, cookie choice, and demo checkout state use browser localStorage. No backend is included, so this project does not transmit the demo checkout form to a ChalkLoft server.
2. In a production implementation, information such as a name, email address, student records, course activity, billing information, and support messages may be processed by the relevant service providers
In a production implementation, information such as a name, email address, student records, course activity, billing information, and support messages may be processed by the relevant service providers. Only information needed to provide the requested service should be collected.
3. Student data belongs to the course owner
Student data belongs to the course owner. ChalkLoft is a software provider and does not claim ownership of student records. Course owners remain responsible for lawful collection, notices, retention, access requests, and security practices applicable to their students.
4. Payment card information should be handled by a compliant payment provider rather than stored in the static site
Payment card information should be handled by a compliant payment provider rather than stored in the static site. This demo deliberately has no payment processing connection and should not be treated as a payment system.
5. You may clear localStorage through browser settings to remove local demo state
You may clear localStorage through browser settings to remove local demo state. A live service would provide account, deletion, export, security, and privacy controls appropriate to the information it actually processes.
6. Google Fonts may make network requests when a visitor loads the site
Google Fonts may make network requests when a visitor loads the site. If a deployment requires stricter privacy or offline behavior, fonts can be self-hosted and the external font links removed.
Last updated: September 21, 2026.
Additional guidance
In addition, the site should not be used to collect sensitive information through the demo form. A production operator should document retention periods, access controls, incident response, processors, international transfers, and applicable rights before accepting real student data. The static files themselves do not create a student database. Any future account system should use secure authentication and least-privilege access, and should provide a clear mechanism for correcting or deleting personal information where required.