Privacy Policy
Effective 29 July 2026
In Plain English
Sturdy Beacon LLC collects the minimum information required to sell you a leadership course and deliver it to you online. Your name, your email, your password, and your payment card. While you take the course, the learning system records which modules you finished and how you did on the exercises, because that is how any online course works. If you visit the website, standard analytics run in the background so the Company can understand what pages people find useful.
The Company does not sell your data. The Company does not share your data with advertisers who then track you across the internet. You can ask for a copy of your data, or ask for it to be deleted, at any time by writing to hello@sturdybeacon.com.
The formal policy below is the legally binding version. It exists so a lawyer, a regulator, or an enterprise procurement team can verify the plain-English summary is literally true.
1. Who We Are
This Privacy Policy is issued by Sturdy Beacon LLC, a limited liability company organized under the laws of the State of New Jersey, with its registered address at 371 US Highway 202N, Suite N, Branchburg, NJ 08876, United States (referred to in this Policy as "Sturdy Beacon," "the Company," "we," "our," or "us").
For all matters relating to this Policy, including data-subject requests, privacy complaints, and general questions, the contact is hello@sturdybeacon.com.
2. Scope of This Policy
This Policy applies to personal information the Company processes in connection with:
- Visits to sturdybeacon.com and any subdomain operated by the Company;
- Enrollment in and completion of Sturdy Beacon leadership courses hosted on the LearnWorlds learning management platform;
- Purchases processed through the Company's payment provider, Stripe;
- Marketing communications sent by the Company, including email newsletters and paid social advertising;
- Any other interaction with the Company via the email address above.
This Policy applies to individuals located in the United States, the European Economic Area (EEA), the United Kingdom, and any other jurisdiction from which a person accesses the Company's services. Where the laws of a specific jurisdiction grant rights beyond those described in this Policy, those laws apply and are honored.
3. Information We Collect
3.1 Information you provide directly
- Account information — name, email address, and password (stored as a cryptographic hash, never in plain text) when you create an account on the LearnWorlds platform.
- Payment information — payment-card number, expiration, security code, and billing address, collected and processed by Stripe at the moment of purchase. The Company does not store payment card numbers on its own systems; Stripe returns a transaction identifier and the last four digits of the card only.
- Communications — the contents of any email you send to the Company, and the contents of any support ticket or contact-form submission.
3.2 Information generated by your use of the course
- Course progress data — which modules you have started, which you have completed, quiz responses and scores, time spent inside each module, badges earned, and Personal Mission Statement responses. This data is generated and stored by LearnWorlds using the SCORM 1.2 and xAPI standards and is required for the course to function.
- Learning analytics — aggregated and anonymized patterns in course usage that help the Company improve module content and instructional design.
3.3 Information collected automatically
- Website analytics — IP address, browser type and version, device type, operating system, referring URL, pages viewed, time of visit, and duration of visit, collected through the LearnWorlds native analytics layer and, where enabled with your consent, Google Analytics.
- Advertising tracking — with your consent, the LinkedIn Insight Tag records when a visitor to sturdybeacon.com has previously seen a LinkedIn advertisement, so the Company can measure advertising effectiveness. See the Cookie Policy for the complete list of cookies used.
4. How We Use Information
The Company uses the information described in Section 3 for the following purposes:
- To create and maintain your Sturdy Beacon account;
- To deliver the course content you have purchased and record your progress through it;
- To process payments and issue receipts;
- To respond to your questions, complaints, and support requests;
- To send transactional communications (course access, receipts, refund confirmations, updates to policies);
- With your consent, to send marketing communications about new courses, resources, or company updates;
- To measure the effectiveness of the Company's marketing;
- To improve the course, the website, and the customer experience;
- To detect, prevent, and respond to fraud, security incidents, and abuse;
- To comply with the Company's legal obligations, including tax, accounting, and consumer-protection law.
5. Legal Bases for Processing (GDPR & UK GDPR)
For individuals in the European Economic Area and the United Kingdom, the Company relies on the following lawful bases under Article 6 of the GDPR and UK GDPR:
| Processing Activity | Lawful Basis |
|---|---|
| Creating and maintaining your account; delivering the course you purchased | Performance of a contract (Art. 6(1)(b)) |
| Processing payments | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional communications | Performance of a contract (Art. 6(1)(b)) |
| Sending marketing communications | Consent (Art. 6(1)(a)), revocable at any time |
| Website analytics and advertising cookies | Consent (Art. 6(1)(a)), captured via cookie banner |
| Fraud prevention, security, and abuse response | Legitimate interests (Art. 6(1)(f)) — protecting the Company and its customers |
| Compliance with tax, accounting, and consumer-protection law | Legal obligation (Art. 6(1)(c)) |
Where the Company relies on consent, that consent can be withdrawn at any time by writing to hello@sturdybeacon.com or by using the unsubscribe link at the bottom of marketing emails. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
6. Sub-Processors
The Company relies on the following third-party service providers to operate the business. Each processes personal information on the Company's behalf under a written data-processing agreement or its provider-published equivalent.
| Provider | Purpose | Data Processed | Provider DPA |
|---|---|---|---|
| LearnWorlds Ltd. | Course hosting, learner accounts, SCORM/xAPI progress tracking, website hosting | Account, course progress, website analytics | learnworlds.com/privacy-policy |
| Stripe, Inc. | Payment processing | Payment card details, billing address, transaction data | stripe.com/legal/dpa |
| Google LLC (Google Analytics) | Website analytics (with consent) | IP address, browser, device, page views | business.safety.google/privacy |
| LinkedIn Corporation | Advertising measurement and retargeting (with consent) | IP address, ad interaction data | linkedin.com/legal/l/dpa |
The Company will update this list when a sub-processor is added, removed, or changed. Material changes will be announced by updating this Policy and, where required, by direct notice to registered customers.
7. International Data Transfers
The Company is based in the United States. When personal information is transferred from the European Economic Area or the United Kingdom to the United States or another country outside those regions, the Company relies on one or more of the following legal transfer mechanisms:
- For transfers to Stripe: Stripe's published Data Processing Agreement incorporates the current European Commission Standard Contractual Clauses (Module Two, controller-to-processor, 2021 version) and the UK International Data Transfer Addendum.
- For transfers to LearnWorlds: LearnWorlds' published Data Processing Agreement incorporates equivalent Standard Contractual Clauses.
- For any additional transfer that arises, the Company will implement Standard Contractual Clauses or an equivalent mechanism recognized by the European Commission or the UK Information Commissioner's Office at the time of transfer.
8. Data Retention
The Company retains personal information only for as long as necessary for the purposes described in this Policy, and in accordance with the following schedule:
| Data Category | Retention Period |
|---|---|
| Account information (name, email, hashed password) | For as long as your paid access term is active, plus twenty-four (24) months after the end of your last paid term so you can resume without losing progress if you re-subscribe. Deleted on request under Section 9, subject to legal retention exceptions. |
| Course progress data (SCORM/xAPI records) | For as long as your paid access term is active, plus twenty-four (24) months after the end of your last paid term. Deleted on request under Section 9, subject to legal retention exceptions. |
| Payment transaction records | Seven (7) years, in accordance with US tax-record retention requirements |
| Marketing communications data (email opens, clicks) | Twenty-four (24) months from the last engagement |
| Website analytics data | Twenty-six (26) months (Google Analytics default) |
| Support and inquiry correspondence | Three (3) years from the last message in the thread |
Where a data-subject requests deletion of their personal information, the Company will honor the request within the timeframe required by applicable law, subject to the exemptions described in Section 9 (e.g., records the Company is legally required to retain for tax or fraud-prevention purposes).
9. Your Rights
Depending on the jurisdiction in which you reside, you may have the following rights with respect to your personal information:
- Right of access — request a copy of the personal information the Company holds about you.
- Right of rectification — ask the Company to correct inaccurate or incomplete personal information.
- Right of erasure ("right to be forgotten") — ask the Company to delete your personal information, subject to legal retention obligations.
- Right of restriction — ask the Company to limit how it processes your personal information.
- Right of portability — request your personal information in a machine-readable format.
- Right to object — object to processing based on legitimate interests, and to opt out of marketing communications at any time.
- Right to withdraw consent — withdraw any consent previously given, without affecting the lawfulness of prior processing.
- Right to lodge a complaint — file a complaint with your local supervisory authority (for EEA residents), the UK Information Commissioner's Office (for UK residents), or the applicable US state regulator.
To exercise any of these rights, contact hello@sturdybeacon.com. The Company will respond within 30 days for EEA and UK residents (extendable by 60 days for complex requests), within 45 days for California residents, and within the applicable statutory period for residents of other jurisdictions.
The Company may need to verify your identity before honoring a request. Verification steps will not require more information than is necessary to confirm you are the person whose data is at issue.
10. California Residents (CCPA / CPRA)
If you are a resident of California, you have the following rights in addition to those described in Section 9, under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- The right to know what categories of personal information the Company has collected about you and the sources, purposes, and third parties involved.
- The right to delete personal information subject to certain exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. The Company does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under the CPRA.
- The right to limit the use and disclosure of sensitive personal information. The Company does not use or disclose sensitive personal information beyond the purposes permitted by CPRA §7027.
- The right to non-discrimination for exercising these rights.
The categories of personal information the Company has collected in the preceding twelve months are: identifiers (name, email), commercial information (transaction history), internet or network activity (analytics data), and inferences drawn from the foregoing (course engagement patterns). The sources are: directly from you, and automatically through your use of the website and course.
To exercise your California rights, contact hello@sturdybeacon.com. The Company will acknowledge the request within 10 business days and respond within 45 calendar days, extendable by an additional 45 days where reasonably necessary.
11. Cookies and Similar Tracking Technologies
The Company uses cookies and similar technologies on sturdybeacon.com. Some are strictly necessary for the website to function; others are used only with your consent. A complete list, along with instructions for managing your preferences, is provided in the Cookie Policy.
12. Security
The Company implements reasonable and appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include: encryption in transit (TLS 1.2 or higher) for all data exchanged with sturdybeacon.com; cryptographic hashing of account passwords; reliance on SOC 2 Type II-audited sub-processors (LearnWorlds and Stripe) for storage of sensitive data; and access controls limiting personal-information access to authorized personnel with a business need.
No security measure is absolute. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the Company will notify the applicable supervisory authority within 72 hours of becoming aware of the breach, where required by GDPR, UK GDPR, or applicable US state law. Affected individuals will be notified without undue delay where required.
13. Children
The Company's services are designed for adult professionals in a workplace context. The Company does not knowingly collect personal information from children under the age of 16. If the Company learns that it has collected personal information from a child under 16 without verifiable parental consent, it will delete that information promptly.
14. Changes to This Policy
The Company may update this Privacy Policy from time to time. When the Company makes material changes, it will update the "Effective" date at the top of this page and, where the change materially affects the rights of registered customers, provide direct notice by email. Continued use of the website or the course after an updated Policy becomes effective constitutes acceptance of the updated terms.
15. Contact
Sturdy Beacon LLC
371 US Highway 202N, Suite N
Branchburg, NJ 08876
United States
Email: hello@sturdybeacon.com
All privacy inquiries, data-subject requests, and complaints should be addressed to the email above.
Sturdy Beacon LLC published this Policy in good faith as an accurate description of its operating practices as of the Effective date above. This Policy is not legal advice. Before relying on it in an enforcement or contractual context, seek review by a licensed attorney admitted in the relevant jurisdiction.
For Managers
Field notes for the newly-promoted. One idea. One tool. One next move.
Submission did not go through. Please try again, or email hello@sturdybeacon.com directly.
For Organizations
Briefings for HR, L&D, and CFO leaders on the manager layer that moves seventy percent of team engagement.
Submission did not go through. Please try again, or email hello@sturdybeacon.com directly.
Sturdy Beacon LLC · 971 US Highway 202N, Ste N, Branchburg NJ 08876 · hello@sturdybeacon.com
© 2026 Sturdy Beacon LLC · NJ Entity 0451499943 · SCORM 1.2 · WCAG 2.1 AA · xAPI Ready

