BBTrain Privacy Policy
Effective and last updated: September 6, 2026
This policy explains how BBTrain handles information needed to operate its cohort-based learning platform.
Information BBTrain handles
- Account and authentication information, including email address, Amazon Cognito identifiers, verification state, and authorization groups.
- Learner display names and instructor profiles, applications, qualifications, biographies, and profile images supplied by users.
- Courses, cohort enrollment, schedules, payment status and external payment references, policy acknowledgements, and payout-administration records. BBTrain does not receive or store full payment-card numbers.
- Live-class access and attendance information, including session identifiers, join/leave events, connection state, periodic heartbeats, attendance results, and security/audit events. BBTrain does not currently record or store class video or audio.
- Assessment attempts, automatically graded results, certificate records, fixed-question ratings, and optional written comments.
- Instructor-uploaded course documents, announcement content, delivery status, and support or operational communications.
- Technical, security, and operational information such as request timing, rate-limit state, service logs, and privacy-safe operational identifiers.
How information is used
BBTrain uses information to authenticate users; manage profiles, courses, cohorts, enrollment, payment status, attendance, assessments, certificates, ratings, resources, and payouts; secure the service; prevent misuse; provide support; send necessary operational communications when configured; troubleshoot services; and meet applicable legal or compliance obligations.
Service providers and current activation
BBTrain uses Amazon Web Services, including Cognito, Amplify, DynamoDB, S3, and related hosting, security, and operational services. Course documents are stored privately in S3 and delivered through short-lived signed links to authorized users. PayPal Live processes production checkout and payment events. BBTrain Live uses BBTrain's self-hosted Jitsi service with authorization and capacity controls. Transactional email uses Amazon SES; while the account remains in the SES sandbox, recipients must be verified before SES can deliver to them. These providers process relevant information under their own terms and privacy practices.
Sharing and visibility
BBTrain discloses information to service providers and authorized instructors or administrators only as reasonably needed for the functions described above, or where required for security, legal process, or compliance. Public course, certificate, sharing, and instructor pages use limited projections and do not publish learner email addresses or internal account identifiers. Public ratings contain aggregated stars; written comments are visible only to BBTrain administrators.
Retention and deletion
Retention depends on the record's purpose, operational and security needs, and applicable obligations. Learner course resources become unavailable when the applicable cohort is completed and their objects and metadata are scheduled for permanent deletion after the established seven-day retention period. Other account, enrollment, attendance, assessment, certificate, audit, communication, and financial records follow their applicable product retention or operational requirements and are not necessarily deleted immediately.
Security and location
BBTrain uses access controls, private storage, signed links, authentication, and operational safeguards appropriate to the service, but no system is completely secure. Service providers may process information in locations supported by their infrastructure and contracts; BBTrain does not promise that all information always remains in one country.
Your choices and contact
You may contact BBTrain to ask about your information or available access, correction, or deletion choices. Some records may need to be retained for security, financial, legal, or service-integrity reasons. Contact support@bbtrain.ca for privacy questions.