Privacy Policy

Last updated: March 31, 2026

CelebSimulation ("we", "us", "our") operates the website course.celebsimulation.com ("Site"). This Privacy Policy explains how we collect, use, protect, and handle your personal information when you visit our Site or purchase our digital course, The Viral Blueprint.

We take your privacy seriously. We do not sell, rent, or trade your personal data to third parties for marketing purposes — never have, never will.

1. INFORMATION WE COLLECT

Information You Provide

When you purchase the Course or create an account, we collect:

  • Name — to personalize your account and communications
  • Email address — to create your account, send login credentials, and communicate important updates
  • Phone number (optional) — if you choose to provide it during checkout

Payment Information

Payment is processed entirely by Stripe. We never receive, store, or have access to your full credit card number, CVV, or bank account details. Stripe handles all payment data in accordance with PCI DSS Level 1 compliance standards. We only receive a confirmation of payment, a transaction ID, and the email/name associated with the payment.

For Stripe's privacy practices, see: stripe.com/privacy

Automatically Collected Information

When you visit the Site, we may automatically collect:

  • IP address — for security purposes (rate limiting, fraud prevention)
  • Browser type and device information — to ensure the Site displays correctly
  • Pages visited and timestamps — to understand usage patterns and improve the platform

2. HOW WE USE YOUR INFORMATION

We use your personal information exclusively for:

  • Delivering the Course — creating your account, granting access, and providing course materials
  • Communication — sending login credentials, password resets, and important service updates
  • Security — protecting against fraud, unauthorized access, and abuse (login rate limiting, session management)
  • Improvement — understanding how students use the platform to improve the learning experience

We do NOT use your data for marketing purposes. We do NOT send promotional emails, newsletters, or advertising. We do NOT sell, rent, share, or trade your personal information with any third party for their marketing use.

3. DATA SHARING

We only share your data with the following third parties, strictly as needed to operate the service:

Service Purpose Data Shared
StripePayment processingName, email, payment details
SMTP ProviderTransactional emailsEmail address, name

We do not share your information with any other parties. We do not use advertising networks, social media tracking pixels, or retargeting services on the Course platform.

4. COOKIES & LOCAL STORAGE

We use only essential cookies required for the platform to function:

  • Session cookie (cs_session) — keeps you logged in. Expires after 7 days. HTTP-only, not accessible to JavaScript.
  • CSRF token — protects form submissions from cross-site attacks. Session-based.

We do not use tracking cookies, analytics cookies, or third-party advertising cookies on the Course platform.

5. DATA SECURITY

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption — all connections use HTTPS/TLS encryption
  • Password hashing — passwords are hashed using Argon2id (industry-leading algorithm), never stored in plain text
  • Rate limiting — login attempts are rate-limited to prevent brute force attacks
  • Access control — course files are served through authenticated endpoints only
  • Secure sessions — session tokens are HTTP-only, preventing XSS-based session theft

While we take reasonable steps to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

6. DATA RETENTION

We retain your personal information for as long as your account is active or as needed to provide you with access to the Course. Specifically:

  • Account data (name, email, progress) — retained as long as your account exists
  • Login attempt logs — automatically deleted after 15 minutes (used only for rate limiting)
  • Session data — expires after 7 days of inactivity
  • Payment records — retained as required by tax and accounting obligations

7. YOUR RIGHTS

Under applicable data protection laws (including the EU General Data Protection Regulation — GDPR), you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate personal data
  • Erasure — request deletion of your personal data ("right to be forgotten")
  • Data portability — request your data in a structured, machine-readable format
  • Objection — object to processing of your personal data
  • Restriction — request restricted processing of your personal data

To exercise any of these rights, contact us at hello@celebsimulation.com. We will respond within 30 days.

Please note that deleting your account data will result in loss of access to the Course, and due to our no-refund policy, no refund will be issued upon account deletion.

8. CHILDREN'S PRIVACY

Our Site and Course are not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we discover that we have collected data from a minor, we will delete it promptly.

9. INTERNATIONAL DATA TRANSFERS

Your data may be processed on servers located in the European Union. If data is transferred outside the EU, we ensure adequate safeguards are in place in compliance with GDPR requirements.

10. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Changes will be posted on this page with an updated "Last updated" date.

For significant changes that materially affect how we handle your data, we will make reasonable efforts to notify you via email.

11. CONTACT US

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: