1. Introduction
Birchgrove Inc., operating as Dr. Jill Birch and The Relational Leadership Academy("we," "us," or "our"), is committed to protecting the privacy and security of all individuals who interact with our platform. This Privacy Policy describes how we collect, use, store, and safeguard your personal information when you visit our website (drjillbirch.com), enroll in the Masterwork Curriculum, engage with our Reflections feed, or otherwise use our digital services.
By accessing or using our platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of our services immediately.
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Full name, email address, professional title, institutional affiliation, and profile photograph when creating a Student or Executive account.
- Course Submissions: Written assignments, reflective exercises, leadership self-assessments, and other academic materials submitted through the Masterwork Curriculum.
- Communications: Messages sent through our internal messaging system, contact forms, and support inquiries.
- Payment Information: Billing details processed securely through Stripe, our PCI-DSS compliant payment processor. We do not store credit card numbers on our servers.
2.2 Information Collected Automatically
- Analytics Data: We use Google Analytics 4 to collect anonymized usage metrics including page views, session duration, geographic region (country/state level), device type, and browser information. Google Analytics uses cookies to distinguish unique users.
- Server Logs: Our hosting provider (Vercel) automatically records IP addresses, request timestamps, referring URLs, and HTTP status codes for security and performance monitoring.
- Cookies and Local Storage: We use essential cookies for authentication session management and optional analytics cookies for platform improvement. See Section 6 for our Cookie Policy.
3. How We Use Your Information
We use collected information exclusively for the following purposes:
- Educational Delivery: To administer the Masterwork Curriculum, evaluate submissions, issue credentials, and personalize your learning experience.
- Platform Operations: To maintain, improve, and secure our digital infrastructure, including database management through Neon PostgreSQL and file storage through Vercel Blob.
- Communication: To send essential notifications about your account, course progress, and platform updates. We will never sell your email to third-party marketing lists.
- Research and Scholarship: Anonymized, aggregated data may be used by Dr. Jill Birch in academic research on relational leadership. No personally identifiable information is ever published.
- Legal Compliance: To comply with applicable laws, regulations, and legal proceedings.
4. Data Storage and Security
4.1 Infrastructure
Your data is stored using enterprise-grade infrastructure:
- Database: Neon Serverless PostgreSQL with encryption at rest (AES-256) and in transit (TLS 1.3). All queries are parameterized to prevent SQL injection.
- File Storage: Vercel Blob for uploaded images and documents, with automatic CDN distribution and access controls.
- Application Hosting: Vercel Edge Network with automatic HTTPS, DDoS protection, and global content distribution.
- Authentication: Passwords are hashed using bcrypt with a minimum cost factor of 12. Session tokens are cryptographically signed and stored in HTTP-only, Secure, SameSite cookies.
4.2 Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Course submissions and academic records are retained for a minimum of seven (7) years for credential verification purposes. You may request data deletion at any time by contacting us (see Section 9).
5. Student Data Protection
We recognize the sensitivity of educational data and adhere to the following principles:
- Student submissions, grades, and academic progress are treated as confidential educational records.
- Access to student data is restricted to authorized administrators (Dr. Jill Birch, Clayton Birch, and Cheryl Durand) on a strict need-to-know basis.
- We comply with applicable provisions of the Family Educational Rights and Privacy Act (FERPA) where relevant to our operations as a professional development platform.
- Student data is never shared with, sold to, or made accessible to third-party advertisers, data brokers, or marketing platforms.
6. Cookie Policy
Our platform uses the following categories of cookies:
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled without breaking core functionality.
- Analytics Cookies: Google Analytics cookies (_ga, _gid) used to understand platform usage patterns. These are anonymized and do not contain personally identifiable information.
- Preference Cookies: Used to remember your display preferences (e.g., sidebar state). These are stored locally and never transmitted to external servers.
You may manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from accessing certain platform features.
7. Third-Party Services
We integrate with the following third-party services, each with their own privacy policies:
- Vercel (hosting and edge functions) — vercel.com/legal/privacy-policy
- Neon (database) — neon.tech/privacy
- Google Analytics (usage analytics) — policies.google.com/privacy
- Stripe (payment processing) — stripe.com/privacy
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of all personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, commonly used, machine-readable format.
- Objection: Object to processing of your data for specific purposes.
For California residents, we comply with the California Consumer Privacy Act (CCPA). We do not sell personal information. For EU/EEA residents, we comply with the General Data Protection Regulation (GDPR).
9. Contact Information
For privacy-related inquiries, data access requests, or to exercise your rights under applicable law, please contact:
Birchgrove Inc.
Data Privacy Office
Email: privacy@drjillbirch.com
Website: drjillbirch.com/contact
10. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Material changes will be communicated through a prominent notice on our platform and, where applicable, via email to registered users. Your continued use of the platform after changes are posted constitutes acceptance of the updated policy.