>
Legal

Privacy Policy

Effective: August 24, 2026  ·  Last updated: August 24, 2026

Fairley Holdings Group LLC, a Wyoming limited liability company ("FHG", "we", "us").

This covers FHG University, FHG Compass, FHG Foundations, and institutional seat licenses. It is written to be understood by the parent of an eleven-year-old, because that is who it most needs to serve. Section 8 is the children's section — if you are a parent or guardian, start there.

The short version. We collect the least we can operate on: your email, your progress, and what you choose to type. Payment goes straight to Stripe and we never see your card number. We run no advertising, belong to no ad network, and do not sell or rent personal information to anyone — there is no version of this business where we do. There is no analytics or tracking of any kind on any page a Compass student can reach, including this one. We tell you exactly how long we keep each thing, and we delete it on schedule.

  1. What we collect
  2. Why we collect it
  3. Payments and card data
  4. Who we share it with
  5. What we never do
  6. Cookies and tracking
  7. How long we keep it
  8. Children's privacy (COPPA)
  9. How we protect it
  10. Your rights and choices
  11. State privacy rights
  12. Institutional participants
  13. Changes
  14. Contact

1. What we collect

CategoryWhat it isWhere it comes from
AccountEmail address; a display name if you choose to set one; which subscription you hold and whether it is activeYou, and Stripe at checkout
Sign-inAn opaque session token in a cookie. If you sign in with Microsoft, your email address from that account and nothing elseCreated when you sign in
Learning progressModules completed, dates, XP and rank, streak, exam outcomes you self-report, the character avatar you pickGenerated as you use the platform
Things you typeModule notes, résumé entries, self-reported prior experienceYou, entirely optional
AssessmentIf you take the free career assessment, your answers and the email you give for the resultYou
PaymentSubscription status, billing period, and Stripe's identifiers. Never your card numberStripe
TechnicalOrdinary server logs kept by our hosting provider — IP address, request time, page requested — used for security and reliabilityAutomatic

We do not ask for and do not want: your date of birth, your home address, your phone number, a photo, your location, your contacts, or anything from your device beyond the page you asked for.

2. Why we collect it

That is the complete list. We do not build profiles, score you, or use your information to decide anything about you beyond what you have completed.

3. Payments and card data

All payments are processed by Stripe, Inc. Your card details are entered on Stripe's own checkout and go directly to Stripe. They never pass through, and are never stored on, any system we control. We receive only the fact that a payment succeeded, which plan it was for, and Stripe's reference identifiers.

Stripe is certified as a PCI Service Provider Level 1, the most stringent level in the payments industry, and publishes SOC 1 and SOC 2 Type II reports annually. Their handling of your payment information is governed by Stripe's privacy policy.

Because we never touch card data, a breach of our systems could not expose your card number. That is by design, not by luck.

4. Who we share it with

We share personal information only with the service providers we need to run the platform, only for that purpose, and only the minimum each one requires. Here is the complete list — not categories, the actual companies:

ProviderWhat it does for usWhat it receives
Stripe, Inc.Payment processing and subscription billingYour email and payment details you enter with them
Netlify, Inc.Website hosting, application runtime, and the encrypted data store holding accounts and progressEverything in section 1, stored at rest
ResendDelivery of service email (welcome, renewal reminders, refund confirmations)Your email address and the message content
MicrosoftOptional "sign in with Microsoft", and our own business email and identity systemsYour email address, only if you choose that sign-in method
GitHub, Inc.Source-code hosting for the platform itselfNo subscriber data. Code only

Each of these is a major infrastructure provider that maintains independent third-party security certifications — Stripe (PCI Level 1, SOC 1 and SOC 2 Type II), Netlify (SOC 2 Type II, ISO 27001), Microsoft Azure and GitHub (SOC 1, SOC 2 and ISO 27001). Multi-factor authentication is enforced on every administrative account we hold with them.

Job search is done without sending your information anywhere. Career Navigation does not query anything on your behalf at all. Our server collects public job postings on a fixed schedule — the same collection, at the same times, regardless of who is signed in — and the matching against your own record happens entirely on our side afterwards. The job boards receive no request that has anything to do with you, so they never learn that you exist, what you studied, or what you are looking for.

We may also disclose information if the law requires it, to protect someone's safety, or in connection with a merger or sale of the business — in which case the acquirer would be bound by this policy or you would be told before anything changed.

5. What we never do

6. Cookies and tracking

We use one essential cookie: an opaque session token that keeps you signed in. It carries no personal information, and without it the platform cannot tell it is you. Your browser also stores your light/dark theme choice locally; that never leaves your device.

On every page a Compass student can reach — including the Compass site, lessons, dashboard, account settings, and this page — there is no analytics, no advertising tag, and no third-party tracking script of any kind. This is enforced by an automated check that fails our build if such a script appears on those pages, so it cannot be reintroduced by accident.

Fonts are served from our own domain. We do not load them from a third-party font service, so your browser makes no request to one.

On the adult FHG University marketing pages we use Google Analytics to understand which pages people find useful. It is not present on any Compass-reachable page. You can opt out with Google's browser add-on or by using your browser's tracking protection.

7. How long we keep it

This is our data retention policy. We do not keep personal information indefinitely. Each category has a purpose and a deletion date, and a scheduled process deletes on that schedule rather than waiting for someone to remember.

CategoryWhy we keep itDeleted
Account and subscription recordProvide access; handle billing questions and refunds12 months after the subscription ends
Learning progress, notes, résumé entries, avatar, display nameShow your progress and rebuild your certificate if you return12 months after the subscription ends
Compass student progress and any information about a childSame as above, for the student90 days after the subscription ends — deliberately shorter, and sooner on a parent's request
Session tokensKeep you signed inOn sign-out, or 30 days, whichever comes first
Sign-in security tokensProtect the sign-in exchangeWithin minutes of use
Free assessment answers and emailSend your result and any follow-up you asked for24 months after your last interaction
Payment and transaction recordsTax and accounting obligations (held by Stripe)7 years, as tax law requires
Server logsSecurity and reliabilityPer our hosting provider's retention, typically 30 days

You can ask us to delete sooner. See section 10.

8. Children's privacy (COPPA)

FHG Compass is designed for students aged 11 to 18, so some of our users are children under 13 and the Children's Online Privacy Protection Act applies to us. We treat that as a design constraint on the product, not a notice to publish. This section tells you exactly what that means.

The subscription belongs to a parent

A Compass subscription is purchased and held by a parent, legal guardian, or an educator or organization acting with parental permission. A child does not create their own account, does not enter payment details, and cannot subscribe.

How we obtain verifiable parental consent

Before we collect personal information from a child, the parent completes a monetary transaction through our payment processor using a credit or debit card, which is an approved method of verifiable parental consent under the COPPA Rule. At checkout the parent is told what will be collected and why, and consents to it. We keep a record of that consent.

What we collect from a child, and what we do not

What we collect: the account email (the parent's, or one the parent provides), progress through modules, and anything the student chooses to type into their own notes.

What we do not collect from a child, ever: full name (unless a parent sets a display name for a certificate), date of birth, home address, phone number, photographs, audio, video, geolocation, persistent identifiers for advertising, contacts, or anything from their device. There is no chat, no messaging, no forum, no profile visible to anyone else, and no way for a child to make anything public. A child cannot be contacted by another user because there is no mechanism for one user to reach another.

No advertising and no tracking, enforced in the build

No page a Compass student can reach carries analytics, advertising, or third-party tracking. We do not use a child's information for targeted advertising or to train AI models, and no third party receives it for those purposes. Our build fails automatically if a tracking script appears on a Compass-reachable page.

Separate consent for disclosure to third parties

We do not disclose a child's personal information to any third party for a purpose that is not integral to providing the service. The only providers who process it are the infrastructure providers in section 4, acting on our instructions to host the platform and deliver service email — which is integral. If we ever proposed a disclosure beyond that, we would ask the parent for separate consent to that specific disclosure first, and the answer could be no without affecting the child's access.

How long we keep a child's information

Only as long as needed for the purpose it was collected: while the subscription is active, and for 90 days after it ends so a returning student does not lose their progress. Then it is deleted. It is never retained indefinitely. A parent can have it deleted sooner at any time.

A parent's rights

As a parent or guardian you may, at any time:

You can do the first three yourself, immediately, from the Manage page while signed in — review what we hold, stop further collection, or delete it, with no email and no wait. If you would rather a person did it: email info@fairleyholdings.com from the address on the account, or call 704-269-9046. We respond within 5 business days and complete deletion within 30 days. We may need to confirm you are the account holder before acting, which protects your child.

We do not condition a child's participation in any activity on disclosing more information than is reasonably necessary for that activity.

If you believe a child under 13 has given us information without a parent's consent, tell us and we will delete it. We do not knowingly permit anyone under 11 to use Compass.

9. How we protect it

We maintain a written information security program covering the personal information we hold, including children's information. In practice:

No system is perfectly secure, and we will not claim otherwise. If a breach affects your information we will tell you, and any regulator we are required to tell, as promptly as the law requires and as promptly as we can establish the facts.

10. Your rights and choices

Whoever you are and wherever you live, you may ask us to:

Email info@fairleyholdings.com from your account address. We respond within 5 business days and complete requests within 30 days. We will never charge you for this or make you justify it.

11. State privacy rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas and other states with comprehensive privacy laws have rights to know, access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and profiling with legal effects.

We exercise none of those last three. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not profile anyone — so there is nothing for you to opt out of. The access, correction, deletion and portability rights are honored through section 10, on the same timeline, regardless of where you live. We will not discriminate against you for exercising a privacy right.

If you disagree with how we handled a request, you may appeal by replying to our response, and you may contact your state Attorney General.

12. Institutional participants

Where an organization licenses seats, that organization decides who is enrolled, and we process participant information on its instructions. Progress reporting visible to the organization's administrator is scoped to its own participants and no one else's. If your organization requires a data processing agreement, we will sign one — write to us.

If you are a participant enrolled by an employer or program and you want your information deleted, contact us and we will work with you and them.

13. Changes

We will update this policy as the platform changes. The "last updated" date will change, and for material changes — particularly anything affecting children's information — we will give at least 30 days' notice by email before it takes effect. Where a change would materially expand what we collect from a child or who receives it, we will obtain new parental consent rather than rely on notice.

14. Contact

Fairley Holdings Group LLC · Wyoming, USA
info@fairleyholdings.com · 704-269-9046

Related: Terms of Service · Refund & Cancellation Policy

Fairley Holdings Group LLC is the operator of FHG University, FHG Compass and FHG Foundations and is the entity responsible for the personal information described here.