Who controls your information
Infernal Compass LLC, operating Collegium Arcanum, is the controller of the academy account database. Privacy requests may be sent to privacy@collegiumarcanum.com. The academy’s business mailing address must be entered in the WordPress legal settings before public enrollment opens.
We do not sell, rent, trade, or disclose member information for another company’s advertising. Information is disclosed only to the named services below when needed to run the site, fulfill a user-selected service, process payment, comply with law, or protect people and systems.
What we collect
Account and identity
First and last name, display name, email address, encrypted date of birth, an indexed birthday month/day, adult-status result, password hash for password accounts, social-provider identifier for social accounts, account dates, consent records, and member ID.
Profile and community
Pronouns, biography, broad location, interests, profile and banner images, the limited personal gallery, posts, reactions, comments, messages, reports, class participation, and privacy choices.
Academic and payment
Applications, enrollment, attendance, submissions, grades, certificates, accommodations a student asks us to record, order totals, currency, transaction references, refunds, and payment status. Collegium does not store full card or PayPal credentials.
Technical and safety
IP address, browser/device information, login and request timestamps, security events, cookie/session identifiers, moderation evidence, support correspondence, and legally required records.
Why we use it
We use account, DOB, profile, and academic data to perform the membership and student contract; verify the 18+ rule; operate classes and the community; authenticate accounts; secure the service; process orders and refunds; keep tax and accounting records; enforce the Code of Conduct; answer requests; and meet legal duties.
Birthday greetings and academy email updates use separate, optional consent. Those boxes are not required for membership and begin unchecked. A member may withdraw either choice in account settings or by using an unsubscribe link. Withdrawal does not affect necessary account, classroom, safety, billing, or legal notices.
Where law requires a stated basis: contract supports account, course, and payment administration; consent supports optional email; legal obligation supports required financial and regulatory records; and legitimate interests support proportionate security, fraud prevention, service improvement, and moderation. We do not use DOB to infer interests or target advertising.
Every outside service with possible access
The entries below are the complete current operational register. Open a provider to see its exact role, data, purpose, and access boundary. Apple Sign-In, an external email-marketing platform, and an external video provider are not active and receive no member data. The register must be updated before any new provider is enabled.
Namecheap, Inc.Active — hosting and domain infrastructure
RoleData processor and infrastructure provider
Data involvedAccount records and site content stored on the server; IP address, request logs, and security metadata.
Why it is usedHosts the WordPress site and database, serves pages, maintains backups, and protects infrastructure.
Access boundaryAuthorized infrastructure and support personnel may access data when required to operate, secure, or troubleshoot the hosting service.
Read this provider’s privacy policy ↗Google LLCConditional — only when Google Sign-In or the public Google Calendar is used
RoleIndependent controller for its sign-in service; calendar platform provider
Data involvedFor sign-in: email address, name, provider identifier, and authentication metadata. For calendar use: requests, device/IP data, and events a user elects to add.
Why it is usedAuthenticates a selected Google account and provides the academy public-calendar connection.
Access boundaryGoogle receives data only when the user chooses a Google feature. Collegium does not receive the user’s Google password or a dependable date of birth.
Read this provider’s privacy policy ↗Microsoft CorporationConditional — only when Microsoft Sign-In is used
RoleIndependent controller for its sign-in service
Data involvedEmail address, name, provider identifier, and authentication metadata.
Why it is usedAuthenticates a selected Microsoft account.
Access boundaryMicrosoft receives data only when the user chooses Microsoft Sign-In. Collegium does not receive the user’s Microsoft password or a dependable date of birth.
Read this provider’s privacy policy ↗PayPal, Inc. (U.S.); PayPal Canada Co. (Canada); PayPal UK Ltd (UK)Conditional — only when a payment is made
RoleIndependent payment controller and payment service provider
Data involvedName, email, billing and transaction information, device/IP and fraud-prevention data. Full payment credentials are entered with PayPal and are not stored by Collegium.
Why it is usedProcesses payments, refunds, disputes, fraud screening, and legally required financial records.
Access boundaryThese are the named entities for the three launch regions. A payer elsewhere contracts with the PayPal entity identified in that region’s checkout terms.
Read this provider’s privacy policy ↗WPManageNinja LLCLimited — software licensing and support for FluentCommunity and FluentCart
RoleSoftware vendor; support recipient only when an administrator opens a support case
Data involvedLicense/site details. Member records remain in the academy’s self-hosted WordPress database. Diagnostic or member data is shared only when an administrator deliberately includes it in a support request.
Why it is usedProvides, licenses, updates, and supports the community and commerce software.
Access boundaryNo routine access to the academy member database is granted merely because the plugins are installed.
Read this provider’s privacy policy ↗Responsibility is not waived
Collegium remains accountable for processors it appoints wherever applicable law requires. Services that act as independent controllers—such as a payment or social sign-in provider—are responsible for their separate processing under their own terms. Nothing in this Statement removes a non-waivable privacy or consumer right.
How long records are kept
- Active member record and encrypted DOBFor the life of the account; deleted from the live system within 30 days after an approved deletion request or account closure, unless a stated legal hold applies.
- Dormant free membershipClosed after 24 months without sign-in, following an email warning at least 30 days before closure.
- Server backupsRotated out within 90 days after live deletion; restored backups are subject to the deletion record.
- Orders, invoices, tax, and refund recordsSeven years after the transaction, or longer only when a governing tax law requires it.
- Email consent and withdrawal evidenceSix years after the preference ends, to demonstrate compliance.
- Moderation and serious safety recordsThree years after case closure; up to seven years for fraud, credible threats, litigation, or a legal hold.
- Routine security logs180 days; longer only for an identified incident or legal obligation.
- Unfinished pending social accountSeven days, unless it is rejected as underage, in which case the pending account is deleted immediately.
Your privacy choices and rights
Depending on residence, a user may request access, correction, deletion, portability, restriction or objection; withdraw consent; opt out of covered sharing or targeted advertising; and complain to a privacy regulator. Collegium does not sell data and does not use cross-context behavioral advertising.
Send a request from the account email to privacy@collegiumarcanum.com. We will acknowledge it within 10 business days, verify identity proportionately, and respond within the period required where the user lives. UK users may complain to the ICO; Canadian users to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator; U.S. users to the applicable state authority.
Commercial-email opt-outs are honored within 10 business days or sooner. Account settings will provide direct birthday and academy-update controls.
Security, transfers, and changes
DOB is encrypted before database storage; passwords are one-way hashed by WordPress; privileged access is limited by role; and accounts, backups, updates, and logs require operational safeguards. No system is risk-free, but security is reviewed in proportion to the sensitivity of the data.
Named providers may process data outside a user’s country. When Collegium acts as controller, it will use the contractual and transfer safeguards required by applicable UK, Canadian, or U.S. law. A material policy change will be dated, archived, and announced before it takes effect when required.
Effective: August 14, 2026. Contact: privacy@collegiumarcanum.com.