Draft · not approved for publication
Privacy Policy
This working notice describes known website and application systems and flags facts the academy must verify before launch.
Who is responsible
Taylor Nursing Academy [VERIFY legal entity, mailing address, and privacy contact] operates this website and receives program inquiries and applications.
Information collected
The application asks for identity and contact details, date of birth, address, class timing, optional funding preferences including optional SNAP/EBT status, initials, signing date, and clinical-screening acknowledgement. The isolated preview does not accept applications. The current live PHP system stores application records in Supabase and generates a PDF. Needs academy confirmation: whether every field is necessary at application time, age policy, logs and IP collection, any uploads, and whether optional answers affect decisions.
People may also contact admissions by phone or email. Needs academy confirmation: whether contact forms, call recordings, texts, or other channels retain inquiries and where those records are stored.
How information is used
Application information is used to review submissions and communicate with applicants. Current systems include a PHP application API, Supabase capture, PDF generation, and email notifications. [VERIFY staff workflows, retention, mailing practices, legal basis where applicable, and whether data is used for any other purpose.]
Services and sharing
Supabase processes live application records. The live site also loads Google Analytics, uses email delivery, and has an AI chat widget whose transcript practices require verification. The isolated rebuild runs on Cloudflare Pages; private R2 document storage, D1 rate limiting, and Turnstile would support an enabled application, but staging submissions are currently disabled. The rebuild's Analytics and AI assistant integrations are disabled, and its code does not send application answers to them. Needs academy confirmation: final vendors, Turnstile and other technical data, cookies, hosting regions, subprocessors, contracts, analytics consent behavior, and whether chat transcripts are stored, reviewed, or used for training.
Staging review feedback
This public staging preview uses Spikes, a third-party feedback service. Anyone who can reach the preview can open the feedback widget; comments are sent to its hosted dashboard. When a person chooses to comment, Spikes receives their chosen name, comment, page title and URL, selected element's CSS selector, short nearby text, position, viewport size, and time. The widget stores the chosen name and a local copy of comments in browser storage. Email collection and screenshot capture are not enabled. The normal application page does not load the widget; its feedback mode locks blank fields. Do not enter applicant or other personal information in feedback. Needs academy confirmation: Spikes hosting location, retention and deletion terms, access policy, and whether a school data-processing agreement is needed.
Security and retention
The new design uses HTTPS and plans server-side secrets, private documents, restricted staff access, and responses that are not publicly cached. Those plans do not describe every control in the current live system. Needs academy confirmation: authorized staff roles, backups and recovery, and retention/deletion periods for application records, PDFs, email, chat, analytics, staging feedback, backups, and logs. Historical public PDF access needs a separate exposure and notification assessment.
Your choices
Contact [Needs academy confirmation: approved privacy contact] to request access, correction, or deletion where applicable. Needs academy confirmation: rights, response procedure, exceptions for admissions records, analytics/chat choices, and minor applicant handling.
Changes
Effective date: [Needs academy confirmation]. Needs academy confirmation: how changes will be announced.