Allure Privacy Policy
Last updated: Version 1.2
1. Who we are
“Allure”, “we” and “us” means Vig Solutions LLC, a Florida limited liability company, based in Lake Nona, Orlando, Florida. We make these products:
- Allure Account: sign-in, organization and subscription management at allureplatform.com.
- Allure Connect: course hosting, delivery and learning measurement for organizations.
- Allure LMS: a learning management system for schools, employers and training providers.
- Allure Create: a course authoring tool.
- Allure Training OS: portfolios and course sharing for instructional designers and trainers.
This policy covers allureplatform.com and Allure Account in full, and sets the family rules for the other products. Each of those products also publishes its own privacy policy with product detail. For that product, its own policy wins if the two differ.
2. Our roles
For account, billing, support and marketing data (your name, email, organization, subscription, support tickets), we decide how it is used (controller). For an organization’s own workspace data in Allure Connect or Allure LMS (learners, rosters, launches, scores, completions, reports), we process it for the organization, on its instructions (processor or service provider); the organization is the controller.
If you are a learner in an organization’s workspace, that organization controls your learning records. Send most requests to it first. We will help it respond.
3. What we collect
You give us: name, email, password or sign-in provider details, organization and role, billing contact and address, tax ID if you give one, profile details, messages to support, and the content you upload or create.
Created when you use the products: course launches, sessions, progress, scores, completions, xAPI statements, assessment results, skill tags, reports, webhook and integration records, and API usage.
Organizations give us about learners: identifiers they choose to send, roles, cohort and class membership and, in Allure LMS, the learner’s age band and any authorization evidence reference.
Collected automatically: IP address, device and browser details, pages used, error logs, and cookies (section 11).
We ask organizations not to send special-category data (such as health data) unless we have agreed it in writing.
4. How we use data and our legal bases
- To provide the products you or your organization signed up for (contract; for workspace data, the organization’s instructions).
- For billing, tax and accounting (contract; legal obligation).
- For security, fraud and abuse prevention (legitimate interests).
- For support and service messages (contract; legitimate interests).
- To understand how our products are used and improve them (legitimate interests; consent where cookie law requires it).
- For marketing emails you can unsubscribe from at any time (consent, or legitimate interests where the law allows).
- For legal claims and compliance (legal obligation; legitimate interests).
The legal bases in brackets apply under EU and UK law. We do not use learning records or course content to train general-purpose AI models. We do not use them for advertising. We do not sell personal information.
5. AI in our products
Some products offer AI features. All of them use the OpenAI API (OpenAI, L.L.C.), our only AI provider for features inside our products; section 7 and each product’s own privacy policy say what each feature sees. OpenAI excludes API data from training by default; training requires explicit opt-in. Abuse-monitoring records may be retained for up to 30 days, or longer when legally required or necessary to prevent harm. AI output can be wrong; check it before you rely on it.
6. Who we share data with
- Service providers who run parts of our products for us, under contracts that limit their use (section 7).
- Your organization, if you are a learner or team member in its workspace.
- Platforms your organization connects, at the organization’s direction.
- Other Allure products, where you or your organization use more than one.
- Authorities or others when the law requires it, or to protect rights, safety and our products.
- A buyer or successor if we are involved in a merger or sale. This policy keeps applying to the data.
7. Service providers (subprocessors)
| Provider | What for | Products |
|---|---|---|
| Vercel | Hosting and file storage (Vercel Blob) | All |
| Convex | Database and backend | All |
| Clerk | Sign-in and user management | All |
| Stripe | Payments, subscriptions and tax calculation | All paid products |
| Cloudflare R2 | Course package storage and delivery | Connect, and products that deliver courses through it |
| Resend | Email delivery | Connect, LMS, Training OS |
| Sentry | Error tracking, with personal data minimized | Connect, LMS, Create, Training OS |
| Google (Firebase Cloud Messaging) | Push notifications to mobile apps | LMS |
| OpenAI, L.L.C. (OpenAI API) | All AI features: skill indexing of course activity titles and types (Connect, and products that publish through it); Ask and report drafting (Connect); course experience drafting, theme suggestions, images and artwork safety checks (LMS); profile help and import (Training OS) | Connect, LMS, Training OS |
Organizations can ask for our full subprocessor register, with regions and transfer terms, at info@allureplatform.com. We give organizations 30 days’ notice before adding a subprocessor that handles their workspace data.
Data processing addendum. Business customers can ask for our data processing addendum (DPA), including Standard Contractual Clauses for EU, EEA and UK data, at info@allureplatform.com.
8. International transfers
We are based in the United States. Our main systems run there. When we move personal data from the EU, EEA, UK or Switzerland, we use approved safeguards, such as Standard Contractual Clauses with the UK Addendum, or a provider’s certification under the EU-US Data Privacy Framework and its UK and Swiss extensions.
9. Your rights
Depending on where you live, you can ask to see, correct or delete your personal data, get a copy, restrict or object to how we use it, and withdraw consent where we rely on it.
EU, EEA and UK. You can also complain to your data protection authority, such as the UK Information Commissioner’s Office.
US state rights. Residents of California and other US states with privacy laws can ask to know what personal information we collect, use and disclose, and to get a copy, correct it or delete it. We collect the categories in section 3, from the sources and for the purposes in sections 3 and 4, disclose them only as section 6 describes, and keep them for the periods in section 12.
We do not sell or share personal information. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics about you. So there is nothing to opt out of, but we still treat a Global Privacy Control signal as a request to opt out. We do not knowingly sell or share the personal information of anyone under 16.
How to ask. Email info@allureplatform.com. We may need to confirm who you are. You can use an authorized agent; we may ask the agent for proof of authority. We answer within the time the law sets. If we turn down your request, you can appeal by replying to our decision or emailing us with the subject line “Appeal”. If your organization controls the data, we will pass your request to it and help it respond. We will not treat you differently for using your rights.
10. Children
Allure Account, Allure Connect, Allure Create and Allure Training OS are for adults aged 18 or over. Allure LMS can be used by schools and other organizations with learners under 18; the organization must record each learner’s age band, and learners under 13 can only be invited with recorded parental consent evidence, in a school-managed workspace.
If you think a child has given us data without the right permission, email info@allureplatform.com and we will delete it.
11. Cookies
allureplatform.com and Allure Account use only the cookies they need for sign-in, sessions, security and preferences. They do not use advertising cookies or third-party analytics cookies. Each product’s own privacy policy describes the cookies it uses. Blocking needed cookies may stop sign-in from working.
12. How long we keep data
- Account data: while your account is open. When you close it, we delete or anonymize it within 30 days.
- Workspace data: while the organization’s account is active. After a workspace closes, the organization has 30 days to export. Then we delete or anonymize it.
- In both cases we keep records the law requires (such as invoices, for as long as tax law requires), and encrypted backups expire on their provider’s schedule. If a backup is restored, we re-apply deletions.
- Each product’s own privacy policy may set shorter periods.
13. Security
We use encryption in transit, access controls that keep each organization’s workspace separate, scoped API keys and redacted logs. No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires.
14. Changes
We will post changes here and update the date and version. For material changes, we will tell account holders and organizations by email or in the product at least 30 days before the change applies.
15. Contact
Vig Solutions LLC, Lake Nona, Orlando, Florida
info@allureplatform.com
See also our Terms of Service and the Accessibility Statement.