Privacy Policy
ASFA Facial Academy respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit onlinefacialcourses.com, create an account, enroll in a course, communicate with us, or use our related online services.
Effective date: July 19, 2026 Last updated: July 19, 2026
Scope of This Policy
This Privacy Policy applies to personal information collected through onlinefacialcourses.com and online services controlled by ASFA Facial Academy, including course enrollment, customer support, certificate services, forms, and communications.
This policy does not govern independent third-party websites, payment providers, course platforms, social media services, or other services that maintain their own privacy policies. When you follow a link to another service, review that service’s privacy practices before providing personal information.
Information We Collect
Depending on how you interact with us, we may collect the following categories of personal information:
- Contact information: name, email address, telephone number, billing address, shipping address, company name, and other contact details.
- Account and enrollment information: login details, course selections, enrollment status, course progress, quiz or assessment results, submitted assignments, completion records, and certificate information.
- Transaction information: courses or products purchased, purchase date, amount paid, payment status, discounts, refunds, and related billing details.
- Communications: messages, emails, form submissions, support requests, call details, attachments, reviews, testimonials, and other information you choose to provide.
- Device and usage information: IP address, browser type, device type, operating system, referring pages, pages viewed, links clicked, session activity, timestamps, and approximate location derived from an IP address.
- Marketing preferences: email subscription choices, promotional preferences, consent records, and interactions with marketing communications or advertisements.
Payment card information is generally collected and processed directly by our payment providers. We do not intentionally store complete payment card numbers on onlinefacialcourses.com.
Please do not send Social Security numbers, government identification numbers, medical records, precise geolocation, or other highly sensitive information unless we specifically request it for a legitimate and lawful purpose.
How We Collect Information
We may collect personal information:
- Directly from you when you enroll, create an account, purchase a course, complete a form, submit course work, request support, or contact us.
- Automatically through cookies, pixels, server logs, analytics tools, and similar technologies.
- From service providers that support payments, course delivery, hosting, analytics, communications, shipping, security, or customer service.
- From business partners, referral partners, schools, organizations, or other parties when they are authorized to provide your information.
- From publicly available sources when permitted by law.
How We Use Personal Information
We may use personal information to:
- Provide, operate, maintain, and improve our website, courses, student accounts, and related services.
- Process enrollments, payments, orders, refunds, shipments, and course access.
- Track course participation, assessments, completion, and certificate eligibility.
- Authenticate users, maintain student records, and verify certificates.
- Respond to questions, provide customer service, and resolve technical or account issues.
- Send transactional messages, course notices, service updates, and administrative communications.
- Send marketing or promotional communications where permitted by law and subject to your choices.
- Measure website performance, understand usage, improve content, and develop new courses, features, or services.
- Detect, investigate, and prevent fraud, abuse, security incidents, or violations of our terms.
- Comply with legal obligations, respond to lawful requests, enforce agreements, and protect our rights or the rights of others.
- Support a merger, financing, acquisition, reorganization, sale of assets, or similar business transaction.
Legal Bases for Processing
Where the European Economic Area, United Kingdom, or another jurisdiction requires a legal basis for processing, we generally rely on one or more of the following:
- Contract: processing needed to provide a course, account, purchase, certificate, or other requested service.
- Legitimate interests: operating and improving our services, protecting our systems, preventing fraud, and communicating with customers in a reasonable manner.
- Consent: where you have given permission, including for certain marketing or cookie activities.
- Legal obligations: processing required to comply with tax, accounting, consumer protection, law-enforcement, or other legal requirements.
You may withdraw consent at any time where consent is the legal basis, without affecting processing that occurred before withdrawal.
Cookies and Similar Technologies
We and our service providers may use cookies, pixels, tags, local storage, and similar technologies to keep the website functioning, remember preferences, understand website traffic, measure performance, prevent fraud, and support advertising or marketing.
These technologies may include:
- Essential technologies required for security, navigation, account access, forms, and core website functions.
- Functional technologies that remember settings and improve convenience.
- Analytics technologies that help us understand visits, traffic sources, and website performance.
- Advertising technologies that may measure campaigns or help deliver more relevant advertising.
You can control many cookies through your browser settings and through any privacy or cookie controls made available on our website. Blocking certain cookies may affect website functionality, account access, or course features.
How We Disclose Personal Information
We may disclose personal information to the following categories of recipients:
- Service providers and contractors that support website hosting, course delivery, payments, shipping, email, analytics, advertising, customer service, security, data storage, and business operations.
- Professional advisors such as attorneys, accountants, auditors, insurers, and consultants.
- Government authorities or other parties when disclosure is required by law, legal process, court order, or a valid governmental request.
- Business transaction parties in connection with a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction.
- Other parties with your direction or consent.
We do not knowingly sell personal information for monetary consideration. Certain disclosures involving analytics or advertising technologies may be considered “sharing,” “targeted advertising,” or a “sale” under some state privacy laws even when no money is exchanged.
Payment Processing
Payments may be processed by independent payment providers. Those providers may collect payment card details, billing information, fraud-prevention information, and other transaction data under their own privacy policies and terms.
We may receive limited payment information, such as a transaction identifier, payment status, billing name, amount paid, and the last digits of a payment method, when needed to process an enrollment, refund, or customer-service request.
Data Retention
We retain personal information only for as long as reasonably necessary to provide our services, maintain business and student records, comply with legal or tax obligations, resolve disputes, prevent fraud, enforce agreements, and protect our rights.
Because some ASFA courses may include ongoing or lifetime access and certificate verification, certain account, enrollment, completion, and certificate records may be retained for as long as needed to provide those services. When information is no longer reasonably necessary, we may delete, de-identify, or securely archive it, subject to legal and operational requirements.
Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
No website, online account, database, or transmission method can be guaranteed to be completely secure. You are responsible for protecting your account credentials and should contact us promptly if you believe your account or personal information has been compromised.
Email and Marketing Choices
You may unsubscribe from promotional emails by using the unsubscribe link included in the message or by contacting us. Even after opting out of marketing, we may still send service-related communications such as enrollment confirmations, payment notices, course updates, security alerts, certificate information, or responses to your requests.
California Privacy Rights
If the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to ASFA and to your personal information, California residents may have the right to:
- Know the categories and specific pieces of personal information collected, used, disclosed, sold, or shared.
- Request access to personal information.
- Request deletion of personal information, subject to legal exceptions.
- Request correction of inaccurate personal information.
- Opt out of the sale or sharing of personal information.
- Limit certain uses and disclosures of sensitive personal information, when applicable.
- Receive equal service and not be discriminated against for exercising privacy rights.
Depending on our activities, categories collected during the preceding 12 months may include identifiers, customer records, commercial information, internet or electronic network activity, approximate geolocation, course or education activity, account credentials, and inferences drawn from interactions with our services.
To submit a California privacy request, email info@onlinefacialcourses.com or call 1 (800) 838-3779. We may request information reasonably necessary to verify your identity and protect your account. An authorized agent may submit a request where permitted by law, but we may require proof of authorization.
We will respond within the period required by applicable law. Some requests may be denied or limited where an exception applies, including when information must be retained to complete a transaction, provide requested course access, maintain certificate records, detect security incidents, comply with law, or establish and defend legal claims.
Privacy Rights in Other U.S. States
Residents of certain U.S. states may have additional privacy rights, depending on the law and whether it applies to ASFA. These may include rights to access, correct, delete, or obtain a portable copy of personal information and rights to opt out of targeted advertising, the sale of personal information, or certain profiling.
You may submit a request using the contact information below. Where a state law provides a right to appeal a denied request, you may appeal by replying to our decision or contacting us again with the subject line “Privacy Request Appeal.”
European and United Kingdom Privacy Rights
If the General Data Protection Regulation, United Kingdom GDPR, or similar law applies, you may have the right to:
- Access personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of personal information in certain circumstances.
- Restrict or object to certain processing.
- Receive certain information in a portable, machine-readable format.
- Withdraw consent where processing is based on consent.
- Object to direct marketing.
- Lodge a complaint with your local data protection authority.
These rights are not absolute and may be subject to legal exceptions. To exercise a right, contact us using the information below.
Children’s Privacy
Our general website and professional training services are not directed to children under 13. We do not knowingly collect personal information directly from a child under 13 without verifiable parental consent or another lawful basis.
When access is arranged through a parent, guardian, school, or authorized organization, personal information may be processed under that arrangement and applicable law. If you believe a child under 13 has provided personal information without appropriate authorization, contact us so we can investigate and take appropriate action.
We do not knowingly sell or share the personal information of consumers under 16 without the authorization required by applicable law.
International Data Transfers
ASFA and its service providers may process personal information in the United States and other countries. Those countries may have privacy laws that differ from the laws where you live.
Where required, we use lawful transfer mechanisms and reasonable safeguards designed to protect personal information transferred across borders.
Third-Party Links and Services
Our website may link to third-party websites, course platforms, social networks, payment services, or other online services. We are not responsible for the privacy, security, accuracy, or content practices of independent third parties. Review their policies before submitting personal information.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, technologies, business practices, or legal obligations. The revised version will be posted on this page with an updated “Last updated” date. Material changes may also be communicated through the website, account portal, or email when appropriate.
Contact Us
Contact us with questions about this Privacy Policy or to submit a privacy request.
ASFA Facial Academy
Email: info@onlinefacialcourses.com
Phone: 1 (800) 838-3779
Website: onlinefacialcourses.com
This policy describes ASFA’s general privacy practices. Specific rights and obligations may vary based on your location, how you use the services, and which laws apply.