Last Updated: 2.27.26
Name
Email address
Organization name
Role
Encrypted password
Employee names
Emails (if entered)
Training completion status
Assessment records
Incident logs
HeatShield acts as a data processor for organization-controlled employee records.
Collected via:
PostHog (behavior analytics)
Sentry (error logging)
May include:
IP address
Browser type
Device information
Interaction metadata
Authentication logs
Worker heartbeat logs
API usage records
We use data to:
Provide platform functionality
Maintain security
Improve performance
Send operational emails via Resend API
Monitor system health
We do not sell personal data.
HeatShield uses:
Secure HTTP-only authentication cookies
Signed CloudFront cookies for training access
Session-based JWT tokens
Cookies are essential for platform functionality.
We share data only with:
AWS (S3 & CloudFront)
VPS hosting provider
Resend (email delivery)
Sentry (error tracking)
PostHog (analytics)
All vendors operate under data processing agreements or standard contractual protections.
Data is retained:
While an organization maintains an active subscription
As required for operational backups
As required by law
Organizations may request data export or deletion upon termination.
We implement:
Encrypted transmission (HTTPS)
Tenant-level data isolation
Secure password hashing
Automated backups
Access-controlled SCORM content
Despite safeguards, no system is immune to risk.
Depending on jurisdiction, users may have rights to:
Access data
Correct data
Delete data
Request data export
Requests may be sent to:
[email protected]
HeatShield is not intended for users under 18.
Data is processed in the United States.
We may update this policy periodically. Continued use constitutes acceptance.
