Skip to content
Scrum Master Toolbox Community Scrum Master Toolbox Community
Subscribe Log in
  • Browse
  • Subscribe

Privacy Policy and GDPR compliance information

Oikosofy runs two websites, and this page covers both:

  • scrum-master-toolbox.org — the podcast site, which has always carried this policy, and
  • the Scrum Master Toolbox Community — our learning platform, currently served at https://beta.oikosofyseries.net. Everything below marked the Community describes that platform.

Questions about this policy, or about your own data, go to [email protected].

Who we are

The data controller is Oikosofy. Our website addresses are https://scrum-master-toolbox.org (the podcast) and the Community platform above.

What we collect on the Community

When you create an account we store:

  • your email address — it identifies your account, and it is how we reach you;
  • a display name, if you choose to give one — it is what other learners see beside your comments;
  • your password, stored only as a one-way hash. We never store, see or send the password itself, and nobody at Oikosofy can read it;
  • your learning activity — which lessons you watch and how far, what you save for later, your votes, the comments you post, your progress in each course, and which of the related lessons we suggest you open (we count that only when the request carries the session we showed the suggestion to, so a search engine following the link is not recorded against you).

If you watch a lesson preview without an account, we store a pseudonymous key tied to your browser session (no email address and no IP address) purely to count the two-minute allowance.

When you buy a subscription, the payment is handled by Stripe. Your card details go to Stripe directly and we never receive them. We keep only the state of your subscription — plan, status, the date the current period ends — and Stripe's reference for your customer record. Tax and invoices are handled inside Stripe's systems, and your receipts come from Stripe.

Comments

When you leave a comment on a lesson we store the comment, the display name you are using, and the time. Comments are visible to signed-in learners, and on a previewable lesson they may be visible to visitors. We do not use Gravatar, and we do not run an automatic spam-detection service over comments: a comment belongs to its author, who can edit or delete it.

Cookies

The Community sets three first-party cookies:

Cookie What it is for Lifetime
session cookie keeps you signed in; for visitors without an account it remembers which suggestion panel you were shown, so a click can be told from a crawler's 8 hours, or until you sign out
csrftoken protects forms against cross-site request forgery 1 year
lms_welcome remembers that the one-time welcome banner has been shown, so you do not see it again 1 year

Your theme choice (light or dark) is remembered in your browser's own local storage, not in a cookie. The Community sets no advertising and no analytics cookies.

Cloudflare, the network that sits in front of the Community, may also set a short-lived security cookie when it needs to check that a request comes from a person rather than a bot.

Embedded content from other websites

Lesson pages play video through a player loaded from Bunny (assets.mediadelivery.net), and the checkout page loads Stripe's script (js.stripe.com) so that you can pay without leaving our site. As with any embedded content, those providers see the request your browser makes to them. We embed nothing else — no social plugins, no advertising, no third-party analytics.

Who we share your data with

We do not sell your data, and we do not give it to anyone for their own marketing. We use these processors, and each sees only what it needs to do its job:

Provider What it does What it receives
Stripe payments, tax and invoices, and the billing portal where you change your card or cancel your card details, your name, your email, and the subscription
Ontraport our contact records and the email lists we send our own product news to your name, your email, and which list you are on
Amazon SES sending our email to you (account, password reset, receipts) your email address
Bunny video streaming, images, downloadable files, and the encrypted backups of our database the requests your browser makes for a file, and an encrypted copy of the database for backups
Cloudflare the network and domain in front of the site the requests that reach the site
OVH the host that runs the application everything the application stores

The podcast site (scrum-master-toolbox.org) additionally uses Google Analytics, Facebook (where Facebook analytics are used) and Optin-Monster, as that site's policy has always said. The Community does not use those three.

We use Ontraport to send you email about our own products. You can ask us to stop at any time by writing to [email protected].

How long we retain your data

  • Your account and its activity are kept while the account exists.
  • A comment is kept while your account exists.
  • Encrypted backups of the database are kept for no more than three months — five daily copies and three monthly copies, pruned automatically.
  • The counters that protect sign-in and password reset from abuse (which record an IP address) are short-lived and pruned automatically.

What rights you have over your data

If you have an account on the Community you can ask us for a copy of the personal data we hold about you, and you can ask us to erase it. Write to [email protected].

Erasing your account removes your email address, your display name, your password and your contact record in our CRM. What remains is anonymised: your progress, viewing records, votes, saves, comments and the suggestions you followed stay as pseudonymous rows — they keep a random identifier instead of your identity — so that course statistics stay correct. A copy of the erased data can remain in the encrypted backups for up to three months, after which it ages out of them.

Where we send your data

Comments on the Community are not checked by an automated spam-detection service. Sign-in attempts and password-reset requests are checked by our own abuse protection, which counts them per account and per IP address.

Your contact information

Oikosofy — [email protected]

How we protect your data

Data is stored in the application and with the service providers listed above, all of which are GDPR compliant. Traffic to the site is encrypted over HTTPS, passwords are stored as hashes, access to the production database is limited to the operating team, and access to learner data through our operations tools is authenticated and audited.

What data breach procedures we have in place

We notify everyone involved as soon as we receive any notice of a possible breach from our providers, and we notify affected learners and the competent authority as the GDPR requires.

What third parties we receive data from

We do not receive any data about you from third parties.

What automated decision making and/or profiling we do with user data

When you subscribe to a product, we decide which of our content interests you based on what you opted in to, and that decision is what selects which email you receive from our lists. For example, everyone who opts in receives information about products in our portfolio. You can ask us to stop at any time by writing to [email protected].

This page is part of the site and is updated with it.

Privacy policy · © Scrum Master Toolbox Community