Privacy Policy
Version 1.0 · Effective 18 August 2026
1. Who we are
1.1 Wayforward Programs LLC is the data controller for swim.institute and platform.swim.institute. Questions and requests go to contact@swim.institute.
1.2 The SWIM Institute is an independent certifying body and receives only what section 5 describes.
2. What we collect
2.1 When you apply, we collect your name, email address, telephone number, postal address, employer, job title, LinkedIn profile, your resume, your answers to the background and open-text questions, and the cohort you asked for.
2.2 When you create an account, we hold a password you set, which we never see in readable form, your time zone, and your acceptance of the Platform Terms of Use recorded with your typed name and the date.
2.3 When you pay, Stripe handles the payment and we never receive or store your card number. We keep the amount, the date, the method type, the payer name and email, and Stripe's own references.
2.4 While you train, we hold your coursework submissions, assessment results, session bookings and attendance, and any merchandise orders you place.
3. Why we hold it
3.1 To decide your application, to run your enrollment and coursework, to take payment and issue receipts, to award and maintain your credential, and to meet our record-keeping obligations.
4. IP addresses
4.1 The application form and the credential verification page each count requests to prevent abuse. Both store a one-way hash of the requesting address rather than the address itself, and the hashes are pruned on a rolling basis. We do not use them to identify anyone.
5. Who else sees your information
5.1 We do not sell your information and we do not share it for advertising.
5.2 Lovable hosts swim.institute and platform.swim.institute and processes the traffic between you and those applications.
5.3 Supabase is our database, authentication, and file storage provider, and holds everything described above.
5.4 Stripe processes payments and holds the payment details you enter directly with them.
5.5 Resend delivers our email and receives your email address and the content of the message.
5.6 Accredible is our credentialing platform, and receives your name, your email address, the name of your credential, and the dates your credential was issued and expires.
5.7 Printful fulfills merchandise orders and receives the name and shipping address for that order.
5.8 The SWIM Institute, an independent certifying body, receives your name, your professional history, and the dates you met each course requirement.
6. How we protect it
6.1 Card details never reach us. Payment happens on Stripe's own hosted page, and we receive only an amount, a date, a method type, and Stripe's references. Card data is never transmitted to or stored on our systems.
6.2 Traffic between you and our applications is encrypted in transit.
6.3 Every table in our database carries row-level access control, so a request only returns the rows the requester is entitled to see.
6.4 Files, including your resume and any coursework you upload, are held in private storage. They are reachable only through a short-lived signed link issued after a permission check on the server, and never through a public address.
6.5 Passwords are held by our authentication provider in hashed form. They are not stored in our own tables and no member of staff can view them.
6.6 Source addresses used for rate limiting are stored as a one-way hash rather than the address itself.
6.7 Assessment material and the scoring that applies to it stay on the server and are never sent to the browser.
6.8 Privileged actions are written to an audit trail recording who acted, what changed, and why.
6.9 Requests to the application form and the credential verification page are rate limited.
6.10 If we become aware of a breach affecting your information, we will notify you and the relevant authorities as the law requires, without undue delay.
6.11 No system is perfectly secure. These measures reduce risk, and they do not eliminate it.
7. The public register
7.1 Anyone can look up a credential at swim.institute/verify without an account. A successful search returns the holder's name, the credential, the date it was issued, the date its term ends, whether it is active, expired, or revoked, and a link to the credential record.
7.2 You may ask us to remove your name from search, in which case your credential remains verifiable by its identifier but will not be found by name. Write to contact@swim.institute.
8. How long we keep it
8.1 Application records and credential records are kept as part of the permanent record of the certification, because a credential has to remain verifiable long after it is awarded.
8.2 Payment records are kept as long as our financial and tax obligations require. Other operational records are kept only as long as they are useful for the purpose they were collected for.
9. Your choices
9.1 You may ask for a copy of what we hold, ask us to correct it, ask us to remove your name from the public register, or ask us to delete what we are not required to keep. Write to contact@swim.institute.
9.2 Some records cannot be deleted while a credential stands, since deleting them would make the credential unverifiable.
10. Changes and governing law
10.1 We will post any revision on this page with a new version number and effective date, and material changes will be sent to candidates by email.
10.2 This policy is governed by the laws of the State of New York.
This policy describes current practice. If something here does not match what you experience, write to contact@swim.institute and we will look into it.