Running a course on Teachable, Kajabi, or Thinkific feels like the platform is handling privacy for you, since it processes your payments, hosts your video, and stores your student accounts. It isn't, not entirely. The platform has its own privacy policy covering how it processes data on your behalf, but you, as the course creator, are the one making privacy promises to your own students, and those promises need to cover exactly what your course setup actually does: progress tracking, quiz and assignment data, payment handling, and video engagement analytics.

Two privacy policies are stacked here, not one

Course platforms like Teachable and Kajabi act as a data processor for your business: they store your students' account data, run your checkout, and host your video content, all under a contract that makes clear you, the course creator, are the one deciding why that data is collected. That arrangement means your students are subject to two separate privacy policies: the platform's own policy, covering how it handles data as infrastructure, and your policy, covering why you (the actual business relationship the student signed up for) collect and use their data.

Most students never read the platform's own policy, they read yours, if they read either. Your policy needs to name the platform you use, state plainly that it processes account, payment, and content-delivery data on your behalf, and cover the parts of the relationship that are specific to your course, not just repeat back what the platform's own generic policy already says about itself.

Student progress data is more detailed than it looks

Beyond a name and email address, most course platforms track a surprising amount about how a student actually moves through the material: which lessons they've completed, quiz and assignment scores, time spent per module, and whether they've claimed a completion certificate. Some platforms add a community or discussion feature, where posts and comments are visible to other enrolled students, not just to you. If your course includes any of that, it belongs in your policy's data-collection section by name, not folded into a vague "usage data" line, since progress and quiz data can be more revealing about a student than a typical form submission, and a student asking "what do you know about me" deserves a specific answer.

What an online course platform typically collects

Collected byVisible to
Account name and emailPlatform, on your behalfYou and the platform
Lesson progress and completionPlatformYou
Quiz and assignment scoresPlatformYou
Community posts and commentsPlatformYou and other students
Payment and billing detailsPayment processorProcessor and you (record only)
Video watch time and drop-off pointVideo hostYou, usually in aggregate

Payment handling: what you actually see versus what the processor holds

Most course platforms route payment through an integrated processor, Stripe and PayPal are the most common, which means you almost never handle or store a student's raw card number yourself; the platform and processor are PCI-scoped for that so you don't have to be. Your privacy policy still needs to say who processes payments, since "we never see your card details, our payment processor handles that directly" is both accurate and reassuring, and it needs to state what you do retain: typically a transaction record (amount, date, plan purchased) without the card number itself, used for receipts, refund handling, and revenue records.

If your course offers a payment plan or subscription-style access (monthly tuition rather than one-time purchase), your policy should also mention how billing retries and failed-payment notifications work, since that's a data flow (the platform contacting a student about a failed charge) that's easy to leave undocumented.

Video hosting adds its own third party

Course video is frequently hosted through a dedicated video platform, Wistia and Vimeo are common choices, embedded inside the course player rather than served directly from Teachable or Kajabi's own infrastructure. That embed is a third party in its own right, and it typically sets its own cookies and collects its own watch-time analytics, sometimes surfaced back to you as engagement data (average watch percentage per lesson, where students commonly drop off). If your course site names Google Analytics or a similar tool in its cookie section but never mentions the video host, that's a real, common gap, since the video player is often the single most active data-collecting element on a course page.

Live sessions and recordings

Cohort-based courses that include live calls, coaching sessions, or office hours usually run them through a video conferencing tool like Zoom, separate again from the platform hosting your recorded lessons. If those sessions are recorded and later shared with enrolled students as bonus content, that recording captures each participant's name, face, and voice, along with anything they said in chat or on camera, which is a meaningfully different kind of data than a quiz score. Your policy should say plainly whether live sessions are recorded, what the recording is used for, and whether a student can join with camera and microphone off if they'd rather not appear in a recording that other students will later watch.

Minors and course marketing

Most online courses are built for an adult audience, but "built for adults" and "no minor will ever enroll" aren't the same thing, especially for courses in categories like tutoring, test prep, hobby skills, or anything a parent might buy access to on behalf of a child. If your course is knowingly marketed to or accessed by children under 13, COPPA in the US imposes specific parental-consent and data-minimization requirements well beyond a standard privacy policy, and several other jurisdictions have their own age-of-consent rules for processing a minor's data. Even if your course isn't child-directed, it's worth a line in your policy stating that enrollment is intended for adults, since that's the kind of sentence that matters if the question ever comes up.

What most templates leave out entirely

A few pieces show up on real course sites often enough to be worth naming even though a generic small-business template rarely includes them: affiliate or referral tracking (if your course runs an affiliate program, an affiliate's referral link typically sets a cookie tying a purchase back to them, which is personal data about the buyer flowing to a third party for commission purposes), email automation tied to enrollment (drip sequences and abandoned-checkout emails usually run through a separate email marketing tool, ConvertKit and ActiveCampaign are common, that needs to be named as a recipient of the student's email address), and certificate issuance, if your course generates a completion certificate that includes the student's name, that's a document created from personal data worth a one-line mention.

Building this without guessing at your own stack

The fastest way to get this right is to actually list your own stack, platform, payment processor, video host, email tool, and any affiliate system, before writing policy language, the same exercise that makes a Shopify store's privacy policy accurate instead of generic. Once that list exists, the policy's job is mostly naming each one and saying plainly what it does.

Our Privacy Policy Generator builds a policy around the tools and data types you tell it about, so a course-specific policy, naming your platform, payment processor, and video host, comes out the same way a mobile app's policy does when it's built from an actual permissions and SDK map instead of a generic template.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.