Privacy Policy
Effective October 5, 2026
Commonwealth Training & Preparedness Group LLC operates this website and its account and training platform. This policy explains how information is collected, used and shared when you browse, create an account, register for training, buy an item, upload a document or contact us.
Who this policy covers
This policy covers students, purchasers, employers, instructors and visitors using commonwealthtraininggroup.com and the platform’s original hosted address. Virginia Tactical Shooting Academy (VTSA) is a separate business. When you choose VTSA training or another VTSA offering on this shared platform, the responsible business uses the relevant registration, training and transaction information to provide that offering. Shared sign-in does not give users unrestricted access to another person’s or organization’s records.
Information we collect
- Account and contact information: name, email, phone number, address, account identifiers, role, organization links, preferences and information you provide in your profile.
- Training and professional records: course selections, registrations, schedules, attendance, assessments, completion and package progress, prerequisites, credentials, certificates and supporting records you or authorized personnel submit.
- Documents and consent: uploaded files, waiver and purchase-agreement versions, signatures or acceptance evidence, signer/account identifiers and timestamps.
- Orders and payments: items or courses purchased, payer and attendee details, totals, discounts, fees, invoices, balances, payment references, refund requests and payment status. Card details entered in hosted Stripe Checkout are handled by Stripe; the training platform stores transaction records rather than your full card number or card security code.
- Communications: inquiries, private-training requests, portal conversations, support requests, marketing preferences and email delivery or interaction information where enabled.
- Technical information: browser and request information, cookies, session identifiers, network information used for security checks, application logs and records of administrative changes. Hosting and authentication providers also process technical information to deliver and protect their services.
A purchaser or employer may provide another attendee’s contact information to arrange training. Invitations allow the intended attendee to claim their registration. Purchasers should provide accurate details and tell attendees that their information is being submitted.
Google sign-in and account authentication
If you choose “Continue with Google,” Google authenticates you through Auth0. Our sign-in integration requests basic identity permissions: openid, profile and email. Google and Auth0 may supply an account identifier, name, email address, email-verification status and basic profile information. We use the identity information received by the platform to sign you in, associate your account with authorized records, communicate about services and protect account access.
This sign-in integration does not request access to your Gmail messages, Google Drive files, contacts or calendar. We do not sell Google sign-in information or use it for advertising targeting. Your Google password is entered with Google, not collected by this website. Auth0 handles authentication for email/password accounts as well.
You can manage or revoke Google access through your Google Account’s third-party connections settings. Revoking that access does not automatically delete training, financial or document records already held by the platform. Contact us before removing your only sign-in method if you need help keeping access to your account.
How we use information
We use information to operate accounts and role permissions; manage classes, employers, instructors and registrations; track training and package allowances; collect and reconcile payments; maintain signed documents; respond to inquiries; send account, registration and payment communications; provide marketing communications according to your preferences; investigate errors, misuse or fraud; and maintain business and audit records.
Who can receive information
- Authorized personnel: administrators, staff and assigned instructors receive information needed for their responsibilities. Employer accounts receive information about their own authorized employee relationships and training. Document access follows account permissions and applicable sharing choices; purchasing another person’s training does not grant access to that person’s private account.
- Service providers: the platform uses hosting and storage services supplied through OpenAI Sites and Cloudflare, Auth0 for authentication, Google when you choose Google sign-in, Stripe for hosted payments and Resend for email. SMS-related information may be processed through Twilio if that service is enabled. Providers process information needed to perform their services and may have their own privacy notices.
- Requested services and necessary disclosures: information may be disclosed when you authorize a service or sharing request, to fulfill applicable reporting obligations, respond to valid legal requests, investigate misuse, resolve disputes or protect people and the platform.
Employer linking alone does not make every historical record or private waiver visible to an employer. Relevant VTSA waiver sharing is subject to the applicable document-sharing rules and choices. Commonwealth and VTSA financial records remain associated with the responsible business.
Cookies and browser storage
The platform uses cookies for secure sessions, sign-in transactions and related security functions. Browser storage keeps cart selections and interface preferences. Authentication and hosting providers may set their own cookies. Blocking these technologies can prevent sign-in or checkout from working. Signing out ends the active account session; clearing browser storage may remove saved cart selections.
Email, marketing and optional text messages
Account, registration, payment and support messages are used to provide requested services. Marketing emails provide an unsubscribe option, and available communication preferences can be managed through your account or by contacting us. Opting out of marketing does not stop necessary service messages.
Text-message consent is separate and optional. Providing a phone number or creating an account is not, by itself, consent to promotional texts. Mobile information is not shared with third parties or affiliates for marketing or promotional purposes. See the SMS Privacy Policy and SMS Terms for the text program. SMS delivery and automatic scheduled reminders are not currently active.
Retention and security
Information is retained according to its purpose, including operating accounts, providing training, maintaining payment and signed-document evidence, resolving disputes and meeting applicable recordkeeping obligations. Retention can differ by record type; account closure does not necessarily remove records that must be retained. Contact us about a specific record or deletion request.
The platform uses HTTPS, access controls, protected service credentials and audit records to help protect information. No website or transmission method can guarantee complete security. Keep your sign-in credentials private and contact us if you suspect unauthorized account access.
Your choices and privacy requests
You can update available profile fields and preferences in your account. To request access, correction, account closure or deletion, email mailadmin@commonwealthtraininggroup.com. Identify the account and request, but do not email passwords, payment-card details or unnecessary sensitive documents. We may ask for information to verify your identity and authority before releasing or changing records. We will assess the request, including any applicable rights and recordkeeping requirements, and explain any limits that prevent us from completing it.
Youth training
Parents and guardians should contact the training office to arrange youth participation and ask about required guardian consent and documents. Do not create an adult account in a child’s name or submit unnecessary information about a child. If you believe a child’s information was submitted without appropriate authority, contact us so we can review it.
Changes to this policy
Updates will be posted on this page with a revised effective date. Where applicable, additional notice or consent will be provided for material changes. This policy describes privacy practices; it does not replace course requirements, purchase terms, waivers or the separate SMS terms.
Contact us
Commonwealth Training & Preparedness Group LLC
5243 South Laburnum Avenue, Henrico, Virginia 23231
Email: mailadmin@commonwealthtraininggroup.com
Phone: 804-234-3346