Privacy Policy

1. Introduction

This Privacy Policy explains how Milestone LMS(“MilestoneLMS,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit https://milestonelms.com/ (the “Site”) or use the MilestoneLMS learning management system and related services (collectively, the “Service”).

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.


2. Who This Policy Applies To

MilestoneLMS is used by organizations (“Customers”) who create accounts to deliver training, and by the individuals those organizations enroll as learners (“Learners” or “Users”). This Policy covers both categories of Users. Where a Customer controls how Learner data is collected and used within its own instance of the Service, the Customer acts as the data controller and MilestoneLMS acts as a data processor or service provider, as further described in Section 10.


3. Information We Collect

3.1 Information You Provide

  • Account & Organization Configuration: Company name, work email, region, LMS display name, custom subdomain, brand title, email signature details (from name, footer text), brand customization details (logo and brand colors), and password. We may also collect optional organization details such as your main industry and company size.
  • Learner and team data entered by administrators: names, email addresses, team/department assignments, and role.
  • Course, assessment, and evaluation data: quiz responses, assessment scores, post-evaluation feedback, and completion status.
  • Billing information: billing name, address, and payment details (processed by our third-party payment processor; MilestoneLMS does not store full card numbers).
  • Communications: messages sent through the built-in support module, emails, and any content submitted in support tickets.

3.2 Information Collected Automatically

  • Usage data: pages visited, features used, enrollment and completion activity, login timestamps, and session duration.
  • Device and log data: IP address, browser type, operating system, and referring URLs.
  • Cookies and similar technologies, as described in Section 6.

3.3 Certificates

When a Learner completes a course and passes any required assessment, the Service automatically generates a certificate record containing the Learner’s name, course title, completion date, and a verification identifier. This record is stored on the platform and may be downloaded or shared by the Learner or made available for verification by the issuing organization.


4. How We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including course delivery, enrollment tracking, assessments, post-evaluations, and certificate issuance.
  • Power the administrator analytics dashboard (e.g., total users, total courses, enrollments, completion rate, certificates issued).
  • Send transactional emails, such as welcome messages, enrollment confirmations, completion notices, certificate delivery, and announcements, and to maintain email logs for delivery verification.
  • Process subscription billing, manage free trials, and communicate about your account or subscription.
  • Provide customer and technical support.
  • Monitor, detect, and prevent fraud, abuse, and security incidents.
  • Improve and develop the Service, and comply with legal obligations.

5. How We Share Information

We do not sell personal information. We may share information in the following circumstances:

  • With the Customer organization that manages your account, since administrators can view Learner activity, scores, and completion data within their own organization’s instance.
  • With service providers who perform functions on our behalf, such as hosting, email delivery, analytics, and payment processing, under contractual confidentiality and data-protection obligations.
  • For legal reasons, such as to comply with a subpoena, court order, or other legal process, or to protect the rights, property, or safety of MilestoneLMS, our Customers, or others.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
  • With your consent or at your direction.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to keep you logged in, remember preferences, understand how the Service is used, and support analytics. You can control cookies through your browser settings; disabling certain cookies may limit functionality of the Service.


7. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Service, including retaining Learner records and certificates for the period required to support verification and audit needs. When a Customer’s subscription ends, we retain data for a limited period as described in our data retention schedule before deletion or anonymization, except where longer retention is required by law or legitimate business need (e.g., billing records, dispute resolution).


8. Data Security

We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and role-based administrator permissions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


9. International Data Transfers

If you access the Service from outside the country where our servers are located, your information may be transferred to, stored, and processed in a different jurisdiction. Where required, we rely on appropriate safeguards, such as standard contractual clauses, to protect information transferred internationally.


10. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal information, and to object to or withdraw consent for certain processing. If you are a Learner and want to exercise these rights, you may need to contact the organization that enrolled you, as they typically control your Learner data within the Service. Customers and administrators may contact us directly at [Privacy Contact Email]. Residents of the European Economic Area, UK, and California (and other jurisdictions with similar laws) may have additional statutory rights, which we will honor in accordance with applicable law.


11. Children’s Privacy

The Service is intended for use by organizations and their adult employees, learners, and administrators. It is not directed to children under 16, and we do not knowingly collect personal information from children under 16 outside of a Customer’s controlled training context (for example, an educational institution enrolling students, where the institution is responsible for obtaining any required consent). If you believe a child has provided us with personal information without appropriate consent, please contact us so we can take appropriate action.


12. Third-Party Links and Integrations

The Service may contain links to third-party websites or support integrations with third-party tools. We are not responsible for the privacy practices of third parties, and we encourage you to review their privacy policies.


13. Account & Data Deletion Policy

You have the right to request the complete deletion of your account and associated personal data at any time, subject to applicable legal requirements.


How to Request Account Deletion

1. In-App Request

You can request account deletion directly within the application by navigating to:

Profile > Onboarding Settings > Delete Account


2. Web-Based Request

If you do not have access to the application, you may submit an account deletion request through our online request form:

https://milestonelms.com/account-request-deletion/

To submit a web-based request, you may be required to provide information associated with your registered account to verify ownership.

Verification & Processing Workflow

Once a deletion request is initiated through the application or web form, our administrative team may contact you to complete an identity verification process. This verification helps prevent accidental, unauthorized, or fraudulent account deletion requests.

Data Scope & Retention

Once the deletion request is verified and finalized, the following information will be permanently deleted from our primary systems:

  • Personal account details and profile information.
  • Course records and enrollment information.
  • Assessment results, scores, and completion records.
  • Activity logs associated with your account.
  • User-generated data and other personal information associated with the account.

If your account is managed by an organization or Customer, certain training records, certificates, or other data may be controlled by that organization. In such cases, your deletion request may need to be coordinated with the organization that manages your account.

We may retain limited information where necessary to comply with applicable legal obligations, resolve disputes, prevent fraud, enforce our agreements, or maintain legally required billing and financial records.

Deletion Timeline

Following successful identity verification, your account and applicable associated personal data will be permanently deleted from our primary systems within seven (7) days, unless a longer retention period is required or permitted by applicable law.

Once your account and associated data have been permanently deleted, the deletion cannot be reversed.


14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised “Effective Date,” and, where changes are material, we will provide additional notice (such as email or an in-app notification).


15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: