Migna Safety Solutions

Privacy Policy

Version 2026-09-14 · Effective 14 September 2026

This policy covers Migna Safety Solutions’ online training platform at training.mignasafetysolutions.com, including the free toolbox talk library and the certificate verification page. It says what we collect, why, who else sees it, and what you can ask us to do about it.

How to reach us

Questions about this policy, or any request about your information, go to our contact form or support@mignasafetysolutions.com. We answer privacy requests from the same inbox as everything else, and we will tell you what we did.

Using the free library without giving us anything

The toolbox talk library is free and needs no account. You can read, print and use every talk and every attendance sheet without telling us who you are, and nothing on those pages is required before the sheet is on your screen and printable.

If you choose to ask us for something — a notice when the weekly talk by email launches, an editable copy of a sheet, or information after checking a certificate — we collect the email address you type and the company name if you give us one. That is a choice, not a condition: the library stays free and complete whether or not you leave an address.

What we collect when you have an account

Account details. Your name, email address, and a hashed form of your password. We never store the password itself. Two-factor settings if you turn them on.

Training activity. Course progress, time spent training, quiz attempts and answers, practice-question responses, and identity checkpoints. A checkpoint records that we asked you to confirm it was you, the method we used, and whether you passed — not what you typed.

Purchases. What you bought, when, for how much, and any refund. Payment card details go directly to Stripe and never reach our servers.

Messages. Anything you send us through the contact form, and problem reports you submit from inside a course.

What we collect automatically

Your IP address when you sign in, when you accept these terms or the Terms of Service, and on security-relevant events in our audit log. It is kept so that a training record can be shown to have been created by someone, somewhere, at a time — which is most of what makes the record worth anything — and so that we can investigate abuse.

Your browser and operating system, as a short text string, on sessions, on legal acceptances, and on problem reports. On a problem report it is the difference between “the quiz is broken” and a bug we can find.

A rate-limiting record derived from your IP address, held briefly to stop one visitor flooding a form or a login. It expires on its own within the hour.

Cookies

One cookie, named migna_training_session. It keeps you signed in, lasts seven days, and cannot be read by scripts. It is what a browser needs to know you are still you between pages.

We use no advertising cookies, no third-party trackers, and no cross-site profiling. Nothing here follows you to another website.

If you check somebody else’s certificate

The verification page is deliberately open: anyone holding a certificate number can confirm that it is real, who it was issued to, for which course, and when. That is what makes the credential worth something to the employer relying on it.

The certificate number you type is used to look up that certificate and nothing else. It is not sent to our outreach system and is not kept as part of any request you make from that page. If you ask us for renewal reminders or retraining information, we keep your own email address and company name — not the record you looked up. The person named on a certificate is not our customer and did not ask to be in our sales system.

Why we keep training records, and for how long

Training records exist to prove your training happened. We keep completion records, training-time logs, and certificates for seven years from the date the certificate is issued, and then we delete them.

We keep them because a certificate anyone can verify is what you bought. A record we deleted on request is a certificate we can no longer stand behind. This is our own retention policy, not a legal obligation imposed on us — the recordkeeping duties in this area fall on employers, not on the company that supplied the training.

You can ask us to delete your account and your contact information at any time, and we will. What stays for the seven years is the minimum needed to answer a verification: the certificate number, the course, the completion date, and the name on the certificate. At the end of the seven years we delete that too, unless you have asked us to keep it.

Other information is kept only as long as it is doing something. Sessions expire after seven days. Rate-limiting records expire within the hour. Contact messages are kept while we are dealing with them and for a reasonable period afterwards. If your email address hard-bounces we keep a record of that address specifically so we stop mailing it.

Who can see your records

You can always see your own records. If your seat was purchased by your employer through a team license, the license manager can see your progress and completion status for that course — that is what they bought, and it is how they demonstrate their own compliance. If you are enrolled through a team license, we tell you so in your account, so you know who can see your progress before you start. Certificate validity is confirmable by anyone holding the certificate number.

We do not sell personal information, and we do not share it for anyone else’s advertising.

Email you can stop

If you ask to hear about the weekly toolbox talk, we email you when it launches and, once it is running, one talk a week. It has not launched and there is no date. Every one of those emails carries an unsubscribe link, one click ends it, and we do not put you into a sequence of anything else.

Separately, if you hold an account, we send email that is part of the service rather than marketing: address verification, receipts, certificates, reminders that a course is unfinished, and notice when a certificate is coming up for renewal. Those follow the account, and closing it ends them.

Service providers

Each of these receives only what it needs to do its job:

Stripe — payments and refunds. Resend — sending email. Neon — the database. Vercel — hosting. Upstash — rate limiting. Migna’s own outreach system — requests you send us from the free library or the verification page.

Where a course is delivered by a training partner rather than by us, the course page names that partner before you buy, and buying it means we pass them what they need to enroll you.

Where your information is processed

In the United States. If you are using this service from outside the United States, that is where your information goes.

The weekly toolbox talk, when it launches, is for United States addresses only, and the signup form says so. The free library itself has no such limit — you can read, print and use every talk from anywhere, without giving us anything.

How we protect it

Passwords are hashed. Sessions are held in cookies that scripts cannot read and are revoked when you sign out. The audit log and seat-time records carry integrity hashes, so a record that was altered after the fact does not verify. Two-factor authentication is available on your account and we recommend it.

If a breach affects your information, we will notify you without undue delay and as required by applicable law.

No system is perfect, and we would rather say that than imply otherwise.

Your choices

You can update your password and two-factor settings at any time, request a copy of your data, correct anything wrong in it, unsubscribe from any email you asked for from the email itself, or close your account by contacting us. Closing an account deletes your account and your contact information. The minimal verification record described above stays for the seven years — that is the trade a verifiable credential makes, and it is why the certificate is still worth something years later.

Depending on where you live, you may have additional rights over your information. Ask us and we will honor them where they apply.

Children

This service is for people in the workforce and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, tell us and we will remove it.

Changes to this policy

When the substance of this policy changes, the version at the top of this page changes with it. Material changes that affect what we collect or who receives it will be notified to account holders by email before they take effect.

Privacy Policy | Migna Safety Training