CyberActive, Inc.
8034 Garden Grove Blvd., Suite C
Garden Grove, California 92844
Last Updated: September 25, 2026
CyberActive, Inc. ("CyberActive," "we," "us," or "our") respects the privacy of students, customers, partners, website visitors, software users, and other individuals who interact with our products and services.
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you interact with CyberActive websites, mobile applications, educational programs, learning platforms, partner portals, white-label platforms, software-as-a-service products, communications tools, third-party integrations, and related products and services (collectively, the "Services").
This Policy also describes our handling of information obtained through Google APIs and other third-party integrations.
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to CyberActive Services that reference this Policy, including CyberActiveOnline.com.
CyberActive operates and supports multiple educational programs, websites, brands, applications, institutional programs, and white-label solutions. Certain products or programs may provide supplemental privacy notices addressing additional practices or regulatory requirements.
When CyberActive processes personal information on behalf of a governmental agency, school, business customer, employer, or other organization, that organization may determine certain purposes and means of processing. In those circumstances, its privacy policy or contractual requirements may also apply.
2. INFORMATION WE COLLECT
The information CyberActive collects depends upon the Services you use, the program in which you participate, the jurisdiction in which the program operates, and the features you activate.
A. Information You Provide Directly
We may collect:
- First and last name;
- Mailing address;
- Email address;
- Telephone number;
- Date of birth;
- Account username and password;
- Organization or employer;
- School or educational institution;
- Business information;
- Course-registration information;
- Billing information;
- Communications preferences;
- Information contained in support requests;
- Information submitted through forms;
- Files and documents uploaded to the Services;
- Information you include in communications sent through our platforms; and
- Other information you voluntarily provide.
B. Student and Regulated Course Information
For regulated educational programs, we may collect information necessary to meet governmental, court, DMV, school, licensing, certification, or regulatory requirements, including where applicable:
- Driver's license or identification information;
- Citation or ticket information;
- Court information;
- Case or docket information;
- Jurisdiction;
- Course eligibility information;
- Permit or licensing information;
- Course enrollment information;
- Course progress;
- Attendance or session information;
- Course completion;
- Examination and quiz results;
- Security-question responses;
- Identity-verification information;
- Certificate information;
- Course activity;
- Completion dates;
- Reporting records; and
- Other information required by the applicable regulatory authority.
Certain programs may require additional identifying information where mandated or authorized by law or regulation.
We collect sensitive information only when reasonably necessary for the applicable Service, regulatory obligation, identity verification, fraud prevention, or another lawful purpose.
C. Partner and Business Information
If you use CyberActive as a business, governmental, educational, affiliate, or institutional partner, we may collect:
- Name;
- Business email address;
- Business telephone number;
- Organization name;
- Job title;
- Website;
- Industry;
- Program interests;
- Partner ID;
- Referral information;
- Commission information;
- Account activity;
- Customer or student referral information;
- Program configuration;
- Administrative-user information; and
- Communications with CyberActive.
D. Payment Information
If you make a payment, we or our payment processors may collect:
- Cardholder name;
- Billing address;
- Payment-card information;
- Transaction information;
- Payment status; and
- Related billing details.
CyberActive may use third-party payment processors. CyberActive generally does not need to retain complete payment-card numbers when payment information is processed directly by an authorized payment provider.
E. Device and Usage Information
When you use our websites, applications, or platforms, we may automatically collect:
- IP address;
- Browser type;
- Operating system;
- Device type;
- Device identifiers;
- Pages viewed;
- Links clicked;
- Referring URL;
- Date and time of access;
- Session information;
- Login activity;
- Course activity;
- Interaction with features;
- Application logs;
- Error logs;
- Security logs; and
- Other technical information.
For regulated programs, some of this information may be retained as evidence of participation, attendance, identity validation, completion, or compliance.
F. Cookies and Similar Technologies
CyberActive and authorized service providers may use cookies, pixels, local storage, session technologies, analytics technologies, and similar tools to:
- Operate the Services;
- Maintain sessions;
- Remember preferences;
- Authenticate users;
- Prevent fraud;
- Maintain security;
- Analyze website and Service performance;
- Understand use of our Services;
- Improve functionality; and
- Measure marketing effectiveness where legally permitted.
Where required by law, we provide choices regarding nonessential cookies and similar technologies.
3. INFORMATION FROM THIRD PARTIES
CyberActive may obtain information from third parties when reasonably necessary to provide the Services.
Depending upon the applicable program, these sources may include:
- Courts;
- DMVs or motor-vehicle agencies;
- Government agencies;
- Schools;
- School districts;
- Employers;
- Driving schools;
- Insurance-related partners;
- CyberActive affiliates and referral partners;
- Identity-verification providers;
- Payment processors;
- Fraud-prevention services;
- Regulatory databases;
- Business customers;
- Users who administer accounts on behalf of others; and
- Third-party services that you choose to connect to CyberActive.
We process information received from these sources in accordance with applicable law, contractual restrictions, and the purposes described in this Policy.
4. GOOGLE ACCOUNT AND GOOGLE API DATA
CyberActive may allow authorized users to connect a Google Account to certain CyberActive Services.
A. Information CyberActive May Receive From Google
Depending upon the functionality selected by the user and the permissions presented on Google's authorization screen, CyberActive may receive:
- Google Account email address;
- Basic Google Account identity or profile information;
- OAuth authorization information;
- Access tokens and refresh tokens;
- Information necessary to identify the Google Account connected to CyberActive;
- Recipient email addresses selected or entered by the user;
- Email subject lines;
- Email message content composed, uploaded, selected, or approved by the user for transmission;
- Attachments selected by the user for transmission;
- Technical message identifiers;
- Message transmission status or related metadata necessary to provide the requested email functionality; and
- Other Google user data expressly authorized by the user and necessary to provide the Google-connected feature displayed within the CyberActive Service.
CyberActive will request only the Google permissions reasonably necessary to provide the functionality made available to the user.
B. How CyberActive Uses Google User Data
CyberActive uses Google user data only to provide or improve user-facing functionality that the user requests or authorizes.
For example, if an authorized CyberActive user connects Gmail for an email or CRM feature, CyberActive may use the authorized Google connection to send messages through that user's Gmail account and to provide related functionality displayed in the CyberActive interface.
CyberActive does not use Google user data for unrelated purposes.
C. Google User Data and Advertising
CyberActive does not use Google user data obtained through Google Workspace APIs to:
- Serve personalized advertisements;
- Retarget users with advertisements;
- Build advertising profiles;
- Sell advertising based on Google user data;
- Transfer Google user data to advertising platforms, data brokers, or information resellers; or
- Determine creditworthiness or eligibility for lending.
D. Google User Data and Artificial Intelligence
CyberActive does not use raw or derived Google Workspace user data to develop, train, or improve generalized artificial-intelligence or machine-learning models.
Google user data will not be incorporated into datasets used to train generalized AI or machine-learning systems.
If CyberActive provides user-facing AI-assisted functionality in the future involving Google user data, it will do so only in accordance with applicable Google policies, required user authorization, and updated disclosures.
E. Human Access to Google User Data
CyberActive personnel do not access the content of Google user data except where access is:
- Necessary to provide user-requested support and the user has authorized the access;
- Required to investigate security, fraud, abuse, or technical problems;
- Required by applicable law, regulation, court order, or legal process; or
- Otherwise expressly permitted under applicable Google policies.
Any permitted access is limited to personnel with a legitimate need for access.
F. Sharing Google User Data
CyberActive does not sell Google user data.
CyberActive does not transfer Google user data to third parties except when necessary:
- To provide or improve a user-facing feature requested or authorized by the user;
- To use service providers acting on CyberActive's behalf that are necessary to operate the authorized feature and are subject to appropriate confidentiality and data-protection obligations;
- For security purposes, including investigating fraud, abuse, or a security incident;
- To comply with applicable law, regulation, legal process, or governmental request; or
- As otherwise expressly authorized by the user and permitted by Google's policies.
G. Storage and Security of Google Authorization Credentials
Where CyberActive stores Google OAuth tokens or other authorization credentials, CyberActive uses reasonable administrative, technical, and organizational safeguards designed to protect those credentials against unauthorized access, disclosure, alteration, or destruction.
CyberActive does not publicly expose Google access tokens or refresh tokens.
H. Revoking Google Access
Users may revoke CyberActive's access to their Google Account through their Google Account security or permissions settings.
Users may also disconnect applicable integrations through CyberActive where that functionality is provided.
After authorization is revoked, CyberActive will cease new access through the revoked authorization. Certain information may remain temporarily in backups, logs, security records, or records CyberActive is legally required to retain.
I. Google Limited Use Disclosure
CyberActive's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Where Google Workspace API data is involved, CyberActive's use of raw and derived Google Workspace user data will also comply with applicable Google Workspace user-data requirements.
5. HOW WE USE PERSONAL INFORMATION
CyberActive may use personal information to:
Provide the Services
- Create and maintain accounts;
- Enroll users;
- Deliver courses;
- Provide software;
- Provide partner portals;
- Operate white-label platforms;
- Process payments;
- Issue certificates;
- Provide reports;
- Provide dashboards;
- Provide technical functionality;
- Send user-directed communications; and
- Provide customer support.
Meet Regulatory and Contractual Requirements
- Validate identity;
- Track instructional time;
- Verify participation;
- Administer examinations;
- Determine completion;
- Maintain required records;
- Report results;
- Submit completion information;
- Communicate with courts, agencies, schools, or other authorized organizations; and
- Comply with government contracts.
Operate and Improve the Services
- Troubleshoot;
- Test;
- Maintain;
- Analyze performance;
- Improve usability;
- Develop features;
- Conduct quality assurance;
- Monitor service availability; and
- Understand how Services are used.
Security and Fraud Prevention
- Authenticate users;
- Detect suspicious activity;
- Prevent fraud;
- Investigate misuse;
- Maintain audit logs;
- Protect users;
- Secure systems; and
- Enforce agreements.
Communications
- Respond to inquiries;
- Provide service notices;
- Send course reminders;
- Send account notifications;
- Provide regulatory communications;
- Send transactional messages; and
- Send marketing communications where permitted.
Legal and Corporate Purposes
- Comply with law;
- Respond to legal process;
- Establish or defend legal claims;
- Protect rights and property;
- Conduct audits;
- Manage corporate transactions; and
- Enforce agreements.
6. HOW WE DISCLOSE PERSONAL INFORMATION
CyberActive may disclose personal information to the following categories of recipients where reasonably necessary and legally permitted.
A. Service Providers
We may use vendors that provide:
- Cloud hosting;
- Software infrastructure;
- Security;
- Identity verification;
- Payment processing;
- Customer support;
- Email delivery;
- Communications;
- Analytics;
- Data storage;
- Course administration;
- Certificate fulfillment;
- Mailing;
- Fraud prevention; or
- Professional services.
These providers are permitted to process information only for appropriate business purposes and subject to applicable contractual obligations.
B. Courts and Government Agencies
Where applicable to the program, CyberActive may provide information to:
- Courts;
- DMVs;
- Departments of public safety;
- Licensing agencies;
- Regulatory authorities;
- Government customers; and
- Other authorized public agencies
for purposes such as verifying enrollment, reporting course completion, submitting certificates, meeting statutory requirements, or administering government programs.
C. Schools and Educational Institutions
Where a student participates through a school, district, educational institution, or sponsored program, CyberActive may provide information reasonably necessary to administer that program.
D. Employers and Organizational Customers
Where a Service is provided through an employer or organization, CyberActive may disclose enrollment, participation, completion, compliance, or administrative information appropriate to that program.
E. Partners and Affiliates
CyberActive may disclose limited information to an authorized partner where necessary to administer a referral, branded program, affiliate relationship, white-label program, or contractual relationship.
Sensitive information is not provided to a partner merely because that partner referred a user when such disclosure would be unnecessary, contractually restricted, or prohibited by law.
F. Legal and Safety Disclosures
We may disclose information if we reasonably believe disclosure is necessary to:
- Comply with law;
- Respond to court orders, subpoenas, warrants, or legal process;
- Protect CyberActive or others;
- Investigate fraud;
- Address security incidents;
- Prevent harm; or
- Enforce our agreements.
G. Corporate Transactions
Information may be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable legal requirements.
7. WE DO NOT SELL PERSONAL INFORMATION IN THE ORDINARY MEANING OF THE TERM
CyberActive does not sell personal information to data brokers for money.
Certain privacy laws define "sale" or "sharing" more broadly and may include some advertising or analytics technologies.
Where required by applicable law, CyberActive will provide appropriate rights to opt out of covered sales, sharing, or targeted advertising.
8. PERSONAL INFORMATION RETENTION
CyberActive retains personal information for as long as reasonably necessary to:
- Provide the Services;
- Maintain accounts;
- Satisfy regulatory recordkeeping;
- Meet governmental contracts;
- Maintain course-completion records;
- Resolve disputes;
- Prevent fraud;
- Enforce agreements;
- Meet tax and accounting requirements;
- Maintain security records; and
- Comply with law.
Retention periods may vary significantly for regulated educational records because applicable governmental agencies may require records to be retained for specified periods.
When information is no longer reasonably necessary, CyberActive may delete, anonymize, or securely dispose of it, subject to legal, contractual, backup, and technical requirements.
9. INFORMATION SECURITY
CyberActive uses administrative, technical, and physical safeguards designed to protect personal information.
Depending upon the nature of the information and Service, safeguards may include:
- Access controls;
- Authentication;
- Encryption in transit;
- Encryption or equivalent protections for appropriate stored information;
- Logging and monitoring;
- Restricted employee access;
- Security testing;
- Vendor controls;
- Backup procedures;
- Incident-response measures; and
- Other security controls.
No Internet transmission, storage system, or security measure can guarantee absolute security.
Users are responsible for protecting their account credentials and devices.
10. DATA BREACH AND SECURITY INCIDENTS
CyberActive maintains processes for investigating suspected security incidents.
Where a security incident triggers legally required notification obligations, CyberActive will provide notices in accordance with applicable law.
11. CHILDREN AND MINORS
Certain CyberActive driver-education products are intended for teenagers and therefore may involve minors.
CyberActive collects information from minors only as reasonably necessary to provide the applicable educational service and comply with applicable requirements.
Where parental or guardian consent is required by law or program rules, CyberActive will obtain or require appropriate consent.
CyberActive does not knowingly use information from children for behavioral advertising in violation of applicable law.
A parent or legal guardian seeking information concerning a minor's account may contact CyberActive using the information below, subject to identity and authority verification and any restrictions imposed by educational or regulatory law.
12. FERPA AND EDUCATIONAL RECORDS
Certain CyberActive Services may involve educational institutions subject to the Family Educational Rights and Privacy Act ("FERPA") or similar education-privacy laws.
When CyberActive acts as a service provider to an educational institution, its handling of education records may also be governed by the institution's agreement, instructions, and applicable education laws.
13. CALIFORNIA PRIVACY RIGHTS
California residents may have rights regarding personal information under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), subject to applicable thresholds, exceptions, and limitations.
Depending upon applicability, these rights may include:
- The right to know the categories of personal information collected;
- The right to know the sources of personal information;
- The right to know the purposes for collecting or using personal information;
- The right to know categories of recipients;
- The right to access specific pieces of personal information;
- The right to request deletion;
- The right to request correction;
- The right to opt out of the sale or sharing of personal information where applicable;
- The right to limit certain uses of sensitive personal information where applicable; and
- The right not to receive discriminatory treatment for exercising privacy rights.
Not all information or processing is subject to every right. Statutory exceptions may apply, including where retention is required for legal, security, educational, regulatory, contractual, or other permitted purposes.
14. CATEGORIES OF PERSONAL INFORMATION
Depending upon your interaction with CyberActive, categories of personal information collected may include:
- Identifiers;
- Customer-record information;
- Protected classifications where voluntarily provided or legally required;
- Commercial information;
- Internet or electronic-network activity;
- Geolocation information at a general or device-derived level where applicable;
- Professional or employment-related information;
- Education information;
- Inferences generated from activity;
- Account credentials;
- Government identifiers where required;
- Communications content where necessary to provide the Service;
- Payment information; and
- Other information that may constitute sensitive personal information under applicable law.
CyberActive uses these categories for the purposes described in this Policy.
15. OTHER U.S. STATE PRIVACY RIGHTS
Residents of certain U.S. states may have additional privacy rights under comprehensive state privacy laws.
Depending upon the applicable jurisdiction, those rights may include:
- Access;
- Correction;
- Deletion;
- Data portability;
- Opt-out of targeted advertising;
- Opt-out of certain sales of personal information;
- Opt-out of certain profiling; and
- Appeal of a denied privacy request.
CyberActive will process valid requests as required by applicable law.
16. EXERCISING PRIVACY RIGHTS
To exercise an applicable privacy right, contact CyberActive at:
Email: info@cyberactive.com
Mail:
CyberActive, Inc.
8034 Garden Grove Blvd., Suite C
Garden Grove, CA 92844
Please describe your request and provide sufficient information for CyberActive to identify the relevant account or records.
CyberActive may need to verify your identity before completing a request.
An authorized agent may submit a request where permitted by law. CyberActive may require evidence of authorization and may separately verify the identity of the individual concerned.
CyberActive will respond within the period required by applicable law.
17. DELETION REQUESTS
Users may request deletion of applicable personal information by contacting CyberActive.
CyberActive may retain information where necessary to:
- Complete transactions;
- Provide requested Services;
- Maintain regulated education records;
- Meet government requirements;
- Detect or prevent security incidents;
- Prevent fraud;
- Exercise or defend legal claims;
- Comply with law;
- Maintain accounting or tax records;
- Enforce agreements; or
- Fulfill another legally permitted purpose.
Revoking a third-party integration does not necessarily require deletion of records CyberActive is legally required to retain.
18. MARKETING COMMUNICATIONS
Users may unsubscribe from marketing email through the unsubscribe mechanism contained in the message or another method provided by CyberActive.
Unsubscribing from marketing does not prevent CyberActive from sending:
- Account notices;
- Transactional messages;
- Course communications;
- Completion information;
- Regulatory notices;
- Security alerts;
- Payment notices; or
- Other nonmarketing communications.
19. COOKIES, TARGETED ADVERTISING, AND PRIVACY SIGNALS
Where CyberActive uses technologies that constitute targeted advertising, sale, or sharing under applicable law, CyberActive will provide legally required choices.
CyberActive will process legally recognized opt-out preference signals, such as Global Privacy Control, where required by applicable law and technically applicable.
Browser "Do Not Track" signals are not standardized. CyberActive responds to legally mandated preference signals as required.
20. ANALYTICS
CyberActive may use analytics providers to understand how users interact with websites and Services.
Analytics information may include device, browser, session, page-view, interaction, and performance information.
CyberActive uses analytics to maintain, evaluate, and improve its Services.
21. THIRD-PARTY WEBSITES AND SERVICES
CyberActive Services may contain links to or integrations with third-party services.
This Privacy Policy does not govern independent privacy practices of third parties.
Users should review the privacy policies of those services before providing personal information.
22. INTERNATIONAL USERS
CyberActive is based in the United States.
If you access the Services from outside the United States, information may be transferred to and processed in the United States or other countries where CyberActive or its service providers operate.
Where legally required, CyberActive will use appropriate mechanisms for international data transfers.
23. BUSINESS-TO-BUSINESS INFORMATION
CyberActive may process professional contact information concerning employees, representatives, contractors, and personnel of business partners, governmental agencies, vendors, schools, or other organizations for purposes such as:
- Administering relationships;
- Communicating regarding Services;
- Managing contracts;
- Providing support;
- Maintaining accounts; and
- Conducting legitimate business operations.
24. CHANGES TO THIS PRIVACY POLICY
CyberActive may update this Privacy Policy to reflect:
- Changes to Services;
- New technologies;
- New integrations;
- Changes to data practices;
- Changes to Google API permissions;
- Regulatory developments; or
- Legal requirements.
The "Last Updated" date identifies the most recent revision.
Where required by law or applicable platform policy, CyberActive will provide additional notice before materially changing how personal information is used.
If changes materially affect Google user data practices, CyberActive will update applicable disclosures before implementing the changed use.
25. CONTACT US
Questions regarding this Privacy Policy or CyberActive's privacy practices may be directed to:
CyberActive, Inc.
8034 Garden Grove Blvd., Suite C
Garden Grove, California 92844
Email: info@cyberactive.com
Users may also contact CyberActive through the customer-support mechanisms provided within the applicable Service.