Skip to content
Culinary Teaching
Request a quote

LEGAL — PRIVACY

Privacy

What we collect when you send a quote request or take a class, why we hold it, how long we keep it, and how to get it back or get rid of it.

PLAIN ENGLISH — NOT LEGAL ADVICE

These pages describe what Culinary Teaching actually does, in the plainest words we could find for it. They were written for this business rather than adapted from a template, and every technical claim about this website was checked against the code that runs it. They are not legal advice, and no attorney has reviewed them yet. If something here turns out to be wrong, tell us and we will fix it rather than argue about it.

Questions about this page?
hello@culinaryteaching.com
+1 (417) 962-8474

ENTITY · CULINARY TEACHING LLCFORMED · WYOMING, USAEFFECTIVE · 21 AUGUST 2026VERSION · 1.3

Who we are

Culinary Teaching LLC is a Wyoming limited liability company. We teach recreational cooking classes at 931 Garst St, Cabool, MO 65689, US, which is the operational and customer-service address — a kitchen in Cabool, Missouri, not the state of formation — and we sell three self-paced online courses. When this page says “we”, that is who it means. When it says “you”, it means whoever is reading — someone who sent us a quote request, took one of the eight seats, bought a course, or just landed here from the footer.

We are small enough that there is no privacy department to route you to. Write to hello@culinaryteaching.com or call +1 (417) 962-8474 and you get the people who run the place, not a queue. The office is open Tuesday to Saturday, 10 to 5.

This page says what we collect, why, who else sees it and how long we keep it. Your data & choices is the page for actually making a request. Cookies & storage has the browser detail, and Trust & security covers how the information is held once we have it.

What we collect, and when

Four moments, and that is the whole list. There is no fifth one running quietly in the background — see the next section for why we can say that so flatly.

When you send a quote request

The form at the bottom of the classes page asks for six things:

  • Your name.
  • A phone number, an email address, or both — whichever way you want us to answer.
  • Which class you are asking about, or that you are not sure yet.
  • How many of you there are, from one to eight.
  • Roughly when suits you, in your own words.
  • Anything else you want to tell us, in a free-text box — which is where allergies usually get typed, because our own placeholder text asks for them.

We do not ask for an address, a date of birth, a card number or an account. There is no account to make. There is one box on that form you will never see: it stays empty for a person and gets filled in by an automated one, which is how we drop spam without putting a captcha between you and a question about a braise.

When you take a class

  • Which class you came to, on what date, and how many seats you took.
  • The allergy, dietary or access needs you asked us to work around, and what we actually did about them.
  • What you paid and how you paid it — card or cash, settled at the door. The amount and the date come to us. The card number does not: we do not write one down and we do not keep one.
  • Anything we wrote down to run the evening properly: that you are nervous with a knife, that it is a birthday, that you are coming back for the second half of a pass.

When you buy a course, a pass or a gift certificate

  • Your name, and the email address the course material goes to.
  • What you bought, when, and for how much — arranged by phone or in person, because this website has no checkout.
  • For a gift certificate, the name of the person you are giving it to, so we know whose it is when they call, and the number we wrote on it.
  • The record that you own what you bought. For an online track that record is what your access depends on, so we keep it for as long as we run the track.
  • If you send a photo of your work for the skills check at the end of a track, we look at it, keep it with your notes and write back. Nothing else. Terms sets out that we ask you separately before we would ever use anything of yours publicly.

There is no course platform, no login and no progress tracking. Access arrives by email; what you do with the material after that is not visible to us.

When you write to us or call

Emails sit in our inbox and voicemails sit on the phone, the same as anywhere. If you tell us something in an email that belongs in your class record — an allergy, a change of date — it gets copied there and treated the same as if you had typed it into the form.

What this website does, and does not do

This is the part most privacy policies are vague about, so we will be exact. There is no analytics, no tag manager, no advertising or social pixel, no A/B testing tool, no session recorder, no fingerprinting, no captcha, no social login, no embedded map and no embedded video. There is a consent banner from Termly, and there is an optional chat widget from tawk.to that stays blocked until you allow it.

Cookie Settings in the footer reopens the same choice. Scrolling is not a yes.

The typefaces are downloaded once when the site is built and then served from our own domain, so no font company learns that you visited. There is no cart, no checkout, no account and no payment form anywhere on this site, which means card details never get typed into it and never touch it. Your browser also stores a first-party setting called ct-motion, holding the word Full, Calm or Off, written only if you use the motion control in the footer. It is not an identifier, it is never sent to us, and clearing your browser data removes it.

Honest exceptions, because “nothing leaves your browser” would be a lie:

  • The pages have to come from somewhere. Cloudflare serves this site, and like every web host it keeps a routine record of requests — IP address, browser, which page, what time. We add nothing to it, we do not read reports off it, and we build no picture of you from it.
  • The quote request itself. When you press send, what you typed is stored in our database and emailed to us through Resend. That is the only thing your browser sends us beyond asking for the pages.
  • Termly. The consent manager loads from Termly so it can show the banner and remember your choice.
  • tawk.to, if you allow it. The optional chat widget loads from tawk.to only after you accept the relevant category. Decline it and it does not load.

One more thing worth naming: the Visit page has an “open in maps” link. It is a link, not an embed. Nothing loads from Google unless you click it, and if you do, you are on Google’s terms from that point, not ours. The full detail on all of this lives on Cookies & storage.

Why we use it

  • To answer your quote request with a price and the times we can run it.
  • To run the class safely — allergies, access needs, how many of you, who is under 18.
  • To take payment at the door and keep the financial records a business is required to keep.
  • To send you course material, a pass or a gift certificate you have paid for.
  • To reply when you contact us, and to sort it out when something goes wrong.

That is the list. We do not sell your information, we do not rent it, and no advertiser has ever received any of it — there is no mechanism on this site by which one could. Your phone number and email address are for answering you and running your class, and nothing else. We do not run a mailing list or a text list off the quote inbox. If we ever start a newsletter we will ask you separately, in plain words, and anything commercial we send will carry a working way to stop it and our street address at the bottom.

GDPR names the lawful bases in Article 6, and health notes also need Article 9. This is the mapping we actually use, not a menu of options:

LAWFUL BASES — ARTICLE 6 AND ARTICLE 9
WhatLawful basisWhy that one
Quote requests and booking the class or track you asked forArt. 6(1)(b) contractSteps at your request before a contract, then performing it
Class and course records (who came, what was taught, what was paid)Art. 6(1)(b) contractWe cannot run the class or keep your access without the record
Tax and accounting records of what the business took inArt. 6(1)(c) legal obligationUS tax retention. Not a choice we get to skip
Cloudflare request logs (IP, browser, page, time)Art. 6(1)(f) legitimate interestsKeeping the site up, stopping abuse. We do not profile you from it
Termly consent choice and the optional tawk.to chatArt. 6(1)(a) consentOff until you allow the category. Cookie Settings withdraws it
Photographs in classArt. 6(1)(a) consentAsked each time. No is a complete answer
Allergy and other health notesArt. 9(2)(a) explicit consentYou type it, or you tell us on the phone. Used only to keep you safe in the room

We do not make automated decisions about you. There is no scoring, no profiling and no algorithm deciding who gets a seat. A person reads your request and a person writes back.

Allergies and anything else about your health

Our own form invites this. The placeholder in the notes box reads “Allergies, a birthday, first time holding a knife”, so we are asking you to type health information, and we should not then be coy about it. We ask because we have to: the kitchen works on shared surfaces and shared air, and we would rather move you to a class that suits you than serve you a compromise. What that means for your food is on Safety & allergens. What it means for your information is here.

An allergy you tell us about is treated as health information. It goes to the people who will be cooking with you and to nobody else, it is used only to keep you safe in the room, and it is deleted on the schedule below.

Concretely: it is never used to decide what to offer you, never attached to marketing of any kind, never sold, and never passed to anyone outside the business except the service that carries the form itself and our email provider — both covered in the next section. It is not shared with the other seven people in the room, though we will sometimes have to tell them a dish contains something, without saying whose allergy it is.

If your allergy is severe, put it in the box and then call +1 (417) 962-8474 as well, before you commit to anything. A line of free text is not a conversation, and Safety & allergens explains why. If you would rather keep the detail off a web form altogether, the phone is enough on its own. And if you are booking for someone else, only tell us what we need to keep that person safe — you are handing over their information, not yours.

Free text is a blunt container. If you would rather we deleted an allergy note early, say so and we will, once the class it relates to is done.

Photographs in class

We sometimes take photographs in class for this website and for our own social posts. A photograph of you is information about you, which is why it sits on this page as well as on Safety & allergens. The rules are the same in both places:

  • We ask first, every time, before a camera comes out near you. Not afterwards, and not by way of a sign on the wall.
  • No is a complete answer. You do not have to give a reason, nobody will ask you for one, and it will not be raised again later in the evening.
  • We do not publish a name alongside a face unless you have told us we can, and we do not caption a photograph with anything else about you.
  • For anyone under 18, the accompanying adult decides in writing and the default is no. If we have not been told yes, the answer is no.
  • Change your mind later and email us. It comes off this website and off our own posts, inside five business days. The one thing we cannot do is pull it back out of somebody else’s repost — that is not us being difficult, it is simply out of reach once it has left our hands.

Photographs you take of your own food are yours and we do not police them. If you send us one and we would like to use it, we ask you first — the same rule Terms sets out for work you send in for a skills check.

Who else sees it

Inside the business: whoever reads and answers your request, and the instructor teaching your class. Nobody sees an allergy note who is not going to be cooking with you.

Outside the business, these are the companies that actually see something, named rather than gestured at:

  • The card terminal at the door and the bank behind it. They see the amount, the date and the card. We see that it went through, how much, and when. Nobody types a card number into this website, because there is nowhere to type one.
  • Migadu, which hosts inbound mail for culinaryteaching.com, so anything you email us — including an allergy — sits in that inbox. Inbox mail we have asked Migadu to forward is also retained there.
  • Cloudflare, which hosts these pages and keeps the routine request log described above.
  • Resend, which carries a quote request from this site to contact@culinaryteaching.com. It delivers the message. It is not a marketing list.
  • Termly, which runs the consent banner and stores the choice you made about optional tools on this site.
  • tawk.to, if you allow the chat widget. Messages you type into that widget go to tawk.to as the company that runs it.
  • Whoever helps with the books, at tax time. They see what the business took in, not who ate what — no allergy notes, and no record of what you cooked.
  • A lawyer or an insurer, if we ever need one for a specific matter, and only what that matter needs.
  • A public authority, where the law actually requires it. We will tell you if that happens, unless we are legally forbidden from telling you.

That is a closed list, not an illustrative one. No advertiser, no data broker, no analytics company, no marketing platform, no lead-generation service. If we ever add a category to that list we will add it here first.

If that information leaves the EEA or the UK

We are a Wyoming LLC with a kitchen in Missouri. Anything we hold about you is held in the United States unless the supplier itself is in Europe. These are the transfer tools those suppliers publish today (checked 21 August 2026). We are not inventing clause numbers of our own.

INTERNATIONAL TRANSFERS
SupplierWhere they sitSafeguard they publish
Cloudflare (this website)United States, with EU points of presenceEU–US Data Privacy Framework certification, plus the EU Standard Contractual Clauses in Cloudflare’s customer DPA
Termly (consent banner)United States; EU consent storage availableEU–US Data Privacy Framework and UK/Swiss extensions, with SCCs where DPF does not cover the transfer
tawk.to (optional chat)United StatesEU–US Data Privacy Framework (active listing) and Module Two SCCs in tawk.to’s DPA
Resend (quote-notification email)United StatesEU–US Data Privacy Framework and the SCCs in Resend’s DPA
Migadu (inbound mail)LuxembourgInside the EEA. No US transfer for the mailbox itself

You can ask us for the current DPA or DPF listing URL for any of those names. We keep an internal record of processing activities under GDPR Article 30 — purposes, categories, recipients, transfers, retention and security — and we will give a relevant extract to a supervisory authority that asks.

How long we keep it

Real periods, not gestures. A retention promise we do not honour would be worse than none, so these are the ones we can actually stick to.

RETENTION — WHAT WE HOLD AND FOR HOW LONG
WhatHow longThen what
A quote request that never became a class12 months from the last message between usDeleted, notes box and all
Class records — who came, what we cooked, what we accommodated24 months after your last classDeleted
Allergy and dietary notesThey live inside the record above and die with it: 12 months if you never booked, 24 months after your last class if you didDeleted, and deleted earlier if you ask
Payment and financial records7 yearsKept because tax law requires it, then deleted
Emails and phone messages24 monthsDeleted, unless the thread is part of a financial record
Gift certificates and six-class passesUntil the certificate or pass has been spent or has run out, plus one yearDeleted
Online course purchasesThe financial part for 7 years; the record that you own the track for as long as we run itYour access depends on that record, so it outlives the receipt
A photograph you agreed toFor as long as we are using itTaken down when you ask, and off the site inside five business days
The hosting provider’s request logKept by them, on their schedule, not oursWe never receive it and never ask for it
The one setting in your browserUntil you clear itIt is on your device, not ours

Where a class ends in a complaint, an injury or anything that might turn into a dispute, we keep that specific record until the matter is closed, and then it goes back on the ordinary schedule above. We will not use that as an excuse to keep everything forever. Your data & choices sets out the short list of things a deletion request cannot reach, and why.

Keeping it safe

Most of what we hold is an inbox, a phone and a folder in the office. It is protected the way a small business protects things: passwords on the accounts, the office locked, paper kept out of the teaching room, and as little written down as the class allows. This website itself holds nothing — there is no customer account to break into. Quote requests are stored so we can answer them, and they are not left sitting in a public folder.

We are not going to claim more than that. No certification, no audit, no badge. What we will say is that we cannot guarantee nobody ever gets at information we hold; nobody honest can. The full description of what we do, in more detail and with the same lack of badges, is on Trust & security, including how to tell us if you find a problem.

Children

Classes are open from age 14, and anyone under 18 has to be accompanied by an adult who is cooking alongside them. That rule is a safety rule first — there are knives, coals and a pressure canner in the room — but it also decides how a minor’s information reaches us.

  • We take a young person’s details from the adult enrolling them, not from the young person, and only what the class needs: a first name, an age if it matters, and any allergy.
  • This website is not aimed at children under 13. There is no account to create, no profile to fill in and nothing to sign up for, so there is very little here for a young child to hand over in the first place.
  • If you believe a child under 13 has sent us something through the quote form anyway, tell us and we will delete it. No process, no proof required — we will just do it.
  • Photographs of under-18s follow the rule in the photographs section above.

A parent or guardian can ask us for anything on this page on behalf of the young person they enrolled, the same as for themselves. The accompanying adult is not automatically that person — it might be an aunt or a family friend — so where it is not obvious we will ask. Your data & choices sets out how that works.

What you can ask us for

These apply to everyone who deals with us, wherever you live. We are not waiting to be legally required to do them.

  • Ask what we hold about you, and we will tell you.
  • Ask for a copy of it, in a form you can actually read — or as a UTF-8 JSON or CSV file emailed inside 30 days so you can take it elsewhere.
  • Correct anything that is wrong.
  • Have it deleted, apart from the short list of things a business has to keep.
  • Tell us to stop contacting you, and we stop.
  • Object to something we are doing with it, and get a straight answer rather than a form letter.

We tell you we have your request inside 3 business days and we answer it in full inside 30 days of the day you asked. Thirty days is a ceiling and there is no extension: an awkward request still gets its answer inside the window, and the answer says which part is still being worked through. It costs nothing, and nothing for a repeat request either, and asking changes nothing about how you are treated here.

Because there is no login on this site, we confirm who you are the old-fashioned way: we match what you tell us against what is already in the record, usually over the phone in under a minute. That is to stop somebody else asking for your details, not to make it hard for you, and we will not ask you to email us a photograph of your driver’s licence.

Your data & choices is the page that walks through how to make each of those requests, what we need from you, and what to do if we say no.

Which privacy laws actually reach us

A lot of policies end with a shrug about consulting a lawyer. Here is our reading instead, so you know what you are relying on.

  • Missouri has no comprehensive consumer privacy statute, so there is no state-wide law here setting out access and deletion rights.
  • The California, Virginia, Colorado, Connecticut, Oregon, Montana and Utah privacy laws all have size thresholds — millions in revenue, or tens of thousands of consumers, or a business model built on selling data. A cooking school teaching eight people at a time does not come close to any of them. Texas sets no headcount threshold but leaves out small businesses, and the one duty it keeps for them is a bar on selling sensitive data without consent, which we do not do.
  • GDPR and the UK GDPR apply when a person in the EEA or the UK uses this site or buys an online track. We are not established in the EU and we have not appointed a DPO; the contact is still the kitchen. The Europe section below is the operational reading, not a claim that the law never reaches a public website.
  • HIPAA is about doctors, hospitals and insurers. A cooking school is none of those, so an allergy you tell us is not protected health information in the HIPAA sense — which is exactly why we set out our own rule for it above.
  • COPPA covers services directed at under-13s. This one is not, and there is nothing here for a child to sign up to.

What does reach us, at any size, is Missouri’s data-breach notification law (section 407.1500 of the Revised Statutes of Missouri), and the general rule under the FTC Act and Missouri’s Merchandising Practices Act that what a business says about itself has to be true. Every commitment on this page is made under that second one. It is why we would rather write “we cannot guarantee” than a promise we would have to break. If any of this reading turns out to be wrong, it changes what we owe you under the law — it does not change a word of what we have promised you above.

If you live in California

We do not sell your personal information and we do not share it, using those words the way California law uses them — sharing meaning handing it over for cross-context behavioural advertising. We have never done either. There is no advertising network attached to this site, no pixel, no identifier to hand anyone, and nothing about you has ever been exchanged for money or for anything else of value.

The footer still carries a link that uses California’s exact words — Do Not Sell or Share My Personal Information — because that is the control people look for. It does not turn a sale on. It takes you to the page that says there is no sale, and to Cookie Settings if you want to refuse the optional chat.

We do not use or disclose sensitive personal information — which is what an allergy is — for anything beyond running your class safely. We offer no financial incentive in exchange for your information, we run no loyalty scheme, and we do not knowingly sell the personal information of anyone under 16, because we do not sell anyone’s at all.

The California statute does not, on our reading, apply to a business this size. You can still ask us for any of the things in the section above — what we hold, a copy, a correction, deletion — on the same timings and at no charge, and you may use an authorised agent to do it. Start at Your data & choices.

If you are in Europe or the UK

This website is public. The online tracks work from anywhere. If you are in the EEA or the UK and you use this site or buy a track, GDPR and the UK GDPR apply to that processing. We do not have an EU establishment and we are not required to appoint a Data Protection Officer at this scale, so the contact for every request is still hello@culinaryteaching.com or +1 (417) 962-8474 — the people who run the kitchen, not a DPO.

You can ask for access, a copy, correction, erasure, restriction, objection, and a portable file. Consent for optional tools and for health notes is withdrawn as easily as it was given: Cookie Settings in the footer for Termly and tawk.to; an email or a phone call for an allergy note.

You may also complain to a supervisory authority. If you are in the EEA that is your local data protection authority; if you are in the UK it is the ICO. We would rather fix the thing first.

Transfers to the United States use the safeguards in the table above. Migadu mail stays in Luxembourg. We keep an Article 30 record of processing; it is an internal file, not a public brochure, and a supervisory authority can have the relevant parts on request.

If something goes wrong

If someone gets at information we hold about you, we will tell you. Not once we are certain how bad it is — when we know enough to be worried. By email if we have one for you, by phone if we do not.

  • GDPR Article 33: we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people.
  • GDPR Article 34: if the breach is likely to result in a high risk to you, we tell you without undue delay, in plain words, with what happened, what of yours was in it, what we have done, and what you should do.
  • Missouri Revised Statutes section 407.1500: we also notify affected Missouri residents, and we use that same 30-day ceiling as a floor for everyone else in the United States even when a shorter European clock has already run.

If the incident sits with one of the companies in the “who else sees it” list rather than with us, we will pass on what they tell us rather than hide behind them. Trust & security sets out the same commitment alongside what we do to make it unlikely in the first place.

We cannot guarantee this never happens. What we can commit to is that you hear it from us, quickly, and in the same plain words as the rest of this page.

Changes to this page, and how to reach us

The effective date and the version number are at the top of this document. If we change what we actually do — a new supplier, a different retention period, a service we have finally chosen — we update this page, bump the version and change the date. If the change matters to you we will say what moved rather than make you compare two versions, and we will mention it the next time we write to you. The version in force on the day you dealt with us is the one that applies to that dealing.

If this page ever describes something we do not actually do, that is a mistake and we want to hear about it. We will fix it rather than argue about it.

Culinary Teaching LLC · 931 Garst St, Cabool, MO 65689 · +1 (417) 962-8474 · hello@culinaryteaching.com

To make a request rather than ask a question, start at Your data & choices. For the rest of the set, including Terms, Cancellations & refunds and Accessibility, see the legal index.