PLAIN ENGLISH — NOT LEGAL ADVICE
These pages describe what Culinary Teaching actually does, in the plainest words we could find for it. They were written for this business rather than adapted from a template, and every technical claim about this website was checked against the code that runs it. They are not legal advice, and no attorney has reviewed them yet. If something here turns out to be wrong, tell us and we will fix it rather than argue about it.
Questions about this page?
hello@culinaryteaching.com
+1 (417) 962-8474
What there is to protect
Short list. That is the whole reason this page can be honest rather than impressive. We hold:
- Your name, and a phone number or an email address — whichever one you gave us.
- Which class you asked about, how many people are coming, and roughly when suits you.
- Whatever you typed into the last box on the quote form. Usually that is empty. Sometimes it is an allergy, and when it is we treat it as health information.
- A record that you took a class and paid for it, because a business has to keep those.
That is it. No password, because there is nothing on this site to log into. No card number — see the next section. No location, no browsing history, no profile assembled out of any of it. What an allergy note means once you are standing at a bench is on Safety & allergens.
What we keep, why we keep it and how long it stays is set out on Privacy, and Your data & choices is the page for getting a copy of it, correcting it or having it deleted.
Your card never touches this website
There is no checkout here today. No cart, no payment page, no card field on any page of culinaryteaching.com. You could not type a card number into this website if you wanted to, because there is nowhere to type it and nothing to receive it.
When online payment is switched on, it will be full-page Stripe-hosted Checkout — a page Stripe operates, after we have quoted you and you have approved the amount. Card details will be typed only on Stripe’s page. They will not pass through this site, our database, our email, or our chat. We are not claiming that flow is live. The footer on every page says the same thing in future tense.
Stripe is a PCI DSS Level 1 service provider. That is Stripe’s status, not ours. This business does not claim PCI DSS certification, an Attestation of Compliance, or a completed SAQ. The correct SAQ/AOC path will be confirmed against the architecture we actually ship, and completed before we take a live card on that hosted page. Until then, classes are still settled at the door, by card or cash. When you pay by card in the room, the reader talks to your bank and we see whether it went through. We do not write your card number down and we do not keep it.
A six-class pass or an online track is arranged with us directly rather than bought on this site, and the same rule holds: nothing about a card is written down, and nothing about a card is kept. What you are buying, and what happens if you change your mind, is on Cancellations & refunds.
While that is true — and this page is rewritten before it stops being true — a page that looks like ours and asks you for card details is not ours. Close it and call us on +1 (417) 962-8474. We would rather field a wasted call than have you find out the hard way.
Do not send us a card number in writing
Not by email, not by text message, not read out onto our voicemail. We will not ask you to, and nobody from here will phone and ask you for one. If you are being asked, it is not us.
If a card number arrives anyway — people do it with the best intentions, usually to hold a seat — we do not use it. We delete the message, and we call you back to take the payment properly. You will not be charged from something you emailed us.
This is not us being awkward. Email, text and voicemail sit on servers neither of us controls, get forwarded, get backed up and get transcribed. A card number in any of those is a card number in a place that cannot be cleaned up afterwards.
Why there is so little of this website to attack
What follows is a consequence of the site being simple, not a claim that anyone here is clever. A site with fewer moving parts has fewer parts that can go wrong, and this one has very few.
- It is served over HTTPS. What passes between your browser and the site is encrypted on the way.
- There are no accounts and no login. There is no password of yours to steal and no session to hijack, because neither exists.
- Quote requests are stored in a private database so we can answer them. There is no customer account, no login and no password of yours on this site.
- It does not run analytics, a tag manager, advertising or social pixels, an A/B tool, a captcha, an embedded map or embedded video. It does load Termly for consent, and it may load tawk.to chat after you allow that category.
- The typefaces are downloaded once when the site is built and served from our own address. Nothing is fetched from a font service while you read, and no font company learns that you visited.
- The site does not announce which software or version it runs on, so it does not hand out a shopping list of things to try.
One thing is kept in your browser, and it is the setting you chose yourself: whether the moving parts of this site run Full, Calm or Off. It is three words in your own browser storage, it identifies nobody, and clearing your browser clears it. Termly also stores the consent choice you made, and the chat widget stores its own cookies only after you allow it. Cookies & storage tells that story at length.
One thing genuinely does leave your browser besides the quote form, and we would rather say it than let you discover it: the company that hosts the pages sees every request, as every web host does, and keeps its own routine record of it — an IP address, a browser, a page, a time. We do not add to that record, we do not receive reports from it and we have built nothing on top of it.
A site can also send your browser a set of standing instructions with every page it serves, and this one does. It refuses to be shown inside a frame on somebody else’s page. It tells your browser not to guess at file types. It hands out no camera, no microphone, no location. It asks for the encrypted connection every time from here on. And it keeps most of where you came from to itself when you follow a link away.
One of those instructions is not all the way on, and we would rather say so than let you assume. The rule that tells your browser to load code, styles, images and fonts from this site and nowhere else is sent in report-only mode: the browser reports a breach instead of blocking it. That is a real statement and it will surface anything unexpected, but it is watching rather than enforcing, and we are not going to describe it as more than that. Being refused a frame does not depend on it — that is a separate instruction, and that one is enforcing.
Where a quote request goes
When you press send on the quote form, your browser makes one request, to this site, and nowhere else. Before the server does anything with it, it checks it: every field is cut to a fixed maximum length, the number of people is forced into the range one to eight, a submission missing what it needs is refused rather than half-processed, and a message that looks like a card number is refused with HTTP 422 before anything is stored or emailed. We do not keep the digits. Use Stripe’s hosted page when that exists; never type a card number into a quote box. Anything much bigger than a filled-in form is turned away without being read, and a submission that arrives from some other website’s address is turned away too.
Spam is handled with a hidden field that a person never sees and an automated one fills in. Those get dropped quietly. It means there is no captcha on the form, which in turn means no outside company gets a look at you on your way to asking us about a braise.
From there it comes to us, so we can reply with a price and some times. Nobody is sent it who does not need it to answer you. Privacy is where every service that handles a quote request is named, and if we ever add one — a shared inbox, a scheduling tool, anything that would receive what you typed — it is named there before it starts receiving anything, not afterwards.
There is no limit on how often that form can be submitted, so somebody determined could flood it. What that costs is a wasted morning at our end. It does not reach you, because there is nothing behind the form to reach.
The office: paper, passwords and who has a key
The rest of this happens in a room in Cabool, and describing it as anything grander would be a lie you could check in five minutes. It is a small business that keeps some paper notes and some password-protected accounts. These are the rules we hold ourselves to, and you are welcome to hold us to them:
- Everyone who works here has their own login. Nobody shares an account, and there is no house password on a card by the till.
- Passwords are long, and a different one for every service. They live in a password manager, not on a note stuck to a monitor.
- Two-step verification goes on wherever a service offers it.
- Paper — tonight’s allergy list, the sign-in sheet — goes back in a drawer at the end of the class rather than staying out on the bench, and anything we no longer need is destroyed rather than dropped whole into an open bin.
- When somebody stops working here, their access is switched off on their last day and their key comes back.
- Class lists do not go home with anyone. What is needed to run a class stays in the building.
- Only the people who are actually cooking with you see what you told us about an allergy.
There is no IT department here and no security team. It is people who cook, doing the ordinary careful thing. If you would like to know how any of that works in practice before you book, ask — we will answer honestly, including where the answer is that we have not thought about it.
Who else holds something about you
A handful of ordinary suppliers, and not one advertiser. The company that hosts this site keeps its request logs. Your bank and the card network handle the payment at the door. Our email provider carries the message you sent us. Whoever helps with the books sees what the business took in, not who ate what.
Privacy is the document that owns this subject properly — who, what for, how long, and what happens when that changes. If anything on this page and anything on that page ever disagree, believe the privacy page and tell us, because one of them is out of date.
The part at your end
Half of this is out of our hands, so a few things that are worth thirty seconds of yours:
- Check the address bar says culinaryteaching.com before you type anything into a form on a page you reached from a link.
- Never send a card number by email or text — not to us, not to anyone.
- If a message claiming to be from us asks you to pay by bank transfer, gift card or a link in the message, stop and phone the number at the bottom of this page. We do not do any of that.
- Tell us when your email address or phone number changes, so a reply about your class does not land in a stranger’s inbox.
- If a class confirmation arrives that you did not ask for, tell us. It is more likely a typo in a phone number than anything sinister, but we would rather chase it.
If something goes wrong
We cannot guarantee that information is never compromised. No business can, and one this size saying otherwise would be the least believable sentence on the site. So instead of a promise, here is what actually happens:
- We find out what happened and stop it. That comes before working out how to describe it.
- We work out whose information was involved and what was in it.
- We tell the people affected, in plain words: what happened, what of yours was in it, what we have done, and anything you may want to do at your end. Where GDPR applies and the risk to you is high, that notice is without undue delay (Article 34). For everyone else we still use a 30-day ceiling unless law enforcement asks us to hold off.
- We tell the authorities where the law requires it: a GDPR supervisory authority within 72 hours of becoming aware (Article 33), and Missouri residents under RSMo 407.1500.
- We write down what we changed, so the same thing does not happen a second time.
We will not wait for a complete picture before telling you something is wrong. A short, honest message early is worth more to you than a polished one a month later. The same commitment, said at more length, is on Privacy.
Found a problem? Tell us
If you have found a weakness in this website, a page doing something it plainly should not, or any way to reach information you should not be able to reach, we want to hear it from you rather than from someone else later.
Email hello@culinaryteaching.com and put SECURITY at the front of the subject line so it does not sit behind a week of class enquiries. Or phone +1 (417) 962-8474 during office hours. Tell us what you found and how to see it happening — a page address and a screenshot is usually plenty.
Every report gets read by a person. We aim to reply within three business days, and to come back to you again once it is fixed to say what we did. If the answer turns out to be that we cannot fix it, we will tell you that too.
Report something in good faith and you will get a thank-you, not a lawyer. We will not take legal action against you and we will not report you for telling us about a problem you found — provided you did not break anything, did not take or keep information that is not yours, and did not hold it over us. We do not pay for reports. There is no bug bounty here, and we would rather say so plainly than let you assume there is one.
What we do not have
Pages like this usually fill the space with badges. Here is the inventory instead, so that nobody has to guess what the absence of a logo means:
- No SOC 2 report, no ISO 27001 certificate, no PCI DSS certification or SAQ/AOC for this merchant, no certification of any kind, and no security questionnaire we have ever been through.
- No penetration test. Nobody has been paid to attack this site, and nobody has volunteered.
- No bug bounty and no payment for reports.
- No security team, no security officer, no dedicated IT staff.
- No status page and no uptime guarantee. If the site is down, the phone still works and the class still runs.
- No round-the-clock monitoring, no intrusion detection, nobody watching a screen overnight.
- No claim about how records are encrypted where they sit. Whatever the everyday services we use do by default, we have not checked it, so we will not take credit for it.
- No cyber-insurance claim, certificate or coverage figure quoted here. If you need to know what cover this business carries, ask us and we will tell you what is true at the time.
None of that should make you nervous about a cooking class. It should make you sceptical of anyone this size who says otherwise.
Keeping this page true
This page describes how the website is actually built, which means it goes stale the moment the website changes. So the rule we hold ourselves to is this: if a script, an embed, a booking widget, a payment page or an outside service is ever added to culinaryteaching.com, this page and Cookies & storage are rewritten before it goes live, not after somebody notices. The same goes the other way: when the one instruction in section 04 that is only watching is switched to blocking, this page says so and not before. The effective date and version at the top tell you which reading you are looking at.
If you check something here and find it is wrong, tell us at hello@culinaryteaching.com. We will correct the page rather than argue about it. That goes for a broken claim about this website just as much as a broken promise about a card — Culinary Teaching LLC would rather have a page that is right than a page that is flattering.