Privacy Policy
Last Updated: May 12, 2026
1. Introduction
Welcome to CertReady ("we," "our," or "us"). This Privacy Policy describes how we collect, use, share, and protect information about users of our educational platform for multi-cloud certification exam preparation. By using our Service, you consent to the data practices described in this policy.
If you have questions or concerns about our privacy practices, please contact us using the information provided at the end of this policy.
2. Information We Collect
2.1 Information You Provide Directly
When you use our Service, we collect information that you provide directly to us:
| Data Type | Description | Purpose |
|---|---|---|
| Account Information | Email address, name (from Google OAuth or Magic Link) | Account creation and authentication |
| Payment Information | Payment card details (via LemonSqueezy) | Processing premium purchases |
| Quiz Interactions | Question reports, user feedback | Quality improvement and issue resolution |
2.2 Information Collected Automatically
When you access our Service, we automatically collect certain technical information:
- Usage Data: Pages visited, quiz interactions, time spent on platform, navigation patterns
- Device Information: Browser type, operating system, device type, screen resolution
- Log Data: IP address, access times, referring URLs, error logs
- Cookies and Local Storage: Session tokens, user preferences, authentication tokens
2.3 Information from Third-Party Services
We receive information from third-party services you use to access our platform:
- Google OAuth: Basic profile information (name, email) when you sign in with Google
- LemonSqueezy: Payment transaction data and payment method information for premium purchases
- Resend: Email delivery status for magic link authentication
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery
- Create and manage your user account
- Authenticate your identity and provide secure access
- Deliver quiz content and track your progress
- Save your quiz answers and performance data
- Provide access to premium content after purchase
3.2 Payment Processing
- Process premium exam purchases via LemonSqueezy
- Verify payment status and grant premium access
- Handle refund requests and billing inquiries
- Prevent fraudulent transactions and abuse
3.3 Communication
- Send transactional emails (purchase confirmations, magic link emails, account notifications)
- Respond to your support inquiries and feedback
- Send important updates about our Service
3.4 Service Improvement
- Analyze usage patterns to improve quiz content and user experience
- Identify and fix technical issues
- Develop new features and enhance existing functionality
- Monitor platform performance and security
- Process question reports and user feedback
3.5 Legal Compliance and Safety
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service
- Protect against fraud, abuse, and security threats
- Resolve disputes and investigate violations
4. How We Share Your Information
We do not sell your personal information. We share your information only in the following limited circumstances:
4.1 Service Providers
We share data with trusted third-party service providers who help us operate our platform:
- Amazon Web Services (AWS): Cloud hosting infrastructure (S3, CloudFront, DynamoDB, Lambda, Cognito, API Gateway)
- Google: OAuth authentication services
- LemonSqueezy: Payment processing (LemonSqueezy handles payment card data directly; we never store full card details)
- Resend: Transactional email delivery for magic link authentication
4.2 Legal Requirements
We may disclose your information if required by law or in response to valid legal processes, government requests, or to protect our rights, property, or safety.
4.3 Business Transfers
If CertReady is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or uses of your personal information.
5. Data Storage and Security
5.1 Data Storage
Your data is stored in AWS services located in the Asia Pacific (Singapore) region:
- AWS DynamoDB: User profiles, premium status, quiz progress
- AWS Cognito: Authentication tokens and session data
- AWS S3: Static content and encrypted quiz data
- AWS CloudFront: Content delivery with encrypted transmission
5.2 Security Measures
We implement industry-standard security measures to protect your information:
- Encryption: HTTPS/TLS encryption for all data in transit; encryption at rest for sensitive data
- Access Controls: Role-based access controls and principle of least privilege
- Authentication: Secure OAuth 2.0 authentication via Google and AWS Cognito
- Monitoring: Automated security monitoring and logging via AWS CloudWatch
- Quiz Content Protection: Client-side and server-side encryption of quiz questions
5.3 Data Retention
- Active Accounts: Data retained while your account is active
- Inactive Accounts: Data retained for 3 years after last login, then anonymized or deleted
- Payment Records: Retained for 7 years for tax and accounting purposes
- Log Data: Retained for 90 days for security and troubleshooting
6. Your Privacy Rights
6.1 Access and Portability (GDPR Article 15, 20)
You have the right to access your personal data and receive a copy in a structured, commonly used, machine-readable format. You can view and export your data through your account settings.
6.2 Correction (GDPR Article 16)
You have the right to correct inaccurate or incomplete personal information. You can update your profile information through your account settings.
6.3 Deletion (GDPR Article 17, CCPA)
You have the right to request deletion of your personal data. To delete your account and data:
- Log in to your account and go to Settings
- Select "Delete Account" in the Account tab
- Confirm deletion (this action is irreversible)
6.4 California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete personal information, and the right to opt-out of the sale of personal information (we do not sell personal information).
7. Cookies and Tracking Technologies
We use essential cookies and local storage for authentication and basic platform functionality. Third-party services (Google OAuth, LemonSqueezy) may also set cookies when you use our platform.
8. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe your child has provided us with personal information, please contact us immediately.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date at the top of this policy. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
CertReady Privacy Team
Contact Page: cert-ready.net/pages/contact.html
We respond to privacy inquiries as promptly as possible.