SecuSparkSecuSpark
Practice TestsFlashcardsFeaturesPricingBlogChangelogAbout
Start Free

© 2026 SecuSpark. CompTIA, Security+, A+, Network+, CySA+, PenTest+, and SecAI+ are registered trademarks of CompTIA, Inc. SecuSpark is not affiliated with, endorsed by, or sponsored by CompTIA, Inc.

PrivacyTermsCookies
SecuSparkSecuSpark
Practice TestsFlashcardsFeaturesPricingBlogChangelogAbout
Start Free
  1. Home
  2. Privacy Policy

Privacy Policy

Last updated: July 2, 2026

Overview

SecuSpark ("we", "us", "our") is an RPG-gamified CompTIA certification exam-preparation platform at secuspark.com. This policy explains what personal data we collect, why, who we share it with, how long we keep it, where it is processed, and the rights you have — including under the UK GDPR and Data Protection Act 2018, the EU GDPR, and the Australian Privacy Act 1988 and Australian Privacy Principles (APPs).

Data controller. The controller of your personal data is [SecuSpark legal entity name], [registered address]. You can reach us about privacy at privacy@secuspark.com.

1. Personal data we collect

  • Account & identity — email address, a display name you choose, and (if you sign in with Google) your Google display name, profile-picture URL, and Google account identifier. If you register with email/password, your password is stored only as a salted hash by our authentication provider.
  • Date of birth— not collected at registration. We store one only if you choose to tell us your age (see §8), and we use it solely to determine whether extra child-protection safeguards apply to your account.
  • Study & game data — your progress, exam results, XP, achievements, and battle history. Most of this is stored locally on your devicein your browser's IndexedDB. Some data is synced to our servers to power leaderboards, guilds, PvP, and cross-device access.
  • Analytics & device data— if you consent to analytics cookies, we collect page views, feature usage, and technical data (device/browser type, approximate location from IP, and an analytics identifier). Analytics do not run until you opt in (see §4).
  • Billing data— if you purchase a subscription or energy pack, we store transaction records and identifiers from our payment processor (customer and subscription IDs, plan, and status). We never receive or store your card number (see §3).
  • Career / résumé data (optional Jobs feature)— if you use the Jobs feature, documents you upload (e.g. a résumé) and information extracted from them (such as your name, contact details, and work history) are processed to provide that feature. This is personal data and is processed by our AI provider (see §3).
  • Communications — emails we send you and records of your email preferences and unsubscribe requests.

2. Why we use your data and our lawful bases

Under the UK/EU GDPR we must have a lawful basis for each use. The table below maps our processing to its basis; under the Australian Privacy Act the same activities are our primary purposes of collection (APP 3 and APP 6).

PurposeData usedLawful basis (GDPR Art. 6)
Create and secure your account; authenticate youAccount & identityContract
Deliver the service (quizzes, progress, leaderboards, PvP, guilds)Study & game dataContract
Process payments and manage subscriptionsBilling dataContract
AI explanations and Jobs featuresQuestion content; résumé data you provideContract
Product analytics to understand and improve the appAnalytics & device dataConsent
Marketing / promotional emailsEmail addressConsent
Age assurance and child protectionDate of birth (only if you provide one)Legal obligation / legitimate interests
Security, fraud prevention, and enforcing our termsAccount, device, and usage dataLegitimate interests

Where we rely on consent, you can withdraw it at any time (see §6) without affecting processing already carried out. Where we rely on legitimate interests, you can object (see §6).

3. Who we share data with (sub-processors)

We do not sell your personal data.We share it only with the service providers below, who process it on our behalf under data-processing agreements. Some are located in the United States, which means some personal data is transferred outside the UK/EEA/Australia (see §5).

ProviderWhat they processRegion
SupabaseDatabase & authentication (account, profile, synced game data)[confirm project region]
VercelApplication hosting; request metadata incl. IPGlobal / US
PostHogProduct analytics (only after you consent)United States
Google Analytics / Google Tag ManagerProduct analytics (only after you consent)United States
LemonSqueezy (Merchant of Record)Payments, tax, subscription management; your emailUnited States
OpenAIAI explanations; résumé text for the Jobs featureUnited States
ResendTransactional and (opt-in) marketing email deliveryUnited States
Trigger.devBackground jobs (e.g. résumé processing)[confirm region]

4. Cookies and analytics

We use strictly-necessary cookies to keep you signed in, secure, and to remember your cookie choice — these do not require consent. Non-essential cookies and similar technologies (analytics) are off by default and only set after you opt invia our cookie banner, in line with UK PECR and EU ePrivacy rules. You can change your choice at any time using the "Cookie preferences" link in the footer, and we honour Global Privacy Control (GPC) browser signals. Full details are in our Cookie Policy.

5. International data transfers

Some of our providers (§3) are in the United States, so your personal data may be transferred there. For transfers of UK/EEA personal data we rely on appropriate safeguards — the UK International Data Transfer Agreement/Addendum and the EU Standard Contractual Clauses, and/or the EU–US and UK–US Data Privacy Framework where a provider is certified — together with a transfer risk assessment. Analytics data is only transferred after you consent. For Australia, we take reasonable steps under APP 8 to ensure overseas recipients handle your data consistently with the APPs. You can request details of the safeguards by emailing privacy@secuspark.com.

6. Your rights

Depending on where you live, you have some or all of the following rights. To exercise them, use the in-app tools in Settings (Download my data, Delete my account, email preferences) or email privacy@secuspark.com. We respond within one month (UK/EU) or a reasonable period (AU).

  • Access— get a copy of your data. Use "Download my data" in Settings for a machine-readable export.
  • Rectification / correction — fix inaccurate data (edit your profile, or contact us).
  • Erasure— delete your account and associated data using "Delete my account" in Settings.
  • Portability — receive data you provided in a structured, machine-readable format (the export tool).
  • Restriction and objection — limit or object to certain processing, including objecting to processing based on legitimate interests.
  • Withdraw consent— turn off analytics cookies or marketing emails at any time (footer "Cookie preferences" and Settings).
  • Revoke Google access — via your Google Account permissions.

7. Data retention

We keep your account and associated data for as long as your account is active. If you delete your account, we erase your personal data from our live systems promptly and within 30 days, and request deletion from our sub-processors under their agreements. We may retain a minimal record where required for legal, tax, or fraud-prevention purposes, and email-suppression records so we do not contact you after you unsubscribe. On-device (IndexedDB) data stays until you clear your browser or use the in-app delete. Backup copies are overwritten on our providers' normal backup cycles.

8. Children and age assurance

SecuSpark is designed to be safe for users of all ages. We do not ask for your date of birth when you register. Because analytics and marketing are off by default for everyone, and because we automatically and permanently disable all analytics and marketing for any account whose holder tells us they are under 16, we do not profile or market to children. We follow the UK Age Appropriate Design Code (Children's Code) principle of high privacy by default. If you believe a child has provided us personal data in a way that needs attention, contact privacy@secuspark.com and we will act promptly.

9. Security

  • All data in transit is encrypted using TLS/HTTPS.
  • Database access is protected by Row Level Security so users can only access their own data.
  • Authentication is handled by our provider using industry-standard practices; passwords are never stored in plain text.
  • Access to production systems is restricted to authorised personnel.

10. Complaints and how to reach the regulators

We hope to resolve any concern if you contact us first at privacy@secuspark.com. You also have the right to complain to a data-protection authority:

  • United Kingdom— the Information Commissioner's Office (ICO), ico.org.uk.
  • EU / EEA — your local supervisory authority (a list is published by the European Data Protection Board at edpb.europa.eu).
  • Australia — the Office of the Australian Information Commissioner (OAIC), oaic.gov.au.

UK/EU representatives. If we are not established in the UK or EU, our Article 27 representatives are: UK — [UK representative]; EU — [EU representative]. [Complete before serving UK/EU users, per privacy counsel.]

11. Google API Services User Data Policy

SecuSpark's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data (email, name, profile picture) only to provide and improve user-facing features; we do not use it for advertising, sell it, or use it for unrelated purposes. Human access is limited to security, legal compliance, or direct user support.

12. Changes to this policy

We may update this policy from time to time. Material changes will be posted here with a new revision date, and where required we will notify you or ask for fresh consent.

13. Contact us

Questions or requests about your privacy: privacy@secuspark.com.