Privacy Policy
Last updated: July 2, 2026
Overview
SecuSpark ("we", "us", "our") is an RPG-gamified CompTIA certification exam-preparation platform at secuspark.com. This policy explains what personal data we collect, why, who we share it with, how long we keep it, where it is processed, and the rights you have — including under the UK GDPR and Data Protection Act 2018, the EU GDPR, and the Australian Privacy Act 1988 and Australian Privacy Principles (APPs).
Data controller. The controller of your personal data is [SecuSpark legal entity name], [registered address]. You can reach us about privacy at privacy@secuspark.com.
1. Personal data we collect
- Account & identity — email address, a display name you choose, and (if you sign in with Google) your Google display name, profile-picture URL, and Google account identifier. If you register with email/password, your password is stored only as a salted hash by our authentication provider.
- Date of birth— not collected at registration. We store one only if you choose to tell us your age (see §8), and we use it solely to determine whether extra child-protection safeguards apply to your account.
- Study & game data — your progress, exam results, XP, achievements, and battle history. Most of this is stored locally on your devicein your browser's IndexedDB. Some data is synced to our servers to power leaderboards, guilds, PvP, and cross-device access.
- Analytics & device data— if you consent to analytics cookies, we collect page views, feature usage, and technical data (device/browser type, approximate location from IP, and an analytics identifier). Analytics do not run until you opt in (see §4).
- Billing data— if you purchase a subscription or energy pack, we store transaction records and identifiers from our payment processor (customer and subscription IDs, plan, and status). We never receive or store your card number (see §3).
- Career / résumé data (optional Jobs feature)— if you use the Jobs feature, documents you upload (e.g. a résumé) and information extracted from them (such as your name, contact details, and work history) are processed to provide that feature. This is personal data and is processed by our AI provider (see §3).
- Communications — emails we send you and records of your email preferences and unsubscribe requests.
2. Why we use your data and our lawful bases
Under the UK/EU GDPR we must have a lawful basis for each use. The table below maps our processing to its basis; under the Australian Privacy Act the same activities are our primary purposes of collection (APP 3 and APP 6).
| Purpose | Data used | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Create and secure your account; authenticate you | Account & identity | Contract |
| Deliver the service (quizzes, progress, leaderboards, PvP, guilds) | Study & game data | Contract |
| Process payments and manage subscriptions | Billing data | Contract |
| AI explanations and Jobs features | Question content; résumé data you provide | Contract |
| Product analytics to understand and improve the app | Analytics & device data | Consent |
| Marketing / promotional emails | Email address | Consent |
| Age assurance and child protection | Date of birth (only if you provide one) | Legal obligation / legitimate interests |
| Security, fraud prevention, and enforcing our terms | Account, device, and usage data | Legitimate interests |
Where we rely on consent, you can withdraw it at any time (see §6) without affecting processing already carried out. Where we rely on legitimate interests, you can object (see §6).
3. Who we share data with (sub-processors)
We do not sell your personal data.We share it only with the service providers below, who process it on our behalf under data-processing agreements. Some are located in the United States, which means some personal data is transferred outside the UK/EEA/Australia (see §5).
| Provider | What they process | Region |
|---|---|---|
| Supabase | Database & authentication (account, profile, synced game data) | [confirm project region] |
| Vercel | Application hosting; request metadata incl. IP | Global / US |
| PostHog | Product analytics (only after you consent) | United States |
| Google Analytics / Google Tag Manager | Product analytics (only after you consent) | United States |
| LemonSqueezy (Merchant of Record) | Payments, tax, subscription management; your email | United States |
| OpenAI | AI explanations; résumé text for the Jobs feature | United States |
| Resend | Transactional and (opt-in) marketing email delivery | United States |
| Trigger.dev | Background jobs (e.g. résumé processing) | [confirm region] |
4. Cookies and analytics
We use strictly-necessary cookies to keep you signed in, secure, and to remember your cookie choice — these do not require consent. Non-essential cookies and similar technologies (analytics) are off by default and only set after you opt invia our cookie banner, in line with UK PECR and EU ePrivacy rules. You can change your choice at any time using the "Cookie preferences" link in the footer, and we honour Global Privacy Control (GPC) browser signals. Full details are in our Cookie Policy.
5. International data transfers
Some of our providers (§3) are in the United States, so your personal data may be transferred there. For transfers of UK/EEA personal data we rely on appropriate safeguards — the UK International Data Transfer Agreement/Addendum and the EU Standard Contractual Clauses, and/or the EU–US and UK–US Data Privacy Framework where a provider is certified — together with a transfer risk assessment. Analytics data is only transferred after you consent. For Australia, we take reasonable steps under APP 8 to ensure overseas recipients handle your data consistently with the APPs. You can request details of the safeguards by emailing privacy@secuspark.com.
6. Your rights
Depending on where you live, you have some or all of the following rights. To exercise them, use the in-app tools in Settings (Download my data, Delete my account, email preferences) or email privacy@secuspark.com. We respond within one month (UK/EU) or a reasonable period (AU).
- Access— get a copy of your data. Use "Download my data" in Settings for a machine-readable export.
- Rectification / correction — fix inaccurate data (edit your profile, or contact us).
- Erasure— delete your account and associated data using "Delete my account" in Settings.
- Portability — receive data you provided in a structured, machine-readable format (the export tool).
- Restriction and objection — limit or object to certain processing, including objecting to processing based on legitimate interests.
- Withdraw consent— turn off analytics cookies or marketing emails at any time (footer "Cookie preferences" and Settings).
- Revoke Google access — via your Google Account permissions.
7. Data retention
We keep your account and associated data for as long as your account is active. If you delete your account, we erase your personal data from our live systems promptly and within 30 days, and request deletion from our sub-processors under their agreements. We may retain a minimal record where required for legal, tax, or fraud-prevention purposes, and email-suppression records so we do not contact you after you unsubscribe. On-device (IndexedDB) data stays until you clear your browser or use the in-app delete. Backup copies are overwritten on our providers' normal backup cycles.
8. Children and age assurance
SecuSpark is designed to be safe for users of all ages. We do not ask for your date of birth when you register. Because analytics and marketing are off by default for everyone, and because we automatically and permanently disable all analytics and marketing for any account whose holder tells us they are under 16, we do not profile or market to children. We follow the UK Age Appropriate Design Code (Children's Code) principle of high privacy by default. If you believe a child has provided us personal data in a way that needs attention, contact privacy@secuspark.com and we will act promptly.
9. Security
- All data in transit is encrypted using TLS/HTTPS.
- Database access is protected by Row Level Security so users can only access their own data.
- Authentication is handled by our provider using industry-standard practices; passwords are never stored in plain text.
- Access to production systems is restricted to authorised personnel.
10. Complaints and how to reach the regulators
We hope to resolve any concern if you contact us first at privacy@secuspark.com. You also have the right to complain to a data-protection authority:
- United Kingdom— the Information Commissioner's Office (ICO), ico.org.uk.
- EU / EEA — your local supervisory authority (a list is published by the European Data Protection Board at edpb.europa.eu).
- Australia — the Office of the Australian Information Commissioner (OAIC), oaic.gov.au.
UK/EU representatives. If we are not established in the UK or EU, our Article 27 representatives are: UK — [UK representative]; EU — [EU representative]. [Complete before serving UK/EU users, per privacy counsel.]
11. Google API Services User Data Policy
SecuSpark's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data (email, name, profile picture) only to provide and improve user-facing features; we do not use it for advertising, sell it, or use it for unrelated purposes. Human access is limited to security, legal compliance, or direct user support.
12. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new revision date, and where required we will notify you or ask for fresh consent.
13. Contact us
Questions or requests about your privacy: privacy@secuspark.com.