Last updated: 29 August 2026
CertExamHQ, operating CertExamHQ, is responsible for the personal information described here. Free previews do not require an account. An account is required for an Exam Pass, private bank delivery and cross-device progress.
Free-preview personalisation uses local storage. It remains on the device and is not part of a server-side profile. It covers:
certexamhq:theme — light or dark modecertexamhq:bookmarked-exams — saved examscertexamhq:bookmarked-questions — saved questionscertexamhq:progress:* — practice answers and revealed solutionscertexamhq:recent-exams — recently viewed examscertexamhq:recent-searches — recent searchesClearing browser data removes the local copy. When you use an Exam Pass, answer and reveal state for that paid exam is also stored with your account so it can follow you to another device.
We process the email address used to sign in, short-lived verification codes, session identifiers, purchased-exam entitlement status, access dates and basic security logs. If you contact us, we process your email address and message to reply, investigate a correction or rights request, and keep a reasonable support record.
Where Paddle checkout is enabled, Paddle acts as merchant of record and processes identity, billing, tax, payment, fraud-prevention and transaction data under its buyer privacy notice. We receive transaction and customer identifiers, customer email, selected exam and access dates needed to grant access and provide support. We do not receive or store complete card numbers.
The service uses Cloudflare for static delivery, security, private storage and the paid-access API. Like any web host, Cloudflare may process IP addresses, request headers, timestamps and security events. Transactional sign-in mail is sent through Resend, which receives the destination email and message metadata. We do not currently load advertising pixels or behavioural analytics.
The public preview uses the local storage keys above, not advertising cookies. A strictly necessary, secure, HTTP-only session cookie keeps signed-in users authenticated. Paddle may use cookies or equivalent storage inside checkout under its policy. Paddle.js is loaded only when a configured checkout is opened.
Local progress stays until you clear it. Account and entitlement records are kept while an account is active and for a reasonable period afterward for support, fraud prevention and legal obligations. Verification codes expire quickly; session and security logs are kept for shorter operational periods. Support and transaction records may be retained for disputes, tax or accounting. We use access controls and encryption in transit, but no system is completely secure.
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may complain to a data-protection authority. You may withdraw consent where processing relies on it. Some records must be retained for legal or transaction purposes. Send requests from the relevant email address to [email protected].
The service is designed for certification candidates and is not directed to children under 16. Service providers may process data in countries other than yours using their contractual and legal transfer safeguards.
We will update the date above when this policy materially changes. Questions or privacy requests: [email protected]. See also the terms of service and contact page.