Privacy Policy
Last updated: 6/9/2026
1. Introduction
ATPL Training ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website (atpltraining.io), mobile application, and related services (collectively, the "Platform").
By using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Platform.
2. Data Controller
ATPL Training is the data controller for the personal data processed through the Platform. For any questions about this policy or your data, contact us at:
Email: info@atpltraining.io
3. Information We Collect
3.1 Information You Provide
- Account Data: Email address and authentication credentials when you register via email or Google OAuth. We do not store passwords — authentication is handled by Supabase Auth.
- Profile Data: Display name, avatar URL, and preferences you set in your account.
- Payment Data: Payment method details and billing address, collected and processed exclusively by Stripe. We do not store full credit card numbers.
3.2 Information Collected Automatically
- Usage Data: Exam attempts, question responses, study progress, time spent per subject, LMS lesson completion, and platform interaction patterns.
- Device Data: IP address, browser type and version, operating system, device type, screen resolution, and referring URLs.
- Cookies: Session tokens for authentication, analytics cookies, and functional cookies. See Section 9 for details.
4. How We Use Your Data
We use your personal data for:
- Service Delivery: Providing the question bank, exam simulator, LMS, progress tracking, and AI-powered coaching.
- Personalization: Tailoring study recommendations and identifying weak subjects based on your performance.
- Payments: Processing subscriptions via Stripe, managing billing, and handling refunds.
- Communication: Sending transactional emails via Resend (welcome, password reset, receipts).
- Improvement: Aggregating anonymized usage data to improve the Platform.
5. Legal Basis (GDPR)
If you are in the EEA, UK, or Switzerland, we process your data under:
- Contractual Necessity: To provide the services you requested.
- Legitimate Interests: Improving the Platform and analysing usage.
- Consent: For optional communications. You may withdraw at any time.
- Legal Obligation: Complying with tax and accounting laws.
6. Sub-processors
| Service | Purpose | Data |
|---|---|---|
| Supabase | Database, auth, storage | Account & usage data |
| Stripe | Payment processing | Payment details |
| Resend | Email delivery | Email address |
| OpenRouter | AI coaching | Anonymized exam data |
| Sentry | Error monitoring | Device & error data |
| Vercel | Hosting | IP & request logs |
We do not sell your personal data.
7. International Transfers
Data is hosted in Europe (Vercel, Supabase). We use Standard Contractual Clauses where required under GDPR.
8. Data Retention
- Account Data: Lifetime of account. Deletable on request.
- Usage Data: Retained for progress tracking. Anonymized after deletion.
- Payment Records: 7 years per tax law.
- Server Logs: Up to 90 days.
9. Cookie Policy
- Essential: Auth session tokens (required).
- Functional: Preferences like dark mode, exam type.
- Analytics: Anonymized usage analytics.
Manage cookies via browser settings.
10. Data Security
We use TLS encryption, database encryption at rest, and role-based access controls. Auth via Supabase Auth (bcrypt/OAuth 2.0). Payments tokenized by Stripe.
11. Your Rights
You may request access, rectification, erasure, portability, restriction, or objection regarding your data. Contact info@atpltraining.io. Response within 30 days. You may also lodge a complaint with your local data protection authority.
12. Children
The Platform is not for individuals under 16. We do not knowingly collect data from children.
13. Changes
We will notify you of material changes by email or via the Platform. The "Last updated" date reflects the latest revision.