Privacy Policy

Who this applies to. This Privacy Policy covers information collected by SummitCert Publications through this website and our study portals.

Depending on how you use the site, this can include:

  • •Order & contact information: name, email, and (optionally) country, plus the products you bought.
  • •Transaction references: payment-processor order/transaction IDs and, when a processor reports it, the general card network used (e.g. Visa, Mastercard) — we never receive or store your full card number, expiry, or CVV.
  • •Access & entitlement records: your access code (stored encrypted, never in plain text), which products it unlocks, and its status (active, revoked, etc.), so we can let you in and honor refunds correctly.
  • •Checkout behavior: which payment method/processor a checkout attempt used, the country selected for it, and whether the attempt succeeded or failed (and a general, non-sensitive reason if it failed, e.g. "declined" — never card details). Used to keep checkout reliable and to detect fraud/abuse, not for marketing.
  • •Preview access: if we grant you a short, time-limited preview of a portal (see "Preview access" in our Terms), the email you provided is used to issue and expire it correctly.
  • •Session/security records: when a portal recognizes your browser, it does so via a secure record tied to a random token — never your code, name, or email — kept only long enough to keep you signed in (up to 180 days if you chose "remember me," much shorter otherwise). See our Cookie Policy for detail.
  • •Study-progress sync: if you use cross-device progress sync, your quiz/study progress for that exam is linked to your unlocked session and the email you provide, so it can follow you between your own devices. If your access code is shared with other owners of the same book, we confirm your email with a one-time code before linking it, so someone else who has the same code can't read or overwrite your progress.
  • •Support messages: whatever you send us through the Contact & Support form.
  • •VAT/location evidence: the approximate country derived from your IP address when checkout opens (only the two-letter country it resolves to — never the IP address itself), the country you select at checkout, a card-issuing country reported by our payment processor when applicable, and, for business customers who provide one, a VAT/GST ID — plus the VAT rate applied and the exchange rate used to convert the VAT amount into the tax authority's reporting currency at the time of sale. Kept attached to the relevant order because tax authorities require us to evidence where each customer was located and how the VAT was calculated.
  • •Technical/security data: your raw IP address itself is used only transiently (a few minutes) to prevent automated abuse of the access-code check, and is not stored in our main database.
  • •Analytics: only if you've consented to it — see "Cookies & analytics" below.
  • •Advert attribution: if you arrived by clicking one of our adverts, the campaign tags and ad click ID in that link (for example a Google Ads "gclid"), so we can tell which adverts lead to purchases. These are not your name, email or card details.

How we use it. To fulfill and deliver your order, authenticate your access to a portal you purchased, maintain and correctly apply entitlements (including refund/dispute-driven access changes), process refunds, prevent fraud and abuse, provide support, meet our accounting/tax/legal recordkeeping obligations, operate and improve the site, and — only with consent — run analytics, measure which of our adverts lead to purchases, or send the occasional product update.

Our legal bases (for visitors covered by GDPR/UK GDPR-style rules). We rely on: contract (to deliver what you bought and authenticate your access), legal obligation (tax/accounting recordkeeping), legitimate interests (fraud/abuse prevention, keeping the site secure, and — where legally permitted with a clear opt-out — telling existing customers about relevant products), and consent (analytics cookies, advert purchase measurement, and any cookie/storage category that isn't strictly necessary — see our Cookie Policy).

Who we share it with. Only the service providers that make the site and delivery work: our hosting and database infrastructure providers, our payment processors (Gumroad and Flutterwave — they only ever receive what's needed to charge your card, never your full order history), our email-delivery provider (to send your receipt and access code), and — only if you've consented — our analytics provider. If you arrived from one of our Google adverts and had accepted Analytics when you checked out, then after your payment is confirmed we tell Google Ads that the ad click led to a purchase: we send only the ad click ID, our order reference, the order value (excluding tax) and its currency — never your name, email address or card details. If you hadn't accepted Analytics, nothing about your purchase is sent to Google. We never sell your personal data to anyone.

International transfers. Some of the providers above operate infrastructure outside your own country (commonly in the United States). Where that happens, your information may be processed there as part of how that provider's service works.

Data retention. We don't apply one blanket deletion date to everything — retention depends on the type of record: order and payment records are kept for as long as needed to meet accounting/tax recordkeeping obligations (for example, records of sales on which EU VAT was charged must be kept for 10 years under the EU One-Stop-Shop rules) and to correctly honor refunds, disputes, and your entitlement over the life of a "lifetime access" product; session/security records expire automatically on the schedule described in our Cookie Policy; support messages are kept as long as needed to resolve your request and for a reasonable period after; technical rate-limiting data (like a transiently-used IP address) expires within minutes. Where we no longer have a legal or operational reason to keep something, we delete it; you can also ask us to delete data sooner, subject to "Your rights" below.

Your rights. Depending on where you live, you may have the right to access, correct, or delete your personal data, object to or restrict certain processing, withdraw consent (including for analytics/cookies — see "Cookie Settings" in the footer of any page), and opt out of marketing emails at any time. Reach us through the Contact & Support form to exercise any of these. We may not be able to delete data we're required to keep for accounting, tax, fraud-prevention, or dispute-evidence purposes — where that applies, we'll tell you.

Marketing email. Your receipt, access code, and any support replies are transactional messages, not marketing — you'll always get those. Separately, we may send you one follow-up email roughly 21 days (three weeks) after a purchase, inviting feedback or a review; every such message says how to opt out (reply "unsubscribe," or tell us through the Contact & Support form), and we honor that immediately. We never sell or rent your email to anyone else for their own marketing.

Cookies & analytics. We use cookies and similar browser storage for a mix of purposes — some necessary to run the site and your purchased access, some only with your consent. Google Analytics, specifically, only loads and only sets any cookie after you actively choose "Accept all" or turn Analytics on in "Customize." The same choice controls advert purchase measurement: only with it do we report a purchase back to Google Ads (see "Who we share it with"). See our full Cookie Policy for the complete list, and use the "Cookie Settings" link in the footer to change your choice at any time.

Security. Access codes are stored encrypted, never in plain text; session tokens are stored only as one-way hashes, never as the raw value a browser holds; all traffic to and from the site is encrypted (HTTPS); and access to customer/order data internally is limited to what's needed to run the business. No system is completely immune to every possible attack, and we can't promise a breach will never happen — but we take reasonable, current security practices seriously and will notify affected customers where legally required if something does go wrong.

Children. Our services are intended for users 16 years of age or older, or the age of majority where you live if that is older. We do not knowingly collect personal data from children below that age.

Contact. Questions about this Privacy Policy, or want to exercise one of your rights above? Reach us through the Contact & Support form.

Last updated October 2, 2026. Questions? Reach us through the support form on any portal.