Privacy Policy
Last Updated: January 16, 2025
1. Introduction
Welcome to AWSReady ("we," "our," or "us"). This Privacy Policy describes how we collect, use, share, and protect information about users of our educational platform for AWS certification exam preparation. By using our Service, you consent to the data practices described in this policy.
If you have questions or concerns about our privacy practices, please contact us using the information provided at the end of this policy.
2. Information We Collect
2.1 Information You Provide Directly
When you use our Service, we collect information that you provide directly to us:
| Data Type | Description | Purpose |
|---|---|---|
| Google OAuth Data | Email address, name, profile picture | Account creation and authentication |
| Quiz Progress | Answers, scores, completed pages | Progress tracking and analytics |
| Payment Information | Payment card details (via Lemonsqueezy) | Processing premium purchases |
| Support Communications | Email content, inquiry details | Customer support and issue resolution |
2.2 Information Collected Automatically
When you access our Service, we automatically collect certain technical information:
- Usage Data: Pages visited, quiz interactions, time spent on platform, navigation patterns
- Device Information: Browser type, operating system, device type, screen resolution
- Log Data: IP address, access times, referring URLs, error logs
- Cookies and Local Storage: Session tokens, user preferences, authentication tokens
2.3 Information from Third-Party Services
We receive information from third-party services you use to access our platform:
- Google OAuth: Basic profile information (name, email, profile picture) when you sign in with Google
- Lemonsqueezy: Payment transaction data and payment method information for premium purchases
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery
- Create and manage your user account
- Authenticate your identity and provide secure access
- Deliver quiz content and track your progress
- Save your quiz answers and performance data
- Provide access to premium content after purchase
3.2 Payment Processing
- Process premium exam purchases via Lemonsqueezy
- Verify payment status and grant premium access
- Handle refund requests and billing inquiries
- Prevent fraudulent transactions and abuse
3.3 Communication
- Send transactional emails (purchase confirmations, password resets, account notifications)
- Respond to your support inquiries and feedback
- Send important updates about our Service (with opt-out option for non-essential communications)
3.4 Improvement and Analytics
- Analyze usage patterns to improve quiz content and user experience
- Identify and fix technical issues
- Develop new features and enhance existing functionality
- Monitor platform performance and security
3.5 Legal Compliance and Safety
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service
- Protect against fraud, abuse, and security threats
- Resolve disputes and investigate violations
4. How We Share Your Information
We do not sell your personal information. We share your information only in the following limited circumstances:
4.1 Service Providers
We share data with trusted third-party service providers who help us operate our platform:
- Amazon Web Services (AWS): Cloud hosting infrastructure (S3, CloudFront, DynamoDB, Lambda, Cognito) - US region
- Google: OAuth authentication services
- Lemonsqueezy: Payment processing (Lemonsqueezy handles payment card data directly; we never store full card details)
These service providers are bound by contractual obligations to protect your information and use it only for the purposes we specify.
4.2 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal processes (subpoenas, court orders, search warrants)
- Government or regulatory requests
- Investigations of potential violations of our Terms of Service
- Protection of our rights, property, or safety, or that of our users or the public
4.3 Business Transfers
If AWSReady is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service of any change in ownership or uses of your personal information.
4.4 With Your Consent
We may share your information for other purposes with your explicit consent.
5. Data Storage and Security
5.1 Data Storage
Your data is stored in the following AWS services located in the Asia Pacific (Singapore) region:
- AWS DynamoDB: User profiles, premium status, quiz progress
- AWS Cognito: Authentication tokens and session data
- AWS S3: Static content and encrypted quiz data
- AWS CloudFront: Content delivery with encrypted transmission
5.2 Security Measures
We implement industry-standard security measures to protect your information:
- Encryption: HTTPS/TLS encryption for all data in transit; encryption at rest for sensitive data
- Access Controls: Role-based access controls and principle of least privilege
- Authentication: Secure OAuth 2.0 authentication via Google and AWS Cognito
- Monitoring: Automated security monitoring and logging via AWS CloudWatch
- Quiz Content Protection: Client-side and server-side encryption of quiz questions
5.3 Data Retention
We retain your personal information for as long as necessary to provide our Service and comply with legal obligations:
- Active Accounts: Data retained while your account is active
- Inactive Accounts: Data retained for 3 years after last login, then anonymized or deleted
- Payment Records: Retained for 7 years for tax and accounting purposes
- Log Data: Retained for 90 days for security and troubleshooting
6. Your Privacy Rights
6.1 Access and Portability (GDPR Article 15, 20)
You have the right to access your personal data and receive a copy in a structured, commonly used, machine-readable format. You can view and export your data through your account settings.
6.2 Correction (GDPR Article 16)
You have the right to correct inaccurate or incomplete personal information. You can update your profile information through your account settings.
6.3 Deletion (GDPR Article 17, CCPA)
You have the right to request deletion of your personal data. To delete your account and data:
- Log in to your account and go to Settings
- Select "Delete Account" in the Account tab
- Confirm deletion (this action is irreversible)
Note: We may retain certain information as required by law or for legitimate business purposes (e.g., payment records for tax compliance).
6.4 Objection and Restriction (GDPR Article 18, 21)
You have the right to object to processing of your personal data or request restriction of processing in certain circumstances. Contact us to exercise this right.
6.5 Withdraw Consent (GDPR Article 7)
Where processing is based on consent, you have the right to withdraw consent at any time. This will not affect the lawfulness of processing before withdrawal.
6.6 California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
To exercise CCPA rights, contact us at privacy@awsready.com.
7. Cookies and Tracking Technologies
7.1 What We Use
We use the following technologies to enhance your experience:
- Essential Cookies: Required for authentication and basic platform functionality
- Local Storage: Stores user preferences, quiz progress, and authentication tokens
- Session Storage: Temporary storage for current session data
7.2 Third-Party Cookies
Third-party services may set cookies when you use our platform:
- Google OAuth: Authentication cookies
- Lemonsqueezy: Payment processing cookies
7.3 Your Cookie Choices
You can control cookies through your browser settings. However, disabling essential cookies may prevent you from using certain features of our Service.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We primarily use AWS services in the Asia Pacific (Singapore) region. When we transfer data internationally, we ensure adequate protection through:
- Standard Contractual Clauses approved by the European Commission
- Adherence to Privacy Shield principles where applicable
- Compliance with applicable data protection laws
9. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will delete such information from our systems.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make changes:
- We will update the "Last Updated" date at the top of this policy
- For material changes, we will notify you via email or prominent notice on our platform
- Your continued use of the Service after changes become effective constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
11. Third-Party Links
Our Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party sites. We are not responsible for the privacy practices of third-party websites. We encourage you to read the privacy policies of any third-party sites you visit.
12. Data Protection Officer
For questions about our privacy practices or to exercise your privacy rights, you may contact our Data Protection Officer:
Data Protection Officer
Email: privacy@awsready.com
Subject Line: "Privacy Inquiry - [Your Request]"
13. Supervisory Authority
If you are located in the European Economic Area (EEA) or United Kingdom, you have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates data protection laws.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
AWSReady Privacy Team
Email: privacy@awsready.com
Support Email: support@awsready.com
Contact Page: www.awsready.com/contact
Business Hours: Monday - Friday, 9:00 AM - 5:00 PM EST
We respond to privacy inquiries within 30 days as required by GDPR.