Who operates this service
CBAT Academy is an independent training service. This policy explains what the service collects, why it is used, the providers that process it, and the choices available to you. Privacy requests can be made through the contact form without signing in.
Information collected
- Account: email address, password credential processed by Supabase authentication, authentication identifiers, display name, sign-in timestamps, role and access status.
- Training: module, mode, difficulty, completion time, answers or result details, calculated scores and progress history.
- Purchases: Stripe customer and transaction identifiers, payment status, product, amount and mock-test credit balance. CBAT Academy does not receive full card numbers.
- Support: name, reply email, category, subject, message, replies and account recipient messages.
- Security and operation: account activity time, short-lived hashed rate-limit identifiers, request and error information, and logs made by hosting providers.
Do not submit service numbers, dates of birth, addresses, medical details, Canadian Armed Forces application information, government identifiers or other sensitive information. CBAT Academy does not need these details and does not request them.
Why information is used
- Authenticate accounts, secure administrator access and prevent abuse.
- Provide training, synchronise progress, calculate results and honour purchased access.
- Answer support or privacy requests and send account messages.
- Process purchases, prevent duplicate credit use and meet financial obligations.
- Diagnose failures, maintain availability and improve the service.
- Display and measure advertising where enabled, subject to Google Privacy & Messaging choices and applicable regional settings.
Information is used with meaningful consent, to provide features you request, and where reasonably necessary to protect the service or meet legal obligations. You may withdraw optional advertising consent at any time; doing so does not affect account or training features.
Browser storage, cookies and advertising
Necessary local and session storage keeps practice history, settings, controller calibration, account-session state, privacy choices, mock-test state and short-lived caches. Guest history remains on that device. Authentication providers may use storage required to keep you signed in.
Public guide pages may use Google AdSense. AdSense and its partners may process IP addresses, device/browser data, cookies or similar identifiers to deliver, limit and measure ads and, where permitted, personalize them. Google Privacy & Messaging provides the site’s certified consent-management flow and applies the choices available for your location.
CBAT Academy measures aggregate visits, page views, practice opens, starts, completions and successful sign-up requests using its own backend. Counters contain the day, a recognised page path, landing page, broad referrer category, screen-size group and whether this browser has been measured before. They do not contain account IDs, email addresses, scores, full referrer URLs, search terms or unique visitor identifiers. A date in local storage marks a previously measured browser; session storage groups activity within a tab after less than 30 minutes of inactivity. Daily counters expire after 100 days. Server security and rate-limiting logs are separate. We honour Do Not Track and Global Privacy Control for this measurement.
Service providers and processing locations
- Supabase: authentication and account identity.
- MongoDB and the deployment host: application records, security controls, logs and backups.
- Stripe: subscriptions, mock-test purchases and donations.
- Configured email provider: support-message delivery and replies.
- Google Fonts: public font-file delivery, which necessarily receives request and device-network information such as IP address.
- Google AdSense and Privacy & Messaging: consent management and advertising on eligible public pages according to your choices and applicable regional settings.
Providers may process information outside your province or Canada, where it can be subject to the laws of that location. Access is limited to what each provider needs for its function.
Retention, deletion and backups
Browser data remains until you clear it. Training history remains until you clear it or request account deletion. Account and inbox records normally remain while the account is open. Resolved support records and routine operational logs are removed when no longer reasonably needed; transaction records may be retained longer where financial law requires. Deleted records can remain temporarily in protected provider backup rotations before expiry. Security-breach records are retained for at least two years as required by Canadian breach-record rules.
Safeguards and breach response
Safeguards include authenticated server-side access controls, a second administrator PIN gate, input validation, rate limiting, encrypted HTTPS transport, restricted browser policies, service-provider controls, and backup/recovery tooling. No online service can promise absolute security. A breach presenting a real risk of significant harm will be reported to the Office of the Privacy Commissioner of Canada and affected people will be notified as required; all safeguard breaches are recorded.
Your choices and privacy rights
You may request access to or correction of personal information, withdraw optional consent, clear training history, or permanently delete your account from Account settings. You may also ask how information was handled. Identity may need to be verified before account data is released or deleted. If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada.
Policy changes will be posted here with a new effective date. Material changes that require consent will be presented before the new processing begins.