Privacy Policy
Last updated: May 20, 2026
FalconCert (“FalconCert”, “we”, or “us”) operates https://falconcert.com (the “Website”). This policy explains what personal data we collect, why we collect it, how it is used, who receives it, and the choices available to you.
By using the Website you acknowledge that you have read and agree to this Privacy Policy and our Terms of Service.
1. What information we collect
1.1 Information you provide
- Account data. When you sign in we receive your email address from the identity provider you chose (Google, GitHub, or magic link). If your provider exposes a display name or avatar URL we may store those alongside your account.
- Study activity. Answers you submit, exams you start, and questions you flag are stored against your account so we can rebuild your progress on later visits.
- Payment data.If you purchase access to an exam, the card details are entered on our payment processor's page; we receive only the resulting transaction reference, the exam purchased, and the billing email. We do not store full card numbers.
- Support messages. If you email us we keep the message, your address, and any attachments long enough to respond and to track recurring issues.
1.2 Information we collect automatically
- Technical data. IP address, browser type, operating system, screen size, and referring URL — sent by your browser on every request and recorded in standard server logs.
- Usage data. Which pages you load, which exams you open, and which answers you submit. We use this to measure performance and to fix bugs.
- Approximate location. Country and region inferred from your IP address. We do not collect precise GPS coordinates.
2. How we collect it
2.1 Cookies and similar technologies
We use a small number of cookies. Session cookies expire when you close the browser; persistent cookies remain for a fixed period. Specifically:
- Authentication cookies issued by Supabase Auth that keep you signed in.
- Preference cookies that remember UI choices such as quiz mode and density.
- Analytics cookies from Google Analytics (or an equivalent first-party analytics tool) used to measure aggregate traffic.
You can clear or block cookies through your browser settings. Blocking authentication cookies will stop you from signing in.
2.2 Analytics
We use Google Analytics and Cloudflare's built-in request analytics to understand how the Website is used. These tools receive technical and usage data described in section 1.2; they do not receive your study answers, payment data, or message content.
3. How we use information
- Operate the Website and keep you signed in.
- Save your study progress, flagged questions, and purchases.
- Process payments and deliver the exams you bought.
- Reply to support emails and investigate reported issues.
- Detect abuse, prevent fraud, and enforce our Terms.
- Measure aggregate traffic and improve performance.
- Comply with legal obligations and respond to lawful requests.
4. Who we share it with
- Service providers. Supabase (database, auth, storage), Cloudflare (hosting, CDN), and our payment processor receive only the data they need to perform their function and are bound by their own data-protection terms.
- Identity providers.When you choose “Continue with Google” or “Continue with GitHub” we share the sign-in request with that provider; they share your email back with us. We do not post anything to your provider account.
- Analytics providers. See section 2.2. They receive aggregated or pseudonymous data, not your account email.
- Legal and safety. We may disclose data when required by law, when responding to valid legal process, or when we believe disclosure is necessary to protect users or the public.
- Successors. If FalconCert is merged, acquired, or sold, the data described in this policy may be transferred to the successor under equivalent commitments.
- Aggregated data. We may publish aggregate or de-identified statistics that cannot reasonably be linked back to you.
We do not sell your personal data and we do not share it with advertising networks for ad targeting.
5. Security
We use TLS for traffic in transit, encrypted storage at rest, and least-privilege access to backend systems. No service can guarantee perfect security; please use a unique password for the email address tied to your account and contact us immediately if you suspect it has been compromised.
6. Your choices
6.1 Updating or deleting your account
You can change your account email through your identity provider. To delete your FalconCert account and the study progress attached to it, email us at admin@falconcert.com. We aim to honour deletion requests within 30 days. We may keep minimal records longer where retention is required by law (for example, payment receipts).
6.2 Cookies and analytics
You can opt out of Google Analytics tracking using the official browser add-on. You can clear authentication and preference cookies through your browser's privacy settings.
6.3 Email
We send transactional email only (sign-in links, purchase receipts, and security notices). We do not run a marketing newsletter.
7. Children
FalconCert is intended for users who are at least 13 years old, and at least 16 in the European Economic Area. We do not knowingly collect data from anyone below that age. If you believe a child has given us data, contact us and we will delete it.
8. Jurisdiction-specific notes
8.1 California (CCPA)
California residents may request the categories of personal data we have collected, request deletion, and request that we do not sell their data — we already do not sell data. The Website does not honour Do Not Track browser signals because there is no industry consensus on how to interpret them.
8.2 European Economic Area / UK (GDPR)
FalconCert acts as a data controller for the information described in this policy. You have the right to access, correct, port, and delete your data, and to lodge a complaint with your local supervisory authority. To exercise any of these rights, email admin@falconcert.com.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced on the Website or by email. The “Last updated” date at the top of this page always reflects the current version; continuing to use the Website after the date changes means you accept the new version.
10. Contact
Questions or requests related to this policy: admin@falconcert.com.