Privacy
Privacy policy
Effective . This describes what BCINprep actually collects and does, not what a template says. The short version: one email address, and a record of how you did on your own practice papers.
Who is accountable
Qordova Inc., carrying on business as BCINprep, is responsible for the personal information described here and handles it under Canada's Personal Information Protection and Electronic Documents Act, known as PIPEDA. One person is accountable for it: the operator of the business, acting as privacy officer.
| Privacy contact | Privacy Officer, Qordova Inc. (BCINprep) |
|---|---|
| support@bcinprep.ca, with "Privacy" in the subject line | |
| Telephone | (648) 549-3473 |
| Address | Suite 820, 2735 Pembina Hwy, Winnipeg MB R3T 6K5, Canada |
What we collect, and why
These are the identified purposes. We collect nothing for any other purpose, and we do not sell or rent personal information to anyone or use it for advertising.
| What | Why we hold it |
|---|---|
| Your email address | To deliver the licence for what you bought, to send the six digit code that signs you in, and to answer you when you write to support. It is the only contact detail we hold and the only thing that identifies you by name, and it is the account itself. |
| The dates on your account | The date the account was created, and the date you last used it. The last used date is written each time you load a signed in page. It exists so that dormant accounts can be found and cleared out later, which is the only use it has. It is a timestamp against your account and nothing more: it records that you were here, not what you looked at. |
| Which exams you bought | To release the right question banks to you and no others. We store the exam identifier, where the entitlement came from (a purchase, a licence key, or a manual grant by us), a reference to the transaction, and the date it was granted. |
| Sign in codes | When you ask for a sign in code we store a one way hash of that code against your email address, its expiry time, and how many attempts have been made, so the code can be checked once and then thrown away. We do not store the code itself. |
| Your practice and mock exam attempts | So your progress survives a lost device and follows you from one browser to another, and so the dashboard can show which topics you have cleared. Each record holds the exam, whether it was practice or a timed mock exam, its label, the start and finish times, the elapsed seconds, the number correct out of the number asked, the percentage, and the correct count per topic. Nothing about the individual questions or your wording is stored. |
| Question reports | If you report a question, we receive the question identifier, which bank and version it came from, the reason you picked, and any comment you type. Reports are anonymous. They are not linked to your email address, your account or your attempts, and they carry no identifier of you. Please do not type personal information into the comment box; it is not needed and we would rather not have it. |
| A sign in cookie | Signing in sets one cookie. It holds your account number, your email address and a session version, signed so it cannot be altered, and it lasts ninety days or until you sign out. It is marked HttpOnly and SameSite Lax, so scripts cannot read it and other sites cannot send it. It is the only cookie this site sets, and it is set only when you choose to sign in. |
| Website analytics | The site is built to load Google Analytics 4 if, and only if, a measurement identifier is configured. No measurement identifier is configured today, so no analytics run and no analytics cookies are set. If that changes, this page will be updated with the effective date before it does, and analytics would count page visits in aggregate rather than identify anyone. |
Our database has no column for your IP address and none for your browser user agent, so neither is stored against your account. We do not build a profile of you and we do not track you across other websites. Error logs are a separate matter and are described under operational logs below.
Payment card details never reach us
Checkout is handled by Stripe, our payment processor. Your card number, expiry, security code and billing details are entered on Stripe's payment page and go to Stripe. They never touch our servers and we never see them or store them. What comes back to us is confirmation that a payment succeeded, the email address you used, and which exams were bought. Stripe holds the order and the receipt as the processor of record.
What stays on your own device
Your decrypted question banks, your cached licence and a local copy of your attempt history are kept in your browser's local storage so the app keeps working with no connection. That storage is on your device, not ours. Clearing your browser data clears it. Your attempt records are also saved to the server as a backup when you are signed in, which is the copy the deletion control below removes.
Who else is involved, and where the data sits
- Cloudflare hosts the website, runs the application interface and holds the database in which the items above are stored. All the data we hold sits on Cloudflare infrastructure.
- Stripe processes payments and holds the payment and order records.
- Resend delivers our email: licence keys, sign in codes and receipts. It therefore handles your email address in order to send to it.
These three are service providers acting for us under their own contractual and legal obligations, and they are the only third parties involved. We use no advertising networks, no data brokers and no marketing list. Because these providers operate internationally, information may be stored or processed outside Canada, where it can be subject to the laws of the country it is in. We would disclose information to anyone else only where the law requires it of us.
Operational logs
Running the site produces error logs on Cloudflare, the way any hosted service does. Almost everything in them is an error message, a Stripe checkout reference or a status code, with no personal information in it at all. There are two narrow cases where an email address can appear in one, and both are failures rather than normal operation:
- A sign in code or a purchase alert that our email provider refused to send. When that happens we raise an alert to our own support mailbox that names the address, because support cannot rescue a customer stuck at the door without knowing who they are, and the same text is written to the log if that alert itself cannot be sent.
- The mailing list endpoint, if it is ever used while unconfigured, writes the address given to it into the log. No page on this site posts to it today, so in practice nothing reaches it.
Question reports are logged only when report delivery is unconfigured, and what is logged is the report itself, which carries no identifier of you. That is the reason we ask you not to type personal information into the report comment box.
We keep no log database of our own and we copy nothing out of these logs. They exist inside Cloudflare's own short term log retention for our service, they are visible only to the operator of the business through the Cloudflare dashboard, and they are not used for analytics, profiling or marketing.
How long it is kept
- Your email address and your entitlements are kept while your account exists, because they are what proves you own what you bought.
- The created and last used dates are kept for the life of the account and go when it goes. The last used date is overwritten each time you sign in, so only the most recent one exists.
- Attempt records are kept until you delete them, or until the account is deleted.
- Sign in codes are short lived. The stored hash is deleted as soon as the code is used, when the attempt limit is reached, or when it expires, which is within minutes of it being sent.
- The sign in cookie expires after ninety days, and signing out clears it immediately.
- Question reports are kept because they are how corrections get made and logged, and they hold nothing identifying you.
- Order records held by Stripe are kept for as long as tax and business record rules require, which is a legal obligation we cannot waive on request.
- Operational logs live only as long as Cloudflare retains them for our service, which is a matter of days. We do not archive them, and an entry that has aged out is gone.
Your rights, and how to use them
PIPEDA gives you rights over your personal information. Here is how each one works here.
- Access. You can see everything we hold about you. Your email address, your entitlements and your full attempt history are visible in the study app as soon as you sign in. If you would rather have it in writing, ask us and we will send it within thirty days, free of charge.
- Correction. If something is wrong, tell us and we will fix it. Attempt records are the one thing you can correct yourself: the deletion control below removes them, and any paper you sit afterwards writes a fresh record.
- Deleting your practice history. Your attempt records are yours to delete without asking us. The study app carries a control, in the history panel, that removes them for one exam or for every exam at once. What goes is the attempt records and the topic breakdowns behind them, and nothing else: your account, your email address, your purchases, your licence key and your access to every exam you own are untouched. The app asks you to confirm first, in the page rather than in a pop up, and tells you before you commit exactly which copies are about to go.
- What deletion actually does. The copy in your browser is cleared first and stays cleared, and the app holds back its background sync while it happens so that a batch already on its way cannot put the rows back. The copy in your account is deleted in the same action. If we cannot reach the server in that moment, the app says so plainly, tells you the copy on your device is gone but the copy in your account was not reached, and gives you the support address, rather than showing you a success message that is not true. If you are studying signed out or from a licence key alone, there is no copy in an account to delete, and the confirmation says that before you commit.
- Deletion by email. Email support@bcinprep.ca and we will delete your attempt records for you. This is the route to use if the control could not reach your account, and it is the only route for deleting the account itself, which is covered in the next point.
- Deleting your account. Email support@bcinprep.ca and ask us to delete your account. We will remove your email address, your entitlements and your attempt records. We will tell you what we cannot remove, which is normally the order record Stripe is required to keep. Deleting the account does not disable a licence key you already hold: the key stands on its own signature, so you keep the access you paid for.
- Withdrawing consent. You can withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. In practice, stop signing in and ask us to delete the account. Be clear about the consequence: your email address is how a purchase is delivered and how sign in works, so withdrawing consent means we can no longer restore access or resend a key, and cross device sync ends. Keep your licence key first.
- Complaining. If you are not satisfied with how we have handled a privacy question, write to the privacy contact above and we will respond. You may also complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
We will ask you to confirm control of the email address in question before acting on an access or deletion request, because that address is the account and we have no other way to know it is you.
How it is protected
Sign in codes are stored only as a one way hash. Session cookies are signed, and rotating our signing secret invalidates every session at once. Question banks are encrypted, and the key for a bank is released only against a purchase we can see in the database. Access to the database is limited to the operator of the business. No system is perfect, and we will tell affected people if a breach ever creates a real risk of significant harm to them, as PIPEDA requires.
Children
This is professional qualification material sold to working adults. The site is not directed at children and we do not knowingly collect information from them.
Changes to this policy
If we change what we collect or why, we will update this page and change the effective date at the top before the change takes effect. The terms of sale are separate and live at terms of use and sale.
Contact
Email support@bcinprep.ca, telephone (648) 549-3473, or write to Privacy Officer, Qordova Inc., Suite 820, 2735 Pembina Hwy, Winnipeg MB R3T 6K5, Canada.