1. Who we are
ExamAce (“ExamAce,” “we,” “our,” or “us”) operates ExamAce.ca, an exam prep platform for Ontario real estate licensing candidates. We are based in Ontario, Canada and comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). For questions about this policy or your data, contact [email protected].
2. What we collect
We collect only what we need to run the service. This falls into four categories:
- Account information: name, email address, and (if you sign in with Google) your Google profile basics. If you set a password, it is stored as a salted hash — we never see your plain password.
- Billing information: if you subscribe, we store a Stripe customer ID, subscription status, and billing history metadata. We do not store your full credit card number, CVC, or banking credentials. Card data goes directly to Stripe under their PCI-DSS Level 1 environment.
- Usage data: quiz attempts, answer choices, time spent, accuracy scores, spaced-repetition review history, and progress through study guides. This is what powers your dashboard and personalized review.
- AI tutor conversations: the messages you send to the AI tutor and its responses. We retain these to improve answer quality and provide chat history within your account.
- Technical and analytics data: IP address, browser, device type, pages visited, and aggregated traffic metrics. See section 7 for cookie details.
3. How we use your information
We use your information to:
- Authenticate you and keep your account secure.
- Deliver the service: serve practice questions, save your progress, and run the AI tutor.
- Process payments, prevent fraud, and provide receipts.
- Send transactional emails (purchase confirmations, password resets, magic links, important account notices).
- Send optional study reminders and product updates if you opt in. You can opt out anytime.
- Improve the platform: identify bugs, measure feature usage, and prioritize content gaps.
- Respond to support requests.
- Comply with legal obligations (tax reporting, lawful requests from authorities).
We do not sell your personal information. We do not use your data to train third-party AI models. We do not share your information with advertisers for targeted advertising.
4. Service providers we share with
We use a small number of vetted service providers to operate ExamAce. They process information only as needed to perform their service for us, under contractual confidentiality and security obligations.
- Stripe (United States): payment processing, subscription billing, fraud prevention. Stripe’s privacy policy: stripe.com/privacy.
- Vercel (United States): web hosting and content delivery for examace.ca.
- Self-hosted infrastructure (Canada): our database and application servers run on infrastructure we operate in Canada.
- useSend (Canada): our self-hosted transactional email service for account emails (welcome, magic links, receipts).
- Google (United States): Gemini API powers the AI tutor. Tutor messages are sent to Google for processing. Per Google’s API terms, Gemini API inputs are notused to train Google’s consumer models.
- Anthropic (United States): Claude API is used for internal content generation (admin question authoring). Your data is not sent to Anthropic.
- Google OAuth (United States): if you sign in with Google, Google authenticates you and shares your name, email, and profile picture with us.
- Google Analytics (United States): aggregated traffic and usage analytics, only if you accept analytics cookies.
Some of these providers are based in the United States. Your information may be transferred to and stored in the U.S., where it may be subject to U.S. legal requirements. We use providers with strong contractual and security commitments to protect your data during transfer and storage.
5. Legal disclosures
We may disclose your information if required by law, court order, subpoena, or other valid legal process; to protect ExamAce’s rights, property, or safety; to investigate fraud or security incidents; or in connection with a corporate transaction (merger, acquisition, or sale of assets), in which case any successor entity will be bound by this policy.
6. How long we keep your data
- Account data: retained while your account is active. If you delete your account, we delete your personal information within 30 days, except where we’re required to retain it by law.
- Payment records: retained for 7 years to meet Canadian tax and accounting requirements.
- Quiz and progress history: retained while your account is active. Deleted with your account.
- AI tutor conversations: retained for up to 12 months for quality and abuse prevention, then anonymized or deleted.
- Analytics data: aggregated and retained for up to 14 months in Google Analytics.
- Backups: encrypted backups may persist for up to 35 days after deletion before being overwritten.
7. Cookies and analytics
We use cookies and similar technologies for two purposes:
- Strictly necessary:session cookies that keep you signed in, remember your cookie consent choice, and protect against CSRF attacks. These cannot be disabled because the service won’t function without them.
- Analytics (optional): Google Analytics cookies that measure traffic patterns and feature usage. These only load if you accept them via our cookie banner.
We implement Google Consent Mode v2: until you accept analytics cookies, no analytics data is sent. You can change your choice anytime by clearing cookies for examace.ca. We do not use advertising or remarketing cookies.
8. Your rights under PIPEDA
As a Canadian user, you have the right to:
- Access: request a copy of the personal information we hold about you.
- Correct: ask us to correct information that is inaccurate or incomplete.
- Delete: request deletion of your account and personal information, subject to legal retention requirements.
- Withdraw consent: withdraw consent for optional processing (e.g. marketing emails, analytics cookies) at any time.
- Portability: request an export of your quiz history and progress data in a common format.
- Complain: file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
To exercise any of these rights, email [email protected] from the address associated with your account. We will respond within 30 days.
9. Security
We use industry-standard safeguards to protect your information: TLS encryption in transit, encryption at rest for sensitive fields, salted password hashing, role-based access controls, and regular security review. No system is perfectly secure, but we work to keep ours as close as we can. If a breach affecting your data ever occurs, we will notify you and the Privacy Commissioner as required by law.
10. Children
ExamAce is intended for adults preparing for Ontario real estate licensing exams. You must be at least 18 years old to use the service. We do not knowingly collect personal information from anyone under 18. If you believe a minor has registered, contact us and we will delete the account.
11. International users
ExamAce is operated from Canada. If you access the service from outside Canada, you understand that your information will be transferred to and processed in Canada and the United States (via our service providers), where privacy laws may differ from those of your jurisdiction.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or by prominent notice on the site at least 30 days before they take effect. The “Effective” date at the top of this page reflects the most recent version. Your continued use after the effective date constitutes acceptance of the revised policy.
13. Contact
Questions, requests, or complaints about your privacy? Reach our privacy contact at [email protected]. See also our Terms of Service.