⚠️ DRAFT DOCUMENT - NOT LEGAL ADVICE
This is a POC (Proof of Concept) template. Before launching, you MUST have this policy reviewed by a qualified lawyer. Budget $5,000+ for proper legal review. This document must comply with Singapore's PDPA (Personal Data Protection Act). Do not use as-is for a live service.

Privacy Policy

Last Updated: April 10, 2026

At Maths Question Bank, we take your privacy seriously. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding your data.

1. Information We Collect

1.1 Information You Provide

Data Type Purpose Required
Email Address Account creation, login, communication, password recovery Yes
Account Password Account security (stored as encrypted hash) Yes
Payment Information Paper purchase billing (processed by Stripe, not stored by us) For paid papers only
Support Communications Customer service and technical support Optional

1.2 Information Collected Automatically

Data Type Purpose
Usage Data Questions generated, topics accessed, features used (to improve service)
Device Information Browser type, operating system, device type (for compatibility and security)
Log Data IP address, access timestamps, pages visited (for security and analytics)
Cookies Session management, preferences, analytics

1.3 Information We Do NOT Collect

2. How We Use Your Data

We use collected data for the following purposes:

2.1 Marketing Communications

With your consent, we may send promotional emails about new features, educational tips, or special offers. You can unsubscribe at any time by clicking the "unsubscribe" link in any marketing email.

3. Data Sharing and Third Parties

3.1 We Do NOT Sell Your Data

We never sell, rent, or trade your personal data to third parties for their marketing purposes.

3.2 Third-Party Service Providers

We share data with trusted third parties only as necessary to operate the Service:

Provider Purpose Data Shared
Stripe Payment processing Email, purchase amount, transaction ID
Email Service Provider Sending transactional and marketing emails Email address, name (if provided)
Analytics Providers Usage analytics and performance monitoring Anonymized usage data, device info
Cloud Hosting Data storage and application hosting All data (encrypted at rest and in transit)

3.3 Legal Requirements

We may disclose data if required by law, court order, or government request, or to protect our rights and safety.

4. Data Retention

We retain your personal data for as long as your account is active. If you delete your account:

5. Your Rights

Under Singapore's PDPA and other applicable laws, you have the following rights:

5.1 Access

You can request a copy of your personal data. Contact us at [email protected] (placeholder).

5.2 Correction

You can update or correct inaccurate data through your account settings or by contacting us.

5.3 Deletion

You can request deletion of your account and personal data. We will respond within 30 days. Note: Some data may be retained for legal compliance (e.g., billing records).

5.4 Data Portability

You can request your data in a machine-readable format.

5.5 Withdraw Consent

You can withdraw consent for marketing communications at any time by unsubscribing.

5.6 How to Exercise Your Rights

Contact us at [email protected] (placeholder) with your request. We will respond within 30 days.

6. Data Security

We implement appropriate technical and organizational measures to protect your data:

However, no system is 100% secure. We cannot guarantee absolute security but will notify you promptly if a breach occurs.

7. Cookies

We use cookies for:

You can control cookies through your browser settings, but disabling essential cookies may break the Service.

8. Children's Privacy

Our Service is intended for use by primary school students (typically ages 7-12). We do not knowingly collect personal data from children under 13 without parental consent. If you are a parent and believe your child has provided us with data without your consent, please contact us.

9. International Data Transfers

Your data may be processed in countries outside Singapore. We ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.

10. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or prominent notice on the Service. Continued use after changes constitutes acceptance.

11. Contact Us

For privacy-related questions, concerns, or requests:

Email: [email protected] (placeholder)
Data Protection Officer: [To Be Appointed]
Address: [Business Address - To Be Added]
Response Time: We will respond within 30 days

12. Complaints

If you are not satisfied with our response, you may contact the Singapore Personal Data Protection Commission (PDPC):

Website: www.pdpc.gov.sg
Hotline: 1800-675-8977

⚠️ FINAL REMINDER: THIS IS A DRAFT
Before launching your service, you MUST consult with a qualified Singapore lawyer to review and customize this Privacy Policy. It must comply with Singapore's Personal Data Protection Act (PDPA). Budget at least $5,000 SGD for proper legal review. This template is a starting point only.