Pular para o conteúdo principal

Privacy Policy

Last updated: 11 August 2026 Effective date: 11 August 2026

This Privacy Policy describes how InSkillBoost ("we", "us", or the "Service") collects, uses and protects your personal information. We are committed to compliance with:

  • Quebec Law 25 (An Act to modernize legislative provisions as regards the protection of personal information),
  • The Canadian PIPEDA (Personal Information Protection and Electronic Documents Act),
  • The EU GDPR (General Data Protection Regulation 2016/679) and the UK Data Protection Act 2018,
  • The California CCPA/CPRA (where applicable),
  • The Brazilian LGPD (where applicable).

1. Who we are (data controller)

The data controller / responsible party is:

Haythem Rehouma — InSkillBoost Quebec, Canada Email (privacy / DPO): privacy@inskillboost.com

2. What data we collect

2.1 Data you provide directly

  • Account data if you create a free account: your email address, an optional password (stored only as a bcrypt hash), and the first and last name you choose to display on your certificates. Accounts are managed by our authentication provider, Supabase. If you sign in with Google or GitHub, we receive your email address and basic profile from that provider.
  • Email address if you contact us.
  • Feedback or messages sent through forms or email.

2.2 Data linked to your account

  • Course enrolments and lesson progress, so your learning resumes where you left it.
  • Quiz attempts and certificates you earn, including the public verification code printed on each certificate.
  • Purchases and subscriptions, if you buy something: which offer you bought, the amount, the currency, the date, the payment status and the identifiers Stripe gives us for your order, your subscription and your customer record. This is what opens your access and what appears on your receipt.

2.2 bis What we never see about your payment

Your card number, its expiry date and its security code are entered on Stripe's own payment page and never reach our servers. We receive the outcome of the payment, not the means of payment.

2.3 Data collected automatically

  • Technical/log data: IP address (truncated), browser type and version, operating system, referring URL, pages visited, timestamps. These may be retained briefly by our hosting provider (Vercel) for security and performance.
  • Audience measurement, without cookies: we run our own counter, hosted in our own database. It records the page viewed, the referring site, the device family (mobile or desktop), the interface language and the country derived from your browser's time zone. It stores no cookie, no identifier in your browser and no IP address; a technical fingerprint is recomputed every day from a rotating secret, which makes following a visitor from one day to the next impossible. No third-party analytics service is involved.

2.4 Data we do NOT collect

  • We do not collect or store your card details, and we never see them (see section 2.2 bis).
  • We do not use Google Analytics or any third-party tracker. If that ever changes, we will ask for your explicit consent first.
  • We do not sell or rent your personal information to third parties.
PurposeLegal basis (GDPR Art. 6)Retention
Operate and secure the SiteLegitimate interest (Art. 6(1)(f))Up to 12 months (logs)
Provide your account, progress and certificatesContract (Art. 6(1)(b))Life of the account
Take payment and open the access you boughtContract (Art. 6(1)(b))Life of the account
Keep accounting records of salesLegal obligation (Art. 6(1)(c))6 years (Canadian tax law)
Reply to your messagesConsent + legitimate interestUp to 24 months
Audience measurement (cookieless, first-party)Legitimate interest (Art. 6(1)(f))90 days detailed, aggregated daily totals thereafter
Comply with legal obligationsLegal obligation (Art. 6(1)(c))As required by law

The Site displays no cookie banner because it needs none: no advertising cookie, no third-party analytics script, nothing non-essential is ever written to your browser. Signing in stores an authentication token in your browser — that is strictly necessary to keep your session open, and it is covered by the exemptions of Quebec, Canadian and EU law. Our audience measurement writes nothing at all to your device (see section 2.3).

If we ever add a tool that requires consent, we will ask for it explicitly before loading anything.

5. Data sharing and processors

We share your data only with the strict minimum of vetted processors:

  • Vercel Inc. (hosting / CDN) — USA, with Standard Contractual Clauses for EU transfers.
  • Supabase Inc. (authentication, database for accounts, progress and certificates) — project hosted in the USA, with Standard Contractual Clauses.
  • Stripe, Inc. (payments: checkout page, cards, receipts, subscriptions and refunds) — USA and Ireland, with Standard Contractual Clauses. Stripe acts as an independent controller for fraud prevention and for its own regulatory obligations; see the Stripe privacy policy.
  • Resend (Plus Five Five, Inc.) (transactional email: sign-in links and confirmations) — USA.
  • Google LLC (only if you choose to sign in with Google) — USA, with Standard Contractual Clauses.
  • Cloudflare (CDN, partial) — global.

We do not sell, rent or trade your personal information.

6. International transfers

Some processors are located outside Quebec/Canada/EU. Where applicable, we rely on:

  • Adequacy decisions of the European Commission, or
  • Standard Contractual Clauses (SCCs) approved by the European Commission, or
  • Privacy framework certifications (e.g. EU-US Data Privacy Framework).

For Quebec residents, transfers outside Quebec are subject to a privacy impact assessment as required by Law 25.

7. Your rights

Subject to your country's law, you have the following rights:

  • Right of access — obtain a copy of your data.
  • Right of rectification — correct inaccurate data.
  • Right of erasure / "right to be forgotten" (GDPR / Law 25).
  • Right to restrict or object to processing.
  • Right to data portability.
  • Right to withdraw consent at any time (without affecting prior lawful processing).
  • Right not to be subject to a fully automated decision with legal effect.
  • Right to lodge a complaint with your supervisory authority:

To exercise any right, email privacy@inskillboost.com. We respond within 30 days (extendable to 60 days for complex requests, with notice).

8. Data security

We apply reasonable technical and organizational measures, including:

  • HTTPS/TLS for all traffic.
  • Strict HTTP security headers (HSTS, X-Content-Type-Options, etc.).
  • Password-hashing for protected courses.
  • Principle of least privilege for administrative access.
  • Periodic security reviews.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours (GDPR / Law 25) and inform affected users without undue delay.

9. Data retention

We keep personal data only as long as necessary for the purposes described. Default retention periods are listed in section 3. After that, data is deleted or irreversibly anonymized.

10. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under that age (or 16 in the EU/EEA where stricter law applies). Parents may contact us to request deletion.

11. Changes to this policy

We may update this policy. The "Last updated" date reflects the latest revision. Material changes will be highlighted on the Site for 30 days.

12. Contact / DPO

For any privacy question, request or complaint:

InSkillBoost — Privacy / DPO Email: privacy@inskillboost.com Postal mail: Quebec, Canada (full address provided on request)

For users in the EU, you also have the right to contact our EU representative (where required by Article 27 GDPR — currently being designated; details will appear here when finalized).