Skip to main content

Privacy Policy

Last updated: May 1, 2026

1. Introduction

CSTQ.ca ("we", "us", "our"), accessible at cstq.ca (operated from Canada), processes personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. This policy describes what personal information we collect and how we use it.

2. Information We Collect

Information you provide:

  • Account information: When you sign in with Google or Apple, we receive your name, email address, and profile picture as provided by the authentication provider.
  • Language preferences: Your selected display language and official test language.
  • Payment information: Payment is processed by Stripe. We do not store your credit card number, CVV, or full payment details on our servers. We receive only a confirmation of payment status and a Stripe customer ID.
  • Reviews: If you submit a review or rating, we collect the content of your review, your rating, and your name (if logged in).

Information collected automatically:

  • Usage data: Practice and mock exam results (scores, category breakdowns, timestamps) to provide your analytics dashboard.
  • Log and device data: When you access our service, we automatically record your IP address, approximate location (city, province, and country derived from IP address), device type (mobile, tablet, or desktop), browser type, operating system, and the pages you visit. This information is collected for the following purposes:
    • Security and fraud prevention: To detect unauthorized access, prevent abuse, and protect against payment fraud.
    • Dispute resolution: To provide evidence of service usage in the event of a payment dispute or chargeback, as required by payment processors (Stripe, Visa, Mastercard).
    • Service improvement: To understand how our service is used and identify technical issues.
    • Legal compliance: To comply with applicable laws and respond to lawful requests.
  • Cookies: We use the following categories of cookies:
    • Essential cookies (always active): language preferences, referral code (set only when you arrive via a referral link, kept for a limited period to apply the discount), cookie consent preference, and authentication session tokens. These are necessary for the site to function or to deliver a service you explicitly requested.
    • Analytics cookies (require your consent): Aggregated pageview counts, traffic sources, anonymous device statistics, session recordings, and heatmaps (Google Analytics 4, Microsoft Clarity).
    • Advertising cookies (loaded with your consent): Our free practice zone displays advertisements served by a third-party advertising network. When you accept non-essential cookies, the advertising network may set third-party cookies to serve personalized ads and measure ad performance. These cookies are set and controlled by the advertising network, not by us. Advertisements are displayed only in our free practice zone; paid users do not see ads.
    • Conversion tracking (loaded with your consent): When you accept non-essential cookies, a third-party conversion tracking script is also loaded. If you arrived at our site from a search ad, the conversion tracking service may set third-party cookies to measure whether you completed a purchase. See Section 4 for details.

    Cookie consent: Analytics, advertising, and conversion tracking scripts are typically loaded after you grant consent through our cookie banner. When you decline, anonymized signals (no cookies, no user identifiers) may still be sent to our analytics provider for aggregate measurement only. You can change your cookie preferences at any time using the "Cookie Preferences" link in the footer.

3. How We Use Your Information

We use your information to:

  • Provide and maintain your account
  • Process payments and manage your purchase
  • Display your practice and exam analytics
  • Remember your language preferences
  • Communicate with you about your account or service updates
  • Detect and prevent fraud, unauthorized access, and payment disputes
  • Improve our service and fix technical issues

Automated decisions: We use automated systems to determine refund eligibility based on objective usage criteria (days since purchase, exams completed, questions answered). You may have certain rights regarding automated decisions under applicable law. For inquiries, contact support@cstq.ca.

4. Third-Party Services

We use the following third-party services:

  • Google Sign-In / Apple Sign-In: For authentication. Subject to Google's Privacy Policy and Apple's Privacy Policy.
  • Stripe: For payment processing. Stripe is PCI DSS Level 1 certified. We do not store or process payment card numbers on our servers. In the event of a payment dispute or chargeback, we may share your name, email address, IP addresses, device information, and account activity data with Stripe and the applicable payment card network (e.g., Visa, Mastercard) to respond to the dispute. Subject to Stripe's Privacy Policy.
  • Google Analytics: Collects aggregated pageview counts, traffic sources, and anonymous device statistics. Subject to Google's Privacy Policy.
  • Microsoft Clarity: Collects session recordings and heatmaps to help us understand how visitors interact with our site. Subject to Microsoft's Privacy Statement.
  • Advertising network: A third-party advertising network displays advertisements in our free practice zone and may collect information about your browsing activity to serve relevant ads. Advertisements are displayed only in the free practice zone; paid users do not see ads.
  • Google Ads (conversion tracking): Google Ads may set cookies to measure whether visitors arriving from search ads completed a purchase. Subject to Google's Privacy Policy.

5. Data Storage and Security

We use commercially reasonable security measures. Personal information may be processed outside Quebec or outside Canada by our service providers. No method of electronic storage or transmission is fully secure, and we cannot and do not guarantee the security of any data transmitted or stored.

6. Data Retention

Personal information is retained for as long as necessary for the purposes described in this Policy, and to comply with applicable legal, tax, regulatory, contractual, and dispute resolution obligations. Following an account deletion request, we will take reasonable steps to delete personal data within a reasonable time.

7. Your Rights

Under PIPEDA and applicable privacy laws, you have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate personal information.
  • Deletion: Request deletion of your account and personal data.
  • Withdraw consent (subject to legal and contractual restrictions): Withdraw your consent to our processing of your data, subject to applicable legal or contractual restrictions; withdrawal may prevent us from continuing to provide some or all of the service to you.
  • Data portability (Quebec residents only, under Law 25): Request to receive your personal information in a structured, commonly used technological format, or request that it be communicated to another organization.
  • De-indexation (Quebec residents only, under Law 25): Request the cessation of dissemination of your personal information or the de-indexation of any hyperlink providing access to it, where dissemination contravenes the law or a court order.

To exercise any of these rights, contact us at support@cstq.ca. We will respond within 30 days, with a possible 30-day extension as permitted by PIPEDA s. 8(3). We may decline a request that is frivolous, vexatious, made in bad faith, or that would unduly affect another person's privacy, as permitted by PIPEDA. We may require verification of your identity before processing a request.

8. Electronic Communications (CASL)

We comply with Canada's Anti-Spam Legislation (CASL). We may send you emails that are transactional or account-related, that notify you of changes to our Terms or Privacy Policy, or that are otherwise permitted under CASL (including under the existing business relationship exemption following a purchase or other CASL exemptions). You may unsubscribe from any commercial electronic message we send by following the unsubscribe instructions in that message. Email addresses collected via our contact form are used to respond to your inquiry and for related follow-up.

9. Data Breach Notification

In the event of a breach involving your personal information that creates a real risk of significant harm, we will notify affected individuals, the Office of the Privacy Commissioner of Canada, and the Commission d'accès à l'information du Québec, as soon as feasible, as required by PIPEDA's Breach of Security Safeguards Regulations and Quebec's Act respecting the protection of personal information in the private sector.

10. Changes to This Policy

We may update this policy from time to time. We may post updates by changing the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or requests, please contact us or email support@cstq.ca.

Our Privacy Officer can be reached at support@cstq.ca for any questions about our privacy practices.