Privacy notice
Last changed 17 September 2026
What we hold about you, why, who else sees it, and how to make us delete it. The short version: an email address, what you answered, and what you paid. No advertising, no tracking pixels, and nothing sold to anyone, ever.
1. Who is responsible
Sitonce decides how and why your personal data is used for this service.
For anything in this notice - a copy of your data, a correction, deletion, or a complaint - email [email protected]. A person reads it.
2. What we hold
- Your account
- The email address and display name your sign-in provider gives us, which provider it was and its identifier for you, the country we infer from your connection, and whether you want reminder emails. We never hold a password.
- Your study
- Every question you were shown, what you answered, whether it was right, how long you took, which lessons and lesson steps you have finished, and the exam date you told us. This is the record that makes the product work - readiness, your weakest topics and the review list are all computed from it.
- Your purchases
- What you bought, when, how much, in what currency, and a reference from the payment processor. Card numbers go to Stripe and never reach us.
- Technical
- A session identifier in a cookie, and a one-way hash of the IP address and browser string the session was created from. Rate limiting keys off a hash of your IP. We do not keep raw IP addresses or browser strings against your account.
- Which messages we sent you and whether they were delivered, so we do not send the same reminder twice, plus an unsubscribe record if you opt out.
3. Why we use it, and on what basis
- To run the service
- Signing you in, showing you the right questions, scoring them, keeping your progress. We cannot provide what you asked for without this - it is necessary to perform our contract with you.
- To take payment and give you access
- Also necessary to perform the contract.
- To email you about your exam
- Reminders timed to the sitting date you gave us. You choose this when you sign up and can turn it off in Settings or from any email, instantly.
- To keep the service working and safe
- Rate limiting, fraud prevention, error logs and aggregate counts of how features are used. Our legitimate interest in a service that stays up and is not abused.
- To meet the law
- Keeping records of what was sold and to whom, for as long as tax and accounting rules require.
We do not profile you for advertising, we do not build audiences, and we do not make automated decisions that have a legal effect on you.
4. Cookies
Sitonce sets no advertising or analytics cookies and embeds no third-party trackers. There is no consent banner because there is nothing to consent to.
The cookies we do set are the ones the site cannot work without: one that keeps you signed in, one that protects forms against cross-site request forgery, one that lets a visitor without an account take the diagnostic and keep the result, and a short-lived one during sign-in that stops a third party completing the sign-in on your behalf.
5. Who else sees it
We do not sell personal data and we do not share it for anyone else’s marketing. We do not send it to third-party AI providers or use it to train models.
These companies process data on our behalf, each for one job and nothing else:
- Your sign-in provider
- Google, Microsoft, Apple or WeChat, depending on which you choose. They confirm who you are and give us an email address and a name. We never send them anything about your study.
- Stripe
- Takes the payment and holds the card details. We receive only the result and a reference.
- Our email provider
- Delivers the messages you have asked for. Receives your email address and the message.
- Our hosting provider
- Runs the servers the site and its database sit on.
We will also hand over data where the law requires it, and would tell you unless we are forbidden to.
6. Where it is held
Our servers and database are hosted in a single region. The processors above operate internationally, which means your data may be processed outside the place you live. Where it is, we rely on the contractual protections those providers offer and on their own published safeguards.
7. How long we keep it
- While you have an account
- Your account and study record stay until you ask us to delete them.
- Dormant accounts
- An account with no access purchased and no activity for three years is deleted.
- Purchase records
- Kept for the period needed for accounting, refunds, fraud prevention and disputes. This is the one thing deletion may not remove immediately.
- Unsubscribe records
- Kept indefinitely. It is the only way to be sure we never email you again after you have told us not to.
- Sessions and rate-limit records
- Deleted automatically once they expire.
8. What you can ask us to do
Email [email protected] and we will do any of the following, free, within 30 days:
- See it
- A copy of everything we hold about you.
- Correct it
- Fix anything that is wrong.
- Delete it
- Erase your account and your study record. We keep only the purchase records section 7 explains, and your unsubscribe record if you have one. This cannot be undone and it does not by itself refund a purchase.
- Stop the email
- Turn reminders off. Settings does it immediately, and so does the unsubscribe link in any message; email works too.
- Object, or ask us to hold off
- Object to something we do on the basis of legitimate interest, or ask us to restrict processing while a dispute is sorted out.
We may need to check you are who you say you are before acting, which usually means replying from the address on the account.
9. Security
Sign-in is delegated to established identity providers, so there is no password of yours for us to lose. Sessions are stored hashed, expire, and can all be ended at once from Settings if you have signed in somewhere you no longer control. Card details never reach our systems.
No system is perfectly secure. If a breach affects you we will tell you, and the regulator, as quickly as we can establish what happened.
10. Children
Sitonce is for people preparing for professional licensing examinations and is not aimed at children. We do not knowingly collect data from children, and will delete it if we find we have.
11. Changes, and complaining
If we change this notice in a way that matters, we will email everyone with an account before it takes effect. The date at the top is when the text last changed.
Tell us first - [email protected]. If we cannot put it right, you can complain to the privacy regulator where you live. In Hong Kong that is the Office of the Privacy Commissioner for Personal Data.