Privacy Policy
Last updated: 2026-10-06
1. Summary
We collect as little personal data as possible. To give you paid access we need your email address and a record of your purchase. We use one strictly necessary cookie to keep you signed in. Your study progress stays in your own browser and is never sent to us. We do not use advertising, analytics trackers or profiling, and we do not sell your data. We do not send marketing emails unless you ask for them.
This policy explains in detail which personal data we process, why, on which legal basis, with whom we share it, how long we keep it and what your rights are under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
2. Who is responsible for your data
The controller of your personal data is Taimur Ali, an individual, Office No. 789, Deans, Peshawar, Khyber Pakhtunkhwa, Pakistan ("we", "us").
For any question about privacy or to exercise your rights, contact us at 207yaseena6@gmail.com. We have not appointed a data protection officer because we are not legally required to do so.
Paddle.com Market Limited ("Paddle"), which sells our access as merchant of record, is a separate controller for the personal data it processes for payment, fraud prevention, tax and invoicing. Paddle's processing is governed by its own privacy notice (paddle.com/legal/privacy).
3. Which data we process, why and on which legal basis
Visiting the website (all visitors)
- Data: your IP address, browser type, requested page, date and time, and similar technical data that your browser sends with every request.
- Purpose: delivering the web pages, protecting the website against attacks and abuse (for example denial-of-service protection by our hosting provider), and diagnosing technical errors.
- Legal basis: our legitimate interest in providing a secure and working website (article 6(1)(f) GDPR).
Buying access
- Data: your email address; the plan you bought; the date and time of purchase; the start and end of your access period; the Paddle transaction and customer identifiers; and the order status that Paddle reports to us (for example completed, refunded or charged back). Depending on the information Paddle shares with us, this may also include your country and the amount paid. We never receive your full card or bank details.
- Purpose: concluding and performing the contract, unlocking your access for the correct period, answering your questions, and handling complaints, withdrawals and refunds.
- Legal basis: performance of a contract with you and steps taken at your request before concluding it (article 6(1)(b) GDPR).
Your record of acceptance
- Data: the date and time at which you ticked the acceptance checkboxes before payment, the version of the Terms you accepted, and your email address.
- Purpose: proving that the contract was correctly concluded and that you gave the request and acknowledgement concerning the right of withdrawal.
- Legal basis: our legitimate interest in being able to prove our compliance and to establish, exercise or defend legal claims (article 6(1)(f) GDPR), and compliance with our legal obligations under consumer law (article 6(1)(c) GDPR).
Signing in
- Data: your email address; a single-use sign-in token and a session token, which we store only in hashed form; the time they were created and when they expire.
- Purpose: sending you sign-in links by email and keeping you securely signed in, without passwords.
- Legal basis: performance of the contract (article 6(1)(b) GDPR).
Preventing abuse
- Data: your IP address and email address, used as counters for the number of sign-in and other requests in a short time window.
- Purpose: limiting the number of requests to protect the Service and its users against abuse, spam and brute-force attacks, and detecting shared or fraudulently used access.
- Legal basis: our legitimate interest in securing the Service and protecting our content (article 6(1)(f) GDPR).
Communicating with you
- Data: your email address, the content of your messages and our replies, and any attachments you send us (for example screenshots supporting a technical problem report).
- Purpose: answering your questions, handling complaints, error reports, refund requests and requests to exercise your rights.
- Legal basis: performance of the contract (article 6(1)(b) GDPR) where your message concerns your purchase; otherwise our legitimate interest in answering you (article 6(1)(f) GDPR); and our legal obligation to answer requests to exercise your rights (article 6(1)(c) GDPR).
Service emails
- We send you emails that are necessary for the Service, such as sign-in links, the purchase confirmation, and important notices about your access or about changes to these documents. These are not marketing. Legal basis: performance of the contract (article 6(1)(b) GDPR) and legal obligations (article 6(1)(c) GDPR).
- We send marketing emails (for example news or offers) only if you have separately asked for them; you can withdraw that consent at any time, with effect for the future, through the link in each such email or by contacting us. Legal basis: your consent (article 6(1)(a) GDPR).
Legal and accounting obligations, and disputes
- Data: purchase records and correspondence.
- Purpose: complying with our accounting and tax obligations, and establishing, exercising or defending legal claims.
- Legal basis: legal obligation (article 6(1)(c) GDPR) and our legitimate interest (article 6(1)(f) GDPR).
Where we rely on legitimate interest, we have balanced our interest against your rights and limited the data to what is necessary. You can object to this processing at any time (see section 9).
Providing your email address is necessary to buy and use paid access. Without it we cannot conclude or perform the contract. You can use the free content without giving us any personal data other than the technical data that every website visit involves.
4. Study progress stays on your device
Your answers, scores, progress and preferences (such as your language) are stored only in your browser's local storage on your own device. This data is never sent to us, and we cannot see, restore or delete it. You can delete it at any time by clearing your browser's site data for drivingtheorypractice.online. Because this information is only stored on your device for the functionality you request, it does not require consent under the rules on cookies and similar technologies.
5. Cookies and similar technologies
We use only one cookie, which is strictly necessary:
- Name: dt_session. Purpose: keeps you signed in after you have used a sign-in link, so that we can show you the Paid Content you bought. Type: first-party, HttpOnly, secure. Duration: up to 60 days, or until you sign out.
Because this cookie is strictly necessary for a service you have explicitly requested, it does not require your consent (article 10/2 of the Belgian Act of 13 June 2005 on electronic communications, implementing article 5(3) of the ePrivacy Directive). We do not use advertising, analytics, social media or other tracking cookies. If we ever wish to use non-essential cookies, we will first ask for your consent.
Our hosting provider Cloudflare may set technical cookies of its own that are strictly necessary for security and bot protection.
6. Who receives your data
We do not sell or rent your personal data, and we do not share it for advertising. We share it only with the following service providers, to the extent necessary for the purposes described above:
- Paddle.com Market Limited (United Kingdom), and its group companies, as merchant of record and independent controller for payment, fraud prevention, tax and invoicing. Paddle tells us that a purchase was made and which email address and plan it concerns.
- Cloudflare, Inc. (United States) and its affiliates, as our processor for hosting the website and our application (Cloudflare Workers), storing our database (Cloudflare D1) and data used for rate limiting and sessions (Cloudflare KV), and for network security and protection against attacks.
- Resend (Plus Five Five, Inc., United States), as our processor for sending transactional emails such as sign-in links and purchase confirmations. Resend receives your email address and the content of the email.
- Google (Gmail), the email service used for the contact address, as our processor for receiving and answering your emails.
We have concluded data processing agreements with our processors as required by article 28 GDPR. We may also disclose data where required by law, by a court order or to a competent authority, or where necessary to establish, exercise or defend legal claims, for example to our lawyer or accountant, who are bound by professional secrecy. If the Service is transferred to another operator, your data may be transferred to that operator, which will be bound by this policy; we will inform you in advance.
7. Transfers outside the European Economic Area
Some of our providers are located, or may process data, outside the European Economic Area:
- United Kingdom (Paddle): the European Commission has decided that the United Kingdom offers an adequate level of protection (adequacy decision).
- United States (Cloudflare, Resend, Google): transfers rely on the EU-US Data Privacy Framework adequacy decision for providers certified under it, and otherwise on the standard contractual clauses approved by the European Commission, together with additional measures where needed (such as encryption in transit and the storage of sign-in and session tokens in hashed form only).
You can request more information about these safeguards, or a copy of them, by contacting us.
8. How long we keep your data
- Sign-in links: until used or for 15 minutes, whichever is shorter; the expired record is deleted shortly afterwards.
- Sessions: until you sign out or the session expires (at the latest after 60 days), after which the record is deleted.
- Rate-limiting counters: for the short time window they measure (normally up to one hour), and at most [24 HOURS].
- Email address, access dates and acceptance record (your account): for as long as you have access, and then for [24 MONTHS] after your last access ended, so that you can see your purchase history, buy again with the same address and so that we can handle complaints and claims. After that period we delete or anonymise them, unless a longer period is required below.
- Purchase records needed for our accounting and tax obligations (plan, date, amount, Paddle transaction identifier): for the period required by Belgian accounting law, currently up to 10 years from the end of the financial year concerned.
- Correspondence: up to [3 YEARS] after the matter has been closed, or longer if needed for a pending dispute.
- Technical logs at our hosting provider: for the short period determined by that provider for security and error diagnosis, normally a few days.
If a dispute or legal claim is pending, we may keep the relevant data until it is finally resolved.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have incorrect data corrected;
- have your data erased, unless we must keep it, for example for accounting obligations or a pending claim;
- restrict the processing of your data in certain cases;
- receive the data you provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller (data portability);
- object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest; and object at any time, without giving reasons, to the use of your data for direct marketing;
- withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of processing before the withdrawal.
To exercise your rights, send an email from the email address linked to your access to 207yaseena6@gmail.com. If we have reasonable doubts about your identity, we may ask for additional information, but we will never ask for more than necessary. We answer within one month of receiving your request; this period can be extended by two further months for complex or numerous requests, in which case we will tell you within the first month. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.
Note that erasing your email address also ends any active paid access linked to it, because we can then no longer recognise you. We will tell you this before erasing.
10. Right to complain
If you think that we process your personal data unlawfully, you can lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels, Belgium, telephone +32 2 274 48 00, email contact@apd-gba.be, website www.dataprotectionauthority.be. You can also complain to the data protection authority of the EU country where you live or work, or where the alleged infringement took place. We would appreciate the opportunity to address your concern first, so please feel free to contact us beforehand.
11. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- encrypted connections (HTTPS/TLS) for all traffic to the website and between our systems;
- passwordless sign-in through single-use links that expire after 15 minutes, so that there are no passwords to steal;
- storing sign-in and session tokens only as cryptographic hashes, so that they cannot be used even if our database were exposed;
- session cookies that cannot be read by scripts (HttpOnly) and are only sent over secure connections;
- rate limiting and protection against automated attacks;
- limiting access to personal data to the persons who need it, and using reputable providers bound by data processing agreements;
- collecting as little data as possible, and keeping study progress on your device rather than on our servers.
No system is perfectly secure. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay, and we will notify the Data Protection Authority where required.
12. Children
The Service is intended for people preparing for the driving theory exam. Paid access can be bought by persons aged 16 or older; younger users may use the Service only through a parent or legal guardian who makes the purchase (see our Terms and Conditions). Our processing is based on the performance of the contract and on legitimate interest, not on consent; where we would rely on consent for an online service offered directly to a child, Belgian law requires the consent of a parent or guardian for children under 13. We do not knowingly collect personal data from children under 16 other than through a parent or guardian. If you believe a child has provided us with personal data without the involvement of a parent or guardian, please contact us and we will delete it.
13. No automated decision-making
We do not take decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Our automatic rate limits only temporarily delay excessive requests; if you believe you have been blocked wrongly, contact us and a person will review it.
14. Changes to this policy
We may update this policy, for example when we change providers or features or when the law changes. The current version is always available on this page with its date. If a change materially affects how we process your data, we will inform customers with active access by email before it takes effect.