Privacy Policy

PATHTO1600 PRIVACY POLICY Last Updated: April 19, 2026 At pathto1600, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational platform and services. Please read this policy carefully. By using pathto1600, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use our services. NOTICE AT COLLECTION At or before the time of collection, we provide notice of the categories of personal information we collect and the purposes for which we use it. This Privacy Policy serves as that notice. We collect the following categories of personal information: - Identifiers (name, email address, username, IP address) - Commercial information (purchase history, payment information) - Internet/network activity (browsing history, usage patterns, device information) - Education information (user-generated content, progress data, test responses) - Inferences (learning preferences, predicted performance) 1. INFORMATION WE COLLECT 1.1 Personal Information You Provide Directly We collect information that you voluntarily provide to us: Account Registration: Name, email address, username, password, age/date of birth (to verify you are 13 or older) Payment Information: Billing name, billing address, payment card information (processed by our third-party payment processor) User-Generated Content: Practice test responses, study notes, comments, forum posts, progress data, performance metrics Communications: Messages sent to customer support, survey responses, feedback 1.2 Information Collected Automatically When you access our services, we automatically collect: Device Information: IP address, browser type and version, operating system, device identifiers, screen resolution Usage Data: Pages viewed, features accessed, time spent on pages, click patterns, session duration, referring URLs, search queries within our site Log Data: Access times, error logs, crash reports, server requests Cookies and Tracking Technologies: See Section 6 for detailed information about our use of cookies and similar technologies 1.3 Information from Third-Party Sources We may receive information from: - Payment processors (transaction verification, fraud detection) - Analytics providers (aggregated usage statistics) - Advertising networks (if you interact with our ads on other platforms) - Social media platforms (if you choose to link your account) 2. SOURCES OF PERSONAL INFORMATION In the preceding 12 months, we have collected personal information from the following categories of sources: - Directly from you (account registration, purchases, content submissions) - Automatically through your use of our services (cookies, analytics) - From third-party service providers (payment processors, analytics platforms) - From publicly available sources (if you engage with us on social media) 3. HOW WE USE YOUR INFORMATION We use personal information for the following business and commercial purposes: Service Provision: To provide, operate, maintain, and improve our educational platform, process transactions, manage your account, enable core features, track your progress Personalization: To customize content recommendations, adapt difficulty levels, provide personalized study plans based on your performance Communication: To send transactional emails (account notifications, password resets, purchase confirmations), respond to support requests, provide customer service Marketing: To send promotional emails and offers (with your consent), which you may opt out of at any time using the unsubscribe link in any marketing email or by contacting us Analytics and Improvement: To analyze usage patterns, measure effectiveness of features, conduct A/B testing, develop new products and services Security: To detect and prevent fraud, abuse, security incidents, and other harmful activity; to verify accounts and activity; to monitor and improve security Legal Compliance: To comply with legal obligations, respond to lawful requests, enforce our Terms of Service, protect our rights and property 4. HOW WE SHARE YOUR INFORMATION We do not sell your personal information for monetary consideration. We do not share your personal information for cross-context behavioral advertising. We may disclose personal information to the following categories of third parties: 4.1 Service Providers and Vendors We share personal information with third-party service providers who perform services on our behalf, including: Payment Processing: Stripe, PayPal (transaction processing, fraud detection, billing) Cloud Hosting and Storage: AWS, Google Cloud Platform (data storage, server infrastructure) Analytics Services: Google Analytics (usage analysis, performance monitoring) Email Service Providers: SendGrid, Mailchimp (transactional and marketing emails) Customer Support Tools: Zendesk, Intercom (help desk, live chat) These service providers are contractually obligated to use your personal information only to provide services to us, to maintain confidentiality, and to comply with applicable privacy laws. 4.2 Legal Requirements and Protection We may disclose personal information when required by law or when we believe in good faith that disclosure is necessary to: - Comply with a legal obligation, court order, or subpoena - Protect and defend our rights or property - Prevent or investigate possible wrongdoing in connection with our services - Protect the personal safety of users or the public - Protect against legal liability 4.3 Business Transfers If pathto1600 is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your personal information may be transferred as part of that transaction. We will provide notice via email and/or a prominent notice on our website before your information becomes subject to a different privacy policy. 4.4 With Your Consent We may share your personal information for any other purpose disclosed to you at the time of collection or with your explicit consent. 5. DATA SECURITY We implement reasonable technical, administrative, and physical security measures designed to protect your personal information. Current security measures include: - Encryption of data in transit using TLS/SSL protocols - Encryption of sensitive data at rest - Secure server infrastructure with access controls - Regular security assessments and vulnerability testing - Authentication and authorization procedures - Employee training on data protection and security best practices However, no method of transmission over the Internet or electronic storage is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials. 6. DATA RETENTION We retain personal information for different periods depending on the type of data and purpose for which it was collected: Account Data: We retain your account information (name, email, username) for as long as your account is active, plus 90 days after account deletion to allow for account recovery Purchase Records: Transaction data and payment information are retained for 7 years to comply with tax and financial regulations User-Generated Content: Practice responses, study notes, and progress data are retained while your account is active and deleted within 30 days of account deletion Support Communications: Customer service tickets and messages are retained for 3 years for quality assurance and training purposes Analytics and Log Data: Aggregated, anonymized usage data may be retained indefinitely for analytics; identifiable log data is retained for 12 months for security monitoring Marketing Data: Email marketing lists and opt-out records are maintained indefinitely to honor your preferences Legal Hold Data: Information subject to legal holds, litigation, or regulatory investigation is retained as required by law When personal information is no longer needed for its original purpose and retention is not legally required, we securely delete or anonymize it. 7. COOKIES AND TRACKING TECHNOLOGIES 7.1 What Are Cookies Cookies are small text files stored on your device that help websites remember information about your visit. We use both session cookies (which expire when you close your browser) and persistent cookies (which remain until deleted or expire). 7.2 Types of Cookies and Tracking Technologies We Use Strictly Necessary Cookies (Always Active): - Authentication and session management - Security features and fraud prevention - Core platform functionality Analytics Cookies (Can Be Disabled): - Google Analytics: Tracks page views, session duration, user paths, demographics - Mixpanel: Monitors feature usage and user engagement - Hotjar: Records anonymized session replays and heatmaps Functionality Cookies (Can Be Disabled): - Remember your preferences and settings - Store progress in multi-step processes - Enable personalized content recommendations Advertising/Marketing Cookies (Opt-Out Available): - Facebook Pixel: Currently not active (will notify if implemented) - Google Ads Conversion Tracking: Currently not active (will notify if implemented) - Retargeting Pixels: Currently not active (will notify if implemented) 7.3 Managing Cookies You can control cookies through: Cookie Preferences: Click the "Cookie Settings" link in our website footer to manage your preferences for non-essential cookies Browser Settings: Most browsers allow you to refuse or delete cookies through their settings. Note that blocking strictly necessary cookies may prevent you from using certain features of our services Google Analytics Opt-Out: Install the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout Do Not Track: Our website does not currently respond to Do Not Track (DNT) signals 8. YOUR PRIVACY RIGHTS Depending on your location, you may have certain rights regarding your personal information. We are committed to honoring these rights. 8.1 Rights Available to All Users Access: Request access to the personal information we hold about you Correction: Request correction of inaccurate or incomplete information Deletion: Request deletion of your personal information (subject to certain legal exceptions) Portability: Request a copy of your data in a portable, machine-readable format Opt-Out of Marketing: Unsubscribe from marketing emails at any time using the unsubscribe link in any marketing email or by contacting us at [email] 8.2 How to Exercise Your Rights To exercise your privacy rights: Email: Send your request to privacy@pathto1600.com Online Form: Submit a request through our Privacy Request Form at pathto1600.com/privacy-request Account Settings: Access, update, or delete certain information directly through your account settings 8.3 Verification Process To protect your privacy, we will verify your identity before processing rights requests. Verification may require: - Matching at least 2-3 data points you provide with information in our records - Confirming access to the email address associated with your account - For deletion requests, additional verification may be required 8.4 Response Timeline We will respond to verified requests within 45 days of receipt. If we need additional time (up to 90 days total), we will notify you of the reason and extension period. We will deliver our response electronically unless you request otherwise. 8.5 Authorized Agents You may designate an authorized agent to submit requests on your behalf. The agent must provide proof of authorization, and we may require you to verify your identity directly with us. 8.6 Right to Appeal If we decline your request, you have the right to appeal our decision by contacting us at privacy@pathto1600.com within 45 days. We will respond to your appeal within 45 days. 9. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA) If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). 9.1 Categories of Personal Information Collected In the preceding 12 months, we have collected the following categories of personal information: - Identifiers: Name, email address, username, IP address, device identifiers - Commercial Information: Purchase history, transaction data, payment card information - Internet/Network Activity: Browsing history, search history, interaction with our website - Education Information: Test responses, study progress, performance metrics - Inferences: Learning preferences, predicted performance levels 9.2 Categories of Third Parties We disclose personal information to the following categories of third parties for business purposes: - Payment processors (commercial information) - Cloud service providers (all categories as needed for hosting) - Analytics providers (identifiers, internet activity) - Email service providers (identifiers) - Customer support platforms (identifiers, commercial information) 9.3 Sale and Sharing of Personal Information We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising. 9.4 Sensitive Personal Information We do not collect or process sensitive personal information as defined by CPRA (such as social security numbers, financial account credentials, precise geolocation, racial/ethnic origin, religious beliefs, or health data). 9.5 California-Specific Rights Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the categories of sources, business purposes, and third parties with whom we share information Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions Right to Correct: Request correction of inaccurate personal information Right to Opt-Out: While we do not currently sell or share personal information, if we were to do so in the future, you would have the right to opt out Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. We will not deny services, charge different prices, provide different quality of service, or suggest you will receive different pricing or service quality 9.6 Retention Periods by Category Identifiers: Duration of account plus 90 days Commercial Information: 7 years from transaction date Internet Activity: 12 months (anonymized data may be retained longer) Education Information: Duration of account plus 30 days 10. OTHER U.S. STATE PRIVACY RIGHTS If you are a resident of Virginia, Colorado, Connecticut, Utah, or other states with comprehensive privacy laws, you may have similar rights to those described in Section 9. These may include the right to access, correct, delete, and obtain a copy of your personal information, as well as the right to opt out of certain processing activities. Contact us at privacy@pathto1600.com to exercise your rights. 11. CHILDREN'S PRIVACY (COPPA COMPLIANCE) 11.1 Age Requirements Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. You must be at least 13 years old to create an account. 11.2 Age Verification During account registration, we require users to confirm they are at least 13 years old. If you are under 18, you represent that you have obtained permission from your parent or legal guardian to use our services. 11.3 Parental Rights If you are a parent or guardian and believe your child under 13 has provided personal information to us, please contact us immediately at privacy@pathto1600.com. We will: - Verify your relationship to the child - Provide you with a description of the information collected - Give you the opportunity to refuse further collection or use - Delete the information from our systems 11.4 Discovery and Deletion Process If we discover that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as quickly as possible, typically within 48 hours of discovery. 12. THIRD-PARTY LINKS AND SERVICES Our services may contain links to third-party websites, applications, or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. When you click on a third-party link or access a third-party service, that third party's terms and privacy policy govern. We encourage you to review the privacy policy of every website you visit or service you use. We are not responsible for the privacy practices or content of third-party websites or services, even if they are linked from our platform. 13. INTERNATIONAL USERS Our services are operated in the United States and intended for users located in the United States. If you are accessing our services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States where our servers are located and our central database is operated. By using our services, you consent to the transfer of your information to the United States. Data protection and privacy laws in the United States may differ from those in your country of residence. 14. CHANGES TO THIS PRIVACY POLICY We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will: - Update the "Last Updated" date at the top of this policy - Post the updated policy on our website - Send you an email notification at the email address associated with your account - Display a prominent notice on our website for at least 30 days For non-material changes, we will update the policy and revise the "Last Updated" date. We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes become effective constitutes your acceptance of the revised policy. 15. CONTACT INFORMATION If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us: pathto1600 Contact Email: support@pathto1600.com Website: pathto1600.com We are committed to protecting your privacy and will respond to all inquiries within 45 days. For California residents exercising CCPA rights, we will respond within the timeframes required by law. IMPORTANT LEGAL DISCLAIMER This Privacy Policy should be reviewed by a qualified attorney before publication. Privacy laws vary by jurisdiction and evolve frequently. Ensure all disclosures match your actual data practices and technical implementation.