yourtoeflprepyourtoeflprep

Legal

Privacy Policy

How we handle account information, exam responses, speaking recordings, payments, support messages, and service-security data.

Effective 30 July 2026

Website: https://www.yourtoeflprep.com

Effective date: 30 July 2026

1. Who We Are and Scope

Dallakyan Tigran Suren (Դալլաքյան Տիգրան Սուրենի), a sole proprietor registered in the Republic of Armenia under taxpayer identification number (TIN) 73046309, with registered business address at 29 Gyulbenkyan Street, Apt. 13, Yerevan, Armenia ("Operator," "we," "us," or "our"), operates https://www.yourtoeflprep.com and the related online practice and mock examination service (the "Service").

For the personal data described in this Privacy Policy, we are generally the controller or person responsible for deciding why and how it is processed. This Policy applies to website visitors, account holders, students, purchasers, and people who contact us.

It does not govern a third party's independent processing, including the processing that Paddle, a bank, a card network, or another payment provider performs for its own payment, fraud, tax, and legal purposes. Those parties provide their own privacy notices.

2. Personal Data We Collect

Depending on how you use the Service, we may collect the following categories.

2.1 Account and identity data

Name, surname, email address, account identifier, password in hashed form, date of birth, gender if provided, profile image if provided, role, plan, and the versions and timestamps of legal terms you accepted.

2.2 Purchase and transaction data

Product purchased, price, currency, tax amount, date and time, order or receipt number, payment status, refund or dispute status, Merchant-of-Record or gateway identifier, billing country, and limited payment metadata provided by Paddle or the Armenian bank gateway.

We do not store full payment-card numbers or card security codes. Those details are collected and processed by Paddle, ACBA or another Armenian acquiring bank, the ArCa network, the card network, and/or your card issuer.

2.3 Exam and learning data

Exam registrations, attempts, start and completion times, answers, essays, selected responses, scores, subscores, feedback, time spent, integrity signals, and progress history. If speaking tasks are offered, this includes voice recordings and derived scoring or feedback data.

2.4 Device, log, and usage data

IP address, browser type and version, device and operating-system information, language, time zone, approximate location derived from IP, referring page, pages and features used, clicks, session identifiers, timestamps, crash and diagnostic data, and security or fraud signals.

2.5 Communications and support data

Messages, support requests, refund requests, survey responses, complaint records, and other information you choose to send us.

2.6 Cookie and similar-technology data

Identifiers and information collected through cookies, local storage, pixels, SDKs, and similar technologies, as described in Section 12.

3. How We Collect Personal Data

We collect personal data:

  • directly from you when you register, purchase, take an Exam, submit a response, or contact us;
  • automatically from your browser or device when you use the Service;
  • from Paddle, the Armenian bank or ArCa gateway, and other payment or fraud-prevention providers;
  • from a parent, guardian, school, or organization that lawfully arranges access for you; and
  • from service providers that help us operate, secure, measure, and support the Service.

4. Why We Use Personal Data and Our Legal Bases

The legal basis depends on the purpose and the law that applies to you. Where the EU or UK GDPR applies, we rely on the following bases.

4.1 To perform a contract or take requested pre-contract steps

We use account, purchase, exam, and communication data to:

  • create and administer your Account;
  • process and confirm Orders and provide purchased access;
  • deliver Exams, calculate practice scores, and provide feedback and reports;
  • remember progress and maintain your exam history;
  • provide support and administer refunds; and
  • send essential service, security, and transaction communications.

Without necessary account, transaction, and exam data, we may not be able to provide the Service.

4.2 For our legitimate interests or those of another party

Where those interests are not overridden by your rights, we use data to:

  • secure accounts, prevent fraud, enforce exam integrity, and investigate misuse;
  • operate, troubleshoot, test, and improve the Service;
  • understand aggregate usage and service performance;
  • protect our Content, users, systems, and legal rights;
  • manage business records, claims, audits, and corporate transactions; and
  • provide limited marketing for similar services where law permits and you can opt out.

We consider the nature of the data, your reasonable expectations, and safeguards before relying on legitimate interests.

4.3 To comply with legal obligations

We process and retain data where necessary for tax, accounting, consumer-protection, sanctions, anti-fraud, regulatory, court-order, or other legal requirements, and to respond to lawful requests from authorities.

4.4 With your consent

Where required, we rely on consent for non-essential cookies, certain analytics or advertising, optional marketing, or processing that applicable law specifically requires to be consensual. You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.

4.5 To protect vital interests or legal claims

In exceptional cases, we may process data to protect someone's life or safety or to establish, exercise, or defend legal claims.

5. Exam Responses, Voice Recordings, and Scoring

We process your Exam responses to provide the assessment, detect technical or integrity issues, generate scores and feedback, and improve the quality and reliability of our independent practice materials.

Scoring may use rule-based processing, statistical methods, artificial-intelligence-assisted tools, human review, or a combination. Practice scores are educational feedback only. They are not official TOEFL scores and are not used by us to make a decision that produces legal or similarly significant effects concerning you. OpenAI API inputs and outputs are not used to train OpenAI models by default unless the Operator separately opts in; OpenAI may retain limited API data under its then-current service and abuse-monitoring rules.

Where required by law, we will provide meaningful information about a scoring process and a way to ask for human review of a suspected material error. Contact support@yourtoeflprep.com and identify the relevant Exam and result.

Do not include unnecessary sensitive information about health, religion, politics, sexuality, biometrics, criminal matters, or another person's confidential information in a response. We do not intentionally ask for those categories. If an open-ended response incidentally contains such information, we process it only as necessary to deliver and protect the Service and otherwise as permitted by law.

6. Payment Processing and Merchant of Record

For international transactions routed through Paddle, Paddle.com Inc. or another Paddle group company identified at checkout acts as the Merchant of Record and authorized reseller. Paddle independently processes payment, billing, tax, fraud, and transaction data and shares limited data with us so we can fulfill the Order, support you, and maintain records. Paddle's own privacy notice governs its processing.

For local transactions, ACBA or another Armenian acquiring bank, the ArCa network, card networks, and your issuing bank process payment credentials and transaction data. We receive confirmation and limited metadata, not your full card number or security code.

7. How We Share Personal Data

We may share personal data with the following recipients only for legitimate purposes and subject to appropriate contractual, technical, or legal safeguards:

  • Payment and commerce providers: Paddle, ACBA or another Armenian bank gateway, ArCa, card networks, issuers, and fraud-prevention providers;
  • Hosting and infrastructure providers: Vercel for application hosting, Supabase for authentication, database and file storage, and Cloudflare for DNS, security and human-verification services;
  • Exam and scoring providers: OpenAI processes written answers, speaking recordings or transcripts, and the relevant exam rubric to provide transcription, scoring, and educational feedback;
  • Email and messaging providers: Resend and Supabase for authentication and transactional email, Cloudflare Email Routing for inbound aliases, and Google Gmail for the support inbox;
  • Professional advisers: lawyers, accountants, auditors, insurers, and consultants under confidentiality duties;
  • Corporate transaction parties: a prospective or actual buyer, investor, lender, successor, or adviser in a merger, financing, restructuring, or sale, with appropriate protections; and
  • Authorities and other parties: courts, regulators, law enforcement, consumer-protection bodies, or others where disclosure is required by law or reasonably necessary to protect rights, safety, security, and legal claims.

Service providers may use personal data only under our instructions for contracted services unless they are independently responsible for their own processing. We do not sell personal data for money. If we ever use data for targeted advertising or another activity treated as a "sale" or "sharing" under applicable law, we will provide the required notice and opt-out mechanism before doing so.

8. Aggregated and De-identified Data

We may create statistics or de-identified data that does not reasonably identify you. We may use and share it for analytics, research, security, product improvement, and business reporting. We will not attempt to re-identify data that applicable law treats as de-identified, except to test whether our de-identification measures work where legally permitted.

9. International Data Transfers

We are established in Armenia and serve users worldwide. Your personal data may be processed in Armenia and in other countries where our providers or recipients operate. Those countries may have privacy laws different from those where you live.

Where the EU, UK, or another law restricts international transfers, we use a legally recognized transfer mechanism where required. Depending on the transfer, this may include an adequacy decision, approved standard contractual clauses, a legally permitted derogation, or another valid safeguard. We also assess and apply supplementary technical or organizational measures where appropriate.

You may contact support@yourtoeflprep.com for information about the relevant transfer safeguards and, where legally available, a copy of them with confidential information removed.

10. Data Retention

We keep personal data only as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain exam history, comply with law, resolve disputes, prevent fraud, and enforce agreements.

Retention periods vary by category:

  • Account and profile data is generally kept while the Account is active and for a reasonable period after closure to complete deletion, prevent abuse, and address claims;
  • Exam responses, recordings, scores, and feedback are kept for the period disclosed in the Account or reasonably needed to provide history and improve or verify scoring, after which they are deleted or de-identified;
  • transaction, tax, refund, and accounting records are kept for the period required by Armenian and other applicable law and by the relevant Merchant of Record or payment provider;
  • security, integrity, and technical logs are kept for a limited period appropriate to the risk, unless needed for an active investigation or legal claim; and
  • consent and opt-out records are kept as necessary to demonstrate compliance.

When retention is no longer necessary, we delete, anonymize, or securely isolate the data unless continued storage is required by law. Backup copies may persist for a limited cycle and are protected from ordinary use until overwritten.

11. Security

We use reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of the data. These may include access controls, least-privilege permissions, encryption in transit, password hashing, logging, backups, vulnerability management, vendor review, staff confidentiality, and incident-response procedures.

No online service is completely secure. You are responsible for using a strong unique password, protecting your device, and notifying us promptly of suspected unauthorized access. Do not send full card details or passwords by email.

If a personal-data breach occurs, we will investigate, mitigate harm, and notify affected individuals and authorities when applicable law requires it.

12. Cookies, Local Storage, and Similar Technologies

The Service currently uses only technologies needed to operate, secure, and remember the Service. These include Supabase authentication storage, browser local storage and IndexedDB for session state, preferences, exam progress, and resilient local copies, and Cloudflare Turnstile signals used to prevent automated abuse.

We do not currently use advertising cookies, cross-site behavioral advertising, or a separate analytics platform. Because no optional analytics or advertising cookies are currently deployed, the Service does not presently display a non-essential-cookie consent banner. If we introduce non-essential cookies or tracking, we will update this Policy and provide any notice and choice required by applicable law before activating them.

You can clear browser storage or block cookies through your browser, but doing so may sign you out, remove locally saved progress, or prevent security and account features from working.

13. Your Privacy Rights

Subject to applicable law and exceptions, you may have the right to:

  • obtain confirmation of whether we process your personal data and access a copy;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
  • withdraw consent at any time;
  • request information about international-transfer safeguards;
  • obtain human review and express your view where a qualifying solely automated decision has legal or similarly significant effects; and
  • complain to a competent data-protection or consumer-protection authority.

To exercise a right, email support@yourtoeflprep.com with the subject "Privacy Request." Describe your request and the Account email concerned. We may ask for proportionate information to verify identity and authority. We will respond within the period required by applicable law and explain any lawful refusal or extension.

You may use an authorized agent where local law permits. We will not discriminate against you for exercising a privacy right. A request to delete data may result in Account closure or loss of exam history where the data is necessary to provide the Service. We may retain limited data despite a request where law permits or requires it.

For data processed independently by Paddle or another payment provider, you may need to submit the request directly to that provider. We will reasonably assist where the law requires.

EU and EEA complaints

If the EU GDPR applies, you may complain to the supervisory authority in the EU or EEA country of your habitual residence, place of work, or the alleged infringement. We encourage you to contact us first so we can try to resolve the concern.

Armenia complaints

You may also have the right to contact the competent Armenian personal-data-protection authority or seek another remedy under the Law of the Republic of Armenia on Protection of Personal Data.

14. Children's Privacy

The Service is not intended for children under 16, and we do not knowingly permit them to create their own Accounts. A student who is 16 or 17, or otherwise below the legal age of majority where they live, must use the Service with the authorization and supervision required by our Terms of Service and local law.

If we later offer a parent-managed or school-managed service for younger students, we will provide any additional notice and obtain any verifiable parental, guardian, or institutional authorization required before collecting their data.

If you believe a child below the permitted age provided personal data without valid authorization, contact support@yourtoeflprep.com. We will investigate and delete or otherwise handle the data as required by law.

15. Email and Marketing Choices

We send service messages needed for your Account, Orders, Exams, security, and policy changes. You generally cannot opt out of essential messages while keeping an active Account.

We send promotional email only where permitted. You may unsubscribe through the link in a marketing message or by contacting support@yourtoeflprep.com. Opting out of marketing does not stop essential service communications.

16. External Links

The Service may link to websites or services we do not control. Their privacy practices are governed by their own notices. Review those notices before providing data.

17. Changes to This Policy

We may update this Policy to reflect changes in law, technology, providers, or our practices. We will post the revised version with a new effective date. If a change is material, we will provide additional notice or obtain consent where required by law.

18. Contact Us

For privacy questions or requests:

Dallakyan Tigran Suren

Armenian TIN: 73046309

Registered address: 29 Gyulbenkyan Street, Apt. 13, Yerevan, Armenia

Website: https://www.yourtoeflprep.com

Privacy and support email: support@yourtoeflprep.com