Legal

Privacy Policy

This Privacy Policy explains how Ivan Polianskyi (“we,” “us”), operating SmartCode Academy at smartcode.academy, collects, uses, shares, and protects personal information. It applies to visitors, trial users, and subscribers.

Last updated: 26 August 2026

1. Who we are (controller)

Controller: Ivan Polianskyi, sole proprietor (FOP), Ukraine
Address: Zastavna, Chernivtsi Oblast, Ukraine
Email: smartcodeacademy@gmail.com
Phone: +380 96 957 67 23

For payment transactions, Paddle acts as an independent Merchant of Record / data controller for billing data it collects at checkout. See Paddle’s Privacy Policy: https://www.paddle.com/legal/privacy.

2. Scope

This Policy covers the website, account area, learning platform, and related communications. It does not cover third-party sites we link to (including Discord community servers operated under Discord’s terms).

3. Information we collect

Account & profile: name or display name, email address, password (hashed), locale/language preference, selected program(s), and account status.

Learning data: course progress, lesson completion, quiz or exercise activity, and similar product-usage events needed to deliver the Service.

Support: messages you send to us, and related metadata (timestamps, ticket context).

Technical data: IP address, browser/device type, approximate location derived from IP, pages viewed, referrer, and diagnostic logs. We use this for security, debugging, and basic product analytics.

Payment data: collected and processed by Paddle. We may receive limited billing metadata from Paddle (e.g. subscription status, plan, renewal dates, country for tax, last four digits or payment method type, transaction IDs). We do not store full card numbers.

Community: if you join our Discord (or similar) community, Discord processes your Discord username and messages under Discord’s privacy policy; we may see membership status to grant access benefits.

Marketing / lead forms (if used): if you submit a lead form (including Meta/Facebook or similar), we receive the contact details you provide for follow-up. Those platforms also process data under their policies.

4. How we use information (purposes & legal bases)

We process personal data to:

  • Provide the Service (account, access, progress) - contract performance (GDPR Art. 6(1)(b)).
  • Process subscriptions via Paddle - contract / legitimate interests in fulfilling orders.
  • Send transactional email (receipts via Paddle, security alerts, service notices) - contract / legitimate interests.
  • Customer support - contract / legitimate interests.
  • Security, fraud prevention, abuse detection - legitimate interests (Art. 6(1)(f)).
  • Improve the product (aggregated or pseudonymized analytics) - legitimate interests.
  • Marketing emails (if you opt in, or where soft opt-in is allowed) - consent or legitimate interests; you can unsubscribe anytime.
  • Legal compliance (tax, accounting, responding to lawful requests) - legal obligation (Art. 6(1)(c)).

5. Cookies and similar technologies

We use essential cookies and local storage required for login, session security, locale preference, and checkout handoff. We do not currently use non-essential advertising cookies on the core learning site. If we add analytics or marketing cookies that require consent under applicable law, we will present a consent mechanism before setting them.

You can control cookies through your browser settings. Blocking essential cookies may break login or checkout.

6. Sharing and processors

We share personal data only as needed:

  • Paddle - payments, invoicing, tax, fraud screening, subscription management (Merchant of Record).
  • Hosting & infrastructure - cloud hosting providers that store application and database data under our instructions.
  • Email delivery - transactional and (if applicable) marketing email providers.
  • Discord - if you choose to join community channels.
  • Professional advisors - accountants, lawyers, under confidentiality.
  • Authorities - when required by law or to protect rights, safety, and security.
  • Business transfers - in a merger, acquisition, or asset sale, subject to appropriate safeguards.

We do not sell personal information for money. We do not “share” personal information for cross-context behavioral advertising as defined under the California CPRA, unless we disclose otherwise and offer required opt-outs.

7. International transfers

We are based in Ukraine and use service providers that may process data in the United States, European Economic Area, United Kingdom, or other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) or other lawful transfer mechanisms offered by our providers.

8. Retention

  • Account & learning data: kept while your account is active. After you request deletion or the account is closed, we delete or anonymize within 30 days, except data we must retain longer (below).
  • Billing & tax records: typically retained up to 7 years (or longer if required by law), often via Paddle’s systems.
  • Support correspondence: up to 24 months after closure of the request, unless needed longer for disputes.
  • Security logs: typically 90 days, longer if investigating an incident.

9. Security

We use industry-standard measures appropriate to the risk, including HTTPS, hashed passwords, access controls, and least-privilege practices. No method of transmission or storage is 100% secure. Notify us promptly of suspected unauthorized access at smartcodeacademy@gmail.com.

10. Your rights

Depending on your location (including GDPR/UK GDPR and CCPA/CPRA), you may have rights to:

  • access a copy of your personal data;
  • correct inaccurate data;
  • delete data (subject to legal exceptions);
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is consent-based;
  • opt out of sale/sharing (we do not sell; see Section 6) and certain profiling where applicable;
  • lodge a complaint with a supervisory authority.

To exercise rights, email smartcodeacademy@gmail.com. We will verify your request and respond within the time required by law (generally 30 days under GDPR; 45 days under CCPA, extendable as permitted). Authorized agents may submit CCPA requests with proof of authority.

California “Do Not Sell or Share My Personal Information”: we do not sell or share personal information as those terms are defined in the CPRA for cross-context behavioral advertising. If that changes, we will update this Policy and provide a clear opt-out link.

Nevada / other US state laws: we do not sell covered information as defined under Nevada SB 220. Residents of other US states with privacy laws may contact us to exercise applicable rights.

11. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). Users under 16 (or higher local digital-consent age) should use the Service only with appropriate parental/guardian involvement where required. If you believe we collected a child’s data, contact us for deletion.

12. Automated decision-making

We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Fraud checks by Paddle may be automated as part of payment processing; see Paddle’s policies for details.

13. Changes

We may update this Privacy Policy. The “Last updated” date will change. Material changes will be communicated by email or a prominent notice where appropriate.

14. Contact / complaints

Privacy questions and requests: smartcodeacademy@gmail.com
Ivan Polianskyi, Zastavna, Chernivtsi Oblast, Ukraine

EEA/UK users may also complain to their local data protection authority. You may contact us first so we can try to resolve the issue.