Privacy Policy
Last updated: August 28, 2026
Record Academy (“we”, “us”, “the platform”) is an online learning platform. This policy explains what personal data we collect when you use Record Academy, why we collect it, who we share it with, and the choices you have. By creating an account you agree to the practices described here.
1. Information we collect
We collect only what we need to run the platform:
- Account details — your name, email address, and a securely hashed password. You may optionally provide a date of birth, gender, and a profile photo.
- Device information — to keep your account secure, we create a device “fingerprint” (a one-way hash derived from your browser and time zone) and record basic device type, operating system, and browser. This is how we limit an account to one device.
- Payment records — when you buy a course, we record the transaction (course, amount in MNT, status, and the payment reference from our payment provider). We never see or store your card, bank, or QR-payment credentials — those are handled entirely by our payment provider.
- Learning activity — your enrollments, module and video progress, assessment attempts and answers, scores, and certificates earned.
- Communications — private messages you send to teachers, comments, discussion-forum posts, and course reviews.
- Security & technical data — login attempts (including IP address) used to detect abuse, an audit log of administrative actions, in-app notifications, and an essential session cookie that keeps you logged in.
2. How we use your information
- To provide the service — deliver courses, track progress, run assessments, and issue certificates.
- To create and secure your account, including verifying your email, enforcing one-device access, and detecting suspicious logins.
- To process course purchases and grant access to paid content.
- To send essential service emails (email verification, password reset, payment receipts, and your certificate) and in-app notifications.
- To respond to your messages and support requests, and to keep the platform safe and lawful.
We do not sell your personal data, and we do not use it for third-party advertising.
3. Cookies
We use a single essential cookie to keep you signed in (your login session). We do not use advertising or third-party tracking cookies. Because the session cookie is essential to the service, the platform will not function without it.
4. Who we share data with
We share data only with the service providers that make the platform work, and only as needed:
- Payment provider (QPay) — to process your course payments. They handle all card/bank data under their own security and privacy terms.
- Email provider — to deliver verification, password-reset, receipt, and certificate emails.
- Cloud storage & hosting providers — to store course media and files and to run the platform’s servers and database.
We may also disclose information where required by law, or to protect the rights, safety, and security of our users and the platform.
5. How we protect your data
- Passwords are stored using strong one-way hashing — no one, including staff, can read your password.
- All access to course content and personal data is enforced on our servers; the browser cannot bypass these checks.
- We never store payment card or bank details.
- Accounts are limited to one device, and access can be revoked immediately if an account is compromised.
- Administrative actions are recorded in an audit log.
- In production, all data is transmitted over encrypted (HTTPS) connections.
No system is perfectly secure, but we take reasonable measures to protect your information.
6. Data retention
We keep your personal data for as long as your account is active. Some records — such as payment transactions and audit logs — may be retained longer where needed for financial, legal, or security purposes. When data is no longer needed, we delete or anonymise it.
7. Your rights
You can:
- Access and update your profile information from your account settings.
- Request a copy of your personal data, or ask us to correct or delete it.
- Ask us to change your registered email if you have lost access to it (handled by an administrator for security).
To exercise any of these rights, contact us using the details below.
8. Children
Some courses on Record Academy are designed for younger learners. Where required by law, an account for a minor should be created and managed by a parent or legal guardian, who accepts this policy and our Terms on the child’s behalf. If you believe a child has provided us personal data without appropriate consent, please contact us and we will address it.
9. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for significant changes, provide notice within the platform.
10. Contact us
Questions about this policy or your data? Contact us at support@recordacademy.com.
