Privacy Policy
Last updated July 30, 2026
This Privacy Policy describes how CompStart (compstart.pro and related sites, apps, and services—the “Services”) collects, uses, stores, and shares personal information.
Privacy requests and questions: https://compstart.pro/contact
By using the Services, you acknowledge this policy. If you do not agree, do not use the Services.
1. Scope
This policy applies to:
- The CompStart website and localized versions
- Accounts, authentication, sessions, and profile settings
- Courses, lessons, academy programs, quizzes, certificates, and free or paid learning content
- Software product pages, downloads, license activation, and related tooling
- Pro memberships, subscriptions, one-off purchases, and coaching checkouts
- Contact forms, waitlists, and product communications
- Analytics, marketing measurement, advertising tags, and conversion tracking we enable
It does not govern third-party websites or apps we only link to (social networks, partner sites, open-source projects, documentation hosts, or pages operated solely by a payment or ad platform under their own policies). When you leave CompStart for Polar checkout, TikTok, Instagram, Google, Discord, or similar, those parties’ policies also apply.
2. Categories of information we collect
2.1 Information you provide
Category | Examples |
|---|---|
Account | Email, display name, authentication method, language/locale preference, optional profile fields |
Communications | Contact-form messages, waitlist signups, coaching or support requests, attachments you choose to send |
Marketing preferences | Subscribe / unsubscribe choices where we offer them |
Account actions | Requests to update data, manage billing, cancel, or delete an account |
We do not require you to send payment card numbers to us by form or email. Checkout is handled by Polar (see §2.2).
2.2 Payments, subscriptions, and commercial data (Polar)
Checkout, billing, subscriptions, invoices, and many license/benefit deliveries are processed by Polar (polar.sh) and Polar’s underlying payment processors.
We do not store full payment card numbers (PAN) on CompStart servers. Card data, if any, is handled by Polar and their PCI-compliant processors under their terms and privacy policy.
Depending on the transaction, we and/or Polar may process:
- Products or plans purchased, amounts, currency, tax lines (where collected), and timestamps
- Subscription status (e.g. active, canceled, past due) and related Polar identifiers
- A Polar customer ID and/or order/subscription IDs linked to your CompStart account
- Metadata needed to grant access (e.g. product, course, software, or membership identifiers; checkout purpose)
- Attribution context we attach to checkout (for example UTM campaign tags and limited first-/last-touch campaign data—see §2.4) so we can measure which campaigns lead to purchases
- Receipt, invoice, and customer-portal information as managed by Polar
- Benefits Polar delivers on our behalf (for example license keys or community access such as Discord, where configured)
Polar’s terms and privacy policy apply to processing on Polar’s systems. Manage billing, invoices, and many subscription actions through the Polar customer portal (linked from CompStart where we provide “Manage billing” or similar).
2.3 Information collected automatically
When you visit or use the Services, we and our processors may collect:
- Technical data — IP address, browser type and version, device type, operating system, language, approximate location derived from IP, network and request metadata, and timestamps
- Usage data — pages and content viewed, referring and exit URLs, navigation paths, clicks, downloads, scroll and interaction signals needed for analytics or (when enabled) session replay, and product events (e.g. opening checkout, completing purchase flows, search within the site—search text may be truncated)
- Security and abuse signals — rate limits, CAPTCHA/bot-protection outcomes (e.g. Cloudflare Turnstile), blocked signup domains, failed auth attempts, and operational logs needed to protect the Services
- Performance and delivery logs — CDN, hosting, media, and application logs as needed to run the platform reliably
2.4 Campaign and attribution data
If you arrive from ads, social posts, email, or partners, we may collect:
- UTM parameters and similar campaign tags in the URL (
utm_source,utm_medium,utm_campaign, etc.) - Optional advertising click identifiers when present in the landing URL (platform-specific parameters used for conversion measurement)
- First-touch and last-touch campaign context stored in first-party cookies or similar browser storage for a limited period (typically on the order of weeks to a few months), so we can attribute signups and purchases after navigation or return from Polar checkout
We may pass a limited subset of this attribution context into Polar checkout metadata and into analytics / advertising tools (Umami, and when enabled TikTok, Meta, etc.) for measurement—not to sell individual visitor profiles.
2.5 Product analytics (Umami)
We use self-hosted Umami web analytics, typically served from our analytics host (for example umami.compstart.pro), to understand how the Services are used and to improve them.
This may include:
- Pageviews and product events — traffic, funnels, feature usage, campaign landings, checkout starts, and related product telemetry
- Opaque user association — if you are signed in, we may associate activity with an internal user identifier (not your name or email as open identity fields in analytics)
- Server-side conversion events — for reliability (including when browser ad blockers drop client scripts), our servers may send purchase or conversion events to Umami after Polar confirms payment via webhook (for example a
purchase_completed-style event with product and amount context, without full card data) - Session replays and heatmaps (when enabled) — for a sample of sessions we may record interaction data (clicks, scroll depth, DOM structure needed for replay) to improve UX, fix bugs, and understand drop-off. Typical configuration includes:
- Sampling (only a portion of sessions, e.g. around 15%)
- Input masking for form fields
- Maximum recording duration (e.g. around five minutes)
- Optional blocking of sensitive UI regions
We use analytics, replays, and heatmaps to operate and improve CompStart. We do not use Umami to sell personal profiles of individual visitors.
2.6 Advertising and social platforms (TikTok, Instagram / Meta, and similar)
If we run paid or organic marketing on platforms such as TikTok, Instagram, Meta (Facebook), Google Ads, or similar, we may use their pixels, SDKs, tags, Events / Conversions APIs, or equivalent tools—including tools loaded through Cloudflare Zaraz or comparable tag management—to:
- Measure visits, signups, purchases, and other conversion events
- Optimize ad delivery and campaign performance
- Build or refine audiences according to each platform’s rules and your settings on that platform
These tools may process device and browser identifiers, page and event data, cookie or similar IDs, IP-derived location signals, and conversion value/product context. They are subject to the privacy policies of TikTok, Meta, Google, and any other advertising partners we use, not only this policy.
You can often limit ad personalization through:
- Browser settings and extensions
- Platform ad preferences (TikTok, Meta, Google, etc.)
- Industry opt-out tools where available in your region
2.7 Cookies and similar technologies
We use cookies, local storage, session storage, and similar technologies for:
Category | Purpose (examples) |
|---|---|
Essential | Sign-in session, CSRF/security, load balancing, language or UI preferences, bot protection |
Analytics | Umami pageviews, events, and (if enabled) replay/heatmap operation |
Attribution | First-party UTM / campaign context so conversions can be linked after navigation or return from checkout |
Advertising | Pixels or tags for platforms such as TikTok or Meta when we enable paid social measurement (often via Zaraz) |
Blocking essential cookies or storage may break sign-in, checkout handoff, or core features. You can clear site data in your browser at any time; attribution cookies will reset on next visit with new campaign parameters if present.
2.8 Authentication providers
If you sign in with a third party (for example Google), that provider shares certain profile data with us (such as name and email) according to your settings with that provider and their privacy policy. Magic-link login uses your email; we send a one-time link via our email provider (see §4).
2.9 Learning, software, and community-related data
Depending on what you use, we may also process:
- Learning progress — enrollments, lesson completion, quiz attempts/scores, certificates or badges we issue
- Software licensing — license keys, activation/seat status, product versions, and related Polar benefit records for tools we sell or distribute
- Community benefits — if a purchase grants access to a third-party community (for example Discord via Polar), Polar and that platform process membership according to their policies; we may store entitlement status so we know you paid
2.10 Information we do not intentionally collect as payment data
We do not intentionally collect full payment card numbers, CVV/CVC, or bank account passwords on CompStart forms. Do not send those via contact forms.
3. How we use information
We use information to:
- Provide the Services — operate the website, accounts, content delivery, software downloads, and membership features
- Authenticate and secure — sign-in, sessions, rate limits, bot protection, fraud and abuse prevention
- Fulfill purchases — process orders via Polar, grant course/software/membership access, handle renewals and cancellations
- Communicate — send transactional messages (login links, purchase confirmations, security notices, service messages); send marketing or product emails only where allowed by law and your preferences, with unsubscribe where required
- Support — respond to contact-form and support requests
- Measure and improve — product analytics (Umami), funnels, UX (including sampled replays), SEO, and reliability
- Marketing measurement — attribute campaigns; when enabled, measure paid social (TikTok, Meta/Instagram, etc.) via pixels, events APIs, and/or Zaraz
- Localize content — language preferences; limited automated translation tooling for content operations where used
- Comply and enforce — legal, tax, and accounting obligations; enforce Terms of Service and policies
- Aggregate insights — produce statistics that do not reasonably identify you
Legal bases (EEA/UK and similar regimes, where required):
Basis | Examples |
|---|---|
Contract | Account, paid access, support for a product you bought |
Legitimate interests | Security, product improvement, analytics, understanding which campaigns work, limited operational notifications—balanced against your rights |
Consent | Where we rely on it (e.g. certain marketing or non-essential cookies/ads, depending on configuration and jurisdiction) |
Legal obligation | Tax, accounting, responding to lawful requests |
4. Sharing of information
4.1 Categories of recipients
We share data with vendors that help us run the Services under appropriate arrangements. Depending on features in use, this may include:
Recipient / role | Role in practice |
|---|---|
Hosting, databases, object storage, CDN | Application hosting, MongoDB (or similar) for product data, Cloudflare R2 / S3-compatible storage for media and files, CDN delivery |
Cloudflare | DNS, security, performance, Turnstile bot protection; Zaraz tag management when ad pixels are enabled; image delivery helpers where used |
Polar and payment processors | Checkout, billing, subscriptions, invoices, license/benefit delivery |
Email delivery (Plunk) | Transactional and, if enabled, marketing email |
Video / media (Bunny Stream / Bunny.net) | Lesson and product video streaming and related media delivery |
Umami (self-hosted analytics) | First-party product analytics on infrastructure we control or operate for CompStart (e.g. |
Advertising platforms | TikTok, Meta (Facebook/Instagram), Google Ads or similar when we enable measurement pixels/APIs |
Identity providers | e.g. Google for OAuth sign-in you choose |
Community platforms | e.g. Discord when access is granted as a Polar/product benefit |
Operational tooling | Internal alerts (e.g. ops notifications) that may include limited event context for reliability—not public marketing |
Professional advisors | Legal, accounting—under confidentiality |
Authorities | When required by law or to protect rights, safety, and security |
Business transfers | Parties in a merger, acquisition, financing, or sale of assets, with steps appropriate under applicable law |
We do not sell your personal information as a standalone product list. Some advertising disclosures may be treated as “sharing,” “sale,” or targeted advertising under certain US state laws when ad pixels are active; use the rights and platform controls in §5 and §8.
4.2 International processors
Polar, Cloudflare, advertising platforms, Google, Bunny, email providers, and cloud hosts may process data in the EU, the United States, and other countries. See §9.
4.3 Third-party links
Outbound links (social media, partners, GitHub, documentation, etc.) are governed by those parties’ policies. We are not responsible for their practices.
5. Your rights and choices
Depending on where you live (including EEA/UK GDPR, and certain US state laws), you may have rights to:
- Access personal data we hold about you
- Correct inaccurate data
- Delete data (subject to legal retention, e.g. tax/purchase records)
- Export / portability in a common format where applicable
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority (in Estonia, the Data Protection Inspectorate / Andmekaitse Inspektsioon; EU residents may also contact their local authority)
Marketing: opt out of marketing emails where offered. Transactional messages related to your account or purchases may still be sent.
Account tools: some profile and preference controls are available when signed in. Billing history and many subscription actions are available via Polar’s customer portal.
Privacy requests: https://compstart.pro/contact. We may need to verify that the request comes from the account holder. We respond within timeframes required by applicable law (for GDPR, typically within one month, extendable as permitted).
Ad and tracking controls: browser settings; TikTok, Meta, Google, and other platform ad preferences; industry opt-out tools where available; clearing cookies/site data.
California / similar US state residents: you may have rights to know, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising. We do not sell personal information for money. To exercise opt-out style requests related to advertising pixels, use the contact form and platform controls above. We will not discriminate against you for exercising privacy rights.
6. Retention
We keep personal data only as long as reasonably necessary for the purposes in this policy, including:
Data type | Typical retention approach |
|---|---|
Account data | While the account is active, then a reasonable wind-down period |
Purchase / subscription records | As needed for access control, tax, accounting, and fraud prevention (often multi-year where law requires) |
Support / contact messages | Resolution plus a reasonable operational period |
Analytics events | According to our Umami configuration and operational needs |
Sampled session replays | Shorter operational windows; sampling limits volume |
Attribution cookies / storage | Limited period (typically weeks to a few months) |
Security logs | As needed for abuse prevention and investigation |
We then delete or anonymize data where feasible. Residual copies may remain briefly in backups until rotated.
7. Security
We use commercially reasonable technical and organizational measures appropriate to the risk, which may include HTTPS/TLS, access controls, session management, rate limiting, bot protection, and least-privilege practices for staff tooling.
No method of transmission or storage is 100% secure. Protect your account and email inbox (especially if you use magic links). Report suspected unauthorized access via the Contact page.
8. Children
The Services are not directed to children under 16 (or the higher minimum age required where you live). We do not knowingly collect personal information from children. If you believe a child has provided data, contact us via the Contact page and we will take appropriate steps.
9. International transfers
We may process and store information in countries other than yours—including where our hosts, CDN, Polar, email, video, analytics infrastructure, or advertising platforms operate (for example EU and United States regions).
Where required by law (including GDPR transfers outside the EEA/UK), we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, or equivalent mechanisms offered by our providers, together with technical and organizational measures.
10. Automated decisions and tracking signals
We do not make solely automated decisions that produce legal or similarly significant effects about you beyond ordinary fraud prevention, access control, entitlement checks (for example whether a purchase unlocks a course or software), and rate limiting.
Browsers may send “Do Not Track,” Global Privacy Control, or similar signals. We may not honor every such signal in a uniform way across all tools. Use account, browser, and advertising-platform controls, and the rights process in §5.
11. Changes to this policy
This policy is effective July 30, 2026 (updating the prior version dated October 1, 2022). We may update it from time to time. The “Last updated” date will change when we do. Material changes may be highlighted on the site or via other reasonable notice. Continued use after an update means you accept the revised policy, except where law requires otherwise (for example additional consent).
12. Contact and operator identity
Privacy requests: https://compstart.pro/contact