Legal
Privacy Policy
Last updated 14 June 2026
This Privacy Policy explains how acaunty (“we”, “us”) collects, uses, and protects your personal data when you use our website and exam-practice service at acaunty.co.uk (the “Service”). We are the data controller for the personal data described here. acaunty is a study aid for ICAEW ACA students and is not affiliated with or endorsed by ICAEW.
Data we collect
- Account data — your email address and authentication details, created when you sign up (by email and password, or via Google or Apple sign-in).
- Profile and onboarding data — your ACA level and, optionally, whether you have an exam booked and its date, which you provide to personalise your practice.
- Usage data — your quiz sessions, the questions you attempt, and your answers, used to show your progress and accuracy.
- Payment data — if you subscribe, your payment is processed by Stripe. We do not receive or store your card details; we retain only a Stripe customer reference and your subscription status.
- Support data — the name, email, and message you send us through the contact form.
How and why we use your data
We process your personal data on the following lawful bases:
- Performance of a contract — to create and run your account, deliver practice questions, track your progress, and manage your subscription.
- Legitimate interests — to secure the Service, prevent abuse, respond to your enquiries, and improve the product, where this is not overridden by your rights.
- Consent — for non-essential analytics and advertising cookies, which we set only after you accept them in the cookie banner. You can decline, and those cookies will stay off.
- Legal obligation — to keep records we are required by law to retain, such as transaction records.
Processors we rely on
We share data with the following service providers, who act on our instructions and only as needed to provide the Service:
- Supabase — database, authentication, and storage (hosted in the EU).
- Stripe — payment processing and subscription billing.
- Resend — sending transactional and support emails.
- Vercel — application hosting and content delivery.
- Google and Apple — only if you choose to sign in with them, to authenticate you.
- Google Analytics — anonymous, aggregated usage analytics, and only if you accept analytics cookies.
- Google Ads — to measure the performance of our advertising and show relevant ads, and only if you accept advertising cookies. You can decline, and no advertising cookies will be set.
Where a processor transfers data outside the UK or EEA, that transfer is covered by an adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
Retention
We keep your account and usage data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we must retain certain records (for example, transaction records) to meet legal obligations.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing;
- data portability; and
- lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
To exercise any of these rights, contact us via our contact page or at hello@acaunty.co.uk.
Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the “last updated” date above.
Contact
Questions about this policy or your data? Reach us at hello@acaunty.co.uk or through our contact page.