This Privacy Policy explains what personal data Mometrix collects when you visit www.mometrix.com, create an account, buy or use our exam preparation products, contact support, or take part in our community features, and what we do with that data.
It is written to meet the requirements of Articles 12 to 22 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR), the UK GDPR and the Data Protection Act 2018, the ePrivacy rules on cookies and similar technologies, and the disclosure duties of the main US state privacy laws. Where a national rule gives you more protection than this policy describes, that national rule applies.
If you only want the short version, read the "At a glance" table below. Everything after it is the detail behind it.
At a glance
| Question | Short answer |
|---|---|
| Who is responsible for your data? | [Registered company name], trading as Mometrix. See Who we are. |
| What do we collect? | Account details, order and billing data, support messages, community posts, and technical usage data. See What we collect. |
| Why? | To run your account, deliver and update the products you buy, provide support, prevent fraud and licence abuse, meet tax and accounting duties, and improve the site. See Why we use it. |
| Do we sell your data? | No. We do not sell personal data and we do not share it for cross context behavioural advertising. |
| Do we use tracking cookies? | Only after you accept them. Analytics and any similar scripts stay switched off until you choose "Accept" in the cookie banner. See Cookies. |
| Where does the data go? | Our hosting, payment, email, and analytics providers, some of which are outside the EEA and UK, under approved transfer safeguards. See International transfers. |
| How long do we keep it? | For as long as your account is open, then per the schedule in Retention. |
| What can you ask for? | Access, correction, deletion, portability, restriction, objection, and withdrawal of consent. See Your rights. |
| How do you reach us? | support@mometrix.com, or the contact form. |
Who we are
[Registered company name] (company number [Company registration number]), registered at [Registered office address], operates www.mometrix.com and is the controller of the personal data described in this policy. "We", "us" and "our" mean that company. "You" and "your" mean any visitor, registered user, or customer of the site.
Contact for privacy matters: support@mometrix.com, or write to us at the registered address above marking your letter for the attention of the privacy team.
EU representative (GDPR Article 27): [EU Article 27 representative, name and address]. Individuals in the European Economic Area may contact our representative on any matter relating to the processing of their personal data.
UK representative (UK GDPR Article 27): [UK Article 27 representative, name and address].
We have not appointed a Data Protection Officer, because our processing does not meet the Article 37 thresholds: we do not carry out large scale systematic monitoring, and we do not process special category data as a core activity. The privacy contact above handles all requests and is answerable to our management.
Who this policy covers
This policy applies to:
- the website at https://www.mometrix.com and all of its subpages,
- your Mometrix account and member area,
- our PDF question sets, web based practice tests, and desktop practice test software,
- our email, support ticket, and live chat channels,
- our community features, including exam comments and discussions.
It does not apply to third party websites we link to, to the certification bodies and test centres you register with (for example Pearson VUE or Prometric), or to the certification vendors whose exams our products cover. Those organisations are separate controllers with their own policies, and we have no control over what they do with your data.
What personal data we collect
We collect data in three ways: you give it to us, it is generated as you use the service, and a small amount comes from our providers.
Data you give us
Account data. When you register, we collect your full name, email address, and password. Your password is stored in hashed form and is never displayed back to you. You may optionally add a phone or mobile number, gender, country, state or province, city, postal code, and street address.
Billing and tax data. When you place an order we record your billing name and address, country, and, where you supply it, your VAT or tax identification number so we can issue a compliant invoice. We record the order contents, the amount, the currency, the discount or coupon code used, the invoice number, the payment status, and the transaction reference returned by the payment provider.
We do not receive or store your full card number. Card details are entered on, and held by, our payment provider. See Payments.
Support and contact data. If you email us, use the contact form, open a live chat, or submit a refund claim, we hold your message, your email address, and anything you choose to attach. Refund claims under our guarantee involve documents you send us, which may include an exam enrolment slip and a score report. Those documents can contain your candidate identification number and exam result, so please redact anything in them that we do not need.
Community content. Comments, discussion posts, replies, votes, and reports you submit are stored with your display name and the time of posting. Anything you post in a public area of the site is visible to other visitors and to search engines. Do not post information you would not want to be public.
Corporate and trainer applications. If you apply for corporate or trainer access we also collect your organisation name, role, and the details needed to assess eligibility and set up sub accounts.
Data generated as you use the service
Technical and device data. IP address, browser type and version, operating system, device type, screen size, referring page, and language settings.
Usage data. Pages viewed, products viewed and added to cart, demo questions opened, demo files downloaded, product downloads, practice test sessions started and completed, login times, and the actions recorded in our activity logs. We use these both to run features (for example, showing which files you have already downloaded against your fair use allowance) and to detect licence sharing and automated scraping.
Licence and activation data. For desktop software, the licence key issued to you and the number of activations against it, so that the per licence device limit described in the Terms can be enforced.
Cookie and local storage data. See Cookies and similar technologies.
Data from others
Payment providers send us confirmation of a payment, the last four digits and card brand for reconciliation, the billing country, the transaction reference, and any chargeback or refund status.
Sign in providers. If you choose to sign in with Google, Google sends us your name, email address, and the fact that the email is verified. We do not receive your Google password, and we do not gain access to any other part of your Google account.
Anti abuse and security services may return risk signals about an IP address or a request, for example whether it is associated with automated traffic.
We do not buy personal data from data brokers, and we do not enrich your profile with data bought from third parties.
Special category and children's data
We do not seek out special category data as defined in Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation). Please do not send it to us. If it reaches us inside a support message or a refund document, we process it only to the extent needed to answer you, on the basis of Article 9(2)(f) where a legal claim is involved, and we delete it as soon as it is no longer needed.
Our service is intended for adults preparing for professional certification exams. It is not directed at children. See Children.
Why we use your data, and our lawful basis
Under Article 6 GDPR every use of personal data needs a lawful basis. The table below sets out, for each purpose, what we use and why we are allowed to.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and running your account, authenticating you, and keeping you signed in | Account data, technical data, essential cookies | Performance of a contract, Art. 6(1)(b) |
| Taking and fulfilling your order, delivering downloads, issuing licence keys, and providing free updates during your entitlement period | Account data, billing data, order data, licence data | Performance of a contract, Art. 6(1)(b) |
| Issuing invoices and meeting tax, accounting, and company law obligations | Billing data, order data, VAT number | Legal obligation, Art. 6(1)(c) |
| Providing customer support and handling guarantee, refund, and exchange claims | Support data, order data, documents you send | Performance of a contract, Art. 6(1)(b); legal claims, Art. 9(2)(f) where special category data is unavoidably involved |
| Sending service messages: order confirmations, download links, update notices, password resets, expiry reminders, and changes to these terms | Account data, order data | Performance of a contract, Art. 6(1)(b) |
| Preventing fraud, chargeback abuse, licence sharing, credential sharing, and automated scraping of our question banks | Technical data, usage data, licence data, order data | Legitimate interests, Art. 6(1)(f): protecting our revenue, our intellectual property, and other customers |
| Keeping the site secure, backed up, and available, and investigating incidents | Technical data, usage data, log data | Legitimate interests, Art. 6(1)(f): network and information security; also Art. 32 GDPR |
| Moderating comments and discussions | Community content, account data | Legitimate interests, Art. 6(1)(f): keeping public areas lawful and usable |
| Measuring how the site is used and improving it | Analytics cookie data, usage data | Consent, Art. 6(1)(a), given through the cookie banner |
| Sending marketing emails about products, offers, and discounts | Email address, purchase history | Consent, Art. 6(1)(a); or the soft opt in for our own similar products to existing customers where national law allows, always with an unsubscribe link |
| Establishing, exercising, or defending legal claims, and enforcing our Terms | Any relevant data | Legitimate interests, Art. 6(1)(f); legal claims, Art. 9(2)(f) |
| Complying with a lawful request from a court, regulator, or law enforcement body | Any relevant data | Legal obligation, Art. 6(1)(c) |
Our legitimate interests, balanced
Where we rely on legitimate interests we have weighed our interest against your rights and freedoms, as Article 6(1)(f) requires. In short:
- Fraud and abuse prevention. Our products are digital and copyable, and licence sharing directly funds the piracy of the material other customers pay for. The data used is limited to what an account already generates, is not combined with outside sources, and is not used to make decisions about you outside the service.
- Security and logging. Logs are kept for a limited period, are access controlled, and are not used to profile you.
- Moderation. Reviewing public posts is limited to content you chose to publish.
You may object to any of these at any time. See Your rights.
Payments and card data
Payments on this site are handled by our payment providers, currently FastSpring and, for certain legacy flows, Stripe.
Where an order is processed by FastSpring, FastSpring acts as the merchant of record: it is the seller of record for that transaction, it takes the payment, it calculates and remits applicable sales tax or VAT, and it is an independent controller of the payment data it collects. Its own privacy notice governs that processing.
In all cases:
- your card number, expiry date, and security code are entered on the provider's payment page or hosted field and go directly to the provider,
- we never see, receive, or store full card numbers,
- we receive only the confirmation, the reference, the billing country, and the masked card details needed to reconcile the order and handle refunds and chargebacks,
- providers are PCI DSS compliant service providers.
If you dispute a charge with your bank, the bank and the provider will share the details of the transaction with us so that we can respond to the dispute.
Cookies and similar technologies
A cookie is a small file placed on your device by a website. We also use browser local storage, which works similarly. This section is our cookie notice for the purposes of the ePrivacy Directive as implemented in your country, and Regulation 5(3) of the UK PECR.
Our consent model
Nothing but strictly necessary storage runs before you choose. When you first visit, a banner asks you to accept or reject non essential cookies. Analytics and any comparable scripts are injected only after you press "Accept". If you press "Reject", or ignore the banner, they are never loaded. This is a genuine choice: rejecting costs you no functionality.
You can change your mind at any time using the Cookie settings link in the site footer, which reopens the banner. Withdrawing consent is as easy as giving it, and takes effect on your next page load.
Categories we use
Strictly necessary. These do not require consent because the service cannot be provided without them.
| Name | Set by | Purpose | Type and lifetime |
|---|---|---|---|
ci_session | www.mometrix.com | Keeps you signed in, holds your cart, and protects forms against cross site request forgery | Session cookie, expires when the session ends |
dg-consent | www.mometrix.com | Records whether you accepted or rejected non essential cookies, so we do not ask again | Local storage, persists until you clear it |
Analytics and performance. Loaded only with your consent.
| Name | Set by | Purpose | Type and lifetime |
|---|---|---|---|
_ga, _ga_* | Google Analytics | Distinguishes visitors and sessions so we can count usage and see which pages are failing people | First party cookies, up to 2 years |
_clck, _clsk, CLID and related | Microsoft Clarity | Aggregated usage measurement and session replay of interactions with the page, used to find broken layouts and dead ends | First party and third party cookies, up to 1 year |
Microsoft Clarity may record pointer movement, clicks, and scrolling in order to reconstruct a session. Input fields are masked by the provider so that what you type into forms is not captured. If you would rather this did not happen, reject cookies.
Advertising. We do not currently run advertising or retargeting cookies, and we do not share cookie data with advertising networks. If that changes, this policy and the banner will be updated first, and consent will be sought before any such cookie is set.
Browser controls and Do Not Track
Every major browser lets you block or delete cookies through its settings, and offers a private browsing mode. Blocking strictly necessary cookies will break sign in and checkout.
There is no agreed standard for how sites should respond to a browser Do Not Track signal, so we do not act on DNT. We do honour the Global Privacy Control signal where we are legally required to treat it as an opt out.
Who we share your data with
We do not sell personal data. We share it only in the situations below.
Service providers acting on our instructions
These are processors under Article 28 GDPR. Each is bound by a written contract that limits them to our instructions, requires confidentiality and appropriate security, restricts onward subprocessing, and requires deletion or return of the data at the end of the engagement.
| Category | What they do | Data they see |
|---|---|---|
| Hosting and infrastructure | Run the servers, database, and backups behind the site | Potentially all data stored on the service |
| Content delivery and security | Serve static files and filter malicious traffic | Technical data, IP address |
| Payment providers | Take payment, handle refunds and chargebacks, remit tax | Billing data, order data, card data (held by them, not us) |
| Transactional email | Deliver order confirmations, download links, password resets | Name, email address, message content |
| Customer support and live chat | Handle your queries | Support data, account data |
| Analytics | Measure site usage, only with your consent | Cookie identifiers, technical data, usage data |
| Anti spam and bot protection | Protect forms from automated abuse | IP address, request metadata, interaction signals |
We will name the specific providers in a category on request. Ask at support@mometrix.com.
Others
- Professional advisers. Accountants, auditors, and lawyers, where they need the data to advise us and are bound by professional confidentiality.
- Authorities. Courts, regulators, tax authorities, and law enforcement, where we are legally required to disclose or where disclosure is necessary to establish, exercise, or defend legal claims. We check that any request is valid and properly served, and we disclose only what the request actually covers.
- Rights holders. In a copyright or DMCA proceeding concerning content you posted, we may pass your notice and the associated details to the counterparty, as the notice and counter notice procedure requires.
- A buyer or successor. If the business or the relevant part of it is sold, merged, or reorganised, personal data may transfer as part of the assets. You will be told before your data becomes subject to a different privacy policy, and your rights are not reduced by the transfer.
Other users
Your public profile name and anything you post publicly are visible to other users. Your email address, order history, and account details are never shown to other users.
International transfers
We are based in, and our operations reach, more than one country, and several of our providers are established in the United States or process data there. That means personal data originating in the EEA, the UK, or Switzerland may be transferred outside those areas.
Where that happens, we rely on one of the following, in this order of preference:
- An adequacy decision. A European Commission decision under Article 45 GDPR, or a UK adequacy regulation, covering the destination country. This includes the EU to US Data Privacy Framework and its UK Extension where the recipient is certified under it.
- Standard Contractual Clauses. The European Commission's SCCs (Decision (EU) 2021/914), and for UK data the ICO's International Data Transfer Agreement or the UK Addendum to the SCCs, together with a transfer impact assessment considering the law and practice of the destination country and any supplementary technical and organisational measures needed.
- A derogation under Article 49, for example your explicit informed consent or the necessity of the transfer to perform a contract with you, used only for occasional transfers that the routes above cannot cover.
You may request a copy of the safeguards we rely on for a particular transfer by writing to support@mometrix.com. We will provide it, redacted where necessary to protect commercial confidentiality.
How long we keep your data
We keep personal data only as long as we need it for the purpose we collected it for, plus any period we are required to keep it by law. In practice:
| Data | Retention period | Why |
|---|---|---|
| Account data | For the life of the account, then deleted or anonymised within 12 months of closure | You may want to return, and orders remain linked to the account |
| Order, invoice, and tax records | 6 to 10 years from the end of the relevant financial year, depending on the applicable national rule | Tax, accounting, and company law retention duties |
| Payment and chargeback records | As long as a dispute or chargeback remains possible, generally up to 18 months, then per the tax rule above | Handling disputes |
| Support tickets and email | 3 years from the last message in the thread | Answering follow ups, showing what was agreed |
| Refund and guarantee claim documents | 2 years from the decision on the claim | Defending a repeated or disputed claim |
| Community posts | Until you delete them or the account is closed; on closure they are anonymised rather than removed, so replies still make sense | Keeping public discussions coherent |
| Security and access logs | 12 months | Investigating incidents and abuse |
| Analytics data | Per the provider's setting, currently no more than 14 months for Google Analytics | Trend analysis |
| Marketing consent records | For as long as the consent is relied on, plus 3 years after withdrawal | Proving that consent was validly obtained |
| Backups | Rolling, overwritten within 90 days | Disaster recovery |
When a deletion request is granted, the data is removed from live systems immediately and falls out of backups as those backups roll over. Data we are required by law to retain is not deleted; it is put beyond routine use until its retention period ends.
Security
We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. These include:
- HTTPS across the whole site, with HTTP Strict Transport Security in production,
- passwords stored using a one way hash, never in plain text, and never emailed to you,
- a Content Security Policy, plus
X-Content-Type-Options,X-Frame-Options,Referrer-Policy, andPermissions-Policyheaders, to reduce the impact of injection and framing attacks, - role based access to the administration panel, with activity logging,
- access to production data limited to staff who need it,
- parameterised database access and validated input on forms,
- rate limiting and bot protection on authentication and contact endpoints,
- regular patching of the platform and its dependencies, and backups held separately from the live system.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as Article 33 requires, and we will tell you directly without undue delay where Article 34 requires it.
Please help by using a strong, unique password, not sharing your account, and telling us at once at support@mometrix.com if you think your account has been accessed by someone else.
Automated decision making and profiling
We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing.
We do run automated checks for fraud and licence abuse, for example flagging an account whose downloads come from many unrelated locations in a short window, or that exceeds the fair use limits in our Terms. A flag can lead to a temporary block on downloads. A human reviews every case before an account is suspended or an order is cancelled, and you can contest the outcome, put your point of view, and ask for the decision to be reconsidered by writing to support@mometrix.com.
Your rights
If the EU or UK GDPR applies to the processing of your data, you have the rights below. They are not absolute, and we will tell you if an exemption applies and why.
- Access (Art. 15). Get confirmation of whether we process your data, a copy of it, and the supporting information in this policy.
- Rectification (Art. 16). Have inaccurate data corrected and incomplete data completed. Most account details can be changed yourself in the member area.
- Erasure (Art. 17). Have your data deleted where it is no longer needed, where you withdraw the consent it rested on, where you successfully object, or where it was processed unlawfully. Note that deleting the data needed to run your account means closing the account and losing access to your purchases and downloads, and that we cannot delete records we must keep for tax purposes.
- Restriction (Art. 18). Have processing paused while a dispute about accuracy or about our legitimate interests is resolved.
- Portability (Art. 20). Receive the data you gave us, and that we process by consent or under a contract, in a structured, commonly used, machine readable format, and have it transmitted to another controller where technically feasible.
- Objection (Art. 21). Object to processing based on legitimate interests, on grounds relating to your situation. You may object to direct marketing at any time, for any reason or none, and we will stop immediately.
- Withdraw consent (Art. 7(3)). Withdraw any consent you gave, at any time, without affecting the lawfulness of what was done before you withdrew it.
- Not be subject to solely automated decisions (Art. 22). See the section above.
- Complain. Lodge a complaint with a supervisory authority. See below.
How to exercise them
Write to support@mometrix.com from the email address on your account, or use the contact form. Say which right you are exercising and what the request concerns.
- We respond within one month. Where a request is complex, or where you have made several, we may extend by up to two further months, and we will tell you within the first month if we do, with reasons.
- There is no charge. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.
- We may ask for proof of identity if we cannot otherwise be confident who is asking. We ask for the least we need, and we do not use what you send for any other purpose.
- An authorised agent may make a request for you if you give them written authority and we can verify it.
Complaining to a regulator
You can complain to the supervisory authority in the EU or EEA country where you live, where you work, or where the alleged infringement took place. The list of national authorities is published by the European Data Protection Board at edpb.europa.eu.
In the United Kingdom, the regulator is the Information Commissioner's Office, ico.org.uk, telephone 0303 123 1113.
In Switzerland, it is the Federal Data Protection and Information Commissioner, edoeb.admin.ch.
We would rather hear from you first, so please give us a chance to put things right, but you are not required to.
Information for people in the United States
California
Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to know what personal information is collected, used, disclosed, and sold or shared; to delete personal information; to correct inaccurate personal information; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
- Categories collected in the last 12 months: identifiers (name, email, IP address, account identifier); customer records (billing address, phone number, payment status); commercial information (products bought and considered); internet activity (pages viewed, downloads, session data); geolocation inferred at country and city level from IP address; and the contents of messages you send us.
- Sources: you, your device as you use the site, and our service providers.
- Business purposes: the purposes listed in Why we use your data.
- Disclosure: to the service provider categories listed in Who we share your data with, for business purposes only.
- Sale or sharing: we do not sell personal information and do not share it for cross context behavioural advertising, including as to consumers we know to be under 16.
- Sensitive personal information: we do not collect it for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted by section 7027(m) of the CCPA regulations, so no "limit the use" link is required.
- Retention: as set out in Retention.
To exercise a right, email support@mometrix.com. We will verify you by matching the details you give against the details on your account. You may use an authorised agent with written permission. We will not deny you goods or services, charge you a different price, or give you a lower quality of service because you exercised a right.
Other US states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights of access, correction, deletion, portability, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We honour these through the same contact route, and where a state gives a right to appeal a refusal, you may appeal by replying to our decision, and we will respond with a written explanation within the period that state's law allows.
Information for other regions
- Canada. We handle personal information consistently with PIPEDA, including the openness, access, and accountability principles. Complaints may go to the Office of the Privacy Commissioner of Canada.
- Brazil. Where the LGPD applies, the rights above map onto Articles 17 to 22, and requests go to the same contact.
- Australia. Where the Privacy Act 1988 applies, we handle personal information consistently with the Australian Privacy Principles.
Children
The service is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16, and we do not knowingly permit them to register or buy.
If you believe a child has given us personal data, contact support@mometrix.com. We will verify the report, delete the data, and close any associated account. Where a national law sets a lower digital consent age under Article 8(1) GDPR, and processing rests on consent, we apply that national age instead.
Links to other sites
Our pages link to certification bodies, test centres, vendor documentation, and other third party resources. Following such a link takes you to a site we do not control. This policy stops at our boundary; read the policy of the site you land on.
Changes to this policy
We may update this policy to reflect changes in the service, in our providers, or in the law.
- The effective date and last updated date appear at the top of this page.
- For a change that materially affects how we use your data, we will give notice in advance: a prominent notice on the site, and, where the change is significant and we hold your email address, an email.
- Where a change requires your consent, we will ask for it rather than assume it.
- Previous versions are available on request from support@mometrix.com.
Continuing to use the service after a change takes effect means you accept the updated policy, except where consent is required.
How to contact us
| Reason | Where to write |
|---|---|
| Privacy questions, data subject requests, complaints | support@mometrix.com |
| Anything else, including orders and support | support@mometrix.com or the contact form |
| Post | [Registered company name], [Registered office address] |
| EEA residents, via our Article 27 representative | [EU Article 27 representative, name and address] |
| UK residents, via our Article 27 representative | [UK Article 27 representative, name and address] |
Related pages: Terms and Conditions, Refund Policy, DMCA, FAQs.