1. Who we are
CcmaSimulator ("we", "us") operates ccmasimulator.com, an independent CCMA® practice simulator. We are the data controller for the personal data described below. Contact: [email protected].
The service is operated by CCMAsimulator.com, registered at 1603 Capitol Ave, Ste 413 E460, Cheyenne, WY 82001, United States.
2. What we collect
- Account data: your email address, an optional first name, and a hashed password (or, if you sign in with Google, the account identifier Google returns). We never see or store your password in readable form.
- Practice data: your exam attempts — answers selected, items seen, raw score, per-domain breakdown, time spent, and when each attempt started and finished.
- Payment metadata: if you buy, Stripe processes the payment and returns to us the amount, currency, product purchased, payment status, and a Stripe customer and payment identifier. We never receive or store your card number.
- Technical and usage data: an anonymous visitor identifier stored in your browser, pages viewed, referring URL, and coarse device/browser information used to keep the app working and to understand aggregate usage.
We do not collect health data, we do not ask for a government identifier, and we have no access to your NHA® account or your official exam results.
3. Why we use it, and our legal basis
- To provide the simulator — build your forms, score attempts, show your history and diagnostics. Legal basis: performance of our contract with you.
- To take and support payments and to honor refunds. Legal basis: performance of a contract, and our legal obligation to keep transaction records.
- To send service emails — receipts, password resets, and your result summaries. Legal basis: performance of a contract.
- To send optional product emails. Legal basis: your consent. Every such email carries an unsubscribe link and unsubscribing never affects your access.
- To keep the service secure and prevent abuse (including verifying that a sign-up email is deliverable). Legal basis: our legitimate interests.
We do not sell personal data, we do not share it with advertisers, and we do not use your practice data to make any automated decision about you.
4. Processors we use
- Supabase — account authentication, database, and server functions. Holds your account and practice data.
- Stripe — payment processing. Receives your email and payment details directly; acts as an independent controller for fraud prevention and its own legal obligations.
- Brevo — sending transactional and optional product email. Receives your email address, first name, and purchase tier.
- ZeroBounce — one-time validation that a sign-up email address is deliverable. Receives the email address only.
Each is bound by a data processing agreement and may only act on our instructions. We disclose data otherwise only where the law requires it.
5. Cookies and similar storage
We use first-party storage for two things: keeping you signed in, and an anonymous visitor identifier so an attempt started before sign-up can be attached to your account. There are no third-party advertising or cross-site tracking cookies on this site.
6. How long we keep it
- Account and practice data: for as long as your account exists.
- Payment and refund records: seven years from the transaction, because tax and accounting law requires it. These survive account deletion.
- Email sending logs: 24 months.
- Anonymous visitor identifier: 12 months from your last visit.
7. Your rights, and how to delete your data
You may request a copy of your data, correct it, export it, restrict or object to processing, withdraw consent to product email, or have your data deleted.
To delete your data, email [email protected] from your account address with the subject "Delete my data". We confirm within 5 business days and erase your account, practice history, and email contact record within 30 days, keeping only the payment records named in section 6. Deletion is permanent — purchased access is lost and is not refundable on that basis alone.
If you are a California resident, the CCPA/CPRA gives you the rights to know, access, correct, delete, and port your personal information, to limit use of sensitive personal information, and to opt out of its sale or sharing — and to be free from retaliation for exercising them. We do not sell and do not share your personal information as those terms are defined under the CCPA/CPRA, we run no advertising and no cross-context behavioral targeting, and we did not disclose personal information for those purposes in the past 12 months. If you are in the EU/UK you may also complain to your local data protection authority.
8. International transfers
Our processors store and process data in the United States and the European Union. Where data leaves the EEA or UK, transfers rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable).
9. Security
Traffic is encrypted in transit, passwords are stored only as hashes, database access is restricted per user by row-level security policies, and card data never reaches our systems. No system is perfectly secure; if a breach affects your data and the law requires notification, we will tell you.
10. Children
The service is not directed to children under 13 and we do not knowingly collect their data. If you believe a child has registered, email us and we will remove the account.
11. Changes
If we change this policy materially we will update the effective date above and notify registered users by email before the change takes effect.