Skip to main content
Back to Home

Privacy Policy

Last updated: May 2026

Effective Date: April 30, 2026 Last Updated: May 2026

1. Who We Are

This Privacy Policy describes how Data212 Inc. ("Data212," "we," "us," or "our"), a corporation incorporated in Canada, collects, uses, and shares information about you when you use NotaMerican, accessible at nota.uno (the "Service").

Contact for privacy matters: privacy@nota.uno Legal entity: Data212 Inc. Jurisdiction: Ontario, Canada

2. Information We Collect

2.1 Information You Provide

  • Account information: email address, username, authentication credentials (via Google OAuth or email)
  • Payment information: processed by Stripe; we do not store full payment card details on our servers (we receive only a Stripe customer ID and subscription status)
  • Game activity: quiz scores, XP, streak history, achievements
  • Communications: any message you send to privacy@nota.uno or other support channels

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, game completion events, click events, session duration
  • Device data: browser type, operating system, screen resolution, language, approximate location derived from IP address
  • Cookies and similar technologies: see our Cookie Policy for details

2.3 Information from Third Parties

  • Google OAuth: if you sign in with Google, we receive your email, name, and profile picture as permitted by your Google account settings
  • Stripe: subscription and payment status

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process payments and manage subscriptions
  • Maintain your game progress, leaderboard placement, and achievements
  • Send service-related communications (account confirmations, payment receipts, security notices)
  • Personalize your experience and serve relevant advertising to free-tier users
  • Detect, prevent, and address fraud, abuse, security risks, and technical issues
  • Comply with legal obligations
  • With your consent, send marketing communications

4. Legal Bases for Processing (EEA/UK Users)

If you are in the EEA or UK, we rely on the following legal bases:

  • Contract: to provide the Service you've signed up for
  • Legitimate interests: to improve the Service, prevent fraud, secure our systems
  • Consent: for non-essential cookies, marketing communications, and personalized advertising
  • Legal obligation: to comply with applicable law

5. Third-Party Services and Data Sharing

We share information with the following service providers, each of whom processes data on our behalf or as an independent controller for their own purposes:

Infrastructure and Hosting

  • Vercel Inc. (USA) — frontend hosting and edge delivery
  • Supabase Inc. (USA) — database, authentication, file storage. Database region: see Supabase project settings.

Payments

  • Stripe, Inc. (USA) — payment processing for subscriptions. Stripe receives your name, email, billing address, and payment card information directly.

Analytics and Product Measurement

  • Google Analytics 4 (Google LLC, USA) — usage analytics, traffic measurement
  • Google Tag Manager (Google LLC, USA) — tag deployment and management
  • Microsoft Clarity (Microsoft Corporation, USA) — session recording and heatmaps. Clarity may capture mouse movements, clicks, scrolls, and page interactions. We have configured Clarity to mask sensitive form inputs.

Advertising

We do not currently show third-party display ads in the Service.

Social Media Tracking (planned, not yet active as of the Effective Date)

We may add the following pixels in the near future. When activated, this Policy will be updated and a notice posted at nota.uno:

  • Meta Pixel (Meta Platforms, Inc., USA) — conversion tracking and ad attribution for Facebook and Instagram campaigns
  • TikTok Pixel (TikTok Inc.) — conversion tracking for TikTok campaigns

Authentication

  • Google Identity Services (Google LLC, USA) — "Sign in with Google" functionality

We do not sell your personal information for monetary consideration. However, certain analytics activities described above may qualify as a "sale" or "sharing" under California law (CCPA/CPRA). See Section 9 for opt-out rights.

6. International Data Transfers

We operate globally. Your information is processed and stored on servers located in the United States, Canada, and potentially other jurisdictions where our service providers operate. By using the Service, you consent to the transfer of your information to these jurisdictions, which may have data protection laws different from those of your country.

For users in the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards where required.

7. Data Retention

We retain personal information for as long as necessary to provide the Service and as required to comply with legal obligations:

  • Account data: retained while your account is active. After deletion, retained for up to 30 days in backup systems before permanent erasure.
  • Game activity: retained while your account is active.
  • Payment records: retained for 7 years for Canadian tax compliance.
  • Analytics data: retained per Google Analytics and Microsoft Clarity default retention (typically 14-26 months).
  • Server logs: typically 30-90 days.

You can request deletion at any time by emailing privacy@nota.uno.

8. Your Rights

8.1 All Users

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated personal information
  • Object to or restrict certain processing
  • Withdraw consent (where processing is based on consent)
  • Lodge a complaint with a data protection authority

To exercise these rights, email privacy@nota.uno. We will respond within 30 days (or as required by applicable law).

8.2 Canadian Users (PIPEDA + Quebec Law 25)

Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), and Quebec residents have additional rights under Law 25 (An Act respecting the protection of personal information in the private sector), including:

  • The right to be informed of automated decision-making
  • The right to data portability (Quebec residents, effective 2024)
  • The right to file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Commission d'accès à l'information du Québec (cai.gouv.qc.ca)

8.3 California Users (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and "sell" or "share"
  • Delete your personal information
  • Correct inaccurate personal information
  • Opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising
  • Limit the use of sensitive personal information
  • Non-discrimination for exercising your rights

To opt out of the sale/sharing of your personal information, use the Do Not Sell or Share My Personal Information link in the site footer when shown (US visitors), use any privacy choices control that Google may display on ad-supported pages, or email privacy@nota.uno. We honor Global Privacy Control (GPC) signals.

8.4 Other US States

Residents of states with comprehensive privacy laws (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others) have rights similar to those in Section 8.3. Contact privacy@nota.uno to exercise these rights.

9. Cookies and Tracking

We use cookies and similar technologies as described in our Cookie Policy. Where required by law, we obtain your consent before setting non-essential cookies through a consent banner.

10. Children's Privacy

The Service is not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact privacy@nota.uno and we will delete it.

11. Security

We implement reasonable technical and organizational measures to protect your information, including encryption in transit (HTTPS/TLS), encryption at rest where supported by our providers, row-level security on database tables, and regular security review. No system is perfectly secure, and we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated by email (where applicable) or via a notice on nota.uno at least 7 days before they take effect. The "Last Updated" date at the top reflects the most recent revision.

13. Contact

For any privacy-related question, request, or complaint:

Email: privacy@nota.uno Mailing address: Data212 Inc., [INSERT REGISTERED ADDRESS], Ontario, Canada

For unresolved complaints, you may contact:

  • Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca
  • Quebec: Commission d'accès à l'information du Québec — cai.gouv.qc.ca
  • California: California Privacy Protection Agency — cppa.ca.gov
  • EEA/UK: your local data protection authority