Privacy and Cookie Notice
This policy explains the information PASSFAST LEARNING LLC may collect, how it may be used, and the choices available to people who use the service.
Effective date: August 30, 2026
Version: 2026-08-30
PASSFAST LEARNING LLC ("PassFast," "we," "us") provides eaexam.co, app.eaexam.co, checkout, digital Enrolled Agent exam preparation, Sarah and other support or AI features, and related communications. This notice explains how we handle personal information through those services.
Controller and contact: PASSFAST LEARNING LLC, 2540 Executive Center Circle, Suite 100, DPT #25140, Tallahassee, Florida 32301-5015, United States. Privacy requests: [email protected]. Telephone: +1-407-917-0818.
Do not send Social Security numbers, government identification, tax returns, bank information, payment-card numbers, or other highly sensitive documents through a general privacy or support message. We will explain a safer route if verification requires additional information.
Information we handle and why
| Category | Examples and purposes | Recipients | Retention |
|---|---|---|---|
| Account and profile | Name, email, phone, password hash, account status, and profile fields used to create, secure, authenticate, and support an account. | Hosting, authentication, email, and support providers. | While the account is active, then deleted or de-identified after 24 months of inactivity unless an entitlement or documented exception remains open. |
| Orders and entitlements | Stripe checkout, customer, payment and session identifiers; product, price, currency, discounts, purchase status, access, refunds, and assent records used to process orders and maintain access. | Stripe, hosting, accounting, and support providers. | Seven years from the transaction or longer when needed for an active entitlement, chargeback, dispute, tax, accounting, fraud, or legal obligation. |
| Learning activity | Answers, exams, progress, time, ratings, notes, and study priorities used to deliver study tools, save progress, and provide reports and explanations. | Hosting and providers used for requested product features. | While the account or entitlement is active, then deleted or de-identified after 24 months of inactivity unless the learner asks us to retain it or an exception applies. |
| Support, Sarah, and communications | Name, contact details, messages, support acknowledgements, optional marketing choice, and conversation context used to answer requests and escalate to a person. | Hosting, OpenAI for configured AI responses, and email or support providers. | Support records are generally retained for three years. Browser session state ends with the session. Narrow legal or security exceptions may apply. |
| AI interactions | Prompts, page context, session or thread identifiers, and generated responses used to provide requested study or support features and diagnose the service. | OpenAI and hosting providers. Current Sarah Responses requests use store: false. | Local records follow the learning or support schedule. Provider handling follows the configured account controls and applicable contract. |
| Device, security, and server data | IP address, browser or device details, timestamps, URLs, sessions, and diagnostic data used to deliver, secure, troubleshoot, and protect the service. | Cloudflare, hosting, security, and operations providers. | Security and fraud logs are generally retained from 90 to 365 days, unless an incident or legal obligation requires longer. |
| Consent and preferences | Necessary, Analytics, and Marketing choices; version; timestamp; and Global Privacy Control-derived opt-outs used to remember and demonstrate choices. | Stored in the browser; vendors receive only the signals needed when a category is activated. | Reviewed after 180 days and replaced sooner when the user changes a choice. Minimal suppression evidence may be retained to honor an opt-out. |
| Consent-enabled analytics and marketing | Page, referrer, device, campaign, cookie, identifier, and conversion data used to measure use, performance, and campaigns. | Google, Microsoft Clarity and Bing, Hotjar, and Meta, according to the selected category. | Only while the applicable choice permits activation, subject to verified vendor settings and deletion controls. |
We process this information as needed to provide or perform a contract, respond to a request, operate and secure the service, comply with law, protect rights, or pursue legitimate interests that do not override applicable rights. We rely on consent where the law or the selected feature requires it. We do not treat this notice itself as consent.
Cookies, storage, and similar technologies
| Technology | Category and purpose | Duration and control |
|---|---|---|
passfastConsent | Necessary. Synchronizes the versioned privacy choice across eaexam.co and app.eaexam.co. | Reviewed after 180 days; replaced when the user changes a choice. |
PHPSESSID | Necessary. Provides the authenticated session and related security. | Session-scoped, subject to server-side inactivity and security controls. |
| Quiz local storage | Necessary for the requested saved quiz state. | Until the flow, user, or browser clears it. |
| Sarah session storage | Necessary for the requested interaction. | Browser session. |
| Google Analytics, Microsoft Clarity, and Hotjar | Analytics. Usage, performance, troubleshooting, and diagnostic functions. | Off until Analytics is selected; withdrawal prevents future initialization. |
| Google Ads, Microsoft Bing UET, and Meta Pixel | Marketing. Campaign, attribution, conversion, and advertising measurement. | Off until Marketing is selected and always off under Global Privacy Control. |
Cloudflare Web Analytics automatic injection is disabled. Routine network information may be sent to infrastructure providers, including when requested font or security resources are delivered.
Use Cookie preferences in the footer to Reject, Accept, make a custom choice, or withdraw permission. Withdrawal stops future vendor initialization and clears recognized vendor state where the control supports it. It does not automatically erase information a vendor already retains under an approved obligation.
Global Privacy Control
When your browser exposes Global Privacy Control, PassFast keeps Marketing, sale or sharing, and targeted-advertising permission off across both hostnames. An older conflicting Marketing preference is corrected. Analytics remains a separate choice. Global Privacy Control does not itself delete historical data or replace an identity-verified request where applicable law requires one.
Marketing communications
Support and marketing are separate. Asking Sarah for support or requesting a human handoff does not enroll you in marketing. Email marketing is sent only under the applicable permission or other lawful basis and includes an unsubscribe route. SMS marketing is disabled. We retain the minimum suppression record needed to honor an opt-out.
Sharing and service providers
We disclose information only for the purposes described above to hosting and security providers, Stripe for payment processing, OpenAI for requested AI processing, email and support providers, and consent-enabled analytics or marketing vendors. We may also disclose information when lawfully required, to protect the service or legal rights, or in a corporate transaction subject to appropriate protections.
We do not publish user profiles or learning activity. We do not sell personal information for money. Where an advertising disclosure may qualify as sale, sharing, or targeted advertising under applicable law, it remains off unless the Marketing choice permits it and is always off when Global Privacy Control applies. A vendor remains disabled at relaunch if its role, contract, transfers, retention, or deletion controls have not been verified.
International transfers
PassFast operates from the United States and uses providers that may process information in the United States and other countries. Where required, we use an approved transfer mechanism, contractual safeguards, and provider due diligence. Contact [email protected] to request information about safeguards applicable to your information. We do not treat acceptance of this notice as consent to an otherwise unsupported transfer.
Retention and deletion
We retain information only for an approved purpose and then delete, de-identify, or restrict it. In addition to the periods above:
- an unlimited-until-pass entitlement keeps the minimum account, entitlement, and continuity record while that contractual entitlement remains open, subject to periodic account check-ins;
- contact information may be kept for up to seven years only when needed for contract, tax, fraud, or dispute records;
- backups are generally cycled within 30 to 90 days;
- a narrow legal hold may pause deletion for the affected records; and
- truly de-identified aggregate information may be retained indefinitely.
Your choices and rights
Depending on where you live and which law applies, you may have rights to know or access information; correct it; delete it; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; appeal a decision; use an authorized agent; and complain to a regulator. We will not unlawfully discriminate or retaliate because you exercise a right.
Submit a request to [email protected] or the mailing address above. Describe the request and the service or account involved. We will acknowledge it, use the minimum information reasonably needed for verification, search the relevant systems, and respond within the period required by applicable law. If we deny or limit a request, we will explain the reason and any available appeal route. An authorized agent must provide evidence of authority, and we may verify the request directly with the account holder where permitted.
Do not send a password or full government identifier by ordinary email. A second authorized reviewer checks the response scope, identity match, exceptions, and third-party actions before completion.
Children and learners
Purchasers must be at least 18 and able to enter a binding agreement. A learner age 13 through 17 may use the service only when an adult purchaser has authorized and is responsible for the account. The service is not directed to children under 13, and children under 13 may not use it. If you believe we collected information from a child in circumstances requiring parental authorization, contact [email protected].
Security
We use administrative, technical, and physical measures designed for the information and service. No system is perfectly secure. Use a unique password, protect account credentials, and report suspected misuse to [email protected].
Changes to this notice
We will version and date this notice. For a material change, we will provide at least 30 days' advance notice where applicable and obtain a new choice when required. A change will not retroactively expand a purpose or reduce an existing purchaser's contractual rights without the notice, consent, or other lawful basis required.