Privacy Policy
Last updated: May 8, 2026
Nextwave Academy ("we", "us", "our") operates the website nextwaveacademybd.com and the Nextwave Academy mobile application (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
1. Information we collect
- Account information: name, email address, phone number, university, and profile photo when you sign up or sign in (including via Google).
- Google account data: when you choose "Continue with Google", we receive your basic Google profile (name, email, profile picture) via Google's OAuth scopes userinfo.email, userinfo.profile, and openid. We do not access your Gmail, Drive, contacts, or any other Google service.
- Learning data: course enrollments, lesson progress, quiz attempts, and certificates earned.
- Payment data: when you buy a course, we receive an invoice id, transaction id, payment method, and amount from our payment processor (UddoktaPay). We do not store card numbers, mobile-banking PINs, or OTPs.
- Device & usage data: IP address, browser/user-agent, pages visited, and session timestamps used for security (e.g. multi-device session limits) and basic analytics.
2. How we use your information
- To create and secure your account and authenticate sign-ins.
- To deliver the courses and features you request.
- To process payments and confirm enrollments.
- To send transactional emails (welcome, password reset, payment receipts).
- To detect abuse, prevent account sharing, and enforce our Terms of Service.
- To improve our content and the Service.
3. How we share your information
We do not sell your personal data. We share it only with the following processors:
- Supabase — database, authentication and file storage.
- UddoktaPay — payment gateway.
- Resend — transactional email delivery.
- Google — only when you sign in with Google.
- Cloudflare — content delivery and DDoS protection.
We may also disclose information when required by law, to protect our rights, or with your explicit consent.
4. Data retention
We keep your account and learning data for as long as your account is active. You may request deletion at any time by emailing info@nextwaveacademybd.com; we will delete your personal data within 30 days, except records we are legally required to retain (such as payment invoices).
5. Your rights
You can access, correct, or delete your data from your dashboard, or by contacting us. If you signed in with Google, you can also revoke our access at any time at myaccount.google.com/permissions.
6. Security
We use TLS in transit, encrypted storage at rest, row-level security policies in our database, and short-lived signed URLs for protected media. No system is perfectly secure; please use a strong, unique password.
7. Children
The Service is intended for students aged 13 and above. If you are under 13, please do not use the Service. If we learn we have collected data from a child under 13 without parental consent, we will delete it.
8. Changes to this policy
We may update this Privacy Policy from time to time. Significant changes will be announced on this page with an updated "Last updated" date.
9. Contact us
Nextwave Academy, Bangladesh
Email: info@nextwaveacademybd.com
WhatsApp: +880 1889-678282