Privacy Policy

Last updated: May 8, 2026

Nextwave Academy ("we", "us", "our") operates the website nextwaveacademybd.com and the Nextwave Academy mobile application (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.

1. Information we collect

  • Account information: name, email address, phone number, university, and profile photo when you sign up or sign in (including via Google).
  • Google account data: when you choose "Continue with Google", we receive your basic Google profile (name, email, profile picture) via Google's OAuth scopes userinfo.email, userinfo.profile, and openid. We do not access your Gmail, Drive, contacts, or any other Google service.
  • Learning data: course enrollments, lesson progress, quiz attempts, and certificates earned.
  • Payment data: when you buy a course, we receive an invoice id, transaction id, payment method, and amount from our payment processor (UddoktaPay). We do not store card numbers, mobile-banking PINs, or OTPs.
  • Device & usage data: IP address, browser/user-agent, pages visited, and session timestamps used for security (e.g. multi-device session limits) and basic analytics.

2. How we use your information

  • To create and secure your account and authenticate sign-ins.
  • To deliver the courses and features you request.
  • To process payments and confirm enrollments.
  • To send transactional emails (welcome, password reset, payment receipts).
  • To detect abuse, prevent account sharing, and enforce our Terms of Service.
  • To improve our content and the Service.

3. How we share your information

We do not sell your personal data. We share it only with the following processors:

  • Supabase — database, authentication and file storage.
  • UddoktaPay — payment gateway.
  • Resend — transactional email delivery.
  • Google — only when you sign in with Google.
  • Cloudflare — content delivery and DDoS protection.

We may also disclose information when required by law, to protect our rights, or with your explicit consent.

4. Data retention

We keep your account and learning data for as long as your account is active. You may request deletion at any time by emailing info@nextwaveacademybd.com; we will delete your personal data within 30 days, except records we are legally required to retain (such as payment invoices).

5. Your rights

You can access, correct, or delete your data from your dashboard, or by contacting us. If you signed in with Google, you can also revoke our access at any time at myaccount.google.com/permissions.

6. Security

We use TLS in transit, encrypted storage at rest, row-level security policies in our database, and short-lived signed URLs for protected media. No system is perfectly secure; please use a strong, unique password.

7. Children

The Service is intended for students aged 13 and above. If you are under 13, please do not use the Service. If we learn we have collected data from a child under 13 without parental consent, we will delete it.

8. Changes to this policy

We may update this Privacy Policy from time to time. Significant changes will be announced on this page with an updated "Last updated" date.

9. Contact us

Nextwave Academy, Bangladesh
Email: info@nextwaveacademybd.com
WhatsApp: +880 1889-678282