1. Who We Are
Match2.Cards ("we", "our", or "us") is operated by Fresh Online Pte Ltd, a company registered in Singapore. We provide educational card-matching games that help students build vocabulary and visual recognition by pairing colour-coded icons with their written words, in English and 15 other languages.
This policy covers the match2.cards website and game.
We are committed to protecting the privacy of our users, especially children. This Privacy Policy explains how we collect, use, and safeguard information when you use our website and applications.
2. How Our Platform Works
Understanding how Match2.Cards works is important for understanding what data we collect. Our platform has three types of users, each with different data requirements:
- Students sign in using a simple share code (e.g., sage.2026) provided by their teacher or parent. No account creation, no email, and no password is required. Students can also play the free game with no sign-in at all.
- Teachers create an account to set up classes, generate student share codes, build custom icon collections, and view learning progress reports.
- Parents (Match2@Home) create an account to manage their child's learning at home.
3. Information We Collect
3.1 Student Data
When a student uses Match2.Cards, we collect only:
- Share code: A teacher-assigned code used to sign in (e.g., sage.2026)
- Nickname or label: A first name or nickname assigned by the teacher (e.g., "Mike") — no full names are required
- Learning performance data: Which icon categories were practised, matches and accuracy scores, game modes played, language selected, and session duration
- Device identifier: A locally-stored browser identifier (using browser local storage) that allows students to reconnect to their share code on the same device. This identifier is stored only on the student's device and is not transmitted to or stored on our servers.
IMPORTANT: Student performance data is completely anonymous and cannot be linked back to individual children. Because this data cannot identify students, it is not considered "personal data" under UK GDPR and is not subject to international transfer restrictions.
Guests who play without signing in have their scores and preferences stored only in their own browser. Nothing is sent to our servers, and guest progress is kept entirely separate from any signed-in student's progress.
We do NOT collect the following from students:
- Email addresses
- Dates of birth or age
- Full names or surnames
- Home addresses
- Parent or guardian contact information
- Photos, videos, or location data
- Microphone or camera access (the game plays audio but never records)
- IP addresses (beyond standard web server logs)
3.2 Teacher Data
When a teacher creates an account, we collect:
- Email address and name: Provided via sign-in with Google, Microsoft, or Apple (using OAuth 2.0)
- Organisation name: Optional, provided by the teacher
- License and subscription details: Plan type, seat count and activation status
- Content you create: Class groups, student nicknames and share codes, and any custom icon collections you build
3.3 Parent Data (Match2@Home)
When a parent creates an account, we collect:
- Email address and name: Provided via sign-in with Google, Microsoft, or Apple (same OAuth scope as teachers)
- Child sign-in codes: The share codes and nicknames you create for your own children
- License details: Purchase and activation status
3.4 Teacher AI Assistant
Teachers can use our AI assistant to manage classes and ask questions about student progress. Messages you type into the assistant, and the anonymous class progress data needed to answer them, are sent to our backend and processed by a third-party AI language model provider to generate a reply. Student nicknames are the only student identifier involved — no student personal information is sent. Please do not type personal information about students into the assistant.
3.5 Automatically Collected Information
For all users, our web servers may automatically log:
- Device information: Browser type, operating system, and device type
- Session data: Session duration and features used within the app
3.6 Website Analytics
Our public website pages use Google Analytics 4 to understand how visitors find and use match2.cards (for example which pages are viewed and how long visits last). Google Analytics collects standard web analytics data such as approximate location (from IP address), device and browser type, and pages viewed. We use it only in aggregate to improve the site. We do not use it to build advertising profiles, and we do not run behavioural advertising of any kind.
All learning analytics — the progress data behind teacher and parent reports — are stored internally in our own database and are never sent to Google Analytics.
4. How We Use Your Information
- Deliver educational games and track learning progress
- Generate progress reports for teachers and parents
- Allow students to reconnect to their share code on the same device (via local browser storage)
- Deliver spoken word audio in the language you choose
- Process teacher and parent purchases and subscriptions
- Improve our educational content and game design using anonymised, aggregated learning data
- Understand website usage in aggregate so we can improve the site
- Provide technical support
- Ensure platform security and prevent abuse
5. Children's Privacy
Our approach: Match2.Cards is designed so that students never need to provide personal information. Students sign in with a share code — there is no account creation, no email required, and no password to manage.
5.1 How We Protect Children
- Students provide no personally identifiable information
- Student share codes are generated and managed by teachers or parents
- No behavioural advertising or ad targeting of any kind
- No social features, messaging, or communication between users
- No user-generated content is shared between students
- Teachers and parents can delete student data at any time
5.2 COPPA Compliance (US)
Because students do not provide personal information, the typical COPPA requirement for verifiable parental consent is addressed by design. Teacher or parent oversight is built into the platform through the share code system.
5.3 School Use
When used in schools, teachers act as the responsible party for their students' data. Teachers control the creation and deletion of student share codes and can remove student data at any time.
6. Legal Basis for Processing (GDPR)
We process personal data based on:
- Contract Performance: To provide the educational services you have subscribed to
- Legitimate Interests: To improve our platform, ensure security, and conduct educational research using anonymised data
- Consent: For optional communications and website analytics (you can withdraw consent at any time)
- Legal Obligation: To comply with applicable laws
7. Data Sharing
7.1 We Do Not Sell Personal Information
We never sell, rent, or trade personal information to third parties for marketing or any other purpose.
7.2 Who Can See Student Data
- Teachers can view learning progress for their own students only
- Parents (Match2@Home) can view their own child's progress only
- Student data is never shared with other students, other schools, or third parties
7.3 Service Providers
We use the following third-party services to operate our platform:
Firebase / Google Cloud — Database, cloud functions, file storage (spoken word audio), and backend infrastructure. Processes all platform data (encrypted at rest and in transit). ISO 27001, SOC 2 Type II certified. Location: United States.
Auth0 — Secure teacher and parent sign-in (OAuth 2.0). Processes email address and name only for authentication. ISO 27001, SOC 2 Type II certified. Location: United States.
Paddle — Payment processing (Merchant of Record). Processes payment details. We do not store payment card data on our servers. Location: United Kingdom.
Netlify — Website hosting and Content Delivery Network (CDN). Serves static website files globally. Netlify is certified under the EU-U.S. Data Privacy Framework. No teacher or student personal data is stored on Netlify servers — only technical data like IP addresses are processed for rate limiting and security purposes. Location: United States (with global CDN).
Google Analytics — Aggregate website usage statistics for our public pages only. Not used inside student gameplay reporting. Location: United States.
AI language model provider — Generates replies in the teacher AI assistant. Receives only the teacher's typed messages and anonymous class progress data. Not used to train third-party models. Location: United States.
All service providers are contractually required to protect your information and process it only as instructed. We have Data Processing Agreements in place with all processors handling personal data.
7.4 Legal Disclosure
We may disclose information where required to do so by law, or where necessary to protect our rights, the safety of users, or to investigate suspected fraud or abuse.
8. Data Storage and International Transfers
Our database is hosted on Google Cloud (Firebase Firestore) in the nam5 multi-region (United States). Google Cloud infrastructure is:
- ISO 27001 certified
- SOC 1, SOC 2, and SOC 3 audited
- GDPR compliant
International Transfer Safeguards
For users in the UK and EU, international data transfers to the United States are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission and UK Information Commissioner's Office (ICO-approved Article 46 mechanism under UK GDPR)
- UK Extension to the EU-U.S. Data Privacy Framework — Google Cloud is certified under this framework, providing additional adequacy-level protections for UK data transfers
- Technical safeguards:
- All data encrypted at rest using AES-256 encryption
- All data encrypted in transit using TLS 1.3
- Regular third-party security audits
- Google Cloud ISO 27001 and SOC 2 Type II certifications
Student Data: Because student performance data is anonymous and cannot identify individual children, it is not considered "personal data" under UK GDPR and is not subject to international transfer restrictions.
Teacher Data: Only minimal teacher data (name and email address) is transferred to the United States, and this is fully protected by the safeguards listed above.
Our website content is served via a global Content Delivery Network (CDN), meaning static assets are delivered from the server closest to each user.
9. Data Security
We implement industry-standard security measures to protect your data:
- All data encrypted in transit using HTTPS / TLS 1.3
- All data encrypted at rest using AES-256 on Google Cloud infrastructure
- Secure authentication via OAuth 2.0 (Google, Microsoft, Apple) and Auth0
- Firebase Security Rules enforce role-based access controls at the database level
- Multi-factor authentication (MFA) available for teacher and parent accounts
- Student share links use opaque, non-guessable tokens rather than exposing internal identifiers
- No payment card data stored on our servers (handled by Paddle)
- Regular security monitoring and updates
- Staff access limited on a need-to-know basis
While no system is 100% secure, we continuously monitor and update our security practices to protect your information.
10. Data Retention
- Active accounts: Data retained while the account remains active
- Deleted accounts: Personal data soft-deleted immediately upon request, then permanently deleted within 30 days. Backup data is automatically purged within 90 days of deletion.
- Student data: Deleted when the student's share code is removed by the teacher or parent, or when the teacher/parent account is deleted
- Guest data: Stored only in the browser; cleared whenever the user clears their browser storage
- Anonymised data: Aggregated, anonymised learning data may be retained indefinitely to improve our educational content
11. Cookies and Local Storage
Match2.Cards uses browser local storage (not tracking cookies) to:
- Remember your sign-in session
- Store your preferences and settings (e.g., sound on/off, language, chosen category)
- Keep guest scores on the device for players who have not signed in
- Allow students to reconnect to their share code on the same device (device identifier stored locally only)
Our public website pages also set Google Analytics cookies for aggregate usage measurement, as described in section 3.6. We do not use advertising cookies or third-party tracking cookies, and we do not sell or share analytics data for advertising. Essential cookies may be set by our hosting and authentication providers for basic site functionality and security.
You can block or delete cookies in your browser settings at any time. Blocking analytics cookies does not affect gameplay.
12. Your Rights
Under GDPR, UK GDPR, and similar laws, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Portability: Receive your data in a portable format
- Restriction: Limit how we use your data
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw previously given consent at any time
How to Exercise Your Rights
For Teachers and Parents:
- Access & Modify: View and update your name and email address in your account dashboard at any time
- Export Data: Request an export of your account data and anonymous student performance data
- Delete Account: Request account deletion via your account settings or by contacting hello@match2.cards
- Delete Student Groups: Teachers can delete individual student groups and all associated anonymous performance data directly from their dashboard
Deletion Timeline:
- Accounts are soft-deleted immediately upon request (you can recover during a 30-day grace period)
- After 30 days, accounts are permanently deleted and cannot be recovered
- Backup data is automatically purged within 90 days of deletion
- You can request a final data export before deletion
For All Users:
To exercise any of these rights, contact us at hello@match2.cards. We will respond within 30 days.
UK and EU residents: You also have the right to lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO) — https://ico.org.uk/
- EU: Your local data protection authority — https://edpb.europa.eu/about-edpb/about-edpb/members_en
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. We will notify account holders of significant changes by email. The "Last Updated" date at the top indicates when the policy was last revised.
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
14. Contact Us
For privacy-related inquiries, data requests, or questions about this policy:
Postal Address
Fresh Online Pte Ltd
68 Circular Road #02-01
Singapore 049422
Data Protection Authorities
UK Data Protection Authority:
If you are in the UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) — https://ico.org.uk/
EU Data Protection Authority:
If you are in the EU and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority — https://edpb.europa.eu/about-edpb/about-edpb/members_en
See also our Terms and Conditions.