The Case Booklet
Privacy policy

Privacy policy

We collect an email address and the work you produce. Nothing else, and none of it is sold.

Last updated 1 August 2026

Who is responsible

The Case Booklet, operating casestudyinterview.com. For anything on this page, write to team@casestudyinterview.com.

What we collect

DataWhy
Your email addressIt is your account. We send sign-in codes to it, and nothing else unless you write to us first.
Your handwriting and typed answersSo your work is saved and appears on your other devices.
Your self-scoresTo show progress across the 15 papers.
Order recordsOrder number, amount, date and status, so you have receipts and we can handle refunds.
A session cookieOne cookie so you stay signed in. It holds a random token, nothing about you.
Anonymous usage eventsWhich pages and cases are opened, and whether a purchase completed. Tied to a random account id, never to your email.
We do not use advertising or advertising cookies, and we never sell or rent your data. We do use a privacy-focused analytics tool to count how the booklet is used – which papers get opened, where people get stuck. It never receives your email address, and it never sees anything you write or type on the paper.

We never see your card

Payments go to Polar Software, Inc. as merchant of record. Card details are entered on Polar's systems and never reach ours. We receive only the fact that an order was paid, its amount, and its reference.

Who processes data on our behalf

ProviderWhat they handle
CloudflareHosting, and the database holding your account, work and orders
ResendDelivering sign-in code emails
Polar Software, Inc.Payments, invoicing and sales tax as merchant of record
PostHogAnonymous usage analytics, so we can see which cases work and which do not

Each acts only on our instructions. Because these are international services, your data may be processed outside your country, including in the United States and the European Union.

How long we keep it

Your account and work are kept until you delete them. Sign-in codes are deleted the moment they are used and expire in ten minutes regardless. Order records are kept for as long as tax and accounting rules require, typically several years.

Your choices

Depending on where you live you may have additional rights – access, correction, deletion, portability, or objection. Write to us and we will honour them.

Security

Sign-in codes are stored hashed, never in plain text, and expire in ten minutes after five wrong attempts. Session tokens are stored hashed as well, so a copy of our database cannot be used to sign in as you. The session cookie is HttpOnly and Secure.

Children

This is aimed at adults preparing for job interviews. It is not directed at children under 16 and we do not knowingly collect their data.

Changes

If this policy changes materially we will update the date above and note the change on this page.