Privacy Policy

Last updated: April 2026

1. Who we are

TutorGrid (“we”, “us”, “our”) operates the TutorGrid platform at tutorgrid.pages.dev. We are the Data Controller for personal data processed through this platform. We are in the process of registering with the Information Commissioner's Office (ICO) as required under the UK GDPR and Data Protection Act 2018.

Contact: privacy@tutorgrid.app

2. Data we collect

Tutors: Name, email address, password (hashed), biography, timezone, pricing, availability, Stripe Connect account ID, lesson history, student records you create, and materials you upload.

Students (booked via a tutor's page): Name, email address, phone number (optional), lesson history, and any notes a tutor adds.

Technical data: IP address, browser type, and request logs processed by Cloudflare as our hosting provider.

Payment data: We do not store card details. Payments are processed by Stripe. We store Stripe session IDs and payment status only.

3. Lawful basis for processing

  • Contract performance — to operate your tutor account, process bookings, and facilitate payments.
  • Legitimate interests — platform security, fraud prevention, and service improvement.
  • Legal obligation — retaining financial records for 7 years as required by HMRC.
  • Consent — where you have explicitly agreed (e.g. GDPR consent at registration).

4. Third-party processors

5. Data retention

  • Account and profile data: retained while your account is active, then deleted within 30 days of account closure.
  • Lesson and payment records: retained for 7 years to meet HMRC financial record-keeping obligations.
  • Student contact data: deleted when the tutor deletes the student record or closes their account.

6. Children's data

TutorGrid accounts are for tutors aged 18 and over. Student records may include minors' data (name, email) entered by their tutor. Tutors who work with under-18s are responsible for obtaining appropriate consent from parents or guardians and confirming they hold a valid DBS check. We adhere to the ICO's Children's Code (Age Appropriate Design Code) and apply high privacy standards to any data that may relate to children.

7. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of your personal data (use the data export in Settings).
  • Rectification — correct inaccurate data via your account settings.
  • Erasure — delete your account and data (use the delete account option in Settings, subject to legal retention obligations).
  • Portability — export your data in machine-readable format (JSON export in Settings).
  • Restriction — ask us to restrict processing in certain circumstances.
  • Objection — object to processing based on legitimate interests.

To exercise any right, email privacy@tutorgrid.app. We will respond within 30 days.

8. Complaints

If you are unhappy with how we handle your data, you can complain to the ICO at ico.org.uk/make-a-complaint or call 0303 123 1113.

9. Changes to this policy

We will notify registered users by email of any material changes to this policy at least 14 days before they take effect.

Privacy Policy — TutorGrid