Tutora Privacy Policy
Last updated: 6 August 2026
This policy explains how Tutora collects, uses and protects personal data when you use our website (tutoratutoring.com) or our tutoring service. It's written for parents, students, tutors and tutor applicants. We've tried to keep it in plain English — if anything is unclear, email us at tutoratutoringltd@gmail.com.
1. Who we are
Tutora ("we", "us", "our") is the data controller for the personal data described in this policy.
- Trading name: Tutora
- Registered company name: Tutora Tutoring Ltd, registered in England and Wales
- Company number: 17402829
- Registered address: 217 Charlton Road, Harrow, England, HA3 9HT
- ICO registration number: ZC224608
- Contact: tutoratutoringltd@gmail.com
If you have a question about your data, this is the email to use.
2. What data we collect
2.1 Account holders
An account is held either by a parent or legal guardian on behalf of a student, or by a student aged 16 or over for themselves. Whoever holds the account is responsible for how it is used. We collect:
- Name and email address
- Password (stored as a secure hash by our authentication provider — we never see or store your plain-text password)
- Payment information (see section 6 — handled by Stripe, not stored by us)
- Booking history, messages sent through the platform, and any support correspondence
2.2 Students
How we hold a student's data depends on their age.
Students aged 16 or over may hold their own account. Where they do, they are the account holder and section 2.1 describes what we collect about them: name, email address, a hashed password, payment information, booking history and messages. They can also add themselves as the student on that account, in which case we hold the subject, level and exam board they are studying, their progress scores against the specification, the lesson summaries their tutor writes, and their booked lesson times.
Students under 16 must be added to a parent's or guardian's account, and cannot register themselves. Because the account belongs to the adult, we deliberately collect the minimum needed to run a lesson:
- First name only (no surname, no date of birth, no school name, unless the account holder chooses to include this in free-text fields)
- Subject, level and exam board being studied
- Lesson progress scores against the exam specification, and written lesson summaries prepared by the tutor after each session
- Booked lesson times
The account holder may also choose to give an under-16 student their own login, so they can see their own progress, lessons and lesson notes and message their tutor. If they do, we hold that student's email address and a hashed password for the login. It is created by the account holder, and it cannot book, cancel or pay for anything.
We do not knowingly collect more than this about a student under 16. If an account holder or tutor includes extra personal detail in a free-text field (e.g. a lesson note), please keep this to what's relevant for tutoring.
2.3 Tutors and tutor applicants
When someone applies to tutor with us, we collect:
- Name, email, phone number
- Subjects and levels they can teach, the grades they achieved, their availability and teaching experience
- References, and the result of an enhanced DBS check including a children's barred list check
- Once approved: ratings and review comments left by parents, lesson summaries they write, and lesson data
DBS results are criminal offence data under Article 10 of the UK GDPR. We hold them under stricter conditions than ordinary personal data: access is limited to the founders and those approving tutors, they are never shared with parents or students, and we retain only the certificate outcome and reference number rather than the full disclosure detail. Tutors are given fuller detail in the Tutor Privacy Notice.
2.4 Technical data we collect automatically
When you use the site, our systems record limited technical information — this happens automatically as part of running a secure service:
- IP address, browser and device type
- Login and authentication events (including failed login attempts)
- Server logs of pages and actions, with timestamps
- Error and diagnostic logs
We use this to keep accounts secure, detect and investigate suspicious activity, and fix faults. We do not use it to build advertising or behavioural profiles, and we do not use analytics or tracking tools (see section 10).
2.5 The free Maths diagnostic
The diagnostic is open to anyone and needs no account. To send you your report we ask for one thing: an email address.
- We use it to send you that report, once.
- We do not store it. It is not added to a mailing list, not kept in our database, and not used to contact you again. If you want to hear from us, you contact us.
- Your answers are sent with it so the report can be written, and they are not stored either.
If you would rather not give an address, you can simply not take the diagnostic — nothing else on the site depends on it.
2.6 Where we get your data from
Most data comes directly from you. Some does not:
| Data | Where it comes from |
|---|---|
| An under-16 student's first name, subject, level and needs | The parent or guardian who holds the account, not the student |
| Ratings and reviews about a tutor | Parents who have booked that tutor |
| Payment, refund and card-status confirmation | Stripe |
| Tutor DBS results | Our DBS umbrella body |
| Tutor references | The referees a tutor nominates |
Where we receive data about you from someone else, this policy is your notice of that processing.
3. Why we process this data (lawful basis)
| Data | Lawful basis |
|---|---|
| Account holder details, booking, payment | Performance of a contract (providing the tutoring service you've signed up for) |
| An under-16 student's first name, subject/level, lesson records | Performance of a contract, entered into by the parent on the student's behalf, plus parental consent (see section 4) |
| A student aged 16 or over holding their own account | Performance of a contract, entered into by the student directly |
| An under-16 student's own login credentials, where the account holder creates one | Performance of a contract, at the account holder's request |
| Tutor applications | Performance of a contract (pre-contractual steps) |
| DBS and reference checks | Legal obligation / legitimate interest in safeguarding, and for the DBS result a condition in Schedule 1 of the Data Protection Act 2018 |
| Ratings and reviews | Legitimate interest (maintaining service quality) |
| Payment, refund and dispute records | Performance of a contract, and legal obligation (tax and accounting records) |
| The email address you give the free Maths diagnostic (see 2.5) | Performance of a contract — sending the report is the thing you asked us to do. It is used once and not stored. |
| Technical and security logs (see 2.4) | Legitimate interest (keeping the service secure and working) |
| Reviewing messages sent through the platform (see 11) | Legitimate interest in protecting children, and our safeguarding responsibilities |
| Reporting a safeguarding concern to the authorities (see 13) | Legal obligation, and substantial public interest in safeguarding children (UK GDPR Art 9(2)(g) / DPA 2018 Sch 1 Part 2) |
Marketing: Tutora does not send marketing emails. Every email we send is transactional — it exists because of something happening on your account, such as a new message, a published progress report, a lesson time change, a password reset, or a payment. If we ever introduce marketing emails, we will ask for your separate opt-in consent first and update this policy.
We do not use automated decision-making or profiling that has a legal or similarly significant effect on any user.
4. Children's data
Tutora is used by school-age children, some of whom may be under 13. Because of this:
- Under 16, the account holder is always a parent or legal guardian, not the child. It's the adult who registers, agrees to these policies, and consents to the child's data being processed. A student under 16 cannot register themselves.
- At 16 and over, a student may hold their own account, register themselves, and agree to these policies for themselves. In practice this is A-Level age. Where a student does this, they are the account holder and their data is handled as described in 2.1 and 2.2.
- By adding a child profile, an account holder confirms they are that child's parent or legal guardian and are consenting on the child's behalf to the processing described here.
- We collect the minimum data necessary to deliver tutoring (see 2.2).
- Every tutor is DBS-checked and approved by a person before they can teach anyone. Approval is never automatic, and access can be suspended or withdrawn at any time. Our vetting standards are set out in the Safeguarding Policy.
- Who can exercise a student's rights. A student aged 16 or over makes requests about their own data directly. Below 16, requests are normally made by the parent who holds the account — but a younger student can still make a request about their own data, and we will consider whether they are able to understand the request themselves before deciding who to respond to.
- Lessons are not recorded by Tutora. They take place over the tutor's video call link (Google Meet or Zoom); see section 7.
5. Where your data is stored and who processes it
We use a small number of trusted service providers ("processors") to run Tutora. We don't sell or rent personal data to anyone.
| Processor | What they do | Location |
|---|---|---|
| Supabase | Hosts our database and handles user authentication (login/password security) | EU (Ireland) region |
| Resend | Sends the transactional emails described in section 3 | EU (Ireland) region |
| Stripe | Processes card payments and refunds. Card details go directly to Stripe and never touch our servers. | UK/EU and US, under Stripe's own Data Processing Agreement and standard contractual clauses |
| Google Meet / Zoom | Video call platform used to hold lessons (tutor's meeting room). We don't route or store the call itself. | Governed by Google's / Zoom's own privacy policies |
| Cloudflare | Provides the anti-abuse check (Turnstile) on the consultation booking form and on the login and sign-up pages. Sees your IP address and basic browser information in order to tell a person from an automated script. It is not used for analytics and does not track you across sites. | UK/EU, under Cloudflare's own Data Processing Agreement |
Fonts, images and code libraries are served from Tutora's own site, not from third-party networks, apart from the two exceptions named in section 10 (Stripe on the Payments page, Cloudflare on the consultation, login and sign-up pages).
All of the above are bound by data processing agreements and, where data leaves the UK/EEA, appropriate safeguards (such as the UK's International Data Transfer Addendum or equivalent standard contractual clauses).
6. Payments
Card payment details are collected and processed directly by Stripe. Tutora does not store full card numbers, CVV codes, or other sensitive payment data on its own servers.
What we hold about your card. When you save a card, Stripe returns us a reference to it along with the card brand, its last four digits, and its expiry date. That is all we store — enough for you to recognise which card is saved, and to charge it for lessons you have confirmed. The card number itself stays with Stripe.
What we hold about payments. For each lesson charged we keep the amount, the date, a description of the lesson, which child and tutor it relates to, whether it succeeded, and Stripe's reference for the transaction. We need this to run your account, pay tutors correctly, and meet our tax and accounting obligations.
Refunds and disputes. If you raise a payment dispute about a lesson, we record the lesson it relates to, the date, and the reason you give us. That information is visible to Tutora administrators reviewing the dispute; the reason you write is not shown to the tutor, though the fact that a lesson was refunded necessarily affects their pay for it and is visible in their payment records. If we uphold a dispute, we instruct Stripe to refund the original card and keep a record that we did so.
Chargebacks. If you dispute a payment with your own bank or card issuer instead, Stripe notifies us and we may have to share transaction records — the booking, the charge, and correspondence about the lesson — with Stripe and your card issuer to respond. Our lawful basis for that is our legitimate interest in defending a claim, and compliance with the card schemes' rules.
Retention. Payment and refund records are kept for 6 years after the end of the relevant tax year, as UK tax law requires, even if you close your account in the meantime. This is why financial records outlive an account deletion.
7. Lessons and video calls
Lessons happen over video call, using a link provided by the tutor (Google Meet or Zoom). Tutora does not record lessons. Anything said or shown on the call is governed by the video platform's own privacy terms, not by us — we only store the booking time and the tutor's written summary afterwards, not the video/audio itself.
A parent or another responsible adult may sit in on or be within earshot of any lesson.
8. How long we keep data
We keep data only for as long as it's needed:
- Active accounts: for as long as the parent's account remains open and in use.
- Inactive accounts: if an account has had no bookings and no logins for 24 months, we will email the account holder and then delete the account and its child profiles if there is no response. We do not keep accounts indefinitely.
- Technical and security logs: logs under our direct control are normally retained for up to 90 days and then deleted or anonymised, unless they are required for an ongoing security, fraud, legal or safeguarding investigation. Our service providers may retain their own operational, security and payment records for different periods where necessary to provide their services, prevent fraud, or comply with legal and financial obligations.
- Safeguarding records: where a concern has been raised, the record of that concern and any action taken is kept for as long as necessary for safeguarding and legal purposes, which may be longer than the periods above. This is a deliberate exception — safeguarding records are not deleted simply because an account closes.
- Removed child profiles: when a parent removes a child's profile, the associated child records are permanently purged from our systems within 7 days.
- Deleted tutor accounts: when a tutor account is deleted (whether by the tutor or by Tutora), their data is permanently purged within 7 days, except for the financial and safeguarding records described here.
- Financial records: payment, refund and tutor payout records are kept for 6 years after the end of the tax year they relate to, as UK tax law requires. This applies even where the related account has been closed, and is why a deleted account does not erase the record that a payment happened.
- Backups: deleted data may persist for a short additional period in routine system backups before being overwritten. Backups are taken and rotated by Supabase, who host our database, and the retention window is the one set by Supabase's terms and the plan we are on rather than a period we choose ourselves.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you (or your child)
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict or object to certain processing
- Data portability (receive your data in a portable format)
- Withdraw consent at any time, where processing is based on consent
To exercise any of these rights, email tutoratutoringltd@gmail.com. We'll respond within one month, as required by law.
If you're not satisfied with how we've handled your data, you have the right to complain to the UK's data protection regulator:
Information Commissioner's Office (ICO) Website: ico.org.uk Helpline: 0303 123 1113
10. Cookies, storage, and third-party requests
Tutora sets no cookies of its own, and uses no analytics, advertising or tracking of any kind.
What we store on your device
- A Supabase authentication session token, held in your browser's session storage, so you stay logged in as you move between pages. Session storage is cleared automatically when you close the tab — it does not persist like a cookie.
- If you take the free Maths diagnostic, your progress through it — which set of questions you chose, how far through you are, and the options you have picked — is held in your browser's session storage so that reloading the page does not lose your place. It holds no name and no contact details, and it is cleared when you close the tab. You can clear it at any time by pressing Start again on the diagnostic itself.
- On the Payments page only, Stripe sets two cookies of its own (
__stripe_midand__stripe_sid) to detect and prevent fraudulent card use. These are Stripe's, not ours. - On the consultation booking page and the login and sign-up pages, Cloudflare's Turnstile check runs to tell a person from an automated script. It reads your IP address and basic technical signals from your browser to do that. It does not set a cookie on Tutora and is not used to track you, here or on any other site.
Every one of these is strictly necessary — to log you in, to keep your place in something you chose to start, and to take a payment safely — so none of them requires your consent. The Turnstile check above is strictly necessary for the same reason: it is what stops the booking form being used to send email in our name, and what stops an automated script working through passwords against the login page. We do not currently use any storage that would require your consent.
Third parties your browser contacts
Our fonts, images and code are served from Tutora's own site rather than from other companies' networks, so browsing Tutora does not hand your IP address to anyone else. There are two exceptions. The Payments page loads Stripe's card-entry library directly from Stripe, as Stripe requires. The consultation booking page and the login and sign-up pages load Cloudflare's Turnstile check, which is what stops the booking form being used to send unwanted email in Tutora's name and what stops an automated script working through passwords; it sees your IP address and basic browser information for that purpose only, and is not analytics.
If we ever introduce analytics or any non-essential storage, we will update this policy and ask for your consent first.
11. Messages sent through Tutora
All communication between parents, students and tutors must take place through the Tutora platform — our Safeguarding Policy prohibits tutors and students contacting each other privately.
We review messages sent through the platform as part of our safeguarding responsibilities. You should not treat platform messages as private correspondence between you and the tutor.
- Reviewing is done by a founder, or a member of the Tutora team acting under their direction.
- We look for signs that a child may be at risk, or that our safeguarding rules are being broken — for example attempts to move contact off the platform, requests for personal contact details, or arrangements to meet in person.
- We are not reading messages for marketing purposes, and message content is never sold or shared with advertisers.
- If a review raises a safeguarding concern, we follow the process in our Safeguarding Policy, which may include reporting to the authorities (see section 13).
If you need to discuss something genuinely private, contact us directly at tutoratutoringltd@gmail.com rather than through platform messaging.
12. What other people can see about you
Tutora shares the minimum needed for a lesson to happen.
A tutor can see, about a family they are booked with: the child's first name, subject, level and exam board, any needs or notes the parent chooses to share, booked lesson times, and messages sent to them through the platform. Tutors do not see the parent's payment details, home address, or the child's surname or date of birth.
A parent can see, about a tutor: their name, the subjects and levels they teach, their teaching experience, their video-call link, and ratings and reviews left by other parents. Parents do not see a tutor's home address, phone number, date of birth, references or DBS certificate — they see only that a tutor has been checked and approved.
An under-16 student with their own login can see: their own progress, lessons, lesson notes and reports, and messages with their tutor. They cannot see payment information of any kind. A student aged 16 or over who holds their own account sees everything an account holder sees, including payments.
Other parents can see: ratings and review comments left about a tutor. If you leave a review, it is shown alongside your first name only.
13. When we share data with authorities and others
We do not sell or rent personal data. Beyond the processors listed in section 5, we will share data in these situations:
- Safeguarding referrals. If we believe a child is at risk, we will share relevant information with the appropriate authority — this may include the police, the Local Authority Designated Officer (LADO), children's social care services, or the Disclosure and Barring Service. Where a child is at risk, we will make a referral without seeking consent first, and may not be able to tell you we have done so if doing that would put the child at greater risk or prejudice an investigation.
- Legal obligations. Where we are required to disclose data by law, a court order, or a regulator such as the ICO or HMRC.
- Establishing or defending legal claims, or investigating suspected fraud or misuse of the service.
- A sale or transfer of the business. If Tutora is ever sold or merged, account data may transfer to the new owner. We would tell account holders before this happened.
14. How we protect your data
- Data is encrypted in transit (HTTPS/TLS) between your browser and our systems, and encrypted at rest by our database provider.
- Passwords are stored only as a secure one-way hash by our authentication provider — nobody at Tutora can see or recover your password.
- Card details never reach our servers; they go directly to Stripe (see section 6).
- Access to personal data is limited to those who need it for their role. Safeguarding records and DBS results are restricted to the founders — see 2.3.
- Database access rules mean a logged-in user can only reach their own account's records.
- We keep our systems and dependencies up to date and monitor authentication logs for unusual activity.
No online service can promise perfect security. If a data breach occurs that is likely to put your rights at risk, we will tell you, and we will report it to the ICO within 72 hours as the law requires.
15. Changes to this policy
We may update this policy from time to time, for example as the service grows or as we add new features. We'll update the "last updated" date at the top of this page. Significant changes will be communicated to account holders by email.
16. Contact us
Questions, concerns, or requests about your data: tutoratutoringltd@gmail.com