Legal
Privacy Policy
Last updated: 2 August 2026
The short version
TutorLab provides software and a tutor directory. We use personal data to operate accounts, profiles, enquiries, teaching records, payments, security and the features people request. We do not sell student or parent data, run advertising, or share one tutor's private records with another tutor. Email harry@trytutorlab.uk to ask a privacy question or exercise a data-protection right.
Who we are and our data-protection roles
TutorLab is operated in the United Kingdom by Harry Wright trading as TutorLab. Contact: harry@trytutorlab.uk. TutorLab is the controller for account administration, the public directory, parent enquiries, platform security, billing records and its own service analytics. A tutor is normally the controller for the student, parent and teaching records they choose to enter; TutorLab processes those records on the tutor's behalf to provide the service. Stripe and some other providers may act as independent controllers for activities they determine themselves, such as payment compliance and fraud prevention.
Personal data we handle
Tutor accounts and profiles: name, email, optional phone number, country, business and profile details, qualifications, availability, subscription and account status. Authentication is provided by Supabase; TutorLab does not store a plain-text password.
Student and teaching records entered by tutors: full name, year group, subjects, exam board, school where entered, rates, attendance, lesson and progress notes, homework and session history. Free-text fields could contain information about health, disability or special educational needs. Tutors must only enter what is necessary and must have an appropriate Article 6 basis and, where relevant, an Article 9 condition.
Parent and client data: names, email addresses, phone numbers, child details, enquiries, bookings, invoices, payment status and messages.
Payments: Stripe handles card and bank details. TutorLab receives identifiers, status, amount, fee and limited display details, but not full card numbers. If Stripe asks for identity evidence, an uploaded document passes transiently through TutorLab server memory to Stripe; TutorLab does not persist the document in its database or filesystem.
AI features: prompts, relevant teaching context and generated output for the feature a tutor invokes. Avoid unnecessary identifying or special-category information in prompts.
Technical and security data: request details, IP address, user agent, device/browser information, security events and a first-party pageview count. The pageview counter converts IP, user agent, host and day into a one-way daily pseudonymous hash; raw IP and user agent are not written to that analytics dataset.
Unclaimed tutor directory profiles
Some profiles use professional information obtained from public tutor directories, business websites or other public professional sources. We may hold the tutor's name, subjects, general location, rate range, professional description, source URL and a private contact email. The email is not displayed publicly. Our proposed basis is legitimate interests in operating an accurate tutor directory, subject to a balancing assessment and the tutor's right to object.
UK GDPR Article 14 requires privacy information no later than one month after collection and, if earlier, at first communication or first disclosure. A tutor can request correction or removal at https://www.tutorlab.uk/opt-out or harry@trytutorlab.uk. Promotional cold-email campaigns are paused while the separate PECR consent position is reviewed; a privacy notice is not marketing consent.
Purposes and lawful bases
Contract: creating and administering an account; delivering requested software, AI, invoicing and payment features; and providing paid plans.
Legitimate interests: keeping the service secure, preventing fraud and abuse, responding to support, improving the service with proportionate first-party statistics, operating and measuring the directory, and handling ordinary business records. We balance those interests against people's rights and honour objections where required.
Legal obligation: tax, accounting, regulatory and valid legal requirements.
Consent: Google Analytics, Microsoft Clarity session replay, bounded signup attribution and optional marketing. Consent can be withdrawn at any time; nothing loads before it is given. A child-data privacy assessment and data protection impact assessment covering Clarity are on file.
For tutor-entered teaching records, the tutor decides and documents the lawful basis as controller; TutorLab acts on the tutor's instructions as processor except where it independently determines a purpose required to run or secure the platform.
Children and special-category data
TutorLab accounts are for tutors and parents, not student children, but teaching records often relate to children. We apply data minimisation, private-by-default records, access controls and heightened incident assessment. Tutors should tell parents or guardians how they use a child's information and should not enter unnecessary details. Health, disability, safeguarding, ethnicity, religion and similar information can be special-category data and needs both an Article 6 basis and an Article 9 condition. TutorLab does not use children's records for advertising or third-party model training.
Recipients and providers
Supabase provides database hosting and authentication. Cloudflare provides hosting, security, Turnstile and first-party Analytics Engine storage. Stripe provides subscription and connected-account payments. Resend provides transactional email. Brevo has provided outreach delivery; promotional cold sends are currently paused. Groq processes prompts for AI features. Google Analytics provides optional analytics only after consent. Microsoft Clarity provides consent-gated session replay and heatmaps with sensitive input fields masked; a child-data privacy assessment and DPIA are on file. Automattic may receive a one-way email hash when a Gravatar URL is requested. Providers receive only the data needed for their task. We do not share personal data with advertisers or data brokers.
International transfers
Some providers may process data outside the United Kingdom. Where UK personal data is transferred to a country without UK adequacy regulations, the relevant controller must use an appropriate UK GDPR safeguard, such as the UK International Data Transfer Agreement or UK Addendum, and complete any required transfer risk assessment. Provider location, contractual role and transfer mechanism are reviewed in TutorLab's internal supplier register; contact us for current information about a particular provider.
Retention
Account and teaching records are generally kept while the account is active and then deleted or anonymised within 30 days of a valid closure request, except where a legal hold or another stated retention rule applies. Billing, invoice and tax records may be retained for six years after the relevant accounting period. Security logs are kept only as long as needed for security and incident response. The first-party pageview dataset is retained by Cloudflare Analytics Engine for up to three months. Unclaimed profile suppression data is retained so a removal or marketing objection is not accidentally reversed. Backup deletion follows the provider's normal secure rotation. Category-level periods and exceptions are maintained in the internal retention register.
Your rights and complaints
Depending on the circumstances, you may have rights to access, correct, erase, restrict or receive your personal data, object to legitimate-interest processing, and withdraw consent. Email harry@trytutorlab.uk. We may verify identity and clarify a request. We normally respond within one month and do not charge for a straightforward request.
You can also make a data-protection complaint at that address. We acknowledge complaints within 30 days, investigate without undue delay, provide appropriate updates and explain the outcome. You may complain to the Information Commissioner's Office at https://ico.org.uk or 0303 123 1113.
Security and incidents
Controls include HTTPS, encryption at rest where provided by our infrastructure, server-side authorization, row-level security, least-privilege service credentials, strict input validation, rate limits, bot controls, payment-webhook signature verification and security logging. No service can guarantee that an incident will never occur. We assess suspected personal-data breaches, record the decision, notify the ICO within 72 hours where required, and notify affected people without undue delay where the law requires it.
Cookies and similar technologies
Essential authentication and security storage operates without optional consent where the law permits. Google Analytics and Microsoft Clarity do not load unless analytics is accepted. TutorLab's cookieless first-party pageview counter does not write to the visitor's device and is described above. See https://www.tutorlab.uk/cookies to change analytics choices.
Changes
We update this notice when processing changes. Material changes will be brought to registered users' attention where appropriate. The date above is the current version date.