TutorStack

Privacy Policy

Effective and last updated: 14 September 2026

Company details

TutorStack is operated by TutorStack Ltd, a company registered in England and Wales under company number 17360160.

Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Contact: admin@tutorstack.co.uk.

Who controls your personal data

TutorStack Ltd is the data controller when you visit our marketing website, request a demo, communicate with us about TutorStack, or when we use account, security, support, and service-administration data for our own purposes.

When a tutoring business uses a TutorStack workspace to manage its parents, students, tutors, applicants, lessons, payments, and communications, that tutoring business will normally be the data controller. TutorStack Ltd acts as its data processor when it hosts and processes that information on the business's instructions. The tutoring business's own privacy notice should explain how it uses that information.

Personal data we collect

  • Your name, email address, chosen appointment time and anything you include when requesting a demo or contacting us.
  • Your TutorStack Assistant conversation, qualification answers and a summary of your business needs. We save these as you use the check and, if you book a call, provide private preparation notes to our team through Google Calendar.
  • Business and account details supplied while configuring or using TutorStack.
  • Support messages, product feedback, and records of our relationship with you.
  • Professional contact details and public business information used for business-to-business outreach, such as your name, role, work email address, employer, website, and public information about the business.
  • Technical, security, and usage information, including device, browser, IP address, authentication, audit, and error information.
  • Analytics information about how the website or product is used, but only where consent is required and you have given it.
  • Where a tutoring business enables the optional lesson-recording feature: foreground microphone audio, transcript text, anonymous speaker labels, recording and processing metadata, and editable lesson-report drafts. The final report sent by a tutor forms part of the ordinary lesson history.
  • Where a tutoring business enables optional AI communications or scheduling assistance: relevant message text and sender role, participant and assignment details, subject, lesson and availability information, existing scheduling records, and draft review metadata.

Client workspaces may contain personal data about administrators, tutors, parents, students, and applicants. The relevant tutoring business decides what information is collected in its workspace and why.

Business and account information marked as required is needed to create or administer an account or perform a customer contract. If it is not provided, we may be unable to provide the relevant account, feature, or service.

Why we use personal data

PurposeLawful basis
Respond to demo requests and pre-contract questionsSteps requested before entering a contract and our legitimate interests
Provide, configure, secure, and support TutorStackContract and our legitimate interests in operating a secure service
Manage accounts, billing, records, and legal obligationsContract and legal obligation
Improve the service using product feedback and necessary operational dataOur legitimate interests
Prepare an editable lesson-report draft when the optional recording feature is usedThe relevant tutoring business's instructions and its applicable lawful basis
Flag a communication for admin review or prepare a proposed scheduling cardThe relevant tutoring business's instructions and its applicable lawful basis
Contact relevant tutoring businesses about TutorStackOur legitimate interests in business-to-business marketing
Optional website or product analyticsConsent

Where we rely on legitimate interests, those interests are running, securing, supporting, and improving TutorStack without overriding your data-protection rights.

Stripe and payment features

A tutoring business may enable Stripe payment and connected-account features in its workspace. Stripe collects card details in the payment form or hosted flow shown to the payer. TutorStack does not intentionally receive or store a full card number or card security code. We may receive and store payment-provider identifiers and limited card display information, such as card brand, last four digits and expiry month or year, where needed to administer, secure, reconcile or remove the relevant payment method.

Saving a card prepares it for a later payment authority. It does not by itself authorise a particular service or charge. For a Split Payment service, TutorStack records the service context, payer, accepted version and hash of the payment statement, timestamp, and other payment-agreement evidence needed to operate and audit that authority.

Depending on the configured model, direct charges are made by the connected Stripe account or accounts belonging to the tutoring business and, where applicable, the tutor. TutorStack does not receive or hold the parent payment principal. The tutoring business remains responsible for its tutoring service, its customer disclosures, cancellation and refund process, and any supplier invoice, receipt or credit note.

Business-to-business outreach

We may obtain professional contact details from a tutoring business's website, Companies House, professional profiles, or other public business sources. We use only the information needed to identify a relevant business contact and send a limited, relevant introduction to TutorStack.

Every marketing email identifies TutorStack and explains how to opt out. We do not send unsolicited marketing email to individual subscribers, including sole traders and some partnerships, unless we have consent or can use the soft opt-in. You can object at any time by replying to the message or emailing admin@tutorstack.co.uk. We will stop the marketing and keep the minimum suppression record needed to respect the request.

Optional Google connections

Google sign-in uses your Google account identity to create or access your TutorStack account. Signing in alone does not connect your Google Calendar or Business Profile. Those connections require a separate action and Google permission screen.

If a parent or tutor connects Google Calendar, TutorStack creates a separate lessons calendar in that account and adds confirmed lessons to it. TutorStack does not read other calendar events for this feature. If a business administrator connects Google Calendar for strategy sessions, TutorStack checks when that account is busy and creates or removes session events on its primary calendar, including Google Meet links. The busy-time check does not retrieve the details of unrelated events.

Where Google reviews are enabled, a business administrator can connect a Google Business Profile, choose a listing, and show that listing's reviewer names, ratings, comments, dates, average rating, and review count on the business website. TutorStack does not post replies or change the listing through this feature.

We store the Google account identifier or email, connection and listing details, and encrypted authorisation tokens needed to keep an optional connection working. Calendar event and booking identifiers are stored where needed to update or remove sessions and lessons. Disconnecting a connection removes its stored authorisation and stops further access for that feature; disconnecting lesson sync also requests removal of the separate lessons calendar. Workspace and backup retention rules below apply to remaining records. We use Google user data to provide these visible features and protect the service, not for advertising or sale.

Service providers and subprocessors

We use the following providers where the relevant service is enabled. They act as subprocessors where they process customer workspace data on our instructions. Depending on the service and processing activity, a provider may instead act as our processor or as an independent controller under its own privacy notice.

ProviderPurposeInformation involved
SupabaseDatabase, authentication, and file storageWorkspace data, account data, files, and technical logs
VercelApplication hosting, delivery, and infrastructureApplication requests, account and workspace data, and technical logs
ResendEmail deliveryRecipient details, message content, and delivery metadata
StripePayments and connected-account servicesIdentity and payment metadata. Payment credentials are collected and held by Stripe.
PostHogConsented analytics and operational monitoringUsage, device, and event data
SentryError and performance monitoringError reports, technical context, and limited identifiers
DeepgramOptional lesson-audio transcriptionAudio sent for transcription, transcript text, anonymous speaker labels, and limited processing metadata
Google GeminiAI drafting, summarisation, and scheduling assistanceUser-selected prompts, generated content, attachments, relevant communication and scheduling context, and, for the optional lesson-recording feature, transcript text and lesson-report questions.
Google CalendarDemo and strategy bookings, Google Meet calls and optional calendar integrationBooking names, email addresses and times; availability, calendar event and authorisation data
Google Business ProfileOptional display of a chosen business listing's reviewsListing identifiers, reviewer names, ratings, comments and review totals

We may also disclose information to professional advisers, regulators, courts, or public authorities where required.

We do not sell personal data.

International transfers

Some providers may process information outside the United Kingdom. Where required, we use an adequacy decision or approved contractual safeguards for those transfers. Contact us if you would like more information about the safeguards that apply.

How long we keep personal data

We keep controller information only for as long as needed for the purpose for which it was collected, including handling enquiries, maintaining security and audit records, resolving disputes, and meeting accounting or legal obligations. We set periods by considering the relationship, the sensitivity of the information, security needs, and applicable limitation, tax, accounting, and regulatory requirements.

Unless a written customer agreement says otherwise, a tutoring business has 30 days after its workspace ends to request an export. We then delete its personal data from active processor-held systems, except where law requires us to retain it. Copies in protected backups remain beyond ordinary use until they expire through the normal backup cycle. Separate records that TutorStack controls, such as billing or security records, follow their own limited retention periods.

For the optional lesson-recording feature, access to stored audio and transcript content ends 30 days after recording starts. Sending a lesson report or discarding a recording ends access earlier and starts deletion of the stored recording content. Scheduled cleanup removes server files after any in-flight upload has finished. A browser may hold a local copy while recording or recovering an interrupted recording; it is removed while the page is open or on the next visit where the browser permits. Provider processing may be subject to the applicable provider terms and technical retention controls.

Message and scheduling records remain in the workspace under the ordinary retention rules that apply to those records. When optional AI communications or scheduling assistance is used, Gemini receives the relevant context to provide the requested classification or draft. Provider processing is subject to the applicable provider terms and technical retention controls.

Restricted information

TutorStack is not intended for deliberate storage of health or disability information that reveals special educational needs, safeguarding case files or allegations, or DBS, criminal-offence, or criminal-conviction data. Customers must not intentionally submit that information unless TutorStack has expressly agreed suitable processing terms and safeguards in writing.

If restricted information is disclosed incidentally, we limit access, notify the relevant customer where appropriate, and delete, return, or otherwise handle it securely under the customer's instructions and applicable law.

The recording feature is not intended for deliberate capture of restricted information. A tutor should stop recording and use the ordinary report route if a lesson is likely to require safeguarding, health, disability, DBS, criminal-offence, or criminal-conviction information to be recorded.

Your rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict, or receive a copy of your personal data, and to object to certain processing. Where we rely on consent, you may withdraw it at any time.

Your right to object: you may object at any time to processing based on our legitimate interests. We will stop unless we have compelling legitimate grounds to continue or need the information for legal claims.

Contact admin@tutorstack.co.uk to exercise a right relating to data controlled by TutorStack Ltd. If your request concerns data held in a tutoring business's workspace, contact that business first. We will assist it as required.

You can complain to the UK Information Commissioner's Office at ico.org.uk.

Automated decisions and children

TutorStack features may draft content, rank information, recommend actions, or carry out configured administrative actions. Depending on the feature and a customer's configuration, an output or action may be reviewed, approved, or automated. Customers remain responsible for choosing appropriate settings, checking outputs where appropriate, and providing suitable privacy information where their workspaces contain children's data.

Lesson-recording speaker labels are anonymous and do not identify participants. A recording is used to prepare a tutor-reviewed report draft, not to profile a child or make an automated decision about a child. The tutoring business remains responsible for giving parents, students, and tutors clear, age-appropriate information before recording begins.

Smart Inbox may flag a relevant communication for an administrator's review. Scheduling assistance may prepare a proposed booking, change, or cancellation from relevant message and scheduling context. Neither feature sends a message, confirms a lesson, or changes a schedule by itself. A person must review and confirm any resulting action.

TutorStack Ltd does not use solely automated processing to make legal or similarly significant decisions about individuals. A customer must not configure TutorStack to make such a decision unless it has a lawful basis and provides the safeguards required by data protection law, including human intervention where required.

Changes and contact

We may update this policy as TutorStack develops. Material changes will be highlighted on this page or communicated directly where appropriate.

Questions about this policy can be sent to admin@tutorstack.co.uk.

Cookies on this site

We use essential cookies to keep you logged in. With your permission we also use PostHog analytics to understand how the platform is used. You can change your choice anytime.

Privacy policy