For everyone
Privacy Policy
What we do with personal data as controller — for tutors and for visitors to this site.
Version 2 September 2026
MyTutoringHome ("we", "us") builds software that independent language tutors use to run their practice. This policy explains what we do with personal data, in plain language.
If you are a student who was invited to a tutor's portal, the short version is in section 2 and the Student Portal Terms.
1. Who is responsible
MyTutoringHome Fluiterlaan 536, 2903 HN Capelle aan den IJssel, The Netherlands Privacy contact: contact@mytutoringhome.com
We have not appointed a Data Protection Officer. Our processing is not large-scale monitoring or special-category processing, so art. 37 GDPR does not require one. The address above reaches the person accountable for privacy.
2. Two different roles
This matters, because it decides who you ask about your data.
We are the controller for:
- tutors — the people who sign up and pay us;
- visitors to mytutoringhome.com.
For that data, this policy applies and you can exercise your rights with us directly.
We are the processor for:
- students — the people a tutor adds to their account.
A student's data belongs to their tutor's practice. The tutor decides what to record, why, and for how long; we only store and process it on their instructions under our Data Processing Agreement. We never use it for our own purposes, never contact students for our own reasons, and never share it with another tutor.
If you are a student: ask your tutor to see, correct or delete your data — they are the one who can decide. If you contact us instead, we will pass your request on to them and tell you we have done so. Sections 6 and 7 still describe how we keep the data safe and where it lives.
3. What we collect, and why
3.1 When you create a tutor account
| Data | Why | Legal basis |
|---|---|---|
| Name, email address, password (hashed by Firebase — we never see it) | To create and secure your account | Performance of a contract (art. 6(1)(b)) |
| Google account name, email and profile ID, if you sign in with Google | To authenticate you without a separate password | Performance of a contract |
| Timezone, preferred settings | To show times correctly and run reminders | Performance of a contract |
| Email verification and password-reset tokens | Account security | Legitimate interest (art. 6(1)(f)) — keeping accounts secure |
3.2 When you use the Service
| Data | Why | Legal basis |
|---|---|---|
| Your students, lessons, availability, prices and notes | This is the product | Performance of a contract (for you as our customer); for the students' data we are the processor — see section 2 |
| Your Stripe connected-account identifier and onboarding status | To route payments to you and take our fee | Performance of a contract |
| Payment records: amount, currency, status, our fee, Stripe payment identifiers | To show your earnings, apply the monthly fee cap, and meet tax and accounting law | Performance of a contract; legal obligation (art. 6(1)(c)) |
| Security and error logs, including IP address and approximate timing | To detect abuse, debug failures, and keep the Service up | Legitimate interest — security and reliability |
We never see or store card numbers, bank details or IBANs. Payment credentials are entered on Stripe's own pages and stay with Stripe.
3.3 When you email us
We keep the correspondence and what it was about, so we can answer and so we have a record if you come back about it. Legal basis: legitimate interest in supporting our customers.
3.4 When you visit the website
Our marketing pages set no analytics or advertising cookies unless you accept them. Fonts are served from our own domain — no request goes to Google Fonts. If you accept analytics, we use Google Analytics 4 to count visits and see which pages work. Legal basis: your consent (art. 6(1)(a)), which you can withdraw at any time from the "Cookie settings" link in the footer. Details are in the Cookie Policy.
3.5 What we do not do
- We do not sell, rent or trade personal data. Not ever, not to anyone.
- We do not use your data or your students' data to train AI models.
- We do not profile you, and we make no decisions about you by automated means that produce legal or similarly significant effects (art. 22 GDPR).
- We do not run advertising on the Service and we do not share data with ad networks.
4. Emails we send
| To | Basis | |
|---|---|---|
| Account: verification, password reset, security alerts | Tutors | Contract / security |
| Service notices: fee changes, terms changes, planned downtime | Tutors | Contract — you cannot opt out of these while you have an account |
| Lesson confirmations, 24-hour and 1-hour reminders, payment receipts, portal invitations | Students | Sent on the tutor's behalf as their processor; the tutor is responsible for the underlying basis |
| Product news and tips | Tutors | Consent — every one has an unsubscribe link, and unsubscribing does not affect your account |
5. Who we share with
We use a small number of processors to run the Service. Each is bound by a data processing agreement, may only act on our instructions, and may not use the data for its own purposes. The current list, with locations and transfer safeguards, is on the sub-processors page, which is also where changes are announced.
Beyond those, we share personal data only:
- with Stripe, which is an independent controller for payments and identity verification under its own privacy policy;
- where a law, court or competent authority requires it — and we will tell you unless we are legally barred from doing so;
- with professional advisers under a duty of confidence;
- with an acquirer, if the business is sold or merged — under section 21 of the Terms, and you will be told.
6. Where your data is
Tutor and student records are stored in Google Cloud Firestore in the eur3 multi-region — data centres in Belgium and the Netherlands. Backups stay in that region.
Some processors are established outside the EEA or have parent companies that are. Where personal data reaches them, the transfer is covered by the European Commission's Standard Contractual Clauses, by an adequacy decision, or by the EU–US Data Privacy Framework, together with the technical measures in section 7. The sub-processors page names the mechanism for each.
7. How we protect it
- All traffic is encrypted in transit (TLS); data is encrypted at rest by our infrastructure providers.
- Sessions use an httpOnly, secure, SameSite cookie that expires after 14 days.
- Every request is authorised server-side against who owns the record, so one tutor's data cannot be reached from another tutor's session. Database rules enforce the same boundary independently.
- Passwords are handled and hashed by Firebase Authentication; we never receive them.
- Access to production data is limited to those who need it, and is logged.
- We use no third-party scripts on authenticated pages.
No system is perfectly secure. If a breach is likely to result in a high risk to you, we will tell you without undue delay, and we will notify the Autoriteit Persoonsgegevens within 72 hours where art. 33 GDPR requires it.
8. How long we keep it
| Data | Kept for |
|---|---|
| Tutor account and profile | While the account is open |
| Students, lessons, notes, availability | While the account is open; available for export on request for 30 days after it closes, then deleted or anonymised within a further 30 days |
| Payment and fee records | 7 years from the end of the financial year — required by art. 52 Algemene wet inzake rijksbelastingen |
| Support correspondence | 24 months after the conversation ends |
| Security and error logs | 90 days |
| Analytics (if you consented) | 14 months |
| Marketing consent and unsubscribe records | Until withdrawn, then a suppression record so we do not email you again |
Where a tutor closes their account, their students' records follow the same schedule — see the Data Processing Agreement.
If we ever cease operating, that schedule is shortened: section 13.6 of the Terms of Service gives at least 14 days from the email announcing it, with export available throughout, and deletion at the end of it. What that deletion covers is personal data — tutor accounts, students, lessons, notes and the payment records held in the Service. Two things sit outside it: the statutory periods in the table above, which are unaffected — payment records are kept for seven years whatever happens to the company — and the financial history in a tutor's own Stripe account, which is held by Stripe under the tutor's own agreement with them and is not ours to delete.
9. Your rights
Under the GDPR you may ask us to:
- access the personal data we hold about you, and get a copy;
- correct it if it is wrong or incomplete;
- erase it, where we no longer have a reason to keep it;
- restrict processing while a dispute about accuracy or basis is resolved;
- port it — receive it in a structured, machine-readable format, or have it sent to another provider;
- object to processing based on legitimate interest, including a general right to object at any time;
- withdraw consent where we rely on it — for analytics, from the "Cookie settings" link in the footer; for marketing email, from the unsubscribe link.
Write to contact@mytutoringhome.com. We answer within one month and will tell you if a complex request needs longer, as art. 12(3) allows. It is free; we only charge for manifestly excessive or repetitive requests.
Tutors asking for an export get their complete data — students, lessons, payments — in a structured, machine-readable format within five business days.
Complaints. If we have not resolved something, you can complain to the Autoriteit Persoonsgegevens (https://www.autoriteitpersoonsgegevens.nl), the Dutch supervisory authority, or to the authority where you live or work.
10. Children
Tutor accounts are for adults — you must be 18 or over.
Student portal accounts are created at a tutor's invitation. In the Netherlands the age of digital consent is 16. A student under 16 must have their portal account held and used by a parent or guardian, and the tutor is responsible for obtaining that consent before adding them. If you believe a child's data is in the Service without a proper basis, tell us at contact@mytutoringhome.com and we will raise it with the tutor immediately.
11. Changes to this policy
We will post any change here and update the version date. If a change materially affects you, we will email you at least 30 days before it takes effect. Earlier versions are available from contact@mytutoringhome.com.
12. Contact
contact@mytutoringhome.com — or by post, to the address in section 1.