Privacy Policy
We collect what we need to run the tutoring service for you and your child — and nothing else. Children’s data is held to a higher bar. We don’t sell data. We don’t use lessons or progress reports to train any model. You can ask for a copy or for deletion at any time.
This Privacy Policy describes how CinderTutor Pty Ltd (ACN 471 836 204) handles personal information in the course of providing online tutoring. We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
01 Who we are
CinderTutor Pty Ltd, ACN 471 836 204, Level 4, 75 Hindley Street, Adelaide SA 5000, Australia. Our Privacy Officer is reachable at privacy@cindertutor.com.
02 What we collect
- Parent account information: name, email, phone (optional), billing address, hashed password.
- Student information: first name, year level, current school (optional), subjects studied, learning goals you share with us.
- Billing information: billing details and card-on-file tokens held by our payment processor (we do not store card numbers).
- Session data: session recordings, shared whiteboard captures, lesson notes written by the tutor, weekly progress reports.
- Usage data: account login times, dashboard activity (used for security and product improvement).
- Communications: support emails, contact form messages, in-platform messages between you and your tutor.
03 Children & minors
We treat data about students who are minors with additional care. A parent or legal guardian must establish the account. Session recordings and progress reports for a minor are visible only to the parent account holder and the assigned tutor. We do not sell, share, or use minors’ data for marketing or advertising. We do not enrol students under 18 directly without parental consent.
If a student turns 18 while using the platform, the account can be transferred to the student with the parent’s consent; this is handled manually by emailing privacy@cindertutor.com.
04 Why we collect it
- To provide the tutoring service (legal basis: contract with the Parent).
- To match a tutor to your child and prepare them for each lesson.
- To produce weekly progress reports and lesson recordings.
- To bill you and meet our accounting obligations under Australian tax law.
- To protect the platform from misuse and to safeguard sessions (recordings serve this purpose as well as the educational one).
05 How it is shared
We don’t sell personal information. We don’t share it for advertising. We do share data with a small list of subprocessors that help us operate the service:
- Stripe Payments Australia Pty Ltd — billing & payment processing.
- Amazon Web Services Inc. — hosting (Sydney region for primary data; Singapore region for backup).
- Daily.co — video conferencing for sessions (recordings are stored on our infrastructure).
- Postmark (ActiveCampaign LLC) — transactional email.
The current list is maintained at /subprocessors. Tutors are contractors of CinderTutor who access only the student data they need to teach the assigned sessions.
06 Where it’s stored
Primary data is stored in AWS Sydney (Australia). Backups are replicated to AWS Singapore. Session recordings and progress reports are stored encrypted at rest.
07 Retention
- Account & billing data: for the life of your account and 7 years after closure (Australian tax recordkeeping).
- Session recordings & lesson notes: 12 months by default; you can extend this or delete on request.
- Progress reports: kept indefinitely while the account is active (they’re among the most-valued artefacts by parents); deleted within 30 days of account closure on request.
- Support communications: 24 months.
08 Your rights
Under the Privacy Act 1988 and the Australian Privacy Principles you have the right to:
- Request access to the personal information we hold about you or your child.
- Request correction of inaccurate information.
- Request deletion of information that is no longer necessary for the service.
- Withdraw consent for recording on a session-by-session basis.
- Make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
To exercise any of these rights, email privacy@cindertutor.com. We respond within 30 days at no charge for routine requests.
09 Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Production access is restricted to Lisa and James, gated by hardware security keys, and logged. We follow Australian Notifiable Data Breaches scheme requirements and would notify affected parents within 72 hours of becoming aware of any qualifying breach.
10 Contact
Email our Privacy Officer at privacy@cindertutor.com, or write to: CinderTutor Pty Ltd — Privacy Officer, Level 4, 75 Hindley Street, Adelaide SA 5000, Australia.
We will post any material changes to this Policy at least 30 days before they take effect and email account holders. The current version is always at this URL.