Privacy Policy
Last updated: March 12, 2026
Introduction
At ConviTutor ("we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile applications, and services (collectively, the "Service").
Please read this Privacy Policy carefully. By using ConviTutor, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
We collect information you voluntarily provide when using our Service:
Account Information:
- Name (first and last)
- Email address
- Password (stored in hashed form)
- Profile photo (optional)
- Timezone preference
- Role type (Student, Parent, Teacher, etc.)
Profile Information:
- For Teachers: Bio, subjects taught, hourly rates, availability schedule, qualifications
- For Students: Grade level, learning goals, study preferences
- For Parents: Children's accounts linked to your profile
Educational Content:
- Lesson notes and materials
- Assignments and submissions
- Grades and feedback
- Study logs and progress data
- Messages and communications
Payment Information:
- Billing address
- Payment method details (processed by Stripe)
- Transaction history
- For Teachers with Stripe Connect: Identity verification details, bank account information, and payout history (collected and stored by Stripe)
1.2 Information Collected Automatically
When you access our Service, we automatically collect:
Device and Usage Information:
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Pages viewed and actions taken
- Time and date of access
- Referring URLs
Location Information:
- General location based on IP address
- Timezone settings
1.3 Information from Third Parties
We may receive information from:
Payment Processors: Transaction status and payment confirmations from Stripe
OAuth Providers: If you sign in using Google or other providers (if enabled)
Educational Institutions: If you join through an organization
2. How We Use Your Information
We use collected information for the following purposes:
2.1 Providing and Improving the Service
- Create and manage your account
- Facilitate communication between teachers, students, and parents
- Process lesson scheduling and payments
- Track educational progress and grades
- Send notifications and reminders
- Provide customer support
- Analyze usage to improve features
2.2 Personalization
- Customize your dashboard and experience
- Recommend teachers or courses based on preferences
- Adjust timezone and display preferences
2.3 Communications
- Send transactional emails (account confirmation, password reset)
- Notify you of lesson schedules and task deadlines
- Send service updates and announcements
- Marketing communications (with your consent)
2.4 Safety and Security
- Detect and prevent fraud and abuse
- Enforce our Terms of Service
- Protect the rights and safety of users
- Comply with legal obligations
2.5 Analytics and Research
- Understand how users interact with our Service
- Measure effectiveness of features
- Conduct research to improve education delivery
3. Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
3.1 With Other Users
Teachers and Students: Information necessary to facilitate educational relationships (e.g., names, profile information, lesson content)
Parents and Guardians: Access to linked student's educational records
Organization Members: Within the same organization, as appropriate for educational purposes
3.2 With Service Providers
We share information with third-party vendors who perform services on our behalf:
Stripe: Payment processing, including Stripe Connect for teacher payouts. When teachers connect their Stripe account, identity verification and banking details are shared directly with Stripe for payout processing
Cloud Hosting Providers: Data storage and infrastructure
Email Services: Transactional and marketing emails
Analytics Providers: Usage analytics and performance monitoring
All service providers are bound by contractual obligations to protect your data.
3.3 For Legal Reasons
We may disclose information:
- To comply with legal obligations
- To respond to lawful requests from authorities
- To protect our rights, privacy, safety, or property
- To enforce our Terms of Service
- In connection with legal proceedings
3.4 Business Transfers
If ConviTutor is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
3.5 With Your Consent
We may share information for other purposes with your explicit consent.
4. Cookies and Tracking Technologies
4.1 What We Use
We use cookies and similar technologies to:
- Keep you logged in
- Remember your preferences
- Analyze usage patterns
- Improve performance
4.2 Types of Cookies
Essential Cookies: Required for the Service to function (authentication, security)
Preference Cookies: Remember your settings and preferences
Analytics Cookies: Help us understand how you use the Service
Marketing Cookies: Used for advertising (only with consent)
4.3 Your Choices
You can control cookies through your browser settings. Note that disabling essential cookies may affect functionality.
4.4 Do Not Track
We currently do not respond to "Do Not Track" browser signals. We will update this policy if this changes.
5. Data Security
5.1 Security Measures
We implement appropriate technical and organizational measures to protect your data:
Encryption: Data encrypted in transit (HTTPS/TLS) and at rest
Access Controls: Role-based access limiting who can view data
Authentication: Secure password hashing and optional two-factor authentication
Monitoring: Regular security audits and vulnerability assessments
Backups: Regular encrypted backups with secure storage
5.2 Your Responsibilities
You are responsible for:
- Keeping your password confidential
- Using a strong, unique password
- Logging out on shared devices
- Notifying us of unauthorized account access
5.3 Breach Notification
In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
6. Data Retention
6.1 Retention Periods
We retain your data for as long as necessary to:
- Provide the Service while your account is active
- Comply with legal obligations
- Resolve disputes
- Enforce our agreements
Specific retention periods:
Account Data: Retained while account is active, plus 30 days after deletion request
Educational Records: Retained for 7 years after last activity (for record-keeping purposes)
Payment Records: Retained for 7 years (tax and legal compliance)
Dispute Records: Payment dispute details, correspondence, and resolution outcomes retained for 7 years for compliance and fraud prevention
Messages: Retained for 3 years after account deletion
Analytics Data: Aggregated data retained indefinitely; individual data for 2 years
6.2 Data Deletion
You may request deletion of your data. Some data may be retained as required by law or for legitimate business purposes. See "Your Rights and Choices" for more information.
7. Your Rights and Choices
7.1 Access and Portability
You have the right to:
- Access your personal data
- Request a copy of your data in a portable format
- Know what information we have collected
7.4 Restriction and Objection
You may:
- Restrict processing of your data in certain circumstances
- Object to processing for direct marketing
- Object to automated decision-making
7.7 Communication Preferences
You can:
- Opt out of marketing emails via the unsubscribe link
- Manage notification preferences in your account settings
- Transactional messages cannot be opted out while your account is active
7.8 GDPR Rights (European Users)
If you are in the European Economic Area (EEA), you have additional rights under GDPR:
- Right to lodge a complaint with a supervisory authority
- Right to data portability
- Right to erasure ("right to be forgotten")
- Right to restrict processing
7.9 CCPA Rights (California Users)
If you are a California resident, you have rights under CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt out of the sale of personal information (we do not sell data)
- Right to delete personal information
- Right to non-discrimination for exercising your rights
7.2 Correction
You can update or correct your information through your account settings or by contacting us.
7.3 Deletion
You may request deletion of your account and personal data. We will delete or anonymize your data, except where retention is required by law.
7.5 Withdraw Consent
Where we rely on consent, you may withdraw it at any time. This does not affect prior processing.
7.6 Exercising Your Rights
To exercise these rights, please use our contact form. We may need to verify your identity before processing your request.
8. Children's Privacy
8.1 Age Requirements
- Users must be at least 13 years old (or the minimum age in their jurisdiction) to create an account
- Users under 18 should have parental/guardian consent
- Teachers and Organization administrators must be at least 18
8.2 Parental Consent
For users under 13:
- Accounts must be created by a parent or guardian
- Parent/guardian maintains control over the account
- We do not knowingly collect personal information from children under 13 without parental consent
8.3 COPPA Compliance
We comply with the Children's Online Privacy Protection Act (COPPA) in the United States:
- We obtain verifiable parental consent before collecting personal information from children under 13
- Parents can review, delete, or refuse further collection of their child's information
- We do not require children to provide more information than necessary
8.4 Educational Records
For students, we may act as a "school official" under FERPA when working with educational institutions. Educational records are protected and only shared as permitted by law.
9. International Data Transfers
9.1 Data Location
Your data may be processed and stored in the United States or other countries where our service providers operate.
9.2 Transfer Safeguards
When transferring data internationally, we use appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with service providers
- Compliance with applicable data protection laws
9.3 Your Consent
By using our Service, you consent to the transfer of your data to the United States and other countries.
10. Third-Party Links and Services
10.1 External Links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies.
10.2 Integrated Services
We integrate with third-party services:
- Stripe: For payment processing. See Stripe's Privacy Policy
- YouTube: For embedded videos. See Google's Privacy Policy
10.3 Social Features
If you use social sharing features, information may be shared according to your settings on those platforms.
11. Changes to This Privacy Policy
11.1 Updates
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website
- Sending an email to your registered address
- Displaying a notice within the Service
11.2 Effective Date
Changes become effective on the date posted, or a later date if specified. Your continued use of the Service after changes constitutes acceptance.
11.3 Review
We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
ConviTutor
For all inquiries, please use our contact form
For EU residents, you may also contact your local supervisory authority.
Acknowledgment
BY USING CONVITUTOR, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS.