Privacy Policy
Last updated: 03.09.2026
This Privacy Policy describes how the TutorTribe service (the "Service") processes the personal data of its users — tutors, students and their parents or guardians — in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
1. Data controller
The controller of your personal data is L.p. Code S.C., with its registered office in Zabrze, Poland, at ul. Grażyńskiego 25 lok. 7, 41-810 Zabrze, Polish tax identification number (NIP) 6482838057, business registry number (REGON) 545200369 (the "Controller").
Contact for personal data matters: [email protected].
2. What data we process
2.1. Tutor data (account owner)
- identification and contact details: first name, last name, e-mail address, optionally a phone number;
- billing data necessary to process payments and issue sales documents;
- account and activity data in the Service (lessons, students, payments, homework, documents).
2.2. Student and parent/guardian data
Student accounts and, optionally, parent/guardian accounts are created by the tutor when adding them to their student base. We process: first and last name, e-mail address (if provided), the assignment to a tutor, and data about lessons, payments and homework. A student may also exist as a "phantom" record (without their own login) — in that case we process only the data needed for billing.
2.3. Data of minors
The Service may process the data of underage students. TutorTribe is not an open registration platform — student accounts are created by the tutor within an existing tutor–student relationship. Obtaining the consent of the legal guardian, in accordance with Article 8 GDPR, is the responsibility of the tutor (and/or the guardian) using the Service. The Controller provides mechanisms for exercising data subject rights and for deleting data at the guardian's request.
2.4. Technical data
- data required to maintain the session and security (including the authentication token and the CSRF token);
- basic server logs (IP address, request time) for security and diagnostic purposes;
- in the mobile app — a device token used to deliver push notifications (about new messages, lessons and payments); the token is deleted when you log out of the device.
3. Purposes and legal bases of processing
- Providing the service (managing the account, lessons, payments, homework) — Article 6(1)(b) GDPR (performance of a contract);
- Processing online payments via Stripe — Article 6(1)(b) GDPR;
- Issuing and storing billing documents — Article 6(1)(c) GDPR (legal obligation);
- Security, fraud prevention, diagnostics — Article 6(1)(f) GDPR (legitimate interest);
- Handling complaints and contact — Article 6(1)(b) and (f) GDPR.
4. Recipients of data and processors
Data may be entrusted to trusted partners only to the extent necessary to provide the service:
- Stripe — online payment processing and payouts to tutors (Stripe Payments Europe / Stripe, Inc.);
- Infrastructure provider (hosting) — Hetzner Online GmbH, servers located in the European Union;
- Google Firebase (Firebase Cloud Messaging) — delivery of push notifications in the mobile app (Google Ireland Ltd. / Google LLC); only the device token and the content of the notification are processed;
- Resend — sending transactional e-mails, e.g. account confirmations and password reset codes (Resend, Inc.).
5. Transfers of data outside the EEA
As a rule, data is processed within the European Economic Area. For payment processing, data may be transferred to Stripe, Inc. (USA), and for push notifications and transactional e-mail — to Google LLC and Resend, Inc. (USA), in each case on the basis of standard contractual clauses and GDPR-compliant transfer mechanisms. Otherwise, the Controller does not transfer data outside the EEA.
6. Retention period
- account data — for as long as you use the Service and, after that, until the account is deleted;
- billing data and sales documents — for the period required by tax law (as a rule 5 years);
- data processed on the basis of legitimate interest — until an effective objection is raised or the purpose ceases to exist.
7. Your rights
You have the right to:
- access your data and obtain a copy of it;
- rectify (correct) your data;
- erase your data ("right to be forgotten");
- restrict processing;
- data portability;
- object to processing based on legitimate interest;
- lodge a complaint with the President of the Personal Data Protection Office (PUODO), the Polish supervisory authority.
To exercise these rights, contact the Controller at the address given in section 1.
8. Cookies and similar technologies
The Service uses only strictly necessary cookies and the browser's local storage (localStorage) to remember your preferences. We do not use analytics or marketing cookies and we do not profile users.
| Name / type | Purpose | Category |
|---|---|---|
| Session / authentication cookie | Keeping the user logged in | Necessary |
| CSRF token (X-XSRF-TOKEN) | Protection against CSRF attacks | Necessary (security) |
| Stripe cookies | Payment processing and fraud prevention (set by Stripe during payment) | Necessary (payments) |
| dark-mode (localStorage) | Remembering the light/dark theme preference | Preferences |
Because we use only cookies that are necessary for the Service to work and for preferences, no consent for analytics/marketing cookies is required. You can manage cookies in your browser settings — restricting the necessary cookies may, however, prevent you from using the Service.
9. Security
We apply technical and organisational measures appropriate to the risk — including encryption in transit (HTTPS), access control and GDPR-compliant processing, also with regard to the data of underage students.
10. Changes to this Policy
The Controller may update this Policy. The current version is always available in the Service, and the date of the last update is shown at the top of the document.
11. Contact
For matters concerning personal data and privacy, write to: [email protected]