1. About This Policy
This Privacy Policy explains how Tutor Marketplace (ABN 67 250 915 494) (“we”, “us”, “our”) collects, uses, stores and protects personal information when you use the Tutor Marketplace website, app and platform at tutor-marketplace.com (the “Platform”).
We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Small businesses with annual turnover under $3 million are generally exempt from the APPs; we have chosen to comply with them anyway, because much of the information on the Platform concerns children.
This policy applies to everyone who uses the Platform — students, parents and guardians, tutors, and people a tutor adds as their own student — and to anyone who contacts us. We are based in Australia and our primary systems are in Australia. If you use the Platform from elsewhere, your information is processed in Australia and in the countries where our service providers operate (Section 10); where your local law gives you stronger rights than this policy describes, we will honour them.
2. Information We Collect
2.1 Information You Give Us
- Account: your name, email address and password (stored only as a hash), your role (student or tutor), timezone and country. If you sign in with Google we receive your name, email address and profile picture from Google.
- Guest checkout: if you pay for a lesson without an account, the name and email you give at checkout create an account for you after payment.
- Messaging identity: before your first message to a tutor we ask for your full name and whether you are a parent or guardian, an adult learner, or a student aged 13–17, together with the student's year level. A student under 18 messaging for themselves also gives a parent or guardian's name and mobile number. Your own mobile number is optional. Tutors see your name and a short line such as “Parent/guardian · Year 9”; they never see your phone number, email address or a guardian's details.
- Tutor profile: qualifications and academic history, headline and bio, photo and introduction video, how you teach (online in our classroom or on your own meeting link, in person, or both), the subjects and year levels you teach, your suburb and how far you travel for in-person lessons, an address for in-person lessons, availability, minimum notice, cancellation and no-show policy, hourly rate and currency, and your personal share link.
- Tutor documents: transcripts, enrolment proof, degree certificates, teaching registrations and identity documents uploaded for verification, with our review notes and outcomes. Accessible only to us.
- School and university tags: if a tutor asks for one, the high school or university they name, whether they study there or graduated, the document they send as proof, and our decision. The document is seen only by us; an approved tag is public.
- Working With Children Check: your WWCC (or equivalent) number, issuing state or territory and expiry date, plus our verification outcome and dates.
- Advertising assets: photographs, video and written material a listed tutor uploads for the advertising we run, with our approval status for each (Section 2.6).
- Subscription and billing: for tutors, which products you hold, their status, trial and billing dates, your Stripe customer and subscription identifiers, and any referral credit on your balance. Card details are held by Stripe, never by us.
- Payouts: tutors connect a Stripe account to be paid; Stripe collects the identity and bank details that requires under its own privacy policy. We hold the account identifier and its status.
- Bookings: lessons booked, dates, times, duration, subject, where the lesson happens, the price locked in, notes a student adds, cancellations, no-shows, and confirmation that a lesson took place.
- A tutor's private marks: a tutor may give a lesson a colour and a private note in their planner. Those are visible to that tutor alone and are never sent to anyone.
- Lesson files, notes and whiteboards: files, notes and whiteboard pages created in the workspace a tutor and student share.
- Work and feedback: work a tutor sets (a title, instructions, a due date, attached files), what a student hands in (files and a note), and the mark, feedback and files the tutor returns.
- Progress updates: updates a tutor writes about a student — a level in each subject, a note on effort, a comment and a list of recently marked work — and a record of where each was sent.
- A parent or guardian's email, if you give one: a family can add it in Settings, and a tutor can record one for a student they added themselves. We use it only to send that student's progress updates. A tutor never sees an address a family adds in Settings.
- Payments: amounts, currency, dates and Stripe transaction identifiers for lessons, packages, refunds and payouts. Card numbers are entered directly into Stripe and never touch our servers.
- Saved cards: if you save a card, Stripe stores it and gives us a reference plus the card brand, last four digits and expiry — enough to show you which card is on file, never the number. We use the reference to charge cancellation and no-show fees under the tutor's policy and, only when you choose it, to pay for an offer in one step. A tutor you are messaging can see that you have a card on file, never which card. Removing a saved card in Settings detaches it at Stripe as well.
- Messages: what you write to tutors or students, lesson-room chat, offers sent and their outcome, reports you submit and your correspondence with us. When you send a message our software checks whether it appears to contain a phone number, email address, link or messaging handle; if so, a count on the conversation is incremented and a reminder is shown to you. That check is automated, is not a person reading your message, and does not block it.
- Offers and packages: lesson offers a tutor sends you (time, price, expiry, whether you accepted) and any lesson package you buy (lessons bought and used, expiry, refund requests).
- Saved replies: message templates a tutor saves for reuse, visible only to that tutor.
- Session summaries and reviews: summaries a tutor writes after a lesson (shared with the student and parent) and ratings and reviews a student leaves.
- Notification settings: which channels you have turned on (email, in-app and push) and any per-category choices.
- Push notifications: if you turn on notifications on a device, your browser gives us a push subscription (an endpoint address and encryption keys) which we store so we can deliver notifications to that device. Turning notifications off, or the browser revoking them, disables that subscription.
- Referral program: a tutor's referral code; for a tutor who joined through someone's link, which link it was; and the checks described in Section 2.7.
- Where an enquiry came from: whether a conversation began from a tutor's shared link, an advertisement, or the directory.
- Contact and waitlist forms: the name, email and message you send through our contact or support form; and, when you ask to be notified about tutors, your email address and — if you choose to tell us — the subject, year level and suburb you are looking for.
2.2 People a Tutor Adds as Their Own Student
A tutor with the Bookings Suite can put lessons in their planner for students they teach outside the Platform — people who have no account with us. For those people the tutor enters a name and, if they choose, a parent or guardian's name, an email address, mobile number, year level, subjects, the price they charge that student and notes — one at a time, or many at once from a spreadsheet they already keep. A spreadsheet is read on the tutor's own device; only the students the tutor confirms are sent to us. A tutor may instead send the people they teach an invite link: the form behind it asks for the student's name and an email address and, optionally, a parent or guardian's name, a mobile number, year level, subjects and a note. What you enter there goes to that tutor and is held in the same way; filling it in does not create an account. We hold that information on the tutor's behalf, use the email only to send lesson details, reminders and calendar invitations about that tutor's lessons (we do not send text messages), and never use it for marketing or show it to anyone but the tutor. The tutor is responsible for having the person's permission. If you have received a message from us about a tutor's lesson and would like your details removed, email support@tutor-marketplace.com and we will remove them.
2.3 Information Collected Automatically
- Device and browser: browser type, operating system and device type.
- Usage: pages visited, features used, and interactions with the Platform.
- Tutor activity: for tutors, the days you open the app and the time of your first and last visit that day, and how often you come back. We use it, with the messages, offers and lessons on your account, to see how tutors use the product and who may need a hand. It is seen only by us.
- Logs: IP address, access times and referring URLs. We also count requests per IP address in ten-minute windows to limit abuse of booking and support forms; those counters are not linked to your account.
- Performance: when a page loads or responds slowly, the browser sends us the measurement and the element involved. It is written to our logs and not stored against you.
- Cookies and browser storage: described in Section 8.
2.4 Information About Minors
Students on the Platform may be under 18. We collect the minimum needed to arrange and deliver tutoring. A child under 13 may use the Platform only through an account created and held by a parent or guardian; a student aged 13–17 may hold their own account and gives a parent or guardian's name and mobile number before messaging a tutor. We do not knowingly collect personal information from a child under 13 without a parent or guardian; if we learn that we have, we delete it.
2.5 Lessons Are Not Recorded
We do not record lessons. Video, audio and whiteboard activity in our classroom pass between the participants and are not captured, stored or reviewed by us. Lessons on a tutor's own meeting link or in person happen outside our systems entirely. (Until 11 September 2026 classroom lessons were recorded and kept for 90 days; that practice has ended and earlier recordings have been deleted.)
2.6 Tutor Advertising Assets
Tutors who hold the Directory Listing may supply photographs, video and profile material for the advertising we run for the directory. This is the one category of personal information we deliberately publish beyond the Platform.
- Approved assets, with the tutor's name, headline, subjects and location, may be uploaded to advertising platforms such as Meta (Facebook and Instagram) and Google and shown publicly as advertisements for the directory.
- Once an advertisement has run, the advertising platform holds its own copy under its own privacy policy and retention rules, which we do not control.
- We use these assets only to advertise the directory and the Platform, under Section 5.3 of our Terms of Service.
- A tutor can delete an asset or end their listing at any time; we stop using it in new advertising, but cannot recall advertising already published or delete copies held by the advertising platform.
This applies only to tutors and only to material a tutor uploads for that purpose. We never use student or parent information, messages or lesson content in advertising.
2.7 Referral Checks
When a tutor joins through another tutor's referral link, we check that the two are not the same person before any credit is given. To do that we compare the payment-card fingerprint Stripe gives us for each account (never the card number), their email identities and phone numbers, and a salted one-way hash of the network address used when the link was fetched and when the new account was created. The hash cannot be turned back into an address. A tutor is told only the status of a referral, never the reason, and never the other tutor's details.
3. How We Use Your Information
- Running the service: accounts, profiles, messaging, bookings, holding and releasing payments, payouts, refunds, the classroom and lesson workspaces, the calendar feed, and the installed app.
- Telling you things: booking confirmations, receipts, message alerts, reminders, offer and package notices, and account notices — by email, in-app notification, and push notification to a device you have turned on. We do not send text messages. A tutor may also ask us to send lesson details or a reminder by hand.
- Billing tutors: charging and managing the Bookings Suite and the Directory Listing through Stripe, including the free trial and referral credits.
- Advertising the directory: producing and running advertising with the assets listed tutors supply (Section 2.6).
- Measuring our advertising: understanding which advertisements bring people to the Platform (Section 8).
- Trust and safety: verifying tutors, checking Working With Children Checks, reviewing reports, moderating content, checking referrals, limiting abuse and enforcing our Terms. WWCC details are stored with access restricted to us and are never shown publicly or to other users.
- Improving the Platform: understanding how it is used so we can fix problems and build what people need.
- Legal obligations: keeping financial records, responding to lawful requests, and protecting our rights and the safety of users.
We use personal information for advertising in the two ways described above only. We do not sell it, we do not use messages or lesson content for advertising, and we do not build behavioural profiles for purposes unrelated to running the Platform.
4. How We Share Your Information
4.1 Between Users
- Anyone can see a listed tutor's profile: name, photo, headline, bio, qualifications, any verified school or university tag the tutor asked for, subjects and year levels, teaching methods, suburb and state, how far you travel for in-person lessons and (when a family searches by distance) roughly how far away you are, rate, availability, reviews and trust metrics. A tutor's street address is never public; a family sees it only once an in-person lesson is booked.
- A tutor sees the full name of a student or parent who messages or books them, the identity line (for example “Parent/guardian · Year 9”), everything written to them, the details of each booking, and whether the person has a card on file. A tutor never sees a student's or parent's email address, phone number or a guardian's details.
- A student or parent sees the tutor's profile, messages, offers, lesson details and session summaries. A tutor and the student they teach can each open the workspace they share: its files, notes and whiteboards, and the work set, handed in and returned. A student a tutor added themselves (Section 2.2) reaches their work through a personal link we email them; anyone holding that link can open that work and the progress updates about that student, and nothing else. Progress updates are also emailed to a parent or guardian's address where one has been given.
- A tutor's own student (Section 2.2) receives lesson emails naming the tutor and the lesson, and nothing about anyone else.
- In a group class a tutor runs, the tutor sees who is in each session. Each student is told about their own place. When a class is held in our classroom, the students in a session see and hear each other on video, see each other's first names, and read the class chat, which we store with the session; nothing else about a student is shown to the others. In any other class we do not show students each other's names or details.
4.2 Service Providers
We use these providers to run the Platform. Each may process your data only on our instructions:
- Supabase (database, sign-in and file storage) — our primary database and file storage, hosted in Sydney, Australia. Holds account data, profiles, messages, bookings, lesson files, documents and advertising assets.
- Vercel (hosting, analytics and performance measurement) — runs the Platform, with our application servers in Sydney, and provides aggregate traffic and speed statistics.
- Stripe (payments, subscriptions and payouts) — processes lesson and package payments, tutor subscriptions and payouts, and holds card and bank details under its own privacy policy. Stripe is based in the United States.
- Resend (email) — sends our transactional emails; it receives your email address and the email's content.
- Browser push services (Apple, Google and Mozilla, depending on your device) — deliver push notifications you have turned on. The notification content is encrypted to your device; the service sees only that a message was sent.
- Google (sign-in) — if you sign in with Google, Google tells us your name, email and picture and knows that you signed in here.
- Meta Platforms (advertising) — receives the advertising assets we publish and the measurement data described in Section 8.
- Our own classroom server (Jitsi Meet, self-hosted) — carries the video, audio and whiteboard of lessons in our classroom, on infrastructure we operate. Nothing is recorded (Section 2.5).
We choose providers with appropriate security standards and do not allow any of them to use your information for their own marketing.
4.3 Legal Requirements
We may disclose information where the law requires it, in response to a lawful request, or where we believe in good faith that it is necessary to protect our rights, your safety or someone else's safety, or to investigate a breach of our Terms. We may be required to report child-safety concerns to the authorities.
4.4 Business Transfers
If Tutor Marketplace is sold, merged or transfers its assets, user data may be transferred as part of that transaction. We will tell affected users before their information becomes subject to a different privacy policy.
4.5 We Do Not Sell Your Data
We do not sell, rent or trade personal information to anyone.
5. Storage and Security
5.1 Where Your Data Is Kept
Our database and uploaded files are stored in Sydney, Australia (Supabase) and our application runs from Sydney (Vercel). Payment data is held by Stripe under PCI DSS. Email, push and advertising providers process the data they need outside Australia, as set out in Sections 4.2 and 10.
5.2 Security Measures
- Encryption in transit (HTTPS/TLS) everywhere
- Passwords stored only as hashes
- Row-level security in our database, so each account can read only what it is entitled to
- Signed, expiring links for lesson files, documents and calendar actions
- Card numbers entered directly into Stripe, never our servers
- Regular review of our code and infrastructure
No system is perfectly secure. We take reasonable precautions but cannot guarantee absolute security.
5.3 Protection of Minors' Data
- We collect only what is needed to arrange and deliver tutoring
- We do not use a minor's information for marketing, profiling or behavioural analysis
- We share a minor's information with third parties only as needed to run the Platform (for example Stripe for payment)
- WWCC verification helps ensure tutors who teach minors have been screened
- A parent or guardian may ask to access, correct or delete their child's information at any time
6. How Long We Keep It
- Account and profile data: for the life of the account. When an account is closed it is retired as described in Section 7.2.
- Booking, payment, refund, payout and subscription records: at least 7 years, to meet Australian tax and financial record-keeping obligations. They are kept in a form that names the other party and a placeholder for a retired account.
- Messages: for the life of both accounts, so either party can refer back, and as long as reasonably needed for safety, moderation and disputes.
- Lesson files, notes, whiteboards, work, feedback and progress updates: for the life of the workspace; a file attached to a piece of work can be removed by whoever attached it until the work is handed in or returned.
- Reports, moderation records and referral checks: as long as reasonably needed for safety, moderation and dispute resolution.
- Tutor documents: while the account is active; deleted when the account is closed.
- WWCC records: the number and issuing state while the account is active, deleted when it is closed; the fact and dates of verification are kept as our record that a check was done.
- Advertising assets: while the listing is active or until the tutor deletes them; copies already published are held by the advertising platform under its own rules.
- Push subscriptions: until you turn notifications off or the browser revokes them; a disabled subscription is kept only as a record and is never used again.
- A tutor's own students: until the tutor removes them, the tutor's account is closed, or the person asks us to remove them.
- Contact and waitlist submissions: as long as needed to respond and follow up.
6.1 Data Breach Response
If a data breach is likely to result in serious harm to anyone whose information is involved, we will contain it, assess it, notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and tell affected people what they can do to protect themselves.
7. Your Rights
You may ask us to:
- Access the personal information we hold about you
- Correct anything inaccurate or out of date
- Delete your information, subject to the records we must keep (Section 6)
- Withdraw consent for optional processing, such as push notifications or advertising measurement
- Complain to us, and to the Office of the Australian Information Commissioner (OAIC) if you are not satisfied with our response
Contact us at the address in Section 12. We respond within 30 days.
7.1 Managing Your Own Data
Most of your information is yours to change in the Platform: your name, timezone and notification settings in Settings; your identity line in Settings under “About you”; a saved card in Settings; and, for tutors, everything on the profile page. Push notifications are turned on and off per device in Settings.
7.2 Closing Your Account
A tutor can close their account from their profile page. A student, parent or guardian asks us at support@tutor-marketplace.com. A closed account is retired rather than deleted, because bookings and payments are financial records we must keep:
- The account can no longer sign in, by any method, and every open session is ended
- Your name becomes “Deleted User”; your email address and phone number are replaced with a placeholder, which also frees your real address to sign up again if you ever want to
- A student's identity line and any guardian's details are erased
- A tutor's profile, photo, video, documents, WWCC number, address, meeting link and share link are removed, and any subscription is cancelled
- Bookings, payments and messages stay, showing the placeholder in your place
We decline to close an account while money is still in motion on it — a paid lesson that has not happened yet, funds not yet paid out, or a refund in progress — and tell you which bookings those are. Once they settle, closure goes ahead.
8. Cookies, Browser Storage, Analytics and Advertising Measurement
- Session cookies: keep you signed in.
- Campaign cookie: if you open the Platform from one of our advertisements or another tagged link, we set a cookie for 30 days holding the campaign and advertisement named in that link (its “utm” tags), the page you landed on and whether it was a Meta ad click. If you create an account in that time we record them against it, so we can tell which advertising brings people who go on to use the Platform.
- Referral cookie: if you open the Platform from a tutor's referral link we set a cookie holding that referral code for 30 days, so that a tutor account created in that time can be attributed to the referrer.
- Promotional code cookie: if you open the Platform from a link that carries a promotional code, or type one on the billing page, we set a cookie holding that code for 30 days so it can be applied when a tutor subscription starts. It is cleared when you sign out.
- Approximate location: to suggest tutors near you on our homepage we use the city, state and postcode that our hosting provider estimates from your internet connection when you load the page. It is an estimate of your network's location, not of your device's; we use it for that page and do not store it or attach it to an account. If you choose a suburb there instead, we remember that suburb in a cookie for 180 days so the page can show it next time; you can clear it on the page.
- Precise location, only if you ask: the “Use my location” button in Find a tutor asks your browser for your position. If you allow it, the position is rounded to about 100 metres and placed in the page's address to measure distances to tutors for that search. We do not save it to an account.
- Browser storage: we keep small per-device conveniences in your browser's local storage — your role, so the app can draw the right screen instantly; whether you have dismissed an install prompt or acknowledged the cookie notice; tutors you saved before signing in; a draft message you have not sent. None of it leaves your device.
- Analytics: Vercel Analytics and Speed Insights measure aggregate traffic and page performance. They do not build cross-site profiles of individuals.
- Advertising measurement: because we advertise the Platform and its directory, we run the Meta Pixel on our pages and send matching events to Meta's Conversions API from our servers.
8.1 What the Meta Pixel Does
The Pixel records that a browser viewed a page on the Platform and certain actions, such as creating an account or paying for a lesson. If you are signed in we also pass your email address, phone number if you have given one, and name to Meta so it can match you to a Meta account — Meta's “advanced matching”. Events sent from our servers carry those identifiers hashed with SHA-256, together with Meta's own first-party cookies (the click identifier it adds to an ad link, which we also store as the _fbc cookie, and the browser identifier _fbp), your IP address and browser type, and a hashed form of your account identifier. For tutors we keep those cookie values, IP address and browser type from the moment you start a subscription, so the event we send when a free trial starts or the first month is paid can be matched to the advertisement that brought you. We use this to understand which of our advertisements bring people here. Meta processes the data under its own terms and may use it for its own purposes, which we do not control.
We never send Meta the content of lessons, messages, summaries, files, documents or Working With Children Check details.
8.2 Your Choices
You can set your browser to reject cookies or block tracking scripts; the Platform keeps working, though rejecting the session cookie will sign you out. You can manage how Meta uses data about you through your Meta ad settings. If you would rather we sent no advertising measurement events for your account at all, tell us at the address in Section 12 and we will exclude it.
9. Children's Privacy
- We collect only what is needed to arrange and deliver tutoring
- We show no advertising inside the Platform to anyone, including minors
- We never use a student's information, messages or lesson content in our advertising
- We do not create behavioural profiles of minors, and never sell or share their information for anyone else's marketing
- The advertising measurement in Section 8 runs across the site, so a signed-in student's page views are covered by it. A parent or guardian who would prefer their child be excluded can ask us and we will exclude that account.
- A child under 13 uses the Platform only through a parent or guardian's account; a student aged 13–17 gives a parent or guardian's name and mobile number before messaging a tutor
- A parent or guardian may ask to access, correct or delete their child's information at any time
If you are a parent or guardian and believe your child has given us information without your consent, contact us and we will remove it.
10. International Data Transfers
Our database and files are in Australia. Some providers process data outside Australia: Stripe, Resend, Meta, Google and the push services operate principally from the United States, and Vercel's analytics may be processed there too. Tutors may also be based outside Australia. Where data goes overseas we rely on the provider's own data-protection measures and contractual commitments.
If you are in the United Kingdom or the European Economic Area you may also have rights under the UK GDPR or EU GDPR — access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. Contact us at the address in Section 12 to exercise them.
11. Changes to This Policy
We may update this policy as our practices, technology or the law change. If we make a material change we will tell you by email or by a notice on the Platform. The date at the top shows when the text last changed.
12. Contact Us
Tutor Marketplace (ABN 67 250 915 494)
Email: support@tutor-marketplace.com
Website: tutor-marketplace.com
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au · 1300 363 992.