Privacy Policy

 Latest Version: May 23, 2026

Effective Date: 23/05/2026 | Version 1.0

Version History

Version | Date | Summary of Changes

1.0 | 23/05/2026 | Initial publication of Privacy Policy.

Introduction

Welcome to Rubicon Tutors ("we," "our," or "us"). We are committed to protecting and respecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our platform serves students, parents, and tutors based in the United Kingdom, and we are committed to handling all personal data responsibly.​

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website https://www.rubicontutors.com, use our services, or interact with us in any other way. Please read this policy carefully to understand our views and practices regarding your personal data and how we will treat it.

Data Controller

The Data Controller for all personal data collected through the Rubicon Tutors platform is:

UK Study Today Ltd, trading as Rubicon Tutors

Company Number: 07192908

Registered Address: 124 City Road, London, England, EC1V 2NX

For all data protection enquiries, please contact our Data Protection Officer at: info@RubiconTutors.com

Information We Collect

We may collect and process the following data about you:

  • Personal Identification Information: Name, email address, phone number, postal address.
  • Account Information: Username, password, and other identifiers.
  • Payment Information:  We do not store, process, or have access to your full payment card details. Payments from Students (including refunds) are processed securely by our third-party payment processor, Stripe, and the disbursement of funds to Tutors is facilitated via Stripe Connect. All payment processing is handled in compliance with PCI-DSS standards.
  • Tutoring Information: A range of personal and professional information to process your application, including your subjects of interest, tutoring preferences, the levels you can teach, your educational qualifications, your tutoring experience both online and in-person, details regarding your specializations or specific areas of expertise, a photo for your profile, your availability, a Disclosure and Barring Service (DBS) check, feedback, necessary compliance documents such as your right to work, proof of identity (e.g., passport or driving license), and proof of address (e.g., utility bill or bank statement), information for two references, which must include their full names, telephone numbers, email addresses, and their relationship to you as the tutor, ensuring we have comprehensive data to verify your skills and character.
  • Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
  • Usage Data: Information about how you use our website, products, and services.
  • Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences.
  • Audio/Visual Data: Recordings of online tutoring sessions (video, audio, and whiteboard activity) via our third-party processor (Lessonspace).
  • Retention: Online lesson recordings are processed and stored securely via our third-party classroom provider, Lessonspace. These recordings are maintained for safeguarding and educational review purposes and are automatically and permanently deleted from the Lessonspace database 90 days after the lesson date.

To provide our services efficiently and in compliance with applicable data protection laws, we collect the following categories of personal data.

Data Category

Examples

Purpose of Collection

Legal Basis (UK GDPR)

Identity & Verification

Full name, date of birth, gender, Proof of Right to Work (e.g., Share Codes, Biometric Residency Cards) and Government-issued ID numbers.

To create user accounts.To comply with UK legal requirements regarding employment verification and platform safety.

Article 6(1)(b) – Contract

Contact Data

Email address, telephone number, billing address

To communicate with users, process bookings

Article 6(1)(b) – Contract

Credit card information and Payment Data

Billing address, transaction history, Stripe-generated payment IDs, and the last four (4) digits of the payment card used. Note: We do not store, process, or have access to the full credit card number or CVV/CVC codes.

To facilitate transactions including billing Students for Lessons as agent for the Tutor and passing on payments to Tutors for lessons taught.

Article 6(1)(b) – Contract, Article 6(1)(c) – Legal obligation

Profile Data

Usernames, account preferences, tutoring subjects, profile bio, professional photograph, teaching style preferences, and public reviews/ratings.

To enable Students to make informed decisions when selecting a Tutor and to facilitate platform community building.

Article 6(1)(f) – Legitimate interests

Qualifications & Experience

Educational certificates, academic degrees, professional work history, and teaching experience records.

To verify tutor suitability, ensure pedagogical quality, and assist Students in making informed selection decisions.

Article 6(1)(f) – Legitimate interests

Technical Data

IP address, browser type, device ID

To ensure platform security and performance

Article 6(1)(f) – Legitimate interests

Usage Data

Page views, session time, user interaction

To analyse user behavior and improve services

Article 6(1)(a) – Consent

Location Data

Approximate or specific location during use

To match tutors and learners for in-person sessions

Article 6(1)(a) – Consent

Marketing Data

Email preferences, marketing engagement

To deliver targeted promotions or newsletters

Article 6(1)(a) – Consent

Professional References

Names, contact details, and professional relationships of two (2) referees. Tutors are responsible for ensuring that their referees have been informed that their personal data will be shared with Rubicon Tutors and have been directed to this Privacy Policy before providing their details.

To verify tutor suitability, experience, and professional background.

Article 6(1)(f) – Legitimate interests

Special categories of personal information including criminal conviction information

DBS Certificate number, status, and issue date

Safeguarding and suitability for working with children/vulnerable adults, to confirm and publish a tutor's verified 'Background Checked' status on their profile, as outlined in our Terms and Conditions.

Article 6(1)(c) (Legal Obligation) and Article 10 (Criminal convictions) in conjunction with the Data Protection Act 2018 (Safeguarding).

Children's Personal Data

Rubicon Tutors is an online tutoring platform designed to be accessed by children and young people under the age of 18, operating under parental or guardian supervision. We are committed to compliance with the ICO's Age Appropriate Design Code 2021 (the Children's Code). In particular:

  • We collect only the minimum data necessary from or relating to child users;
  • Default privacy settings for child users are set to the highest level of protection;
  • We do not use the personal data of child users for profiling or targeted advertising;
  • All processing of child personal data is carried out with the informed consent of the parent or guardian, in accordance with UK GDPR Article 8 and Section 9 of the Data Protection Act 2018;
  • Lesson recordings involving children are retained for 90 days only and are used solely for safeguarding and quality assurance purposes;
  • Parents and guardians may exercise all data rights on behalf of their minor child by contacting info@RubiconTutors.com.
  • Given the nature and scale of our processing of children's personal data, we conduct Data Protection Impact Assessments (DPIAs) in accordance with UK GDPR Article 35 and ICO guidance for all processing activities that involve the personal data of children and young people under the age of 18. These assessments are reviewed regularly and updated where there are material changes to our processing activities.
  • A separate short-form privacy notice written in clear, age-appropriate language is available for children and their parents or guardians. This notice summarises the key points of this Privacy Policy in an accessible format, in line with the ICO's Age Appropriate Design Code 2021. It can be accessed on our website or requested by contacting info@RubiconTutors.com.

How We Use Your Information

We use the information we collect in the following ways:

  • To Provide Services: Facilitate the connection between students and tutors, schedule sessions, and manage accounts.
  • Payment Processing: Process payments from Students and refunds via Stripe, and facilitate Tutor payouts via Stripe Connect.
  • Communication: Send administrative information, respond to inquiries, and provide customer support.
  • Personalization: Customize user experience and deliver content relevant to your interests.
  • Marketing: Send promotional materials, subject to your preferences. You have the right to object to the processing of your personal data for direct marketing purposes at any time, including any profiling related to such marketing, by contacting us at info@RubiconTutors.com or using the unsubscribe link in any marketing email.
  • Legal Obligations: Comply with legal requirements, such as tax and accounting obligations.
  • Security: Maintain the safety and security of our services, including fraud detection and prevention.
  • Automated Decision-Making: We use automated processes to rank Tutors in search results based on criteria including availability, qualifications, subject specialisation, student feedback scores, and response rate. This ranking may significantly affect a Tutor's ability to receive bookings. Tutors have the right to: (a) obtain an explanation of any automated ranking decision that significantly affects them; (b) request human review of any such decision; and (c) contest decisions they believe to be inaccurate or based on incorrect data. To exercise these rights, contact info@RubiconTutors.com. We do not make fully automated decisions that affect Tutors' or Students' legal rights without human oversight.

Legal Bases for Processing

Under the UK GDPR, we rely on the following legal bases for processing your personal data:

  • Consent: When you have given clear consent for us to process your personal data for a specific purpose.
  • Contractual Necessity: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
  • Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject.
  • Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. We have carried out Legitimate Interests Assessments (LIAs) for all processing activities that rely on this basis, and copies are available on request by contacting info@RubiconTutors.com.

Sharing Your Information

We may share your personal data with:

  • Tutors and Learners: To facilitate tutoring sessions, we may share relevant information between learners and tutors.
  • Service Providers: Third-party vendors who provide services on our behalf, such as payment processing (Stripe for Student payments and refunds, and Stripe Connect for Tutor payouts) and online classroom infrastructure (Lessonspace for hosting and recording tutoring sessions).
  • Legal Authorities: When required by law or to protect our rights, we may disclose your information to regulatory authorities.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the new entity.​

International Data Transfers

UK Study Today Ltd transfers personal data to the following countries: United States of America (via Stripe, Inc. for payment processing and Lessonspace for online classroom infrastructure). These transfers are made pursuant to the UK-US Data Bridge (UK Extension to the EU-US Data Privacy Framework) where the relevant processor is enrolled in that framework, or alternatively pursuant to International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner's Office. Transfer Impact Assessments have been completed for each such transfer and are available on request. For other international transfers, we use UK-approved IDTAs or SCCs with the UK Addendum as appropriate.

Your information may be transferred to and processed in countries outside the UK. When we transfer your data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes we collected it for, including satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, and the applicable legal requirements.

Specific Retention Examples

  • Account Information: We retain your account data for as long as your account remains active or as required to comply with our legal obligations.
  • Lesson Recordings: For safeguarding and quality assurance purposes, interactive lesson recordings are stored securely and are automatically deleted ninety (90) days after the date of the session.
  • Financial Records: Transactional data is retained in accordance with applicable UK tax and accounting laws.
  • DBS Certificate Data: Copies of Enhanced DBS certificates are retained for a maximum of 6 months from the date of receipt, after which they are securely destroyed in accordance with the DBS Code of Practice. A record of the certificate number, date of issue, type, and verification status may be retained for the duration of the Tutor's engagement and for such further period as is required by Keeping Children Safe in Education.
  • Profile Data & Contact Data: Retained for the duration of your active account and for up to 2 years following account closure or last activity, unless earlier deletion is requested.
  • Qualifications & Experience and Professional References: Retained for the duration of the Tutor's engagement with the platform and for up to 2 years thereafter, to support any outstanding disputes, complaints, or regulatory enquiries.
  • Technical Data & Usage Data: Retained for up to 13 months from the date of collection, in line with standard analytics retention practices.
  • Location Data: Retained only for as long as necessary to facilitate tutor-student matching and deleted promptly thereafter, and in any event no longer than 12 months from the date of collection.
  • Marketing Data: Retained until you withdraw your consent or unsubscribe, after which your marketing preferences are updated and promotional communications cease within 10 working days.

Your Data Protection Rights

Under the UK GDPR, you have the following rights:

  • Access: Request access to your personal data.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data, subject to legal obligations.
  • Restriction: Request restriction of processing your personal data.
  • Data Portability: Request the transfer of your data to another service provider.
  • Objection: Object to the processing of your personal data in certain circumstances.
  • Withdraw Consent: Withdraw consent at any time where we are relying on consent to process your personal data.​

To exercise any of these rights, please contact us at [info@RubiconTutors.com]. We will respond to all legitimate requests within one (1) month of receipt, in accordance with UK GDPR Article 12. In exceptional circumstances, where requests are complex or numerous, we may extend this period by a further two (2) months, but we will inform you of any such extension and the reasons for it within the initial one-month period.

Security Measures

Unfortunately, the sending of information via the internet is not totally secure and on occasion such information can be intercepted. Although we will take steps to protect your information, we cannot guarantee the security of data that you choose to send us electronically and sending such information is entirely at your own risk. To ensure that all new features and changes to our service adhere to GDPR requirements we follow a design by data protection by design and default approach to all development of our website and service. This includes conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities, in line with ICO guidance.

We also implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption: Protecting data in transit and at rest.
  • Access Controls: Limiting access to personal data to authorized personnel.
  • Regular Testing: Assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of processing.

Data Breach Response

In the event of a personal data breach, we will: (a) notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required by UK GDPR Article 33; (b) notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with UK GDPR Article 34; (c) maintain a record of all personal data breaches in our internal breach register, regardless of whether notification is required. If you believe your personal data has been involved in a security incident, please contact us immediately at info@RubiconTutors.com.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website to provide a more streamlined, personalized, and secure user experience. These technologies help us understand how visitors interact with our platform, improve site functionality, tailor content, measure the effectiveness of our marketing, and provide users with relevant advertising.

Cookies are small text files that are stored on your browser or the hard drive of your device when you visit a website. They contain information that is transferred to your device and are widely used to make websites work more efficiently, as well as to provide information to the site owners. Cookies can be "session" cookies (which expire once you close your web browser) or "persistent" cookies (which remain on your device for a set period or until deleted).

We use the following categories of cookies:

  • Strictly Necessary Cookies: These are essential to enable you to move around our website and use its features, such as accessing secure areas. Without these cookies, services you request (like logging into your account) cannot be provided.
  • Performance and Analytics Cookies: These cookies collect information about how visitors use our website, such as which pages are visited most often, and whether users receive error messages. These are used only to improve how our site works.
  • Functionality Cookies: These cookies allow our website to remember choices you make (such as your username, language, or the region you are in) and provide enhanced, more personalized features.
  • Targeting or Advertising Cookies: These cookies are used to deliver adverts more relevant to you and your interests. They may also limit the number of times you see an advertisement and help measure the effectiveness of advertising campaigns.

We may also use third-party cookies, including but not limited to services provided by Google Analytics, Meta (Facebook), LinkedIn, and other analytics or advertising networks. These third-party services may use cookies to collect data about your browsing habits across websites and build profiles for targeted advertising or performance metrics.

You have full control over how cookies are used. Upon your first visit to our website, you will be presented with a cookie banner seeking your consent to use certain types of cookies in accordance with the Privacy and Electronic Communications Regulations (PECR) and the UK GDPR. You can manage your cookie preferences or withdraw your consent at any time by visiting the cookie settings section, or by adjusting the settings in your browser to block or delete cookies.

Please note that if you disable cookies, some parts of our website may not function properly or may become inaccessible.

"Do Not Track" Disclosure:Our platform currently does not respond to 'Do Not Track' (DNT) signals in HTTP headers, as there is no industry standard for how these signals should be interpreted. We will periodically review this position as industry standards and regulatory guidance evolve.

For a comprehensive overview of the cookies we use, including their names, purposes, and expiry periods, please see our full Cookie Policy located at Click here.

We are committed to transparency in how we use cookies and other technologies, and we regularly review our use of tracking technologies in line with guidance from the UK Information Commissioner's Office (ICO).

Cookie Overview Table

Below is a non-exhaustive list of the cookies used on our site. For the full list and current cookie settings, please refer to our Cookie Policy.

Cookie Name

Type

Purpose

Duration

First/Third Party

__cf_bm

Strictly Necessary

Helps Cloudflare distinguish between bots and legitimate users.

30 minutes

Third-party (Cloudflare)

sessionid

Strictly Necessary

Maintains user session across requests after login.

Session

First-party

_ga

Performance / Analytics

Tracks user behavior with Google Analytics.

2 years

Third-party (Google)

_gid

Performance / Analytics

Distinguishes users for Google Analytics.

24 hours

Third-party (Google)

csrftoken

Functionality

Protects against Cross-Site Request Forgery attacks.

1 year

First-party

locale

Functionality

Stores the user's language and region preferences.

1 year

First-party

fbp

Targeting / Advertising

Facebook pixel for delivering targeted ads.

90 days

Third-party (Meta)

stripe_mid

Strictly Necessary / Secure

Identifies and secures Stripe payment sessions.

1 year

Third-party (Stripe)

Third-Party Links

Our website may include hyperlinks to external websites, plug-ins, applications, and other services that are not operated or controlled by us. These third-party links are provided for your convenience and to provide additional information or services that may be relevant to your interests. Examples include links to educational resources, tutor profiles hosted on external platforms, or social media platforms.

Clicking on these third-party links or enabling those connections may allow third parties to collect or share data about you. We do not have control over these third-party websites and are not responsible for their privacy practices, terms and conditions, security standards, or how they handle your personal data. This includes any personal information you may provide to such sites, such as login credentials, payment data, or contact details.

We strongly encourage you to read the individual privacy policies, cookie policies, and terms of use of every third-party website you visit. These policies will outline how those third parties process personal data, including whether they share data with advertisers, transfer it internationally, or use it for profiling and tracking purposes. You should also be aware that third-party websites may have different data retention practices and legal bases for processing your data, which may not align with our practices or with the UK GDPR.

Although we strive to only link to reputable, secure, and relevant third-party sites, inclusion of a link does not imply endorsement or affiliation unless specifically stated. We are not responsible for any harm, loss, or damage that may result from your use of any third-party sites or services.

Should you suspect that a third-party link on our platform leads to malicious or inappropriate content, please notify us immediately at [info@RubiconTutors.com], and we will review the link promptly.

For your protection, we recommend using up-to-date antivirus software and enabling security features in your browser to help safeguard your information when browsing beyond our platform.

Changes to our Privacy Policy

Any changes to our Privacy Policy will be posted to the Website and, where appropriate, via e-mail. Where we make material changes to this Privacy Policy that affect how your personal data is processed, we will notify you at least 30 days in advance of the changes taking effect, giving you the opportunity to review the updated policy and, where applicable, withdraw your consent or exercise your data protection rights before the changes become effective. This 30-day advance notice requirement does not apply where changes are required urgently to comply with applicable law, a court order, or a binding direction from the Information Commissioner's Office or another regulatory authority, in which case changes may take effect immediately upon notice being given to you.

Privacy-Related Inquiries and Complaint Procedures

Feel free to reach out to us by email at [info@RubiconTutors.com] if you have any questions about this Privacy Policy. If you're not happy with how we handle your concerns or think we're not processing your data legally, you can also get in touch with the UK's data protection authority, the Information Commissioner's Office (ICO), at ico.org.uk, or by post at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113.