Privacy Policy
Last updated: 8 September 2026
classadmin.io (“classadmin.io”, “we”, “us”) is a software platform that education businesses (“Customers”) use to run their online tutoring operations — scheduling classes, managing rosters, and issuing invoices. This policy explains what personal data we handle and why.
Our role
For data that a Customer enters or generates through the platform — including information about their teachers, parents, and students — the Customer is the data controller and classadmin.io acts as a data processor on their behalf, under our agreement with them. Customers are responsible for having a lawful basis to provide that data to us, including any parental consent required for information about children.
For data relating to the people who administer classadmin.io accounts (for example, the person who signs in to manage an organisation), we act as a data controller.
Data we handle
- Account data — name, email address, and profile picture from Google Sign-In, and the role assigned to you within an organisation.
- Organisation data — records a Customer creates: subjects; teachers and guardians (name, email, phone, WhatsApp); students (name, and where the Customer records them, date of birth, grade, school, city, and country); the links between students and their guardians; batches, schedules, enrolments, attendance, and invoices.
- Fees and invoices — the price a Customer sets for a student, the invoices generated from it (amount, period, due date, status), and any payment reference a Customer records. classadmin.io does not process card or bank payments.
- Curriculum and coursework — subject levels; learning resources a Customer uploads or links (including external links such as Google Drive URLs); homework instructions and attachments; and student submissions, including files a student or their guardian uploads and any grade or feedback a teacher records. Uploaded files are held in private storage and are reachable only through short-lived links issued after an access check.
- Connected-service credentials — when a Customer connects a payment provider or a messaging service, we store the access tokens or API keys needed to operate that integration. These are encrypted at rest.
- Meeting links — the Google Meet (or other) link a Customer pastes onto a class. classadmin.io does not connect to or access anyone’s Google Calendar, Gmail, or Drive — these links are plain text you provide.
- Usage and audit records — log entries recording actions taken in the platform (who changed what, and when), and standard server logs.
Google sign-in
classadmin.io uses Google Sign-In (via our authentication provider, Supabase) only to confirm who you are — your name and email address. We do not request access to your Google Calendar, Gmail, Drive, or any other Google data.
How we use data
- To provide the platform’s features to the Customer and their users.
- To send transactional messages — class reminders, schedule changes, and invoices — on the Customer’s behalf.
- To secure the platform, prevent abuse, and troubleshoot problems.
- To meet legal and accounting obligations.
We do not use personal data for advertising and we do not sell personal data.
Service providers
We share data with a small number of processors that help us run the platform:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Google — sign-in only.
- Resend, our transactional email provider, and, where a Customer enables it, a WhatsApp Business provider, for notifications.
- The payment provider a Customer connects (for example CCAvenue via ClassCard) for invoicing and payment links.
Retention
We keep organisation data for as long as the Customer’s account is active. On termination we delete or return it within 60 days, except where we must retain records (for example invoices) to meet legal obligations. Connected-service tokens are deleted when the integration is disconnected.
Security
Data is encrypted in transit. Integration credentials are encrypted at rest with a dedicated key. Access between organisations is isolated at the database level, and administrative access is logged.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. If your data was provided to us by a Customer (for example, your child’s tutoring provider), please contact that Customer first, as they control it; we will assist them in responding. For account data we control, or to raise a concern, contact privacy@classadmin.io.
International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for those transfers.
Changes
We will update this policy as the platform evolves and will change the date above. Material changes will be notified to account administrators.
Contact
classadmin.io is operated by The Online Master. Questions about this policy: privacy@classadmin.io.