Privacy Policy
Last updated: 5 October 2025
1. Information We Collect
From Students/Parents:
- Name, email address, and phone number
- Student year level and subject requirements
- Preferred tutoring times and location
- Budget preferences
From Tutors:
- Name, email address, and qualifications
- Teaching subjects and experience
- Location and availability
- Verification documents and references
Automatically:
- Website usage data and analytics
- IP addresses and browser information
- Payment transaction details (via Stripe)
2. How We Use Your Information
- Matching: Connect students with suitable tutors
- Communication: Send introductions and platform updates
- Verification: Validate tutor qualifications and credentials
- Payment Processing: Handle finder’s fees via Stripe
- Improvement: Analyse usage to enhance our services
- Legal Compliance: Meet regulatory requirements
3. Information Sharing
We Share Information:
- With Matched Parties: Student and tutor details after payment
- With Service Providers: Stripe (payments), email provider, hosting
- For Legal Reasons: When required by law or to protect safety
We Never Sell:
- Personal information to third parties
- Contact details to marketing companies
- Student or tutor data for commercial purposes
4. Data Security
- Encrypted data transmission (HTTPS/TLS)
- Secure database storage with access controls (e.g., MongoDB Atlas)
- Regular security updates and reviews
- PCI DSS compliant payment processing via Stripe
5. Your Rights
Under New Zealand privacy law, you have the right to:
- Access: Request copies of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request removal of your data (subject to legal requirements)
- Portability: Receive your data in a portable format
- Objection: Opt out of certain processing activities
6. Data Retention
- Active Users: Data retained while the account is active
- Inactive Accounts: Deleted after 2 years of inactivity
- Transaction Records: Kept for 7 years for tax/legal purposes
- Communications: Email records kept for 1 year
7. Cookies and Tracking
We use cookies and similar technologies to enhance your experience:
- Essential: Login, security, session management
- Analytics: Google Analytics for usage insights (anonymised)
- Preferences: Remember settings and subject preferences
- Performance: Monitor platform performance
You can disable cookies in your browser settings, though this may affect functionality. Essential cookies cannot be disabled as they are necessary for the platform to work.
Third-Party Cookies: Stripe (payments) and Google Analytics set their own cookies. Their privacy policies govern their data collection.
8. Children’s Privacy
Our platform is designed for students aged 14–18. For users under 16, parental consent is required. We take extra care to protect young users’ information.
9. International Transfers
Your data is primarily stored in New Zealand or Australia (e.g., Vercel regions and MongoDB Atlas). Some providers (like Stripe and Google) may process data in other countries under appropriate safeguards.
10. Changes to This Policy
We may update this privacy policy periodically. We’ll notify users of significant changes via email or platform notices.
11. Contact Us
For privacy-related questions or requests, email us at info@nceatutor.co.nz
12. Privacy Act 2020 Compliance
We comply with New Zealand’s Privacy Act 2020 and its principles, including:
- Purpose & Source: We collect only what’s needed, directly from you where possible
- Transparency: We tell you what we collect and why
- Security & Retention: We protect and don’t keep information longer than necessary
- Access & Correction: You can request access and corrections
- Use & Disclosure: Limited to stated purposes unless you consent otherwise
- Unique Identifiers: Assigned only when necessary
13. Data Breach Notification
- We will notify affected individuals as soon as practicable if serious harm is likely
- We will notify the Privacy Commissioner when required
- Notifications include the nature of the breach and steps being taken
- We maintain an incident response plan to minimise harm
14. Third-Party Services
We use these providers to operate the platform:
- Stripe: Payment processing (PCI DSS compliant)
- Vercel: Front-end hosting and infrastructure
- MongoDB Atlas: Database hosting
- Google Analytics: Website analytics (anonymised data)
- Email Service: Transactional emails and notifications
Each provider has its own privacy policy and security standards.
15. Marketing Communications
- Opt-In: We send marketing emails only with your consent
- Unsubscribe: Every marketing email includes an unsubscribe link
- Transactional Emails: Service emails (receipts, matches) cannot be opted out
- Frequency: We limit marketing communications to avoid spam
16. Fair Trading Act Compliance
We do not make false or misleading representations about how we collect, use, or protect your data.
17. Automated Decision Making
We use algorithms to suggest tutor matches based on:
- Subject expertise and qualifications
- Location preferences (distance)
- Availability compatibility
- Ratings and review history
These are suggestions only; final choices are up to students/parents. You can contact us to learn more.
18. Your Privacy Rights Summary
Quick Reference — Your Rights:
- ✓ Access your personal information
- ✓ Correct inaccurate information
- ✓ Delete your data (subject to legal requirements)
- ✓ Export your data in a portable format
- ✓ Opt-out of marketing communications
- ✓ Complain to the Privacy Commissioner if dissatisfied
To exercise these rights: Email info@nceatutor.co.nz.