Privacy Policy

Last updated: 6 August 2026

We are a tutoring practice, not an advertising business. We collect the minimum needed to answer your enquiry and to run your lessons.

We do not sell, rent, lease or share personal information. We do not run targeted advertising, and we never build commercial profiles of students.

Signing in is optional. You can read every page of this site, including the course material, without an account.

1. Who this is for

This is a mixed audience site. It is for students, parents and schools looking for mathematics tutoring, and it is not directed primarily at children.

Signing in with a Google Account is strictly optional and no part of the site requires it. That is deliberate: Google's API Services User Data Policy prohibits an application directed primarily at children from using Google Sign-In at all, and permits a mixed-audience site to offer it only where users can access the site in its entirety without an account.

Students under 13 should not create an account. A parent, guardian or teacher should make contact on their behalf.

2. What we collect, and why

If you send the contact form

We receive your name, email address and message. We also record the IP address the message came from, and the form is protected by a bot check.

This is used to reply to you and to arrange tutoring. It is not added to a marketing list, and you will not receive anything you did not ask for. Enquiries are automatically deleted after 90 days.

If you sign in to the Student Portal

Signing in with Google gives us an opaque Google account identifier and your email address. We never see your Google password, and we request no access to Gmail, Drive, Calendar or Contacts.

Your course progress is then stored against that identifier so it follows you between devices. Your session is stored as a hash of a random token — never the token itself — and expires after 30 days.

Site analytics

We use Cloudflare Web Analytics, which counts page views without cookies and without building a profile of you or following you to other sites. It exists to tell us which pages are useful. It is not an advertising product and there is no advertising network involved.

3. How long we keep things

DataRetention
Contact form enquiries (name, email, message, IP)90 days, then automatically deleted
Sign-in sessions30 days, then expired
Course progressUntil you ask us to delete it

Retention is enforced by expiry set on the record when it is written, not by anyone remembering to clear it out.

4. Who else receives data

The complete list. There are no others — no data brokers, no advertising networks, no social media pixels.

PartyWhat they receiveWhen
CloudflareHosting, storage, bot protection, cookieless page-view analyticsAlways
Google (Identity)Authentication onlyOnly if you sign in
BrevoYour enquiry, so it reaches us as an emailOnly if you send the contact form
WyzantNothing from us. The booking link takes you to their site, where their own privacy policy applies.Only if you follow it

5. What we never do

6. Schools and FERPA

Where a school or district engages us, we act as a school official with a legitimate educational interest in the student records involved, under the school's direct control as to their use and maintenance. We do not re-disclose student records and we do not use them commercially.

Schools requiring a signed Data Processing Agreement should request one before students use the service. Parents and eligible students may review, correct or delete student data through the school; requests made to us directly are answered within 45 days.

7. COPPA and children under 13

Written data retention policy

The amended COPPA Rule requires a written retention policy rather than merely a practice. Personal information is kept only as long as reasonably necessary for the purpose it was given for; the periods are in section 3; nothing is retained for a secondary purpose such as analytics, resale or model training.

Written information security program

Consistent with the amended COPPA Rule — effective 23 June 2025, with full compliance required from 22 April 2026 — we maintain a written information security program, scaled to the size of this practice as the Rule permits:

Adam Staples is responsible for this program.

8. Your rights

You may ask us to show you what we hold, correct it, delete it, or send it to you in a portable form. Write to the address below and we will act within 45 days. If we refuse a request we will say why, and you may appeal by replying to that decision.

Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy statutes have these rights by law; we extend them to everyone, because operating two standards would be more work than doing it properly once.

9. Security incidents

If we become aware of a breach affecting personal information, we will notify affected people and, where student data is involved, the relevant school, without undue delay and consistent with applicable law.

10. Other Staples Education products

The Interactive Quiz App is a separate, local-first product with its own architecture and its own privacy policy. It stores your material on your own device by default and does not share a database with this site.

11. Changes

Material changes are reflected in the date at the top of this page.

12. Contact

Staples Education — addstaples@gmail.com

For a Data Processing Agreement, a FERPA or COPPA question, or a data request, use the same address and say which it is.