PRIVACY POLICY
Privacy, without the legal fog.
This Privacy Policy explains how The Dalton Grant Academy handles personal data. Have qualified counsel review before launch.
1. What we collect
- Account data: email, profile name, avatar, and preferences you choose.
- Content you create: posts, messages, event details, media uploads (if enabled).
- Device & usage: basic diagnostics to keep the app stable (crash logs, performance).
- Subscription status: entitlements from the App Store (iOS) or Stripe (web) when you subscribe.
2. How we use data
- Provide and improve the app’s training, community, and event features.
- Secure accounts and prevent abuse.
- Support customer service requests.
- Comply with legal obligations.
3. Lawful basis & consent (UK GDPR)
- Contract — to provide your account, subscriptions, and features you request.
- Legitimate interests — security, fraud prevention, and service improvement (balanced against your rights).
- Consent — where required (e.g. non-essential cookies, optional marketing, AI assistant on the contact page). You may withdraw consent at any time without affecting lawfulness before withdrawal.
- Legal obligation — records we must keep for tax, accounting, or regulatory purposes.
4. Sharing & processors
We share data only when needed to operate the service, to complete purchases, or as required by law. We do not sell personal data.
- Supabase — authentication, database, and file storage (EU/US regions per their terms).
- Stripe — web subscription checkout and billing (when you pay on web).
- Apple / Google — in-app purchases and subscription status (mobile).
- RevenueCat — subscription entitlement sync on mobile.
- Vercel — website and web app hosting.
5. Data retention
- Account & profile — until you delete your account, then removed from live systems (see account deletion in-app).
- Billing records — retained as required by UK tax and accounting law (typically up to 6 years).
- Security audit logs — retained for fraud prevention and compliance after account deletion.
- Support messages — until the request is resolved and for a reasonable period thereafter.
6. Your rights
- Update profile information in-app.
- Adjust notification and accessibility preferences.
- Request access, correction, erasure, restriction, or portability via the contact form (Privacy & data requests).
- Object to processing based on legitimate interests.
- Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
7. Data security
We implement technical and organisational measures including TLS encryption in transit, encrypted storage with our cloud providers, role-based access controls, row-level security on the database, regular dependency and infrastructure updates, and security audit logging. No method of transmission or storage is 100% secure; report suspected issues via the contact form.
8. International transfers
Your information may be processed in countries other than your own. Where required, we use appropriate safeguards.
9. Children
The App is not directed to children under the minimum age required in your country. If you believe a child has provided personal data, contact us.
10. Contact
Privacy questions? Use the contact form and pick “Privacy & data requests”. We usually respond within 24–48 hours. If you are in the EU/UK, you may also have the right to lodge a complaint with your local authority.
See also our Cookie Policy and Terms of Use.