Legal

Privacy Policy

Last updated: 2nd February 2026

UK GDPR Compliance

StartSprint is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1Data We Collect

For Teachers

  • Email address (for account creation and communication)
  • Password (encrypted)
  • Payment information (handled securely by Stripe — we do not store card details)
  • Quiz content you create
  • Usage analytics (quiz views, student performance data)

For Students

  • Student gameplay does not require accounts
  • We collect anonymised gameplay session data (quiz responses, scores, timing)
  • No personally identifiable information is collected from students
  • Session data is linked to anonymous session IDs, not student identities

2How We Use Your Data

  • To provide and maintain the StartSprint service
  • To process teacher subscriptions and payments
  • To generate performance analytics for teachers
  • To improve our service and develop new features
  • To communicate important service updates
  • To comply with legal obligations

3Data Sharing

We do not sell or share your personal data with third parties for marketing purposes.

We may share data with:

  • Stripe: Payment processing only (they handle card data securely)
  • Supabase: Our secure hosting provider (UK/EU data centres)
  • Law enforcement: Only when legally required

4Data Security

  • All data encrypted in transit (HTTPS/TLS)
  • All data encrypted at rest in secure databases
  • Regular security audits and updates
  • Access controls and authentication required for all teacher accounts
  • Payment data handled exclusively by PCI-DSS compliant Stripe

5Your Rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data (right to be forgotten)
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to certain types of processing
  • Restriction: Request limited processing of your data

To exercise any of these rights, email us at privacy@startsprint.app

6Data Retention

  • Teacher account data: Retained while account is active, plus 90 days after deletion request
  • Quiz content: Retained while account is active, deleted 90 days after account closure
  • Student session data: Anonymised gameplay data retained for analytics purposes
  • Payment records: Retained for 7 years as required by UK law

7Children's Privacy

StartSprint is designed for use in educational settings. Student gameplay requires no account creation and collects no personally identifiable information. Teachers are responsible for ensuring appropriate use in their classroom contexts.

8Cookies

We use essential cookies only:

  • Authentication cookies (to keep teachers logged in)
  • Session cookies (for anonymous student gameplay)

We do not use advertising or tracking cookies.

9International Transfers

Your data is stored on secure servers within the UK/EU. We do not transfer personal data outside the UK/EEA.

10Changes to This Policy

We may update this Privacy Policy from time to time. We will notify teachers of significant changes via email. Continued use of the service after changes constitutes acceptance.

11Contact & Complaints

For privacy concerns or data requests:

privacy@startsprint.app

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): www.ico.org.uk

Summary

We comply with UK GDPR
We only collect data necessary to provide the service
Student gameplay requires no accounts
Teacher data is never sold or shared for marketing
Stripe handles all payment data securely
You can request data access or deletion at any time
StartSprint  ·  Privacy Policy  ·  Last updated 2nd February 2026