Privacy Policy
Last updated: 2nd February 2026
UK GDPR Compliance
StartSprint is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1Data We Collect
For Teachers
- Email address (for account creation and communication)
- Password (encrypted)
- Payment information (handled securely by Stripe — we do not store card details)
- Quiz content you create
- Usage analytics (quiz views, student performance data)
For Students
- Student gameplay does not require accounts
- We collect anonymised gameplay session data (quiz responses, scores, timing)
- No personally identifiable information is collected from students
- Session data is linked to anonymous session IDs, not student identities
2How We Use Your Data
- To provide and maintain the StartSprint service
- To process teacher subscriptions and payments
- To generate performance analytics for teachers
- To improve our service and develop new features
- To communicate important service updates
- To comply with legal obligations
3Data Sharing
We do not sell or share your personal data with third parties for marketing purposes.
We may share data with:
- Stripe: Payment processing only (they handle card data securely)
- Supabase: Our secure hosting provider (UK/EU data centres)
- Law enforcement: Only when legally required
4Data Security
- All data encrypted in transit (HTTPS/TLS)
- All data encrypted at rest in secure databases
- Regular security audits and updates
- Access controls and authentication required for all teacher accounts
- Payment data handled exclusively by PCI-DSS compliant Stripe
5Your Rights (UK GDPR)
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data (right to be forgotten)
- Portability: Receive your data in a machine-readable format
- Objection: Object to certain types of processing
- Restriction: Request limited processing of your data
To exercise any of these rights, email us at privacy@startsprint.app
6Data Retention
- Teacher account data: Retained while account is active, plus 90 days after deletion request
- Quiz content: Retained while account is active, deleted 90 days after account closure
- Student session data: Anonymised gameplay data retained for analytics purposes
- Payment records: Retained for 7 years as required by UK law
7Children's Privacy
StartSprint is designed for use in educational settings. Student gameplay requires no account creation and collects no personally identifiable information. Teachers are responsible for ensuring appropriate use in their classroom contexts.
8Cookies
We use essential cookies only:
- Authentication cookies (to keep teachers logged in)
- Session cookies (for anonymous student gameplay)
We do not use advertising or tracking cookies.
9International Transfers
Your data is stored on secure servers within the UK/EU. We do not transfer personal data outside the UK/EEA.
10Changes to This Policy
We may update this Privacy Policy from time to time. We will notify teachers of significant changes via email. Continued use of the service after changes constitutes acceptance.
11Contact & Complaints
For privacy concerns or data requests:
privacy@startsprint.appIf you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): www.ico.org.uk