Privacy Policy

This Privacy Policy explains how GCSE Maths Lab collects, uses, and protects your information. By using the site, you agree to this Policy.

1. Who we are

GCSE Maths Lab (“we”, “us”, “our”) provides online maths revision materials, quizzes, and progress-tracking tools for GCSE students. You can contact us through the Contact page for any privacy-related questions or concerns.

2. What information we collect

We collect information you provide when creating an account, such as your name, username, email address, and password. We also store your quiz progress, scores, and related usage data so that you can track your learning. When you make a payment, Stripe processes your card details securely on our behalf — we do not store payment card information on our servers.

3. How we use your information

We use your information to provide and manage your account, record your progress, process payments, send essential service emails (for example, verification links and receipts), and improve the learning experience. We may analyse anonymised, aggregated usage data to understand how the site is used and to make improvements.

4. Cookies and analytics

GCSE Maths Lab uses cookies and similar technologies to operate the website and understand how it is used.

We use Google Analytics to help measure visitor activity and improve the site experience. Google Analytics may collect information such as pages visited, device type, browser information, and general usage patterns.

Analytics cookies are optional and are only enabled if you choose to accept them through the cookie banner shown when you visit the site. If you decline analytics cookies, Google Analytics will not be activated.

If you previously accepted analytics cookies and would like to change your choice, you can do so by clearing your browser cookies and local site storage, then revisiting the site to see the cookie banner again.

You can also opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

5. Legal basis for processing

We process personal data under one or more of the following legal bases:
– To perform a contract with you (for example, to provide access to your account);
– To comply with legal obligations (such as tax and accounting requirements);
– For our legitimate interests (improving and securing the service);
– With your consent (for optional analytics or communications).

6. How we protect your data

We use secure connections (HTTPS) across the entire site. Passwords are stored using industry-standard hashing. Payments are handled by Stripe in compliance with PCI-DSS security standards. We regularly review access permissions and security configurations to protect your data from unauthorised access or disclosure.

7. How long we keep your data

We retain your personal data only for as long as necessary to provide our services and fulfil legal obligations. If you delete your account, most personal data will be removed within 30 days, except where retention is required by law (for example, payment records).

8. Sharing your information

We only share data with trusted providers who help us operate the service. These include:

  • Supabase – secure database hosting and account management
  • Stripe – payment processing and subscription management
  • Cloudflare – website security, DDoS protection, and Turnstile human-verification
  • Mailtrap – sending account-related emails such as verification or password resets
  • Cloud hosting and infrastructure providers that support our website operations
  • Google Analytics – usage analytics, where consent has been given

These providers act as data processors and handle information only on our instructions, under appropriate data-protection agreements.

9. Your rights

Under UK GDPR, you have the right to access, correct, delete, or restrict the processing of your personal data. You may also object to certain types of processing (such as marketing or analytics) and request a copy of your data in a portable format. To exercise any of these rights, please contact us via the Contact page.

10. Children’s privacy

GCSE Maths Lab is designed for GCSE-level learners. Users under 16 should register only with parental consent. We do not knowingly collect data from children without such consent.

11. International access

Our service is available worldwide. If you access the site from outside the UK, your data may be transferred to servers located in the UK or other countries that may have different data-protection laws. We ensure that appropriate safeguards are in place for such transfers.

12. Changes to this Policy

We may update this Privacy Policy from time to time to reflect improvements or legal changes. Updates will appear here with a revised “last updated” date.

Last updated: 4/19/2026