Last updated: [DATE]
This Privacy Policy explains how [LEGAL ENTITY] (“Mastery”, “we”, “us”, “our”) collects, uses, and protects personal data when you use mymasteryapp.com (the“Platform”). We are the data controller for the personal data described in this policy and are registered with the UK Information Commissioner’s Office (ICO registration number: [ICO NUMBER]).If you have any questions about this policy or how we handle your data, contact us at [PRIVACY EMAIL].
1. Who we are
[LEGAL ENTITY] operates Mastery, an online learning marketplace connecting learners with independent instructors who offer courses, live classes, and coaching sessions. Our registered address is [REGISTERED ADDRESS].
2. The data we collect
We collect the following categories of personal data:
Account data: name, email address, password (stored in hashed form), profile photo, and role (learner or instructor).
Payment data: billing address, transaction history, and payment method identifiers. Full card details are processed and stored by Stripe, our payment processor — we do not store full card numbers on our systems.
Instructor data: additional information including bio, professional experience, course content, bank account details for payouts (via Stripe Connect), and tax information where required.
Learner activity data: courses viewed, enrolled in, and completed; progress through course content; quiz and assignment results; reviews and Q&A submissions.
Communications data: messages between learners and instructors, support requests, and marketing preferences.
Technical data: IP address, browser type, device information, operating system, and pages visited, collected via cookies and analytics tools.
Marketing data: your preferences for receiving communications from us and your interaction with our marketing emails.
3. How we use your data and our legal basis
| Purpose | Legal basis |
| Creating and managing your account | Performance of contract |
| Processing course purchases and instructor payouts | Performance of contract |
| Providing customer support | Performance of contract / Legitimate interests |
| Sending service emails (receipts, course updates, password resets) | Performance of contract |
| Sending marketing emails | Consent (withdrawable at any time) |
| Platform analytics and improvement | Legitimate interests |
| Fraud prevention and platform security | Legitimate interests / Legal obligation |
| Complying with tax, accounting, and legal obligations |
4. Sharing your data
We share personal data with the following categories of recipients:
Instructors — where you enrol in a course, the instructor receives your name and relevant learner activity to deliver the course, respond to questions, and mark assignments. Instructors are independent data controllers for their direct communications with you.
Service providers: Stripe (payments and instructor payouts), our hosting provider, email delivery providers, and email marketing tools (Mailchimp or equivalent). These providers act as data processors under contract.
Analytics providers: Google Analytics, for aggregated platform usage data. Where required, analytics cookies are only set with your consent.
Legal and regulatory bodies where we are required to disclose data by law.
Business transfers — if Mastery is sold, merged, or restructured, your data may be transferred to the new entity, subject to the same protections.
We do not sell your personal data.
5. International transfers
Some of our service providers (including Stripe, Google, and email platforms) are based outside the UK and EEA. Where personal data is transferred internationally, we rely on the UK’s adequacy decisions, Standard Contractual Clauses, or the UK International Data Transfer Addendum to ensure your data is protected to equivalent standards.
Because Mastery is a global platform, your data may also be shared with instructors or learners based outside the UK when you choose to interact with them.
6. How long we keep your data
Account data: for as long as your account is active, plus 12 months after closure.
Transaction and tax records: 7 years, to comply with UK tax and accounting law.
Marketing data: until you withdraw consent or unsubscribe.
Support correspondence: 3 years from the date of resolution.
Website analytics: in line with Google Analytics’ default retention (currently 14 months).
7. Your rights
Under UK GDPR, you have the right to:
Access the personal data we hold about you
Correct inaccurate data
Request deletion (“right to be forgotten”) where applicable
Restrict or object to processing
Data portability (receive your data in a machine-readable format)
Withdraw consent where processing is based on consent
Lodge a complaint with the ICO (ico.org.uk)
To exercise any of these rights, email [PRIVACY EMAIL]. We will respond within one month.
8. Cookies
Mastery uses cookies for essential site functionality, analytics, and marketing. Non-essential cookies are only set with your consent, which you can manage at any time via the cookie banner or settings link in the footer. Full details are available in our [Cookie Policy].
9. Security
We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords, access controls, and regular security reviews. No online platform is 100% secure, and we cannot guarantee absolute security of data transmitted to us.
10. Children
Mastery is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or via a prominent notice on the Platform before taking effect.
12. Contact
For any privacy-related questions, contact [PRIVACY EMAIL] or write to [LEGAL ENTITY] at [REGISTERED ADDRESS].