Privacy Policy
Last updated: 14 May 2026
Who we are
Steel Learning Platform is operated as a sole trader business based in the United Kingdom. Contact: info@steellearning.com
Data we collect
- Email address — collected at sign-up via Supabase Auth
- Subscription status and plan tier — stored in our database
- Stripe customer ID — stored when you subscribe, used to manage billing
- Anonymised usage analytics — page views via Vercel Analytics (no cookies, no PII)
We do not collect names, addresses, or payment card details. Card data is handled entirely by Stripe.
How we use your data
- To provide and manage your account
- To process subscription payments via Stripe
- To send transactional emails (account confirmation, password reset) via Supabase
- To understand aggregate usage patterns and improve the platform
We do not sell your data. We do not send marketing emails without your explicit consent.
Legal basis for processing (UK GDPR)
- Contract performance — processing your email and subscription data to deliver the service you signed up for
- Legitimate interests — anonymised analytics to improve the platform
Third parties
- Supabase — database and authentication, hosted in EU (eu-west-1). Privacy policy
- Stripe — payment processing. Privacy policy
- Vercel — hosting and privacy-friendly analytics (cookieless, no PII). Privacy policy
Cookies
We set one first-party cookie: a Supabase session cookie required for authentication. It is strictly necessary and does not require consent under UK GDPR. Vercel Analytics does not use cookies.
Data retention
We retain your account data for as long as your account is active. If you delete your account, your email and subscription records are deleted within 30 days. Stripe retains payment records as required by financial regulations.
Your rights
Under UK GDPR you have the right to: access your data, correct inaccurate data, request deletion (right to erasure), and data portability. To exercise any of these rights, email info@steellearning.com.
ICO registration
We are registered with the UK Information Commissioner's Office (ICO) as required for businesses processing personal data of UK residents.
Changes to this policy
We will notify you by email of any material changes to this policy before they take effect.