Legal

Privacy Policy

Tutor Platform collects only the information needed for Stage 1 tutor onboarding and administrator verification. This includes account details, contact information, profile data, qualifications, service areas, teaching preferences, availability, uploaded documents, and administrator review notes.

How Information Is Used

Information is used to create accounts, save tutor applications, validate required sections, support administrator review, verify documents, and record status changes for operational accountability.

Document Storage and Access

Uploaded tutor documents are stored outside the public web directory. Access is limited to the owning tutor and authorized administrators through protected application routes.

Security

Passwords are hashed before storage. Protected forms use CSRF tokens, database queries use prepared statements, and private configuration such as credentials and mail settings should remain in environment configuration rather than committed files.

Retention

Application records, uploaded documents, review history, and status history may be retained while an account or application remains active, pending, suspended, rejected, or otherwise needed for verification records.

User Control

Tutors can update permitted account and application details from their dashboard. Administrators can activate, suspend, or deactivate administrator accounts and manage master data without destructive deletes.