Privacy Policy
Last updated: pending launch.
Haddee Education, LLC | tutoring.haddee.com Status: DRAFT — not effective; pending legal review Effective Date: [Pending — set at publication] | Last Reviewed: July 18, 2026 2006 Kala Bagai Way SPC10, Berkeley, CA 94704
This Privacy Policy describes how Haddee Education, LLC ("Haddee," "we," "us," or "our") handles personal information in the tutoring web service at tutoring.haddee.com (the "Service"). It does not describe a Haddee mobile app, internship program, or another Haddee product.
Contact hello@haddee.com with privacy questions or requests.
1. Information we collect
1.1 Visitors and technical information
When you visit the Service, our hosting, security, and application systems may process:
- IP address and approximate location derived from it;
- browser, operating system, device category, screen size, referring page, and requested URL;
- dates/times, pages viewed, clicks, scrolling, and other interactions;
- authentication/session-cookie data, security events, rate-limit keys, and application logs; and
- the analytics choice stored in your browser's local storage.
Optional analytics described in Section 8 do not load until the visitor selects Accept on the cookie banner and a provider is configured. Essential session and security processing is not controlled by that banner.
1.2 Account and sign-in information
For an account, the Service may store:
- name, email address, email-verification status, role, and account-creation time;
- a password hash for credentials accounts; we do not store the readable password;
- Google account/OAuth identifiers and tokens when Google sign-in is used;
- display-name preferences for Teachers;
- notification preferences and account-security timestamps; and
- an internal user id used to connect records in the database.
1.3 Age gate and Parent/Guardian information
Student signup asks for a date of birth to enforce the 13+ age gate. The full date is used for the age decision and is not saved as a date-of-birth field. For a Student who is 13–17, the Service stores birth month and year, a minor/adult flag, and the Parent/Guardian name and email. For an adult Student, it stores the adult flag but not birth month/year.
The Service sends the Parent/Guardian a one-time informational account email. The email does not contain an acceptance link, create a guardian account, or record direct Parent/Guardian consent. The Student uses the ordinary Student Terms/Privacy acceptance flow. For Stripe checkout by a minor, the Student must affirm that the Parent/Guardian authorized that specific purchase; that affirmation is recorded with the checkout/purchase. An authorized Admin who records a paid off-platform purchase or paid Trial grant for a minor must separately attest to that purchase-specific authorization; the server rejects the valued grant if the Student's age cannot be established or the attestation is missing. Purchase receipts are also sent separately to the Parent/Guardian.
1.4 Student profile information
A Student profile may include:
- academic level and graduation year;
- school name with the city/state label returned by the school search, or a free-text school value;
- IANA time zone;
- optional profile biography; and
- onboarding status.
Students do not upload a public profile photo or provide a phone number for SMS in the current Service.
1.5 Teacher profile and payout information
A Teacher profile may include:
- legal/account name and the title/name format shown to Students;
- public headline, biography, approved photo, classes, and class descriptions;
- time zone, recurring availability, date overrides, enabled holidays, and booking-pause state;
- Zoom or Google Meet link used for Sessions;
- private phone number and its verification status;
- SMS consent text/time and SMS preferences;
- Veem payout email and verification status; and
- U.S. payout address, standardized address, and address-verification/review status.
Teacher profile text and photos may be held for Admin review before being shown publicly. Uploaded Teacher photos are converted to a supported format and image metadata is removed before storage.
Teacher tax forms and tax identifiers such as SSNs or EINs are handled off-platform by authorized personnel. They are not stored in the tutoring application database.
1.6 Bookings, Hours, purchases, and payouts
The Service stores records needed to operate and account for tutoring, including:
- booking participants, Class, start/end time, status, cancellation actor/reason/time, Session length, and booking-time price/payout snapshots;
- attendance/reliability flags and authorized Admin clawback records;
- per-Class Hour purchases, packages, Trials, lots, spends, returns, grants, removals, and adjustments;
- Stripe Checkout/session/payment identifiers, amount paid, Stripe fee when available, purchase kind, and minor purchase-authorization flag;
- manually recorded off-platform payments/refunds and the responsible Admin/reason; and
- Teacher earnings, payout records, month, amount, included Sessions, and external payout readiness.
Stripe processes card information on Stripe-hosted checkout. Haddee does not receive or store a full card number or card security code.
1.7 Messages, reviews, support, and Admin records
The Service stores:
- direct/Concierge thread participants, messages, booking proposals, system messages, escalation state, and read times;
- Student reviews, star ratings, selected Classes, edit/moderation history, and reports;
- support emails and other information you send to
hello@haddee.com; and - Admin audit records about sensitive actions, including the acting Admin, target internal id, reason, and structured details.
Admins may review in-product messages for support, safety, moderation, and operation of the Service, particularly because Students may be minors.
1.8 Email, SMS, and in-app notifications
The Service stores notification preferences and delivery records. Email records may include destination address, template/payload, provider id, delivery/bounce state, and timestamps. Teacher SMS records may include the verified phone, verification attempts, exact consent disclosure, consent/opt-out time, category preferences, message body, Twilio id/status, and STOP/START state.
Students are not sent SMS by the current Service.
2. Information received from other services
Depending on the feature you use and production configuration, we may receive:
- account identity and OAuth information from Google sign-in;
- payment status, amount, fee, and transaction identifiers from Stripe;
- email delivery, bounce, or complaint status from Resend;
- SMS delivery status and inbound STOP/START/HELP information from Twilio;
- school/address/place suggestions and public Haddee review statistics from Google services;
- website usage/session-replay data from Google Analytics and Microsoft Clarity after analytics consent;
- error and performance information from Sentry; and
- external payout information handled by authorized staff through Veem.
The Teacher supplies the Zoom or Google Meet link used for a Session. Users interact with the meeting provider under that provider's own terms and privacy policy. Haddee does not record tutoring Sessions.
3. Why we use information
We use information to:
- create, authenticate, secure, and support accounts;
- enforce the 13+ age gate and operate the Parent/Guardian notice and purchase workflow;
- show Teacher profiles, Classes, availability, and public reviews;
- let Students buy Hours, book/cancel Sessions, join meetings, and message Teachers/Haddee;
- calculate and administer Hours, revenue, Teacher earnings, manual clawbacks, and payouts;
- send account, booking, purchase, payout, review, and support communications;
- verify Teacher phone/payout details and honor SMS choices;
- moderate profiles, photos, reviews, and messages;
- prevent fraud, abuse, unauthorized access, duplicate fulfillment, and operational errors;
- maintain audit/accounting records and respond to legal process; and
- understand and improve the website when optional analytics consent is given.
We do not use the Service to send behavioral advertising or sell personal information for money.
4. When information is visible to other users
- Students and public visitors can see approved Teacher identity, headline, biography, photo, Classes, class descriptions, availability, ratings/reviews, and booking status such as whether the Teacher is accepting bookings. A confirmed Student can access the Teacher's current meeting link from the dashboard.
- Teachers can see the booked Student's name, school, academic level, graduation year, Class, Session information, and messages/proposals needed to teach the Student. Teachers do not receive a Student's email address or phone number through the Service.
- Message participants see the content and author labels in their shared thread.
- Review readers see the review text, stars, Class tags, and a privacy-minimized Student label rather than the Student's full account identity.
- Parents/Guardians receive the minor-account notice and separate copies of purchase receipts sent to the email recorded on the Student account.
- Admins see information according to their role and permissions for support, safety, moderation, user management, bookings, Hours, finance, and payouts.
5. Service providers and disclosures
We disclose information to providers only for the relevant operational purpose. The implemented/provider-configured categories include:
| Provider/category | Current tutoring-service purpose | Typical information |
|---|---|---|
| Vercel | Hosting, serverless execution, edge/network delivery, and production photo storage through Vercel Blob | Requests, logs, application data in transit, uploaded Teacher photos |
| Neon/PostgreSQL | Application database | Account, profile, booking, Hours, message, notification, finance, and audit records |
| Stripe | Hosted checkout, card-payment confirmation, fees, receipts, fraud/dispute administration | Email/account reference, purchase description, amount, checkout metadata, payment/dispute records |
| Resend | Transactional email delivery | Recipient email, subject/body, attachments such as calendar invitations, delivery state |
| Twilio | Teacher phone verification and optional SMS alerts | Teacher phone, message body, consent/opt-out/delivery state |
| Optional sign-in; school/public-review Places requests; optional Analytics; payout-address validation when enabled | Data needed for the feature, such as OAuth identity, search text, website usage after consent, or Teacher address | |
| Microsoft Clarity | Optional website analytics, heatmaps, and session replay after consent | Website interactions with masking configured |
| Sentry | Application error monitoring | Error/stack/technical context; default PII sending and Sentry replay are disabled in code |
| Upstash | Shared rate limiting when configured | Pseudonymous rate-limit keys and request counts/expiry |
| Veem | Off-platform Teacher payout administration | Teacher payout identity/contact and transfer information supplied outside or exported from the Service |
| Zoom / Google Meet | Third-party Session meeting selected by the Teacher | Information users provide to or expose to that meeting provider when joining |
We may also disclose information:
- to comply with applicable law, legal process, or enforceable government request;
- to prevent fraud, protect safety/security, or enforce applicable agreements;
- in a merger, financing, acquisition, reorganization, bankruptcy, or asset transfer, subject to applicable notice requirements; or
- with your direction or consent.
6. Retention and account deletion
The current application does not implement the fixed category-by-category retention schedule that appeared in an earlier draft. Account, booking, Hours, payment, payout, review, message, email/SMS event, and audit records generally remain in the database unless an authorized deletion/anonymization operation or manual operations process changes them. Provider-held information follows the provider configuration and applicable contract.
There is no self-serve account-deletion button. A User or Parent/Guardian requests deletion through hello@haddee.com, and an authorized Admin performs the operation.
Under the implementation reviewed July 17, 2026, deletion uses a short-lived, signed preparation receipt bound to the target User, preparing Admin, Admin role, and checks performed. Preparation cancels future confirmed Sessions and returns the corresponding Hours. Final deletion locks and rechecks the User and refuses to continue if a new future Session exists, a Student still has unspent Hours, a Teacher has unsettled earnings, the receipt is stale, or required external attestations are absent.
When those gates pass, the deletion operation:
- disables sign-in and deletes active sessions, Google/OAuth links, and email/phone verification rows;
- clears the account name, email, password hash, image reference, guardian details, stored minor fields, contact destinations, and Teacher profile/schedule/meeting/payout configuration;
- deletes the Student profile, Teacher availability and date overrides, and non-required queued communication payloads; and
- retains booking, purchase, Hours, payout, review, message, selected delivered-notification, and audit records tied to an internal user id where needed for the current operational record.
Teacher profile-photo deletion runs after the database commit. A provider failure creates a durable pending-cleanup audit record and returns an operations warning so the deletion can be retried rather than silently abandoned.
Those retained records are not necessarily fully de-identified. Free-text messages, reviews, retained notification content, or audit details can contain or reveal personal information. Haddee retains them only while reasonably needed for the criteria below and handles unusual required free-text redaction manually; the MVP does not use an automatic message scrubber or fixed 60-day deletion timer. A Student deletion fails closed while any unspent balance remains. An Admin must resolve and document the balance first rather than silently forfeiting or stranding value.
A delayed or replayed Stripe event cannot grant new Hours to a deleted/non-Student
account. The Service records and alerts the exception for operator handling through
Stripe and hello@haddee.com.
We may retain information where reasonably necessary and permitted by law for accounting/tax obligations, fraud/security, legal claims, dispute handling, and enforcing agreements. Retention is based on those purposes rather than one universal fixed period, with periodic reassessment and normal backup/provider expiry.
7. Children's and teen privacy
The Service is intended for Students age 13 and older.
Under 13
Credentials signup validates age on the server and rejects an under-13 registration before creating an account. Google sign-in creates a provisional Student account before the onboarding age step; if the Student reports an age under 13, the Service atomically clears the provisional identity, deletes Google/OAuth, session, verification, and empty-profile records, stamps the account deleted, and blocks access. The client signs out only after that transaction commits. If the purge fails, the Student remains on a terminal retry-only screen and cannot continue into the Service.
If we learn that personal information from a child under 13 remains in the Service, contact hello@haddee.com so we can investigate and delete it as appropriate. The FTC's COPPA rules may impose additional obligations depending on the Service's audience and actual knowledge; counsel must approve this analysis.
Ages 13–17
For a Student age 13–17, the Service stores the minimized birth month/year and Parent/Guardian contact described in Section 1.3. The Parent/Guardian notice is informational and does not record acceptance or create a guardian account. The Student's account automatically stops being treated as a minor after the stored month/year indicates age 18 under the application's month-based rule.
A Parent/Guardian may contact hello@haddee.com to ask about, review, correct, close, or request deletion of the minor's account, subject to verification and applicable law.
8. Cookies, browser storage, analytics, and error monitoring
Essential processing
The Service uses essential cookies for authentication/security and local browser storage for the analytics-consent choice. Disabling essential cookies may prevent sign-in.
Optional analytics
The cookie banner offers Decline and Accept. Until Accept is selected, configured Google Analytics and Microsoft Clarity scripts do not load. When enabled:
- Google Analytics is configured in code with IP anonymization on and Google Signals, ad storage, ad user data, and ad personalization off; and
- Microsoft Clarity provides interaction analytics, heatmaps, and website session replay, with strict masking configured operationally.
These tools observe the website, not the third-party Zoom/Google Meet tutoring Session. Haddee does not use them to record tutoring Sessions.
The current product does not expose a persistent footer preference manager. To change a prior choice, you can clear this Site's browser storage/cookies or contact us.
The Service does not currently interpret a browser Do Not Track or Global Privacy Control signal as a substitute for its own analytics choice. Counsel must confirm whether additional signal handling is required.
Error monitoring
Sentry may run as an operational/error-monitoring service independently of the optional analytics choice when a Sentry DSN is configured. The code disables Sentry's default PII sending and Sentry session replay and defaults tracing to errors-only, but an error event may still include technical context such as the page, stack trace, browser/runtime details, and information placed in an error by the application. We do not intentionally send form contents, passwords, payment card data, or tutoring-session content to Sentry.
9. Email and SMS choices
The Service sends necessary account and transaction email, including verification, security/account notices, booking confirmations/cancellations, purchase receipts, Hours returns/adjustments, and payout notices. Some non-essential email categories can be changed in notification settings; required transaction/account email cannot always be disabled.
Teachers may optionally verify a phone and separately opt in to SMS. At opt-in, the Service records its canonical consent disclosure and timestamp and enables the standard booking/cancellation/request categories; payout SMS remains off until selected. Teacher notification settings and Teacher onboarding display that same canonical disclosure. A failed consent write is surfaced for retry and is not treated as a successful opt-in. Teachers can pause SMS in the app. Replying STOP creates a carrier-level block; only replying START to the Haddee number lifts that block. Reply HELP for help. See the separate SMS Terms.
Students are never sent SMS by the current Service.
10. Security
The Service uses safeguards represented in the reviewed code and deployment docs, including TLS in production, hashed passwords, secure/HTTP-only/SameSite session cookies, server-side validation/authorization, rate limiting, provider-webhook signature checks, audit records for sensitive Admin actions, and restricted file serving routes. Card data is handled by Stripe-hosted checkout, and tax identifiers are handled off-platform.
No system is completely secure. Contact hello@haddee.com promptly if you believe an account or information has been compromised.
11. Privacy requests
You may ask to access, correct, or delete personal information, or ask a question about its use, by emailing hello@haddee.com with the subject “Privacy Request.” We may need to verify identity and authority before acting, especially for a request about a minor or another person. Some information can be corrected in account settings; deletion is currently processed manually as described in Section 6.
Depending on where you live and which privacy law applies to Haddee, you may have additional rights such as data portability, objection/restriction, withdrawal of consent, appeal, or complaint to a regulator. Haddee will honor applicable rights and exceptions after appropriate verification.
12. California notice
To the extent the California Consumer Privacy Act, as amended (CCPA), applies to Haddee, California residents may have rights to know/access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discriminatory treatment. Requests can be sent to hello@haddee.com.
In the preceding 12 months, the tutoring Service may have collected the categories described in Section 1: identifiers; customer/account records; commercial and transaction information; internet/network activity; approximate geolocation; education/professional profile information; uploaded Teacher visual information; communications/user content; and sensitive information such as account credentials, minor status/guardian data, and Teacher payout details.
Haddee does not sell personal information for money and does not use the Service for cross-context behavioral advertising. The current Site does not have a “Do Not Sell or Share” footer link because the implemented product does not offer such advertising. Optional analytics can be declined as described in Section 8.
California residents under 18 may request removal of content they posted by contacting hello@haddee.com, subject to applicable exceptions. Removal may not remove copies that another person independently retained or that we must keep by law.
13. International users
The tutoring Service is operated from the United States and is currently designed primarily for U.S. use. Information is processed and stored in the United States and through the providers described in Section 5. If you use the Service from another country, your information may be transferred to a country with different privacy laws.
This draft does not claim that Haddee has appointed EU/UK/China representatives, executed every international-transfer mechanism, or implemented a country-specific minor-consent flow. Do not publish broader international compliance claims until counsel confirms launch markets and the required operational measures.
14. Changes to this Policy
When this Policy becomes effective, we may update it to reflect legal, provider, or product changes. We will post the new effective date and provide additional notice or obtain consent where required. A material change must also be considered under the Service's planned legal-document versioning and re-acceptance process.
15. Contact
- Haddee Education, LLC, Attn: Privacy
- 2006 Kala Bagai Way SPC10, Berkeley, CA 94704
- hello@haddee.com
- 858-449-9689
© 2026 Haddee Education, LLC.
