This Privacy Policy explains how Kapseller LLC collects, uses, stores, shares, and protects personal data when you use our websites, products, and digital platform services.
1. Company information
Kapseller LLC
2. What we collect
Depending on how you use our websites and products, we may collect:
- account information, such as name, email address, password authentication data, role, and account type;
- profile information, such as educator or institution profile details;
- listing information, such as titles, descriptions, categories, subjects, availability, service-area or listing-address fields you provide, prices, program details, and images;
- verification information, where applicable, such as identity, professional, institutional, or qualification documents submitted for review;
- communication and support information, such as messages, requests, feedback, and support tickets;
- billing and subscription information, such as product purchased, subscription status, billing country, transaction identifiers, and tax-related information;
- technical information, such as IP address, device information, browser type, language preference, pages viewed, session information, cookies, and similar technologies;
- analytics information, such as page views, traffic source, language changes, product usage events, and aggregated performance metrics.
3. How we use personal data
We may use personal data to:
- create and manage user accounts;
- provide, operate, secure, and improve our websites and products;
- display and manage profiles, listings, categories, availability, and discovery features;
- review listings and user-submitted content;
- perform verification checks where applicable;
- process subscriptions, billing, renewals, cancellations, tax information, and payment-related records;
- provide customer support;
- detect fraud, abuse, spam, technical issues, or security risks;
- comply with legal, regulatory, tax, accounting, court, law enforcement, and payment provider requirements;
- send service notices, account updates, policy updates, and operational messages;
- send marketing communications where permitted by law or where consent has been provided;
- analyze usage, product performance, traffic, and feature adoption.
4. Payments
For web purchases, payments may be processed by Paddle, our authorized reseller and Merchant of Record.
Paddle may collect and process payment, tax, billing, fraud prevention, and transaction information to complete purchases, manage subscriptions, calculate and collect applicable taxes, issue compliant invoices, and provide buyer support. Paddle states that as Merchant of Record and reseller it handles tax calculation, collection, remittance, and compliant invoices for supported transactions.
Kapseller does not receive or store full card numbers. Card data is handled by the payment channel used — Paddle for web purchases, the Apple App Store on iOS, or Google Play Billing on Android — each of which processes payment information under its own privacy terms.
Mobile app purchases, where available, may be processed by Apple App Store or Google Play depending on the platform used.
5. Legal bases
Where applicable data protection law requires a legal basis, we may process personal data based on:
- performance of a contract;
- legitimate interests, such as operating, securing, improving, and preventing abuse of our products;
- consent, such as for certain cookies, marketing communications, or optional features;
- compliance with legal obligations;
- establishment, exercise, or defense of legal claims.
6. Verification documents
Where verification features are offered, users may submit documents or information for review.
Verification documents are used only for verification, compliance, fraud prevention, safety, and platform integrity purposes.
Sensitive verification documents are not intended to be shown publicly. Public profiles may show verification status or limited non-sensitive verification indicators where the product supports this.
7. Cookies and analytics
We may use cookies and similar technologies to operate our websites, remember preferences, improve performance, measure traffic, understand usage, and protect against abuse.
On the website we use consent-gated analytics and advertising pixels — currently Vercel Web Analytics, the Meta Pixel, TikTok Pixel, and the LinkedIn Insight Tag. These are loaded only after you accept the relevant categories in the cookie consent banner and can be withdrawn at any time from the Cookie Preferences opener in the footer. The current inventory of cookies and third-party tags, and their retention, is listed in the Cookie Policy.
Where required, we will request consent for non-essential cookies or tracking technologies.
8. Service providers
We may share personal data with trusted service providers that help us operate our business and products, including providers for:
- hosting and infrastructure;
- database and storage;
- security and content delivery;
- analytics;
- payment and subscription processing;
- email and communications;
- customer support;
- verification and compliance;
- professional services, such as legal, tax, and accounting support.
9. Examples of providers
Examples of providers may include Paddle, Cloudflare, Vercel, Turso, Google Analytics, email service providers, and other infrastructure or operational vendors.
Service providers are only allowed to process personal data as needed to provide services to us, subject to applicable contractual, security, and confidentiality obligations.
10. Legal and safety disclosures
We may disclose personal data where we reasonably believe it is necessary to:
- comply with applicable law, regulation, legal process, court order, or lawful government request;
- respond to law enforcement, judicial, regulatory, or tax authority requests;
- enforce our Terms of Service;
- investigate fraud, abuse, security issues, or policy violations;
- protect the rights, safety, property, or integrity of users, Kapseller, or the public.
11. International transfers
Kapseller LLC is based in the United States, and our service providers may operate in multiple countries.
When personal data is transferred internationally we rely, where they apply, on transfer mechanisms accepted under applicable data protection law, including the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, applicable adequacy decisions, and the EU–US and UK–US Data Privacy Frameworks in respect of vendors that self-certify. Where a specific mechanism does not apply, we rely on other lawful bases available under the relevant law.
12. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention periods may vary depending on the type of data and the reason for processing. In general:
- account data is kept while the account remains active;
- billing, tax, transaction, legal, and accounting records may be kept for up to 5 years or longer where required by law;
- support and communication records may be kept as needed for customer service, disputes, compliance, and quality control;
- verification records may be kept as needed for fraud prevention, compliance, safety, and platform integrity;
- analytics data may be aggregated or anonymized and retained for product improvement.
13. Your rights
Depending on your location and applicable law, you may have rights to:
- access your personal data;
- correct inaccurate data;
- request deletion;
- object to certain processing;
- restrict processing;
- request data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with a data protection authority.
14. Children
Our products are not intended for children below the age of digital consent in their country.
In the European Economic Area this age is 16 unless the member state has set it lower (as permitted, down to 13); in the United States it is 13; in Türkiye educator and institution accounts require the account holder to be at least 18.
Anyone below the applicable age must use our products only with the verifiable consent of a parent or legal guardian.
15. Security
We use reasonable technical and organizational measures to protect personal data.
However, no system can be guaranteed to be completely secure. You are responsible for keeping your account credentials confidential.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
The updated version will be posted on this page with a new “Last updated” date.
17. Mobile-App Data Processing
The Tutoryum mobile application (iOS and Android) collects a narrower set of personal data than the website. Where the two overlap, both this section and the general disclosures above apply.
Location. When you use discovery features that show educators near you, the app may request your device location. Location access is requested only in the foreground (while the app is open) and only when you initiate a nearby-discovery action; it is never collected in the background. The precise coordinates read by your device are used on-device to centre the map view; only an approximate viewport (a bounding box roughly 1–5 km wide) is transmitted to Tutoryum servers to look up listings within that region. If you decline location access, the app falls back to a manual city / district selection and continues to work.
Push notification token. The app relies on Google Firebase Cloud Messaging (FCM) to deliver push notifications on both Android and iOS. When notifications are enabled, the FCM device token issued by Google is stored on Tutoryum servers and used only to route notifications to your device. The token is not used for advertising, analytics, or cross-device tracking. Tutoryum does not collect the mobile advertising identifier (IDFA or AAID).
Diagnostics and analytics. The mobile application does not integrate any third-party analytics or crash-reporting SDK. It does not send screen-view telemetry or automatic crash reports to any external service.
Profile, listing and appointment data. Content you create in the app — profile fields, listings, availability and appointment records — is transmitted to Tutoryum servers over TLS and stored under your account, as described in the general sections above.
Documents uploaded from the app. Identity documents, professional certificates and other verification files uploaded from the app are transmitted over TLS to the same verification pipeline described in Section 19.
Messages between users. Direct messages are transmitted over TLS (websocket for real-time delivery, HTTPS for history retrieval) and stored on Tutoryum servers so that both participants can access their conversation history. End-to-end encryption is not implemented; server operators can technically access message content when required by law, court order or a safety investigation.
Purchase history. When you subscribe through the App Store or Google Play, the store issues a receipt or purchase token. That token is transmitted to Tutoryum servers so we can confirm the entitlement associated with your account. Tutoryum does not receive card data through these channels.
Third-party components active on the mobile client. Google Firebase Cloud Messaging (push), the Google Maps SDK (map rendering and tile requests, which necessarily expose the device IP address to Google), Google Fonts (typography, which exposes device IP to Google), and the Apple App Store or Google Play Billing SDK for in-app purchases. These are the only third-party components active on the mobile client.
18. Third-Party Service Provider Inventory
We share personal data with the service providers listed below. Their legal role varies and is identified on each row: processors act on our documented instructions under GDPR Article 28 / KVKK Madde 12 arrangements; joint controllers (advertising pixels) act under joint-controller arrangements of the kind recognised by the Court of Justice of the EU in C-40/17 (Fashion ID); independent controllers (Apple and Google, for in-app purchase data) process purchase data under their own privacy terms and not on our instructions.
- Paddle.com Market Ltd (Ireland; group entities in the UK and US) — Merchant-of-Record for web subscriptions and independent controller for the payment, billing, tax and fraud-prevention data it collects to satisfy its own regulatory obligations; also acts as our processor for the invoice and entitlement data it hands back to us.
- Apple Inc. (United States) — independent controller for in-app purchase and subscription data collected through the App Store on iOS; we receive only the entitlement information we need to unlock features.
- Google LLC (United States) — mixed role: independent controller for in-app purchase and subscription data collected through Google Play Billing on Android; processor for Firebase Cloud Messaging (device tokens for push), Google Maps SDK map tiles (device IP exposed to Google), and Google Fonts (device IP exposed to Google) on our behalf.
- Vercel Inc. (United States) — processor: web hosting, edge delivery, and Vercel Web Analytics (consent-gated).
- Cloudflare, Inc. (United States) — processor: content delivery, security, and DDoS protection.
- Turso Corporation (United States) — processor: database hosting for account and operational data.
- Resend, Inc. (United States) — processor: transactional email delivery (waitlist confirmations, subscription notices, verification emails).
- Frankfurter.app (Germany; European Central Bank reference-rate mirror) — no personal data is transmitted in the request body; as with any HTTPS request, standard connection metadata (device IP address, User-Agent) reaches the origin server.
- Meta Platforms Ireland Limited (Ireland) — joint controller for the Meta Pixel on the website (consent-gated); not active without your consent.
- TikTok Technology Limited (Ireland) — joint controller for the TikTok Pixel on the website (consent-gated); not active without your consent.
- LinkedIn Ireland Unlimited Company (Ireland) — joint controller for the LinkedIn Insight Tag on the website (consent-gated); not active without your consent.
19. Verification Documents and Identity Data
Where our products offer identity verification for educators or institutions, you may be asked to submit documents such as identity cards, passports, diplomas, professional certificates, or institution licenses.
Purpose. Verification data is used only for identity verification, fraud prevention, credential authenticity signalling and compliance with legal or platform-integrity obligations. It is not used for advertising or profiling.
Legal basis and consent. Where processing of any part of this data is treated as special-category / özel nitelikli personal data under KVKK Article 6 or GDPR Article 9 in the jurisdiction that applies to you, explicit consent will be requested at the point of collection in the product before that specific processing takes place. Where such treatment does not apply, we rely on the legal bases listed in Section 5.
Presentation. Identity documents themselves are never shown on your public profile. Where the product supports a “verified” badge or similar non-sensitive indicator, only the indicator is displayed. Certificates and diplomas may be shown on your profile after any personal-information redaction that is available in the product.
Retention. Verification documents are kept for as long as your account remains active and for any further period necessary to comply with legal, tax, audit and fraud-prevention obligations.
20. Data Subject Rights Operations
How to exercise the rights listed in Section 13. Send a written request to the contact address listed below from the email address associated with your account. We will acknowledge receipt within a reasonable time and respond in full generally within one month of receipt. Under GDPR Article 12(3) we may extend the response period by up to two further months for complex or numerous requests. Under KVKK Madde 13, requests received from Türkiye are answered within thirty days and no statutory extension mechanism applies. Where necessary to protect you against impersonation, we may ask for information that lets us confirm you are the account holder before we act on the request. Requests for portable data are provided in a structured, commonly used, machine-readable format (typically JSON).
Right to complain. You always have the right to lodge a complaint with your local supervisory authority — in Türkiye the Kişisel Verileri Koruma Kurumu (KVKK), whose complaints are decided by its Board (Kişisel Verileri Koruma Kurulu / KVK Kurulu); in the European Economic Area your national data protection authority; in the United Kingdom the Information Commissioner's Office.
21. How to Delete Your Account
You can delete your Tutoryum account at any time.
In the mobile app. Open the app and go to Settings → Account → Delete Account. The flow requires you to re-enter your password and confirm.
By email. Send a written request to the contact address listed below from the email address associated with the account you want to delete.
Public request page. A copy of these instructions and a public-facing account-deletion page is available at kapseller.com/en/account-deletion.
What happens after deletion. Your account, profile, listings, uploaded documents, appointment records and message history are removed from live systems. Certain data may be retained in server backups for a limited period and in accounting, tax, audit and legal-defence records for as long as applicable law requires (see Section 12 Retention). Anonymised or aggregated data that no longer identifies you may be kept for statistical purposes.
22. Security Incident Notification
If a personal data breach occurs that affects personal data we process, we will notify the competent supervisory authority and affected individuals where and within the periods required by applicable data protection law, including GDPR Articles 33 and 34 and Turkish KVKK Madde 12 where they apply.
Suspected security issues can be reported to the contact address listed below with the subject line “security incident”.
23. Contact
For privacy questions or requests, contact:
Kapseller LLC