Privacy Policy
How we handle personal data — in plain English, the UK way.
Last updated: 18 July 2026
LessonLoop (“we”) provides music-school management software. This policy explains what personal data we process, why, and the rights you have under UK GDPR and the Data Protection Act 2018. We are the data controller for our own account and website data, and a data processor for the pupil, guardian and lesson data a studio stores in LessonLoop.
What we collect
- Account data — names, email addresses and roles of studio staff.
- Studio data — pupils, guardians, lessons, attendance, invoices and messages a studio enters or generates.
- Payment data — handled by Stripe; we store references, never full card numbers.
- Usage & device data — privacy-light analytics to improve the product.
How we use it
To provide and secure the service, process payments, send the messages a studio chooses to send, provide support, and meet legal obligations. We do not sell personal data.
Sub-processors
We use a small set of trusted providers to run LessonLoop. Each is bound by a data-processing agreement:
- Supabase — application database, authentication and storage (EU region).
- Cloudflare — website hosting, CDN and security.
- Netlify — application hosting.
- Stripe — payment processing.
- Resend — transactional and studio email delivery.
- Anthropic — provides the large-language-model that powers LoopAssist, our in-app assistant. Prompts necessary to answer a request are processed transiently and are not used to train models.
- 360dialog / Meta — WhatsApp delivery, only where a studio enables it.
Google user data (Google Calendar integration)
Teachers can optionally connect their Google Calendar to LessonLoop. This section explains exactly how we handle Google user data, in line with the Google API Services User Data Policy, including the Limited Use requirements.
- What we access. With your explicit consent via Google's OAuth screen, LessonLoop requests two scopes: calendar.events (create, update and remove the lesson events LessonLoop places in your calendar) and calendar.readonly (list your calendars and read event times and availability so your busy times can block online bookings). We access nothing else in your Google account.
- How we use it. Two user-facing features only: (1) your LessonLoop lessons appear in your Google Calendar and stay in sync; (2) events in your Google calendars mark you as busy in LessonLoop so families cannot book over them. Event titles from secondary or third-party calendars are never stored — we keep the times only, recorded simply as “Busy”.
- Who we share it with. No one. Google user data is never sold, never transferred to advertisers, data brokers or any other third party, and never used for advertising. It is stored only on our infrastructure sub-processor (Supabase, EU region) as required to provide the features above. Google user data is not sent to Anthropic or any other AI provider, and is never used to develop, improve or train AI/ML models. The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
- How it is protected. OAuth tokens are stored encrypted at rest in a dedicated secrets vault, all traffic is TLS-encrypted, and row-level security isolates every studio's data.
- Retention & deletion. Stored busy times are replaced on every sync. Disconnecting Google Calendar (Settings → Calendar, one click) immediately deletes your stored tokens and all Google-derived data from LessonLoop; deleting your account does the same. You can also revoke LessonLoop's access at any time at myaccount.google.com/permissions.
Your rights
You have the right to access, correct, export or erase your personal data, to restrict or object to processing, and to lodge a complaint with the ICO. Studio data deletion requests are actioned through the studio that controls the data. To exercise any right, email privacy@lessonloop.net.
Retention & security
We keep personal data only as long as needed to provide the service or meet legal obligations, and delete or anonymise it thereafter. Data is encrypted in transit and at rest, with row-level security isolating every studio’s data.
Contact
LessonLoop, United Kingdom — privacy@lessonloop.net.