Skip to content
LearnStatisticspowered by UpThink

Privacy

Privacy notice

What we hold about you, why we hold it, who else it reaches, and how to get it back or get rid of it.

In force from [effective date] · applies to [registered legal entity name], trading as UpThink and as LearnStatistics.

1. Who is responsible for your data

[registered legal entity name], trading as UpThink and as LearnStatistics, of [registered address], decides what is collected here and why. Questions, requests and complaints go to [privacy contact address], or through our contact page.

Whether a data protection officer or an EU/UK representative is required and appointed — [TO BE CONFIRMED]

2. What we store, and why

This is the complete list of what our own database holds about a student. Each item is one table.

  • Your account. Your name and the email address you sign in to Canvas with. If that address was issued by one of our partner universities, we record it and which university it belongs to, because that is how their students are recognised here and what credit is filed against — there is no separate field to fill in, and most students belong to no partner at all. A university student id is stored only if one is given to us. We also keep the id Canvas knows you by, so a returning buyer does not become a second account.
  • Your registrations. Which dated run you bought, when, and the name and email as they stood on your account at the time — a receipt has to keep matching what you saw. Plus the state of the place: held, paid, enrolled.
  • Your payments. The amount, the currency, the status, and the identifiers Stripe gives the transaction. We never see or store card numbers, expiry dates or security codes. Those are typed on Stripe’s own pages and never reach us.
  • What a programme purchase granted you. Which courses you own but have not yet scheduled, and which start date each was eventually spent on.
  • Records of completion. When you finish a run, we record the grade and score as they stood on the day, the credit hours claimed for that course at that time, the completion date, and whether it has been reported to a university and to which one. This is not a copy of your gradebook — it is a fixed record, because credit reporting is a compliance process that has to be able to show what was filed and when.
  • Waiting lists. If you ask to be told when a full or closed run reopens: your email, the run, and optionally your name.
  • Our administrators’ activity. Every sign-in, every change, and every view of a page that shows student details is logged with the administrator’s identity, the time, what was acted on and the IP address the request came from. This log deliberately never contains passwords, password hashes, session cookies, grades or scores — it records who touched a record, not what the record said.

There is no advertising, no profiling, no third-party analytics and no tracking pixel anywhere on this site.

We do keep one anonymous count, and it is worth being exact about because it is the only thing on this site written down about a visit rather than about a person. When somebody opens a page with a price on it, or leaves that page to sign in, we store a row saying which course or programme it was, whether anybody was signed in at the time, and the date. That is the whole row. It carries no name, no email address, no account reference, no session identifier and no IP address, so it cannot be tied back to you, to another row, or to a visit. It exists so we can tell how many people give up at the sign-in step, and it is used for nothing else.

3. Canvas, and what lives there instead

Teaching happens in Canvas, our learning management system. Canvas — not this store — holds your enrolment, your coursework, your submissions, your interactions with your instructor and your gradebook.

  • When you sign in here, you sign in through Canvas. We hold no password of yours. The access token from that sign-in is used once, to read your name and email, and is then thrown away; we do not store student access tokens, because a table of them would be a key to every student’s gradebook.
  • Your session on this site is a signed cookie holding an account reference and an expiry time. It contains no name, no email and no grade, and it lasts fourteen days. A second short-lived cookie exists only during the few minutes of a Canvas sign-in, to stop that sign-in being tampered with. These two are the only cookies this site sets, and both are strictly necessary.
  • Your progress and grades on your account page are read live from Canvas each time you look — not copied into our database, and not cached. The one exception is the completion record described above, which is written once when a run ends.

Canvas is operated by [who hosts Canvas, and where]. Its own privacy terms apply to what is stored in it.

4. Who else processes your data

  • Stripe takes the payment and holds the card details we never see. Stripe keeps its own record of the transaction.
  • Amazon SES sends transactional email — the message confirming your enrolment and giving your Canvas sign-in, the receipt for a programme, and the notice that a place has opened on a date you asked about. It receives your name, address and the course title.
  • Canvas holds the course itself, as described above.
  • Our hosting and database providers [hosting provider and region] and [database provider and region] — store the data at rest.

We do not sell personal data, and we do not share it with anyone for their own marketing.

Reporting to a partner university is the one place your data leaves us for a purpose other than delivering the course: for students whose account carries a university address, the completion record — course, grade, credit hours, completion date — is filed with that university so the credit can be applied to a degree. If your account carries no such address — which is the ordinary case — nothing is filed.

Whether data is transferred outside the US, and on what basis — [TO BE CONFIRMED]

5. Education records, FERPA and admin access

For students in the United States, coursework, grades and completion records may be education records within the meaning of FERPA, the Family Educational Rights and Privacy Act. The question that law eventually asks is not only who changed a record but who looked at it, so the store is built to answer it:

  • Administrator access is per person. There is no shared login and no shared password.
  • Every administrator page that displays student details records the view, not just the change. The log is append-only — nothing in the application updates or deletes a row in it, and there is no interface that offers to.
  • An administrator who leaves is disabled rather than deleted, so the record of what they did stays answerable.

How FERPA obligations are divided between us and a partner university for students on the partnership degree, and the formal procedure for a student to inspect or challenge a record — [TO BE CONFIRMED]

6. How long we keep it

  • Account, registration and payment records — [TO BE CONFIRMED], though financial records normally have to be kept for a statutory minimum.
  • Completion records — kept as the evidence of what was reported for credit. [TO BE CONFIRMEDhow long]
  • Waiting list entries — [TO BE CONFIRMED]
  • The administrator audit log — [TO BE CONFIRMED]

7. Your rights, and how to use them

Write to [privacy contact address] from the address on your account, or through the contact page, and say what you want. We will ask you to confirm it is you before we act on anything.

  • See it. A copy of what we hold. Your own account page already shows most of it.
  • Correct it. A wrong name or address, in particular — we never overwrite your details from Canvas automatically, so a change you make there does not reach us.
  • Delete it. See below: this one is not a single switch.
  • Which statutory rights we offer, and to whom — GDPR, UK GDPR, CCPA/CPRA and the rest apply differently by residence — [TO BE CONFIRMED]
  • The regulator you may complain to, and how — [TO BE CONFIRMED]

8. What deletion actually involves

Your data is not in one place, so an honest deletion request touches four systems and each has to be done separately:

  • Our database — the account, registrations, entitlements, waiting-list entries and completion records described in section 2.
  • Canvas — the account, the enrolments, the submitted work and the grades. Deleting here does not delete there; it is a separate system with its own record of you.
  • Stripe — the payment record. Stripe retains transaction data to meet financial regulation, so this one usually cannot be erased in full for as long as that obligation runs.
  • Amazon SES, our mail provider — delivery logs of the messages sent to you.

Two things we cannot simply erase:

  • A completion already reported to a university. It is part of your academic record at that university, and asking us to forget it does not remove it from them.
  • The administrator audit log. It exists precisely so that access to student records can be reconstructed, and editing it would defeat the protection it provides. It holds identifiers and actions, never the content of a record.

Turnaround for a deletion request, and what is kept afterwards — [TO BE CONFIRMED]

9. How it is protected

  • Administrator sessions expire after eight hours, and repeated failed sign-ins lock further attempts.
  • Sign-in cookies are signed, are not readable by scripts in your browser, and carry no personal data.
  • Administrator passwords are stored only as salted, computationally expensive hashes. Student passwords are not stored at all — Canvas owns that credential.
  • No system is perfectly secure. Our breach notification process — [TO BE CONFIRMED]

10. Children

These are university-level courses intended for adults. The minimum age we accept, and how it is checked — [TO BE CONFIRMED]

11. Changes to this notice

When this notice changes materially we will change the date at the top of the page, and tell registered students where the change affects them.