Legal
Privacy Policy
How we collect, use, and protect your personal data.
Draft — not yet in effect
This policy is being finalised and is not yet legally binding. A complete version will be published before any paid services go live.
Last updated: 22 June 2026
This policy explains what personal data Retail Academy collects, why we collect it, who we share it with, and the rights you have over your data. It applies to our website at retailacademy.biz and the Retail Academy learning platform (the "Service"). We work mainly with retail organisations that deploy training to their teams, and with individuals who sign up directly.
We've tried to keep this readable. If anything is unclear, email us at connect@retailacademy.biz and we'll explain.
1. Who we are
Retail Academy is a learning platform for retail professionals. The data controller responsible for your personal data is:
[Legal Entity Name]
[Registered Address]
[EU Country]
Email: connect@retailacademy.biz
For any privacy question or request, contact us at connect@retailacademy.biz.
2. Who this policy covers
We serve two groups:
- Companies and their teams (B2B) — organisations that buy seats and assign courses to their staff. Section 11 covers how data flows in these arrangements.
- Individual learners (B2C) who sign up directly.
If your employer enrolled you, see section 11 for how that affects your data.
3. What data we collect
Account and profile. Your name, email address, password (stored encrypted, never in plain text), and your role on the platform. If you add profile details, we store those too.
Company membership (B2B). If you belong to a company account, we store your membership and your role within that organisation, and we link your progress to that organisation so your administrator can see it.
Learning activity. The courses you enrol in, your progress through lessons, quiz attempts and scores, certificates you earn, and any notes or bookmarks you create.
Payment data. When we take payments, they're processed by Stripe. We don't store your full card number on our servers. We keep a record that a payment happened and basic billing details. (Payments are being rolled out, so this applies once that's live.)
Communications. Emails we send you (such as sign-in links, course updates, and certificates) and any messages you send us, including pilot or team enquiry forms.
Technical and usage data. Basic information your browser sends automatically, such as IP address, device and browser type, and pages you visit. We use this to run the Service securely and to fix problems.
4. Why we use your data, and our legal basis
Under the GDPR we need a lawful basis for each use. Here's ours.
- To provide the Service (create your account, deliver courses, track progress, issue certificates): performance of our contract with you.
- To process payments and prevent fraud: performance of our contract, and our legitimate interest in protecting the business.
- To send service emails (sign-in, account, course, and certificate notifications): performance of our contract.
- To support B2B accounts (let your company administrator manage seats and see assigned-course progress): performance of our contract with the company, and legitimate interest.
- To keep the Service secure and working: our legitimate interest in a safe, reliable platform.
- To send marketing (if and when we do): your consent, which you can withdraw at any time.
5. Cookies and similar technologies
Right now we only use essential cookies. These keep you signed in and keep the Service secure. They're required for the platform to work, so they don't need consent.
In the future we plan to use web analytics (to understand how people use the site) and marketing or advertising cookies (to measure and run campaigns). We won't set those until we've updated this policy and, where the law requires it, asked for your consent through a cookie banner. You'll be able to accept or reject non-essential cookies and change your choice later.
6. Who we share your data with
We don't sell your personal data. We share it only with service providers who help us run the platform, and only as far as they need it. Each one acts as our processor under a data processing agreement.
- Supabase — database, authentication, and file storage.
- Stripe — payment processing (once payments are live).
- Resend — sending our emails.
- Vercel — website and application hosting.
- Cloudflare — DNS and network security.
- YouTube and Vimeo — video hosting. When a lesson video plays, these providers may set their own cookies. Their use of data is governed by their own privacy policies.
We may also share data if the law requires it, to protect our rights or users' safety, or as part of a business sale or reorganisation (in which case we'll tell you).
7. Where your data is stored and transferred
We aim to store data within the EU or European Economic Area. Some of our providers operate outside the EEA. When data is transferred outside the EEA, we rely on safeguards approved under the GDPR, such as the European Commission's Standard Contractual Clauses, so your data stays protected. You can ask us for details of these safeguards.
8. How long we keep your data
We keep your data for as long as your account is active. After that:
- Account and learning data: kept while your account exists, then deleted or anonymised within a reasonable period after you close it, unless we need to keep some of it for legal reasons.
- Certificates: we may keep a record so we can verify a certificate's authenticity.
- Payment and billing records: kept as long as tax and accounting law requires (commonly several years).
- Support and enquiry messages: kept only as long as we need them to handle your request and our records.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Correct data that's wrong or incomplete.
- Delete your data ("right to be forgotten"), where applicable.
- Restrict or object to how we use your data in certain cases.
- Port your data, receiving it in a portable format.
- Withdraw consent at any time, where we rely on consent (such as marketing).
To use any of these rights, email connect@retailacademy.biz. We'll respond within one month. Using your rights is free, and we won't treat you differently for exercising them.
10. Children
The Service is for working adults and isn't directed at children. We don't knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we'll delete it.
11. Company accounts (B2B)
Retail Academy works with retail organisations who buy seats and deploy training to their teams. If you're a company administrator, you can view the assigned-course activity of your members — completion status and progress on courses you've assigned. You're responsible for having a lawful basis to process this data and for informing your employees how you use it.
If you were enrolled by your employer, your company can see your activity on assigned courses — which you've completed and your progress. Your company decides what training to assign and is responsible for its own handling of your data. For how your employer uses your data, check their privacy notice. We still protect your data as described in this policy.
12. How we protect your data
We use encryption in transit, encrypted password storage, access controls, and row-level security so people can only see the data they're allowed to. No system is perfectly secure, but we work to keep your data safe and to fix problems quickly.
13. Changes to this policy
We'll update this policy as the Service grows, for example when we add payments, analytics, or marketing. When we make a significant change, we'll update the date at the top and, where appropriate, tell you by email or a notice on the site.
14. Complaints
If you have a concern, contact us first at connect@retailacademy.biz and we'll try to put it right. You also have the right to complain to your local data protection authority in the EU country where you live or work.