1. When this policy applies
Lesson Lineup is provided by Hyungjoon Kim, doing business as Lesson Lineup (“we”, “us”). This policy covers our website, the Lesson Lineup web app and our phone apps (together, “the service”), and the personal information of the teachers who hold accounts, of people who visit the website, and of anyone who writes to us.
Studio data
Teachers use the service to keep records about their own families and students. For that information the teacher decides what is collected and why: the teacher is the controller (in California terms, the business), and we are the processor (the service provider) that stores and handles it on the teacher’s instructions. If you are a parent or student and have a question about your information, please ask your teacher first; section 5 says more, and we will help your teacher answer.
2. Information we collect
Account information
Your name, email address and password when you sign up (the password is held by our sign-in provider and never seen by us), and what you enter about your studio: its name, address, phone number, logo, time zone, currency and settings.
Billing information
Your plan, trial and subscription dates, whether payments succeeded, and the identifiers Stripe gives your customer record and subscription. Card details go to Stripe, not to us (section 7).
Messages to us
What you send when you email us, and our replies.
Technical information
Like any online service, the systems we run on record technical details of requests — such as IP address, browser or device type, the time, and which account made the request — in logs we use to keep the service working and secure.
Analytics in the apps
If you choose “Accept analytics” in the web app, it also tells Google Analytics which screens you visit and when you take a few key steps, such as adding your first student or running a report. If you decline, or never answer, none of it is collected. Our phone apps send the same from the time you install them, unless you turn off Analytics in the app’s Business Settings. Neither ever sends names, email addresses, amounts or anything you type. Section 8 lists exactly what is sent. The website uses no analytics, and we use no advertising tools anywhere.
Marketing information
We do not currently send marketing email, and we do not buy or receive information about you from data brokers or advertisers.
3. How we use it
- to create and run your account, and to provide the features you use;
- to send the messages you ask the service to send, and to deliver them;
- to run your trial and subscription, and to tell you about your billing;
- to answer your questions and help when something goes wrong;
- to keep the service secure and prevent fraud and abuse, including the same person taking more than one free trial;
- to find and fix faults and to improve the service — including, where analytics is on (section 8), by counting which screens and features are used;
- to meet our legal obligations and enforce our terms.
We do not sell personal information, and we do not use it for advertising.
4. Legal bases
Where laws such as the EU or UK GDPR require a legal basis for using personal information, ours are:
- Contract — to provide the service you signed up for.
- Legitimate interests — to keep the service secure, prevent abuse, and fix and improve it, in ways you would reasonably expect.
- Consent — for analytics (section 8): in the web app, the answer you give our cookie banner; in our phone apps, installing the app after this policy has told you what it sends. You can withdraw it at any time, on the web with “Cookie settings” and in a phone app with the Analytics switch in Business Settings. And wherever else we ask for it.
- Legal obligation — where the law requires us to act.
For studio data the teacher, as controller, decides the legal basis.
5. Studio data we handle for teachers
Teachers enter the records they need to run their studio. Depending on what they use, that can include:
- family and contact names, email addresses, phone numbers and postal addresses;
- student names, birthdays, schools and other details a teacher chooses to note;
- lessons and events, attendance, make-up credits and lesson notes;
- practice logs and repertoire;
- charges, payments, invoices, packages and account balances;
- the teacher’s own expenses and income, and receipts they upload;
- the teacher’s mileage log: trips, destinations, vehicles and odometer readings;
- files a teacher uploads to their file library, such as sheet music or recordings;
- messages the service sends to families, and a record of their delivery.
Families and students do not have accounts and cannot sign in; there is no parent or student portal. We use studio data only to provide the service to the teacher, as the teacher directs. We do not use it for our own purposes, do not contact families about our own products, and do not sell or share it.
Requests from a family — to see, correct or delete their information, or to stop receiving messages — are for their teacher to decide. If one reaches us, we will pass it to the teacher and help them respond.
6. Companies that help us
We use a small number of companies to run the service. Each receives only what it needs for its part, and is bound to protect it.
- Google (Firebase and Google Cloud) — sign-in, the database, file storage, the servers that run our background work, report and receipt processing, and website hosting. All studio data is stored here.
- Stripe — the teacher’s subscription to Lesson Lineup: checkout, card payments, invoices and the billing portal.
- SendGrid (Twilio Inc.) — delivering the emails the service sends to teachers and, on teachers’ behalf, to families.
- Google Fonts — our pages load their typeface from Google, which receives your IP address and browser details when it serves it.
- Google Analytics (Google) — counting how the web app and the phone apps are used: on the web only for people who accept analytics, and in the phone apps unless it is turned off (section 8).
The service can send text messages through Twilio, but that is not switched on. We will update this policy before it is.
7. Payments
Teachers subscribe through Stripe’s hosted checkout and manage their subscription in Stripe’s billing portal. Stripe collects and stores the card details under its own privacy policy; we receive only what we need to know the state of your subscription, never the full card number.
Families never pay through us. When a teacher records a payment from a family, it is a note of money the teacher has already received, not a transaction we process.
8. Cookies and storage on your device
The website and the app share one cookie of their own, called
coda_consent. It records your answer to our cookie banner —
whether you accepted or declined analytics — and when you gave it, so that we
do not ask you again on every visit. It is set for lessonlineup.app and its
subdomains, so one answer covers both the website and the app at
app.lessonlineup.app, and it lasts 12 months, after which we ask again.
Because it only remembers your choice, it is strictly necessary and is set
whichever answer you give.
Analytics in the app
Analytics is optional and off unless you choose “Accept analytics”. Until then the app does not even download the analytics code. If you accept, the app uses Google Analytics for Firebase, provided by Google, and sends it:
- which screens you open, named by the kind of screen (for example “students” or “a student’s page”), never by whose page it is;
- when an account is created or deleted;
- when a studio adds its first student and schedules its first lesson or event;
- when attendance is taken, with only a yes or no for whether lesson notes were written and whether payment was taken at the lesson;
- when invoices are created, with how many families they were for;
- when a report is run, with which kind of report it was.
It never sends names, email addresses, amounts, notes or anything else you type, and we do not give Google your account’s identity. Google’s code also sends what any website analytics does: your browser and device type, screen size, language, and a random identifier for this browser. Google uses your IP address to estimate your country and city and does not store it. We have turned off Google signals and ad personalisation, so none of this is used for advertising. Google keeps the detailed records for 2 months.
To do this Google Analytics sets two cookies on lessonlineup.app,
_ga (the random identifier) and _ga_ followed by
a code (your visit), which last up to 12 months, and Firebase keeps an
installation identifier in your browser’s storage.
You can change your answer at any time with “Cookie settings” in the website’s footer or the app’s sidebar. Declining stops analytics straight away, and the app deletes those cookies and the installation identifier. What was already sent is not linked to your name or account, so we cannot find it as yours; Google deletes it when its 2 months are up.
Analytics in the phone apps
Our iPhone and Android apps send Google Analytics for Firebase the same things as the web app, from the list above: which screens you open, named by the kind of screen and never by whose page it is, and the same key steps with the same yes-or-no and count details. A phone app cannot create an account, so it never sends that one. The phone apps do not ask first: installing the app is your agreement to this, and this section is our notice of it.
You can turn it off at any time in the app, under Business Settings → Analytics. Turning it off stops collection on that phone straight away and resets the random identifier the analytics code keeps there. The setting belongs to the phone, not your account, so turn it off on each phone you use; it stays off until you turn it back on.
With those events, Google’s code sends what any app analytics does: the phone model, its operating system and our app’s version, the language, and a random identifier for this installation of the app. Google uses your IP address to estimate your country and city and does not store it. The phone apps never collect your phone’s advertising identifier (Apple’s IDFA or Android’s Advertising ID), and leave out the code that would; they do not collect the phone’s device or vendor identifier either, so the iPhone app never asks to track you. Advertising features are turned off, as on the web. Google keeps the detailed records for 2 months. Deleting the app removes the random identifier from the phone.
The app is built to work without a connection, so it keeps a copy of your studio’s records, and any changes not yet sent, in your browser’s storage (IndexedDB and local storage), and our sign-in provider keeps you signed in the same way. When you sign out, the app removes most of that copy and the rest is removed when someone next signs in on that browser. Changes you made offline that have not been sent yet are kept on the device until you sign in there again, so that they are not lost. On a shared computer, clear the site’s data in your browser settings once you are done.
Our phone apps keep a similar local copy, and a queue of unsent changes, in the app’s own storage on the phone. Deleting the app removes it. Deleting your account — on the website or in the app — also clears the copy on the device you delete it from.
9. Emails we send
To teachers we send only email about the account: address confirmation and password resets (sent by our sign-in provider), and notices about your subscription, such as the email before your price changes.
To families we send only what a teacher asks the service to send, or sets it up to send — invoices, payment receipts, lesson notes, cancellations and reminders. These go out in the teacher’s name and replies go to the teacher. If you are a family member and would like them to stop, please tell your teacher.
10. Where data is processed
We are based in the United States, and the service is hosted in the United States. If you use it from elsewhere, your information, and that of your families, is transferred to and processed in the United States, where data protection law may differ from yours. Where the law requires a safeguard for that transfer, we rely on our providers’ standard contractual clauses.
11. How long we keep it
- Your account and studio records — for as long as the account exists, including after a subscription ends, so that you can come back to them or ask for a copy. They are deleted when the account is.
- Files in your file library — while you have access, and for 60 days after your access ends; then they are deleted. A deleted file may still load from a copy saved in a network cache for up to an hour.
- Messages sent to families — the message itself for 90 days after it is sent or fails, and a delivery record (who it went to, when, and what happened) for 400 days.
- Records of Stripe’s notifications to us — 90 days.
- Codes for signing in to the phone app — they stop working after two minutes or one use.
- When you delete your account — you can do this yourself at any time, from Business Settings → Membership on the website or from Settings in the phone app. The account and everything in the studio are deleted: records, files and receipts. Most of it goes within minutes; a second pass about an hour later removes anything a device that was still signed in sent in the meantime. Any subscription is cancelled at once, no further payment is taken, and the card saved with Stripe is removed from your customer record. Stripe keeps its own records of past payments, as the law requires of it. We keep three things: a one-way scrambled (hashed) form of your email address with the dates of your trial, so that deleting an account cannot be used to get another free trial; for 30 days, a note that the account was deleted, holding nothing but the account’s internal identifier and dates, so that anything arriving for it afterwards is discarded rather than stored; and a billing record of the deletion, kept for one year and then deleted, so that a refund can still be issued after the account is gone. The billing record holds your email address, the identifiers Stripe gives your customer record and subscriptions, what each subscription cost and the period it covered, the amount and date of your latest invoice, and the date of each step of the deletion.
Our providers keep logs of requests for their own limited periods. We do not keep separate backup copies of studio data, so what you delete is gone once deletion finishes.
Deleting your Lesson Lineup account
You can delete your account, and with it your whole studio, yourself:
- In the phone app (iPhone or Android): open Business Settings, choose Delete Account, type DELETE and your password.
- On the website: sign in, open Business Settings → Membership, choose Delete Account, type DELETE and your password.
- If you cannot sign in, write to us from the address on the account (section 21) and we will delete it for you once we have confirmed it is yours.
What is deleted, what is kept and for how long is set out above, under “When you delete your account”.
12. Security
- Everything travels over encrypted connections, and our providers encrypt it where it is stored.
- Each studio’s data is walled off by access rules, so that only that teacher’s signed-in account can read or change it.
- Passwords are handled by our sign-in provider; we never see them.
- Phone sign-in codes work once, for two minutes, and we store only a scrambled form of them.
- Uploaded files and receipts are opened through long links that cannot be guessed, and each link stops working 30 days after the day it was made. Until then, anyone who has one of those links can open that file without signing in, so treat a link as you would the file itself. A link in an email is the same kind of link, made when the email is sent, and the email says how long it works.
No system is perfectly secure. If a breach affects your information, we will tell you as the law requires.
13. Your rights
Depending on where you live, you may have the right to ask us for access to your personal information, to correct it, to delete it, to receive a copy in a portable form, to restrict or object to how we use it, and to withdraw consent you have given. You can delete your account and your studio yourself at any time (section 11). To make any other request, write to us (section 21). We may need to confirm who you are first, and we will answer within the time the law sets. Some information we must keep, for example to meet legal obligations.
If you are a family member or student, your teacher controls your information; please contact them, and we will help them respond. You also have the right to complain to your local data protection authority.
14. California residents
What we collect and why. In the last 12 months we have collected identifiers (such as name, email and IP address), commercial information (your subscription and payment history), internet activity (technical logs and, where analytics is on, how the apps were used — section 8), and the studio records described in section 5, which we hold as a service provider for the teacher. We collect them from you, from your use of the service, and from Stripe, for the purposes in section 3, and we keep them for the periods in section 11.
No selling or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising: the analytics in section 8 has Google’s advertising features turned off. We do not use sensitive personal information for anything beyond providing the service.
Your rights. You can ask us to tell you what personal information we have collected about you and how we used and disclosed it, to delete it, and to correct it. You can make a request yourself or through an authorised agent, and we will not treat you differently for exercising these rights. Write to us (section 21); we will confirm who you are before acting.
15. Children
The service is for teachers, and account holders must be at least 18. Many of the students in a teacher’s records are children, but their information is entered by the teacher — children do not use the service and we do not knowingly collect information directly from any child. We use children’s information only to provide the service to their teacher, never for marketing or profiling. The teacher is responsible for having any consent from a parent or guardian that the law requires. If we learn that a child has opened an account, we will delete it.
16. Automated decisions
We do not make decisions about anyone based solely on automated processing that have legal or similarly significant effects.
17. If the business changes hands
If the service is sold, merged or transferred, personal information may pass to the new owner, who must keep protecting it as this policy describes. We will tell you before that happens.
18. Legal disclosures
We disclose information only where we believe it is required to comply with the law or a valid legal request, or necessary to protect the rights, safety or property of our customers, their families, the public or us.
19. Other websites
The service links to other sites and services, such as Stripe’s checkout. Their own privacy policies apply to them, and we are not responsible for how they handle information.
20. Changes to this policy
When we update this policy we change the date at the top. If a change is significant, we will tell account holders by email or in the service before it takes effect.
21. Contact us
For privacy questions or requests, write to 73hkrn+lessonlineup@gmail.com, or by post to:
Hyungjoon Kim, doing business as Lesson Lineup207 King St., Apt 710, San Francisco, CA 94107, USA