1. Overview & Policy Statement
My V.I.P. Academy ("we", "us", "our") operates the website at www.myvipacademy.com (the "Platform"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Platform.
By creating an account or using our Platform, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please discontinue use of the Platform.
This policy applies to all users of the Platform, including students, instructors, and visitors. References to "you" and "your" refer to you as a user of the Platform regardless of your role.
Summary:
We collect only the data necessary to provide our service. We do not sell your personal data to third parties. We use it solely to operate the Platform, facilitate tutoring sessions, and communicate with you.
2. What Data We Collect
We collect the following categories of personal data:
a. Account Information (provided by you)
- Students: Full name, email address, phone number, timezone, profile photo (optional)
- Instructors: Full name, email address, phone number, professional bio, subjects taught, qualifications, hourly rate, availability schedule, profile photo
- Both: Username, password (stored as a hashed value — we never store plain-text passwords)
b. Session & Booking Data
- Booking details: subject, date, time, duration, session type (intro or paid)
- Payment status and transaction reference numbers (we do not store full card details)
- Session chat logs (saved to support session review and dispute resolution)
- Session recordings (video files stored on Bunny.net CDN)
- Session notes created by instructors or students during a session
- Post-session ratings and reviews submitted by students
c. Instructor Application Data
- Educational qualifications and background
- Subjects and teaching experience
- Demo video submission URL (if applicable)
- Application status history
d. Technical Data (collected automatically)
- IP address and device type
- Browser type and version
- Pages visited and actions taken on the Platform
- Date and time of access
- Authentication tokens (via Supabase Auth — session cookies)
e. Communication Data
- Emails sent to and from our support team
- Conduct reports submitted through the Platform
- In-session chat messages
3. How We Use Your Data
We use your personal data only for the following purposes:
✓ Account Creation & Authentication
Your name and email are used to create and maintain your account, verify your identity, and provide secure login via Supabase Authentication.
✓ Facilitating Tutoring Sessions
Booking details, schedules, and payment information are used to match students with instructors, create video rooms via Daily.co, process payments via WiPay, and send session reminders.
✓ Communication
Your email address is used to send booking confirmations, session reminders, password reset emails, application status updates, and important platform notifications via Resend.
✓ Session Recording & Review
Session recordings are stored on Bunny.net and made available exclusively to the student and instructor who participated. They are not shared with third parties.
✓ Platform Safety & Trust
Conduct reports, booking history, and ratings are used to ensure the safety and quality of the Platform, including moderation decisions such as suspensions or bans.
✓ Payment Processing
Your booking and payment details are shared with WiPay solely to process the transaction. We do not store full card details.
✓ Platform Improvement
Anonymised technical data (page visits, error logs) may be used to diagnose problems and improve the Platform's performance and user experience.
✓ Legal Compliance
We may process your data where required to comply with applicable laws, court orders, or regulatory requirements.
We do NOT:
- Sell your personal data to any third party, advertiser, or data broker
- Use your data for targeted advertising
- Share session recordings with anyone other than the session participants
- Store your full payment card details
- Use your data for automated decision-making that produces legal effects on you
4. Legal Basis for Processing
We process your personal data on the following legal grounds:
Contract Performance
Processing your name, email, booking details, and payment information is necessary to create your account and fulfil the tutoring service you have requested.
Legitimate Interests
We may process technical data (IP addresses, error logs) based on our legitimate interests in maintaining a secure and functional platform.
Consent
Where we ask for your consent (e.g. optional profile photo, optional session notes visibility), you may withdraw that consent at any time by contacting us at support@myvipacademy.com.
Legal Obligation
We may process your data where required by applicable Jamaican law, including the Data Protection Act 2020, or court orders.
6. How We Protect Your Data
We implement industry-standard security measures to protect your personal data:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
- Encryption at rest: Data stored in Supabase is encrypted at rest using AES-256 encryption.
- Password hashing: Passwords are never stored in plain text. They are hashed using bcrypt via Supabase Auth.
- Row Level Security (RLS): Our database uses Supabase RLS policies so that users can only access their own data. Admin access requires a separate service-role key never exposed to clients.
- Access controls: Only authorised My V.I.P. Academy administrators can access raw user data, and only when necessary for platform operations.
- Signed URLs: Session recordings are served via pre-signed, time-limited URLs — not publicly accessible links.
- Session expiry: Authentication sessions expire automatically and refresh tokens are rotated on use.
While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at support@myvipacademy.com.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes outlined in this Policy:
Active account data
Retained for the duration of your account plus 2 years after account closure
Session recordings
Retained for 12 months from the session date, then automatically deleted unless specifically requested
Session chat logs
Retained for 12 months from the session date
Payment transaction records
Retained for 7 years to comply with financial record-keeping requirements under Jamaican law
Conduct reports
Retained for 3 years from the date of the report
Instructor application data
Retained for 2 years from application submission
Email communications with support
Retained for 2 years
Upon account deletion, we anonymise or delete your personal data within 30 days, except where retention is required by law. Booking and payment records may be retained in anonymised form for financial audit purposes.
8. Your Rights
Under the Jamaica Data Protection Act 2020 and applicable privacy principles, you have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data, subject to legal retention obligations.
Right to Restrict Processing
Request that we limit how we use your data in certain circumstances.
Right to Data Portability
Request your data in a structured, machine-readable format.
Right to Object
Object to processing of your data where we rely on legitimate interests.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent.
Right to Complain
Lodge a complaint with the relevant data protection authority in Jamaica.
To exercise any of these rights, contact us at support@myvipacademy.com. We will respond within 30 days.
10. Children's Privacy
My V.I.P. Academy is designed for students of all ages in the Caribbean. We take the privacy of young users seriously.
- Users under the age of 18 should have a parent or guardian review this Privacy Policy.
- We recommend that parents or guardians create and manage accounts on behalf of students under 13 years of age.
- We do not knowingly collect personal data from children under 13 without verifiable parental consent. If you believe we have collected such data, please contact us immediately at support@myvipacademy.com.
- Session recordings involving minors are accessible only to the student and their instructor.
- We do not share the personal data of minors with any third party beyond what is necessary to operate the tutoring service.
11. Jamaica Data Protection Act
My V.I.P. Academy operates under the laws of Jamaica and complies with the Jamaica Data Protection Act 2020 (DPA 2020), which came into force in 2023 and establishes the framework for personal data protection in Jamaica.
Key principles we adhere to under the DPA 2020:
Lawfulness, Fairness & Transparency
Data is processed lawfully and transparently. We explain clearly why we collect each piece of information.
Purpose Limitation
Data is collected for specified, explicit, and legitimate purposes and not further processed in ways incompatible with those purposes.
Data Minimisation
We collect only the personal data that is adequate, relevant, and limited to what is necessary for the purpose.
Accuracy
We take reasonable steps to ensure personal data is accurate and kept up to date. You can update your account information at any time.
Storage Limitation
Personal data is not kept longer than necessary. See Section 7 for our retention schedules.
Integrity & Confidentiality
We use appropriate technical and organisational measures to protect data against unauthorised processing, accidental loss, destruction, or damage.
Accountability
As the data controller, My V.I.P. Academy is responsible for and can demonstrate compliance with these principles.
The Jamaica DPA 2020 is administered by the Office of the Information Commissioner (OIC). If you believe your data rights have been violated, you may lodge a complaint with the OIC at oic.gov.jm.
12. International Data Transfers
My V.I.P. Academy is based in Jamaica. However, some of our service providers are located in other countries, which means your data may be transferred internationally as part of our service delivery:
- Supabase — Data may be hosted in the United States (AWS infrastructure)
- Daily.co — Video infrastructure hosted in the United States
- Vercel — Hosting platform operates globally (primarily US/EU edge network)
- Resend — Email delivery infrastructure in the United States
- Bunny.net — CDN with global edge servers
Where your data is transferred outside Jamaica, we ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements with each provider.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to registered users if the changes are material
- Displaying an in-platform notice for a reasonable period following the update
Your continued use of the Platform after changes are posted constitutes your acceptance of the updated Policy. We encourage you to review this page periodically.
14. Contact & Complaints
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a concern about how we handle your data, please contact us:
My V.I.P. Academy — Data Enquiries
Email: support@myvipacademy.com
Website: www.myvipacademy.com
Response time: We aim to respond to all data-related enquiries within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Information Commissioner (OIC) Jamaica at oic.gov.jm.