Privacy policy

Last updated: 17 July 2026

Who we are

ALC EDUCATION LIMITED, trading as ALC Education ("ALC", "we", "us", "our"), is the controller of your personal data for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We're registered in England and Wales (company number 12291365), with our registered office at 1 Blackmans Yard, 44a Cheshire Street, London, England, E2 6EQ.

We haven't appointed a statutory Data Protection Officer, as our processing doesn't require one under UK GDPR. For any data protection question, contact .

Information we collect

  • Account information: your name, email address, and password (stored securely, never in plain text).
  • Profile information: your handle, country, experience level, and, if you add one, a profile photo.
  • Billing information: your subscription plan and billing history. We never see or store your full card number — that's handled directly by our payment providers.
  • Practice submissions: photos or video you upload of your haircutting work — which may show a client or model — for review by an Educator. Where someone else appears, you're responsible for their consent (see our Terms of Service).
  • Progress data: which lessons and quizzes you've viewed or completed, and your quiz scores.
  • Device and usage information: your IP address, general location (country/city, derived from your IP), device type, and how you use the Service, including usage analytics (see "How we share your information" below).
  • Push notification tokens: a device identifier used to deliver notifications, if you enable them.
  • Communications: messages you send us, for example through our contact form, and any support correspondence.

How we use your information

  • To create and manage your account and subscription.
  • To provide course content and track your progress.
  • To let Educators review your practice submissions and answer your questions.
  • To check the quality of the feedback we give and train our Educators, using practice submissions in a de-identified form where practicable.
  • To process payments and manage billing.
  • To send you service messages (for example, about your subscription or account security) and, if you've opted in, marketing emails.
  • To understand how the Service is used and improve it, using aggregated or pseudonymised analytics.
  • To detect and prevent fraud, abuse, or misuse of the Service.
  • To comply with our legal obligations.

How we share your information

We don't sell your personal data. We share it only with service providers who help us run the Service, under contracts that require them to protect it and use it only for the purposes we specify:

  • Amazon Web Services, Inc. — Cloud hosting, database, file storage, transactional email delivery, and push notification delivery (United Kingdom and Ireland).
  • Stripe, Inc. — Payment processing for web subscriptions (card details are tokenised by Stripe and never reach our servers) (United States).
  • RevenueCat, Inc. — Subscription management for iOS and Android in-app purchases (United States).
  • Google LLC — "Sign in with Google" authentication and Android push notification delivery (Firebase Cloud Messaging) (United States).
  • Apple Inc. — "Sign in with Apple" authentication and iOS push notification delivery (APNs) (United States).
  • PostHog Inc. — Product analytics on the public website and native app (event analytics only — no session recording) (European Union (EU Cloud, Frankfurt)).

Some of these providers — including our payment and sign-in providers — also act as independent controllers of certain data for their own purposes, such as fraud prevention and meeting their own legal obligations. Their own privacy policies govern that processing.

We may also disclose personal data if required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets, in which case we'll ensure your data continues to be protected under an equivalent policy.

International data transfers

Some of our service providers are based outside the UK, or may access data from outside the UK, including from the United States (see the list above). Where we transfer personal data outside the UK, we put appropriate safeguards in place, such as Standard Contractual Clauses approved for use in the UK, reliance on the UK–US Data Bridge, or another adequacy mechanism recognised under UK GDPR. Details of the specific safeguard used for a given transfer are available on request at .

Data retention

We generally retain your personal data for as long as your account remains open. If you delete your account, we delete or anonymise this data, except where we need to retain it for longer to provide the Service, comply with our legal, accounting, or tax obligations, resolve disputes, investigate misuse of the Service, enforce our agreements, or protect our legitimate interests.

Your rights

Under UK GDPR, you have the right to:

  • access the personal data we hold about you;
  • ask us to correct inaccurate or incomplete data;
  • ask us to delete your data;
  • ask us to restrict how we use your data;
  • object to certain processing;
  • ask us to provide your data in a portable format; and
  • withdraw your consent at any time, where we rely on consent.

To exercise any of these rights, contact us at . You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).

California and other US state privacy rights

If you're a resident of California or another US state with a similar privacy law, you have rights broadly equivalent to those above, including the right to know what personal data we hold about you, delete it, and correct it. We do not sell or share personal data as defined under these laws — for example, we don't share it for cross-context behavioural advertising. To exercise any of these rights, contact us at ; we may need to verify your identity before responding, and you won't be discriminated against for exercising your rights.

Cookies and tracking

The Service uses a small number of cookies and similar technologies, described in full in our Cookies Policy. On the website, our analytics run in a privacy-friendly, cookieless way by default; we ask for your consent before storing any non-essential cookies on your device. In the mobile app, you can turn analytics off at any time in Settings.

Children's privacy

Our Service is not directed at children, and we do not knowingly collect personal data from children below the age required by applicable law in their jurisdiction. If we become aware that we have done so, we will delete that data. If you believe a child has provided us with personal data, please contact us at .

Security

We use appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls limiting who can view your data, and regular review of our security practices. No method of transmission or storage is completely secure, but we work to protect your information to an appropriate standard.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you before they take effect, for example by email or an in-app notice. The "last updated" date at the top of this page shows when it was last revised.

Contact us

Questions about this Privacy Policy or how we handle your data? Contact us at , or by post at 1 Blackmans Yard, 44a Cheshire Street, London, England, E2 6EQ. If you're not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).

Questions? Email

Get the app