1. Introduction
Tearn ("we," "our," or "us") operates a two-sided skills marketplace that connects students with independent trainers for personalized skill-building sessions. This Privacy Policy describes how Tearn collects, uses, discloses, and safeguards your personal information when you use our mobile application and website (collectively, the "Platform").
By creating an account or using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Platform immediately.
For privacy-related inquiries or requests, contact us at: privacy@tearnapp.com or via our website at tearnapp.com.
2. Information We Collect
2.1 Account Information
When you register, we collect:
- Full name — used to personalize your experience and display on your profile
- Email address — used for authentication, booking confirmations, and platform communications
- Phone number (optional) — used for account recovery and booking reminders
- Password — stored as a bcrypt hash; we never store or transmit plain-text passwords
- Account type — whether you registered as a student, trainer, or both
2.2 Profile Information
To enable meaningful trainer-student matching, we may collect:
- Profile photos — uploaded voluntarily, stored securely via Firebase Cloud Storage
- Biography and description — free-text fields you provide to describe yourself or your services
- Location — city, state, or ZIP code used for proximity-based trainer search
- Skills and categories — trainers list skills they teach; students list skills they want to learn
- Availability schedule — trainers set available times; this is stored in our database
- Hourly rate (trainers only) — publicly displayed to potential students
2.3 Usage Data
We automatically collect data about how you use the Platform, including:
- Pages or screens viewed and features accessed
- Search queries entered (e.g., skill categories, trainer names)
- Timestamps of actions (login, booking creation, session completion)
- Interactions with other users (booking requests, messages)
- Error logs and crash reports to improve app stability
2.4 Device Information
To provide push notifications and improve performance, we collect:
- Firebase Cloud Messaging (FCM) tokens — unique device tokens used to deliver push notifications; refreshed automatically by Firebase
- Device identifiers — anonymized device IDs for analytics and debugging
- Operating system and version — used for compatibility and crash analysis
- App version — used to ensure you receive relevant feature updates
2.5 Payment Information
All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. Tearn never stores raw card numbers, CVV codes, or full bank account details on our servers. When you enter payment information:
- Stripe tokenizes your card data before it reaches our servers
- We store only Stripe's customer ID and the last four digits of your card for display purposes
- Stripe's Privacy Policy governs the handling of your payment data: stripe.com/privacy
2.6 Location Data
If you grant location permissions, we use your device's GPS or network location to show you trainers within your search radius. Location data is used only during active search sessions and is not stored permanently on our servers or shared with third parties for advertising.
3. How We Use Your Information
We use collected information for the following purposes:
- Trainer-student matching — to surface relevant trainers based on your skill interests, location, and availability
- Booking management — to create, confirm, modify, and cancel session bookings between students and trainers
- Payment processing — to charge students, distribute payouts to trainers, and handle refunds through Stripe
- Push notifications — to send booking confirmations, reminders, cancellation alerts, and platform updates
- Platform improvement — to analyze usage patterns, fix bugs, and develop new features
- Customer support — to respond to your inquiries and resolve disputes
- Legal compliance — to comply with applicable laws, respond to legal process, and enforce our Terms of Service
- Fraud prevention — to detect, investigate, and prevent fraudulent transactions and misuse of the Platform
- Communications — to send you important service announcements, policy updates, and (with consent) promotional materials
4. Information Sharing
We do not sell your personal information. We share data only in the following circumstances:
4.1 Service Providers
- Firebase / Google LLC — authentication (Firebase Auth), database (Cloud Firestore), file storage (Cloud Storage), and push notifications (FCM). Google's data processing terms apply.
- Stripe, Inc. — payment processing, fraud detection, and payout disbursement to trainers.
4.2 Between Users
When a student books a trainer, certain profile information (name, profile photo, bio, rating, location area) is shared between the two parties to facilitate the session. Direct contact details such as personal phone numbers are not shared without explicit consent.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Tearn, our users, or the public.
4.4 Business Transfers
If Tearn is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change and the applicable privacy choices.
5. Data Security
We implement industry-standard safeguards to protect your personal information:
- Encryption in transit — all data is transmitted over HTTPS/TLS 1.2 or higher; plaintext HTTP connections are rejected
- Encryption at rest — Firebase Cloud Storage and Firestore encrypt data at rest using AES-256
- Password security — passwords are hashed using bcrypt before storage; we never store or log plain-text passwords
- Stripe PCI compliance — card data is handled exclusively by Stripe, which maintains PCI-DSS Level 1 certification
- Firebase Security Rules — database and storage access is governed by Firebase Security Rules that restrict data access to authorized users only
- API authentication — all API endpoints require valid JWT or Passport OAuth tokens; unauthenticated requests are rejected
- Rate limiting — login and registration endpoints are rate-limited to prevent brute-force attacks
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify you as required by applicable law.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services:
- Active accounts — data is retained for the lifetime of your account plus any legally required retention period
- Account deletion — upon a verified account deletion request, we will delete or anonymize your personal data within 90 days, except where retention is required by law (e.g., financial records for tax compliance, which may be retained for up to 7 years)
- Booking records — transaction records are retained for 7 years for tax and legal compliance purposes, with personal identifiers anonymized where possible after 90 days
- Push notification tokens — FCM tokens are deleted when you log out or delete your account
- Log data — server logs are retained for up to 90 days and then purged automatically
To request account deletion, email privacy@tearnapp.com with the subject line "Account Deletion Request."
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request deletion of your personal data (subject to legal retention requirements)
- Data portability — request your data in a structured, machine-readable format
- Opt-out of marketing — unsubscribe from promotional emails at any time using the unsubscribe link in each email
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing
- Object to processing — object to processing based on legitimate interests
GDPR (EU/EEA users): You have rights under the General Data Protection Regulation including Articles 15–22. Our legal bases for processing include performance of a contract, legitimate interests, and consent. You may lodge a complaint with your local supervisory authority.
CCPA (California residents): Under the California Consumer Privacy Act, you have the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale. Tearn does not sell personal information. To exercise your rights, contact us at privacy@tearnapp.com.
We will respond to verified requests within 30 days (or as required by applicable law).
8. Children's Privacy
Tearn is intended exclusively for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under the age of 13. If you believe a child under 13 has provided us with personal data, please contact us immediately at privacy@tearnapp.com and we will promptly delete that information. If you are between 13 and 17 years old, you are not permitted to use the Platform.
9. Push Notifications
Tearn sends push notifications for important events including booking confirmations, session reminders, cancellation alerts, trainer responses, and platform updates. Push notifications require your opt-in consent, which is requested the first time you install the app.
You can disable push notifications at any time through your device settings:
- Android: Settings → Apps → Tearn → Notifications
- iOS: Settings → Tearn → Notifications
Disabling notifications will not affect your ability to use the Platform, but you may miss time-sensitive booking updates.
10. Location Data
Location information is used solely to enable trainer search by proximity. Specifically:
- Your location is used to compute distance between you and available trainers
- Approximate location (city or region) may be displayed publicly on your profile if you choose
- Precise GPS coordinates are never displayed to other users or stored permanently in our database
- Location is not used for targeted advertising or shared with third-party advertisers
- You can revoke location permissions at any time in your device settings; the app will fall back to manual city/ZIP entry
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Send a notification to your registered email address
- Display an in-app banner for significant changes
Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:
- Email: privacy@tearnapp.com
- Website: tearnapp.com
- Support page: tearnapp.com/support
We aim to respond to all privacy-related inquiries within 5 business days.