Legal
Privacy Policy
Last updated: 27 August 2026 (version 2026-09)
01Introduction & scope
Glassroom is a tuition-centre management platform built for Singapore: class scheduling, bookings and attendance, student billing and invoicing, WhatsApp invoice delivery and reminders, tutor payouts and a tutor portal, run from one place.
This Privacy Policy explains how we handle personal data. It is governed by the laws of Singapore, including the Personal Data Protection Act 2012 (PDPA). It applies to our marketing site, the Glassroom application, the pages families reach through it (invoice pay pages and trial or enrolment forms), and the messaging features delivered through it.
Tuition centres that subscribe to Glassroom sign a Service Agreement whose Data Processing Addendum (Schedule B) makes the commitments below contractual. This page restates them for the individuals whose data a centre keeps in Glassroom.
02Our roles (organisation vs. data intermediary)
Personal data flows through Glassroom in two distinct ways, and our role differs between them.
Data a centre keeps about its students, families, tutors and staff
For the personal data that a tuition centre enters about its own students, their parents and guardians, prospective students who apply for a trial, its tutors and its staff, Glassroom acts as a data intermediaryunder section 4 of the PDPA, processing that data only on the centre’s behalf and on its instructions. The tuition centre is the organisation responsible for that data, including obtaining the necessary consent from, and giving the required notice to, the individuals concerned.
The centre’s own account data
For the contact details of the people who sign up for and administer a centre’s Glassroom workspace (its signatory, admin user and billing contact), Glassroom is the organisation responsible for that data.
03Personal data we collect
(a) Account data
Name, email address, phone number, business details about the tuition centre, and login credentials.
(b) Data the centre keeps in Glassroom
Information about the centre’s students (many of whom are under 18), their parents, guardians and billing contacts, prospective students who apply for a trial and their families, tutors and staff: names, mobile numbers, email addresses, school and level, class enrolments, attendance, trial and enrolment applications, invoices, payment records, tutor payout records, notes the centre’s staff record, and audit records of actions in the workspace.
(c) WhatsApp messaging data
Phone numbers, the content of messages exchanged over WhatsApp between the centre and its families, and delivery status. Where a centre enables Caitlin, our automated assistant, inbound messages may be handled by it (see the WhatsApp & Meta section below).
(d) Usage & technical data
Server and access logs, device and browser information, and cookies used to keep you signed in and to operate the service.
04How we use personal data
Consistent with the PDPA’s purpose-limitation principle, we use personal data only to provide, secure, support and improve the service for the centre, and for nothing else. That includes:
- providing, operating and securing the Glassroom service;
- managing classes, attendance, billing, invoicing and tutor payouts;
- delivering WhatsApp messages between a centre and its families;
- where a centre enables it, operating Caitlin, an automated assistant that answers inbound WhatsApp messages from the centre’s published FAQs and helps book trial sessions (booking and support only);
- providing customer support;
- maintaining security and audit logging;
- improving and developing the service, using usage data only in a form that identifies no centre and no individual.
We do not sell personal data, and we do not use a centre’s data to market to its students or families.
05Consent
Where we are the responsible organisation, we collect and use personal data on the basis of express or deemed consent under the PDPA, or as otherwise permitted by law.
Where a centre keeps data about its students, families, tutors or staff, the centre is responsible for obtaining the necessary consent from those individuals before entering their data into Glassroom, including consent for us to hold and process the data and for the service to send WhatsApp messages on the centre’s behalf, and for honouring any withdrawal of consent. Individuals may withdraw consent at any time on reasonable notice; doing so may affect the centre’s ability to provide certain services to them.
06Children's personal data
Most of the students in a Glassroom workspace are children (under 18), and their personal data is sensitive. We apply the higher standard of protection the Personal Data Protection Commission’s guidelines call for, and we collect only what the service needs.
The centre is responsible for obtaining consent in the right way: from a parent or guardian for a child under 13, and from either the child (where the child can understand what they are agreeing to) or a parent or guardian for a child aged 13 to 17. Because centres operate in an education setting, we recommend obtaining a parent’s or guardian’s consent for every student under 18.
We do not use children’s personal data for any purpose other than providing the service to the centre, and we do not contact a student directly except through features the centre enables.
07WhatsApp & Meta
Messaging in Glassroom is delivered over the WhatsApp Business Platform provided by Meta, from either a WhatsApp Business number that Glassroom operates or a number the centre provides. It is therefore also subject to WhatsApp’s and Meta’s terms and policies, including the WhatsApp Business platform policies.
- Recipients must have agreedto receive messages from the centre. Centres are responsible for ensuring they have a lawful basis and the recipient’s consent before messaging, and no marketing messages are sent to anyone without their consent.
- Message templates are approved by Meta before use. Meta may reject, restrict or delay templates and may limit or suspend a number; those decisions are outside Glassroom’s control.
- Where a centre brings its own number, the number stays the centre’s. When its agreement with us ends we disconnect the number and stop using it.
- Data obtained through WhatsApp is used only as reasonably necessary to support messaging with that person, not for unrelated purposes.
- Where enabled, Caitlin operates strictly as an automated booking and supportassistant, grounded in the centre’s own published FAQs. It is not a general-purpose chatbot, consistent with Meta’s WhatsApp Business platform policies.
- WhatsApp messages are end-to-end encrypted in transit. Meta handles and retains certain data in accordance with its own policies, which are outside Glassroom’s control.
08Disclosure & service providers
We use the following providers to run the service, and share personal data with them for that purpose only:
- Railway: application and database hosting. Servers in Singapore.
- Vercel: delivery of the web application and the pages families see (invoice pay pages, enrolment forms). United States, with global edge servers.
- Meta Platforms: WhatsApp Business Platform, message delivery to and from families. United States and Ireland.
- HitPay: only where a centre enables HitPay payments, payment links on its invoices. Singapore.
- Airwallex: our billing of the centre. Handles the billing contact’s details and card. Singapore and Australia.
We may add or replace a provider. Centres receive at least 14 days’ written notice before a new provider receives personal data, and this list is kept current. We remain responsible for our providers’ handling of personal data, and we require them to protect it and to use it only for the purposes we specify. We may also disclose personal data where the law or a court requires it.
09Cross-border transfer
Some of the providers above store or process personal data outside Singapore. Where they do, we make sure through our contracts with them that the personal data receives a standard of protection comparable to that under the PDPA, as the Transfer Limitation Obligation requires.
10Retention & deletion
We keep personal data only for as long as needed to provide the service to the centre. When a centre’s agreement with us ends we keep its workspace data for 30 days so it can be exported, then delete it from our live systems within a further 60 days. Backup copies are overwritten in our normal backup cycle and are only ever used to restore the service.
A centre may ask us to delete specific records during its agreement; we do so within ten business days, anonymising a record where the service needs it to keep billing history accurate. We may keep records we need for accounting, tax or legal reasons for as long as the law requires. WhatsApp-derived identifiers are retained only for as long as reasonably necessary to support messaging with the relevant person.
11Security
We keep reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification, disposal or loss of personal data, including:
- encryption of all data in transit;
- strict separation of each centre’s data at the database level;
- role-based access for the people a centre invites into its workspace;
- an append-only audit log of changes in each workspace;
- access to production systems limited to the people who need it;
- daily backups stored separately from the live system;
- encrypted storage of credentials and secrets.
Anyone who works on the service for us and can access personal data is bound by confidentiality obligations. No system is perfectly secure, but we work to protect data appropriately and to improve our safeguards over time.
12Your rights (access & correction)
Under the PDPA you may request access to, or correction of, the personal data we hold about you. Where the data is held by Glassroom on behalf of a tuition centre (for example, a student’s or guardian’s records), please direct your request to that centre, which is the responsible organisation; we refer such requests to the centre and help it respond within the time the PDPA allows. For account data for which Glassroom is responsible, contact our Data Protection Officer at the address below.
13How to request deletion of your data
This section explains how to ask us to delete personal data, including the data we obtain through the WhatsApp Business Platform provided by Meta. It applies whether you are a parent, a guardian, a student, or a tuition centre.
If you are a parent, guardian or student
The tuition centre you deal with is the organisation responsible for your data, and Glassroom only processes it on that centre’s instructions. Ask the centre to delete your records and it will instruct us. You may also write to us at titus@glassroom.cloud and we will pass your request to the centre and help it respond within the time the PDPA allows. If you only want the messages to stop, you can withdraw your consent instead of deleting your records: reply to any WhatsApp message asking to opt out, or tell the centre directly.
If you are a tuition centre
Email us from an address on your account and say whether you want specific records deleted or your whole workspace removed. We delete specific records within ten business days. When your agreement ends we keep your workspace for 30 days so you can export it, then delete it from our live systems within a further 60 days, as set out under Retention & deletion above.
Data we obtain through WhatsApp
For a centre that connects its own WhatsApp Business number, the number and its WhatsApp Business Account belong to that centre, not to Glassroom. What we hold is the account and phone number identifiers, an access token, the message identifiers and delivery statuses of messages we send, and the status of the message templates we manage on the centre’s behalf.
A centre can end our access at any time, without contacting us, in either of two ways: remove the Glassroom app from its Meta business portfolio under Business settings, Integrations, Connected apps; or open the WhatsApp Business app and disconnect under Settings, Account, Business Platform. We then stop sending, and we delete the access token we hold for that account. The identifiers and delivery records in the workspace are deleted on the timelines above.
Data held by Meta on its own systems is governed by Meta’s terms and retention periods, which we do not control. Requests about that data should go to Meta.
We confirm in writing once a deletion request has been carried out.
14Data breach notification
If we become aware of a data breach affecting personal data we hold for a centre, we tell the centre without undue delay and in any case within three (3) calendar days, with what we know about what happened, the data and people affected, and what we are doing about it, and we help the centre assess whether the breach must be reported to the Personal Data Protection Commission (PDPC) and the affected individuals. For data for which Glassroom is the responsible organisation, we notify the PDPC and affected individuals ourselves where the PDPA’s mandatory breach-notification regime requires it, within the timeframes set by law.
16Changes & contact (DPO)
We may update this policy from time to time. Material changes are reflected in the “Last updated” date and version at the top of this page, and centres receive at least 30 days’ written notice of a new version of their Data Processing Addendum.
For privacy questions, or to reach our Data Protection Officer, contact titus@glassroom.cloud.