Privacy Policy

Privacy Policy

Last updated: 2 October 2026

Who I am and how to contact me

This website, tim-thornton.com, is run by me, Tim Thornton, trading as Tim Thornton Ceramics. I decide how and why your personal data is used, which makes me the “controller” under data protection law.

I run a small business on my own and have no data protection officer. I am personally responsible for how your data is handled, including for the purposes of Canada’s privacy law (PIPEDA).

Your data at a glance

The table summarises what I hold, why, the legal basis I rely on, and how long I keep it. The following sections give the detail.

What forDataLegal basisRetention period
Booking and running coursesName, email, country, preferred language, course progress including video viewing, quiz results, attendance at live sessionsContractWhile you have an account, then up to 7 years after your last course completion
Shop orders and paymentsName, billing address, email, phone, order details (payment card details go straight to the payment provider)ContractUp to 7 years since last order/payment
Financial recordsInvoices, payments and refundsLegal obligation (HMRC)Up to 7 years
EnquiriesWhat you send through the contact form or by emailLegitimate interest (answering you)Up to 7 years after the last message
Newsletters and announcementsName, email, which emails you open and links you clickConsent; for existing customers, legitimate interests with an easy opt-outContacts who stop opening emails are removed at most 7 years after the last contact. Contacts who unsubscribe are immediately sent no more emails.
Community, comments and testimonialsProfile, posts and comments; testimonial text, name and countryContract (community); consent (published testimonials)Until you delete them, or up to 7 years after your account is closed
Analytics and advertisingCookie identifiers, pages visited, device and browser, approximate location, session recordingsConsent (cookie banner)Google analytics: 14 months; Microsoft Clarity 9 months; advertising cookies 1 year unless reset by visitor
Security, spam and fraud preventionIP address, browser details, login attemptsLegitimate interests (keeping the site and payments safe)Server logs: up to 1 month
Supporters (Patreon and my own membership)Name, email, membership tier, payment historyContractWhile you are a supporter, then as for financial records

Where my tools do not delete data automatically, I review what I hold once a year, when I prepare my tax records, and delete anything I no longer need.

Payment providers keep their own records under financial regulations, which I cannot shorten. PayPal keeps data for as long as you have a PayPal account plus 10 years; Stripe keeps transaction records for as long as anti-money-laundering rules require.

What I collect and why

Courses and students

When you book a course I create an account for you and a record in my customer database. Both are stored on my own website and/or my office computer, not with a third-party CRM. I hold your name, email address, country, and, if you give them, your preferred name, pronouns and preferred language.

While you take a course, my course software (TikiWiki or LearnDash, depending on the course) records which lessons you have opened and completed, quiz answers and scores, and how much of each lesson video you have played. Video progress comes from the Vimeo player embedded in the lesson. I use this to see whether the course is working, to help anyone who gets stuck, and to confirm completion. If you join live sessions, the video-conferencing service (currently ClickMeeting, possibly Zoom in future) records your attendance.

Shop orders

When you buy something I need your name, billing address, email and phone number to process the order and contact you about it. For physical items I also need your shipping address. Payment card details are entered directly with Stripe or PayPal; I never see or store them. WooCommerce records how you reached the site (for example a search engine, an email or an advert) against your order, so I can tell which kinds of promotion are effective.

Enquiries

Messages sent through the contact form are stored on the website and emailed to me. I use them only to reply and to keep a record of the conversation.

Newsletters and course announcements

If you sign up, or if you are a customer and have not opted out, I send occasional emails about courses and related news. Emails are sent through Brevo. They contain small tracking images and tracked links that tell me whether an email was opened and which links were clicked; I use this to judge which content is useful and to remove contacts who never open anything. Every email has an unsubscribe link.

Community, comments and profiles

The community area is private. Only students on my courses and my supporters can join, and its contents are not visible to the public or to search engines. Anything you post there, and your profile, can only be seen by other members. If you leave a comment elsewhere on the site, I store your IP address and browser details to help detect spam. If the community software checks whether you have a Gravatar profile picture, a scrambled version of your email address is sent to Automattic, which runs Gravatar.

Testimonials

If you send a testimonial and agree to it being published, I show it with your name, business name and country. You can ask me to remove it at any time.

Supporters

If you support me through Patreon or my own membership scheme, I hold your name, email address, membership tier and payment status. Patreon has its own privacy policy for the data it holds.

Cookies and similar technologies

Cookies are small files your browser stores for a website. “Similar technologies” here means tracking pixels, the small images or scripts that report a page view, and local storage in your browser. I use them in two groups.

Always on: these are set for every visitor, because the site and the courses cannot work properly without them, or because they only adapt the site to how you use it. They are allowed without consent under UK law.

Only with your consent: analytics, advertising and visit tracking are only set if you choose Accept on the cookie banner. If you choose Decline, or ignore the banner, none of them load. Your choice is applied to all of them; you can’t change them individually.

You can change your mind at any time with the Cookie settings link at the bottom of every page, or by clearing cookies for this site in your browser.  A year after your cookie settings were last changed, the settings are deleted and you are asked again.

Always on

ServiceProviderWhat it doesTypical cookies or storage
Login and basketMy site (WordPress, WooCommerce)Keeps you logged in and remembers your basketwordpress_logged_in_*, wp_woocommerce_session_*, woocommerce_cart_hash
Cookie choiceMy site (SEOPress)Remembers whether you accepted or declined, for 1 yearseopress-user-consent-accept, seopress-user-consent-close
Course progressMy site (TikiWiki, LearnDash)For logged-in students, records lessons completed, quiz results and how much of each lesson video has been playedStored in your account; uses the login cookie
VideosVimeoPlays course and preview videos, with Vimeo’s “do not track” settingNo tracking cookies
MapGoogle Maps, contact page onlyShows where I amGoogle may set its own cookies when the map loads
Payment securityStripe, PayPalFraud prevention at checkout__stripe_mid, __stripe_sid, PayPal fraud checks
Site securityCloudflareFilters out bots and attacks__cf_bm, cf_clearance
Pop-upsMy site (Holler Box)Counts pages viewed so a pop-up is not shown repeatedlyholler-page-views

Only with your consent

ServiceProviderWhat it doesTypical cookies
Google AnalyticsGoogleCounts visits and shows how the site is used_ga, _ga_* (up to 14 months since last site visit)
Google AdsGoogleMeasures whether adverts lead to bookings_gcl_au (up to 37 months for detailed data, or 11 years for summary over a month or more)
Microsoft ClarityMicrosoftHeatmaps and recordings of how pages are used (mouse movement, clicks, scrolling); text you type is masked_clck, _clsk (up to 1 year)
Microsoft AdvertisingMicrosoftMeasures whether adverts lead to bookings_uetsid, _uetvid (up to 13 months)
Meta pixelMeta (Facebook, Instagram)Measures whether adverts lead to bookings and builds audiences for adverts_fbp (180 days)
Visit trackingMy site (Groundhogg)Records which pages you visit and how you arrived; if you are on my mailing list, links this to your contact recordgroundhogg-lead-source, groundhogg-page-visits (14 days)
Order sourceMy site (WooCommerce)Records how you reached the site, saved with any ordersbjs_* (up to 1 month)

Cookie names and lifetimes are set by the providers and can change. Whilst this information is believed to be correct at the time of writing, please verify with the organisation managing the cookie if that is important to you.

Embedded content

Videos are embedded from Vimeo with Vimeo’s “do not track” setting, so Vimeo does not set tracking cookies. It still receives your IP address and browser details in order to play the video. For logged-in students, the Vimeo player reports how far each lesson video has been played, and my site saves this in your account as part of your course progress. It is not shared with anyone else.

The map on the contact page is provided by Google Maps and loads with the page. When it loads, Google receives your IP address and may set cookies under its own privacy policy.

Emails

Tracking in my emails is described under Newsletters and course announcements above.

Who I share data with

I do not sell your data. I share it only with the service providers below, so they can do a job for me, and with HMRC or other authorities where the law requires. Providers marked own controller also decide for themselves how they use the data, under their own privacy policies.

ProviderPrivacy policyWhat forWhere data is processed
InMotion
www.inmotionhosting.com/legal/privacy-policy/
Hosts the website, its database and my customer recordsUSA
Cloudflarewww.cloudflare.com/en-gb/privacypolicy/Delivers the site quickly and blocks attacks; handles every visitWorldwide, HQ in USA
Brevowww.brevo.com/legal/privacypolicy/Sends emails from the site and my newslettersFrance (HQ), Germany, USA
Stripehttps://stripe.com/gb/privacyCard paymentsIreland, UK and USA
PayPalOwn controller, www.paypal.com/uk/legalhub/paypal/privacy-fullCard paymentsUK customers: PayPal UK Ltd, London; EU customers: Luxembourg
Vimeovimeo.com/legal/privacy/policyHosts and plays course videosUSA
ClickMeetingknowledge.clickmeeting.com/uploads/2024/02/clickmeeting-security-policy.pdfLive online sessionsPoland
Zoomwww.zoom.com/en/trust/privacy/privacy-statement/Live online sessionsUSA
GoogleOwn controller for advertising; policies.google.com/privacy?hl=en-GBAnalytics, advertising, the map on the contact pageUSA
MicrosoftOwn controller for advertising and OneDrive; www.microsoft.com/en-gb/privacy/privacystatementlarity analytics, Microsoft Advertising; OneDrive for website backupsUSA and EU
MetaJoint controller and Advertising measurement and audiencesIreland and USA
Automatticautomattic.com/privacy/Gravatar profile picturesUSA
PatreonOwn controller, privacy.patreon.com/policies/en/Supporter membershipsUSA

Meta: my Facebook and Instagram pages, and the Meta pixel

For two kinds of processing, Meta and I count as joint controllers, meaning we share responsibility for them:

  • The Meta pixel on this website, if you accept cookies. Meta collects the data directly from your browser.
  • The statistics Meta gives me about my Facebook page and Instagram account (“Insights”): numbers such as reach, interactions, and the age, gender and location of followers. I only ever see these as totals.

How responsibility is shared is set out in Meta’s Page Insights Controller Addendum and its Business Tools Terms. For UK and EU users the Meta company responsible is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Requests about data Meta holds are best made to Meta directly; if you send one to me, I will pass it to Meta within 7 days.

I use my Facebook page and Instagram account to tell people about my courses and activities, and to answer messages. My legal basis is legitimate interests. When you like, follow, comment or message me, Meta handles that data under its own privacy policy. You can control how Meta uses your activity for adverts in your Facebook ad preferences.

International transfers

Some providers process data outside the UK. When they do, the transfer is protected in one of these ways:

  • EU and EEA countries (Brevo, PayPal’s EU company, ClickMeeting): the UK recognises their data protection law as adequate.
  • US companies certified under the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”), which include Google, Microsoft, Meta, Stripe, Cloudflare and Zoom: the UK recognises this certification as adequate.
  • Any other provider: the provider’s data processing terms include the UK’s International Data Transfer Agreement or Addendum, the standard contract the ICO approves for this purpose.

If you are in the EU, data you send me is transferred to the UK, which the EU recognises as providing adequate protection.

Your rights and how to complain

These rights apply to anyone whose data I hold, whether or not you have an account. To use any of them, contact me using the details at the top of this policy. It is free. I may need to confirm who you are first, and I will reply within one month (longer for complex requests, in which case I will tell you why).

  • Access: a copy of the personal data I hold about you.
  • Correction: to have inaccurate or incomplete data put right.
  • Erasure: to have your data deleted, except what I must keep by law, such as financial records.
  • Restriction: to have me stop using your data while a question about it is resolved.
  • Objection: to object to my using your data on the basis of legitimate interests. You can always object to marketing emails, and I will stop.
  • Portability: to receive data you gave me in a common electronic format, or have it sent to someone else.
  • Withdraw consent: where I rely on consent (cookies, newsletters, published testimonials), you can withdraw it at any time. This does not affect what happened before.

I do not make decisions about you by purely automated means.

Complaints

If you are unhappy with how I have handled your data, please tell me first. I will acknowledge your complaint within 30 days and try to put things right.

You can also complain to a data protection authority:

Security and data breaches

The website is served over an encrypted connection (HTTPS), and access to its administration area, my customer records and my backups is restricted to me. Backups are kept on a storage device in my office and in Microsoft OneDrive. The web server is protected by my hosting provider’s firewall, and my own computers by their firewall. I keep software up to date.

If a breach puts your data at risk, I will report it to the ICO within 72 hours of becoming aware of it, as the law requires. If it is likely to cause you serious harm, I will also tell you directly without undue delay, saying what happened and what you can do.

Changes to this policy

I update this policy when what I do with data changes, for example when I add a new service. The date at the top shows when it last changed. I do not keep records of previous versions of this policy. If a change significantly affects how I use data I already hold about you, I will tell you by email.