Privacy Policy

Last updated: 9 March 2026

1. Who We Are

London PCO Centre LTD ("we", "us", "our") operates the SERU Prep platform at seru.londonpcocentre.com. We are the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have questions about this policy or your data, contact us at privacy@londonpcocentre.com.

2. What Data We Collect

We collect the following categories of personal data:

  • Account information — name, email address, and password (hashed) when you register an account.
  • Google OAuth data — if you sign in with Google, we receive your name, email address, and profile picture URL from Google. We do not access your Google contacts, calendar, or other Google services.
  • Usage data — quiz scores, progress metrics, courses accessed, lesson completion status, and achievements earned.
  • Payment data — when you subscribe to a paid plan, payment is processed securely by Stripe. We store your subscription tier and status but never store your full card number or bank details.
  • Technical data — IP address, browser type, device type, and pages visited. Collected automatically through server logs.

3. How We Use Your Data

  • Provide the service — create and manage your account, deliver quizzes, track progress, and unlock features based on your subscription.
  • Process payments — manage subscriptions, issue refunds, and prevent fraud.
  • Improve the platform — analyse aggregate usage patterns to improve question quality, user experience, and platform performance.
  • Communicate with you — send account-related emails (password resets, subscription confirmations). We do not send marketing emails unless you opt in.
  • Legal obligations — comply with applicable laws, regulations, and legal processes.

4. Legal Basis for Processing

We process your data based on:

  • Contract — processing necessary to provide you with the SERU Prep service you signed up for.
  • Legitimate interests — improving our platform, preventing fraud, and ensuring security.
  • Consent — where you have given explicit consent, for example opting in to marketing communications.
  • Legal obligation — where we are required by law to process or retain your data.

5. Who We Share Your Data With

We do not sell your personal data. We share data only with:

  • Stripe — payment processing (PCI DSS Level 1 certified).
  • Supabase — database and authentication hosting (data stored in the EU).
  • Google — if you use Google sign-in, Google processes authentication data under its own privacy policy.
  • Law enforcement — only when legally required.

6. Data Retention

We retain your account data and usage history for as long as your account is active. If you delete your account, we will erase your personal data within 30 days, except where retention is required for legal or financial record-keeping purposes (up to 7 years for payment records).

7. Your Rights

Under the UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data.
  • Restriction — ask us to limit how we process your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email us at privacy@londonpcocentre.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Cookies

We use essential cookies to keep you signed in and remember your preferences. These are strictly necessary for the platform to function and do not require consent.

We do not use advertising or third-party tracking cookies.

9. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) and at rest.
  • Passwords stored using industry-standard hashing (bcrypt).
  • Row-level security on our database ensuring users can only access their own data.
  • Regular security monitoring and updates.

10. International Transfers

Your data is primarily stored within the European Economic Area (EEA). Where data is transferred outside the EEA (for example, to Stripe in the US), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK ICO.

11. Children

SERU Prep is intended for individuals aged 18 and over who are applying for or renewing a TfL private hire driver licence. We do not knowingly collect data from anyone under 18. If we become aware that we have collected data from a child, we will delete it promptly.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or by displaying a notice on the platform. The "last updated" date at the top of this page indicates when the policy was last revised.

13. Contact Us

If you have any questions about this privacy policy or how we handle your data, please contact us: