Gramora

Privacy

Privacy Policy

Last updated: 16 July 2026

1. Who we are

Gramora (“we”, “us”, “our”) provides a structured 52-week Kent Test 11+ preparation programme for Kent’s grammar schools, at gramora11plus.co.uk.

For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), Gramora is the data controller for the personal data described in this policy.

If you have any questions about this policy or your data, contact us at hello@gramora11plus.co.uk — this is the quickest way to reach the person responsible for data protection at Gramora.

2. The information we collect

Information you give us:

  • Free roadmap requests: when you request our free 52-week roadmap through an ad on Facebook or Instagram (a Meta “Instant Form”), we receive the details you submit on that form — your name, your email address, your child’s school year, and your marketing-consent choice.
  • Account details: the parent/guardian’s name and email, your child’s study name (a first name or nickname), and optionally their year group, date of birth, target exam date and target schools — used to build and pace the programme.
  • Learning activity: your child’s mission and mock-paper results, and the SAS estimates we calculate from them.
  • Payment details: handled by our payment processor (Stripe). We never see or store full card numbers — only a reference to your Stripe customer record and your subscription status.

Information collected automatically: basic usage and device/browser information, and data from cookies and similar technologies (see Cookies & tracking).

3. How we use your information, and our lawful bases

  • To send the free roadmap and occasional 11+ tips you requested — on the basis of your consent, which you can withdraw at any time (see Marketing).
  • To provide the programme — create your account, deliver weekly missions, track progress and estimate SAS — to perform our contract with you.
  • To take payment and manage your subscription — to perform our contract with you.
  • To secure, maintain and improve the service, and to measure our advertising — on the basis of our legitimate interests (and your consent where cookies require it).

4. Children’s data

Gramora is bought and managed by a parent or guardian — the account holder must be an adult. We deliberately ask only for a child’s study name (a first name or nickname), not a full identity, and a surname is optional and used only on printed score reports.

We do not knowingly allow children to create their own accounts or to provide us with personal data directly — signing up requires the parent’s own email address and payment details, and all emails we send go to the parent. If you believe a child has given us personal data without a parent’s involvement, contact us and we will delete it. We keep the collection of children’s data to the minimum needed to run the programme, and we never use a child’s data for marketing or advertising.

5. Cookies & tracking

We use essential cookies to keep you signed in and to operate the site. We also use the Meta (Facebook) Pixel to measure the performance of our advertising — it records page views and when someone requests the roadmap, and may set cookies and share limited event data with Meta for ad measurement.

The Meta Pixel is an optional cookie: it does not load until you accept optional cookies in our cookie banner. If you decline, it is not loaded and no advertising cookies are set. You can change your choice at any time by clearing this site’s stored data in your browser, and you can manage ad tracking in your Meta ad preferences.

6. Who we share your information with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under data-processing agreements:

  • Supabase — database, authentication and storage.
  • Stripe — payment processing.
  • Resend — sending account and service emails (for example password resets and replies to your messages).
  • MailerLite — sending the roadmap and the 11+ tips emails you consented to.
  • Meta — advertising: delivering the Instant Form you filled in, and measuring our ads (the Pixel, only with your cookie consent).
  • Vercel and Railway — hosting the website and the application servers.

We may also disclose information where required by law.

7. International transfers

Some of our providers (for example Stripe, Meta, Resend, MailerLite and our hosting providers) process data in the United States or elsewhere outside the UK. Where they do, we rely on the safeguards recognised by UK law — UK adequacy decisions (including the UK–US Data Bridge where the provider is certified) and the International Data Transfer Agreement / Standard Contractual Clauses in the providers’ data-processing terms.

8. How long we keep it

We keep personal data only as long as we need it:

  • Account and learning data — kept while your account is active. If you delete your account (or ask us to), it is deleted; we may retain minimal records where the law requires it.
  • Roadmap-lead data — kept while we are in touch with you. If you unsubscribe, we stop emailing you immediately and delete or anonymise your lead data within 30 days of a deletion request.
  • Payment records — kept for up to 6 years after the transaction, as required by UK tax and accounting law (held by Stripe and in our financial records).

9. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to our processing;
  • data portability;
  • withdraw consent at any time (this does not affect processing already carried out).

To exercise any of these, email hello@gramora11plus.co.uk. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

10. Marketing & unsubscribing

We only send marketing emails (the roadmap and 11+ tips) to people who have given consent. Every one of those emails includes an unsubscribe link, and unsubscribing stops the whole sequence immediately. You can also email us to opt out at any time.

11. How we protect your information

We use encryption in transit, access controls and reputable infrastructure providers to protect your data. No system is perfectly secure, but we take reasonable steps to keep your information safe and to limit who can access it.

12. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the date at the top and, where appropriate, notify you.

13. Contact us

Questions, requests or complaints about your data: hello@gramora11plus.co.uk.