Train Aid Solutions
Log in Get started

Privacy policy

How Train Aid Solutions handles personal data.

Last updated: 27 July 2026

Who we are and our role

Train Aid Solutions ("TAS", "we") provides a platform that UK classroom-based training businesses use to run attendance registers, issue verifiable certificates, collect feedback, and send renewal reminders.

For a learner's training records, the training business is the data controller and TAS is the data processor acting on its instructions. For our own account holders' details and our website, TAS is the controller. If you are a learner, the training business that trained you is your first point of contact for any data request.

What we collect and why

  • Account holders (Admins, Instructors): name, email, and a securely hashed password — to provide access to the platform. Lawful basis: contract.
  • Learners: name, email, an optional organiser/L&D contact email, attendance, assessment outcomes, instructor notes, and feedback responses — to maintain training records, issue certificates, and send renewal reminders. Lawful basis: the training business's legitimate interest in maintaining compliance records.
  • Certificates: name-bearing PDFs that can be verified via a QR code / verification code. The public verification page deliberately shows a redacted name (first name and last initial only) alongside the course, dates, and validity — never an email address or full personal details.
  • Historical records: a training business may import its past training records into the platform. The same controller/processor split applies — the business remains the controller of those records, and no emails are sent to imported learners as part of an import.
  • Email logs: a record of transactional emails sent (or deliberately suppressed) — so a business can prove what was and wasn't sent.
  • Payments: subscription payments are handled by Stripe; we store only Stripe reference IDs and invoice records for VAT receipts, never card details.

Learners under 16

We deliberately minimise data held about minors. When a learner is under 16, the platform does not store the learner's own email address — all correspondence goes to a responsible organiser (for example a parent or the booking organisation), whose email is required instead. Under-16 learners receive an attendance-style certificate that carries no public verification record.

Cookies and storage

We use no analytics, advertising, or tracking cookies. The only browser storage we use is strictly necessary to keep you logged in (a short-lived session token and your business context, held in your browser). Because this storage is essential to the service, no cookie-consent banner is required.

How long we keep data

  • Active learners — where a learner has attended a course in the last 37 months — are retained so renewal reminders keep working (most certificates run up to three years).
  • Records with no certificate issued (e.g. no-shows) are deleted once a learner has had no course activity for 37 months.
  • Certificated records are kept while relevant, then anonymised — personal identifiers removed while the certificate record and its verification code are retained — once the certificate has been expired for 36 months. They are not deleted outright because the certificate underpins QR verification. Certificates issued without an expiry date remain valid, and are retained, indefinitely.
  • Email logs are kept for up to 37 months from last activity.
  • If a training business closes its account, its data is retained securely so the account can be reactivated, and every certificate it issued remains publicly verifiable — closing an account never invalidates a learner's certificate.

Who we share data with

We use a small number of sub-processors to run the service: DigitalOcean (hosting, database and file storage — located in London, UK), Postmark (transactional email), and Stripe (payments). Each processes data only to provide their part of the service. We do not sell personal data.

Email delivery and payment processing involve providers with operations in the United States; those transfers are covered by the providers' standard contractual safeguards for international data transfers. The platform's database and files themselves stay in the UK.

Your rights

You have the right to access, correct, or erase your personal data, and to object to or restrict its processing. Training businesses can export a learner's full data or erase it directly from within the platform. Where erasure is requested for someone with an issued certificate, the certificate record is anonymised rather than deleted, so historical verification isn't broken.

How we protect data

Data is encrypted in transit (TLS) and at rest, passwords are hashed with bcrypt, and access is scoped so each business can only see its own data. Payment card details are handled entirely by Stripe.

Contact

For any privacy question or to exercise your rights, contact us at [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ICO).