(Legal · last updated 7 August 2026)
Privacy
(Template notice · delete this block)
This page is scaffolding, not legal advice. If you take payments you almost certainly have obligations under GDPR, UK GDPR, CCPA or an equivalent. Replace this with a policy that names your real processors and lawful bases, and check it against the tools you actually use.
Your name and email when you enrol. Payment details are handled by our payment processor and never reach our servers. If you submit work during the course, we hold it for as long as the cohort runs plus the review period.
To deliver the course you paid for, to send you session details and critique, and to meet our tax and accounting obligations. We do not sell anything to anyone.
Payments are processed by [your processor]. They act as an independent controller for the card data they hold. We only ever see the last four digits and the outcome of the transaction.
The tools that run the course: [list your processors, for example the email provider, the cohort chat, the video host]. Each is bound by its own agreement with us. Nobody outside that list gets your data.
Course records for as long as you are a student plus twelve months. Financial records for as long as tax law requires, usually six or seven years. Marketing emails only until you unsubscribe.
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Email hello@raster.school and we will respond within thirty days. You can also complain to your local data protection authority.
This site uses only what it needs to function. If you add analytics, advertising or session recording, say so here and get consent before loading them.