Privacy policy
Last updated 10 September 2026 · Primary Coding League CIC, trading as Primary Coding Hubs
This policy explains what personal data we collect when you use this website (www.primarycodinghubs.co.uk) and the Curriculum Builder, why we collect it, and the choices you have. We keep it short and plain because we collect very little.
Who we are
Primary Coding Hubs is a service of Primary Coding League CIC, a Community Interest Company registered in England and Wales. We are the data controller for the data described here. You can contact us at community@primarycodinghubs.co.uk.
What we collect and why
Contact form and email
When you use the contact form we receive the name, email address, organisation and message you type. The form is delivered to our inbox by FormSubmit (formsubmit.co), which processes it on our behalf. We use it only to reply to you and to arrange the outreach, equipment loan or training you asked about. We keep contact messages for up to two years, then delete them.
Website hosting
The site is hosted on Cloudflare Pages. Cloudflare records standard server logs (IP address, browser type, pages requested, timestamps) to keep the service running and secure. We do not use analytics or advertising cookies, and we do not track you across other sites.
Curriculum Builder
The Curriculum Builder runs entirely in your browser. There is no account to create. The details you enter (school name, subject lead, class structure and unit choices) are saved only in your browser's local storage so you can come back to your plan; they are never sent to us. The documents in your pack are generated on your device.
When you download slide decks, worksheets or quizzes from Oak National Academy through the builder, your request passes through a small relay on our hosting so the file can be fetched and named for you. The relay does not log who requested what beyond Cloudflare's standard server logs, and it stores nothing about you.
When payment is introduced, checkout will be handled by Stripe, and we will update this policy before that happens.
Google Forms feature and Google user data
In short: if you choose "Create quizzes in Google Forms", the Curriculum Builder asks your permission to create quizzes in your own Google Drive. It never sees, reads, stores or shares anything already in your Google account.
The Curriculum Builder can turn Oak National Academy starter and exit quizzes into Google Forms quizzes for you. This is optional. If you use it:
- What we ask for. We request the Google Forms "create and edit forms" permission (the
forms.bodyscope). We ask for no other Google permission. - What we do with it. Your browser creates new Google Forms in your Drive and fills them with the quiz questions, answers and points from the pack you built. The forms belong to you from the moment they are created.
- What we do not do. We do not read, list, change or delete any existing forms or files in your account. We do not use Google user data for advertising, profiling, or training artificial-intelligence or machine-learning models, and we never sell it.
- Where the data goes. Everything happens between your browser and Google. The access token Google issues is held in your browser's memory only for the sign-in session; it is not stored, and it is never sent to Primary Coding Hubs or to anyone else.
- Sharing. We do not share Google user data with any third party, and we do not transfer it to our own servers.
- Retention and deletion. Because we hold no Google user data, there is nothing for us to retain or delete. The quizzes stay in your Drive under your control. You can remove the builder's access at any time at myaccount.google.com/permissions.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect Google user data
The Google Forms permission is classed by Google as sensitive, so this section sets out exactly how that data is protected, even though our design means we never hold it.
- Encryption in transit. Every request from the Curriculum Builder to Google (sign-in, creating a form, adding questions) is made over HTTPS (TLS 1.2 or later) directly from your browser to Google's servers. The website itself is served only over HTTPS, and Cloudflare redirects any insecure request to the secure address.
- No storage at rest. Primary Coding Hubs has no server, database or file store that receives Google user data. The access token is kept in your browser's memory for the sign-in session only. It is never written to cookies, local storage, our hosting, our logs or any backup, so there is no copy for us to encrypt, lose or leak.
- Least privilege. We request a single scope (
forms.body) and use it for only two operations,forms.createandforms.batchUpdate, on a form the app has just created. Tokens are short-lived and are issued for that scope alone, and the app never requests offline access or refresh tokens. - Access controls. No member of our team can see Google user data, because it never reaches us. The Google Cloud project and the Cloudflare hosting account are protected by strong passwords and two-step verification, and access is limited to the named staff who maintain the site.
- Secure development. The Curriculum Builder is a static, open web application whose source is version-controlled. The document-generation libraries it uses are fixed versions served from our own site, the Google sign-in library is loaded directly from Google, and changes are reviewed and tested before release.
- Incident response. If we ever became aware of a security incident affecting Google user data, we would notify affected users and Google without undue delay, and the Information Commissioner's Office within 72 hours where UK law requires it, and we would revoke the affected credentials.
- Retention and deletion. We retain no Google user data. Your quizzes live in your Google Drive, where you can edit or delete them, and you can revoke the builder's access at any time at myaccount.google.com/permissions. Closing the browser tab discards the access token.
Cookies and local storage
The website sets no cookies of its own. The Curriculum Builder uses your browser's local storage to remember your plan; clearing your browser data or pressing "Start again" removes it. Embedded Google sign-in uses Google's own cookies under Google's privacy policy.
Children
This website and the Curriculum Builder are for teachers, school leaders and adults who work with young people. We do not knowingly collect personal data from children. Our outreach work with children is covered by our safeguarding policy and the consent arrangements agreed with each school or group.
Your rights
Under UK data protection law you can ask us for a copy of the personal data we hold about you, ask us to correct or delete it, or object to how we use it. Email community@primarycodinghubs.co.uk and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk.
Changes to this policy
If we change how we handle data, we will update this page and the date at the top. Significant changes will be flagged on the Curriculum Builder itself.