Privacy policy
What personal data this billing service holds, why, and for how long.
Last updated 2026-09-05
1. Who is responsible
LMS Pay is the controller of the personal data described here. It bills only platforms that hold a written agreement with us, and enquiries reach us through that agreement.
2. What we hold
This service bills businesses, so the personal data involved is limited:
- The name and email address of the billing contact for each platform we invoice.
- Invoice records: amount, currency, billing period, reference, issue date and payment date.
- A transaction reference issued by our payment provider, and whether the payment succeeded or failed.
- The email address and password hash of each person who administers this service.
- Ordinary server logs, including IP addresses, kept for security and troubleshooting.
3. What we do not hold
We do not receive, transmit or store card numbers, expiry dates or security codes. Card details are entered on our payment provider’s hosted page and are never sent to our servers.
We hold no data about the students or customers of the platforms we bill. That data stays in each platform’s own system.
4. Why we hold it
To issue and collect invoices under a contract with you; to keep accounting records we are required to keep; and to secure the service against fraud and abuse.
5. Who we share it with
Our payment provider, to the extent needed to take a payment. Our hosting provider, which stores the data on our behalf. A professional adviser or authority where the law requires it. We do not sell personal data and we do not use it for advertising.
6. How long we keep it
Invoice and payment records are kept for as long as accounting and tax law requires, and then deleted. Administrator accounts are deleted when the person stops administering the service. Server logs are retained for a short operational period and then discarded.
7. Your rights
You may ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. Requests are made through the contact route set out in your platform agreement, and we respond within thirty days.
8. Security
Traffic to this site is encrypted in transit. Administrator passwords are stored as salted hashes and never in readable form. API keys are stored hashed, so a copy of our database does not yield a usable key. Details on the security page.