We use cookies
We use essential cookies to keep you signed in, and optional analytics cookies to improve the platform. Your affiliate referral is tracked via URL parameters, not cookies. Cookie policy
How we collect, use, and protect your personal data. Compliant with UK GDPR and the Data Protection Act 2018.
Last updated: March 2026
Lesso ("we", "us", "our") is the data controller for personal data processed through lesso.app. For data protection queries, contact us at privacy@lesso.app.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data correctly.
| Data | Lawful Basis | Purpose |
|---|---|---|
| Name, email address | Contract | Account creation, authentication, communications |
| Payment details (card via Stripe) | Contract | Processing subscription payments — card data never touches our servers |
| Course content (creators) | Contract | Hosting and delivering courses to subscribers |
| Discussion posts (learners) | Contract | Providing community features within courses |
| Bank/payment details (creators, affiliates) | Contract | Processing manual monthly payouts |
| Usage data (pages viewed, session data) | Consent | Improving the platform with Vercel Analytics — only collected after you accept analytics cookies. |
| Affiliate referral data | Contract / Consent | Tracking referral attribution for commission purposes |
| IP address | Legitimate interest | Security, fraud prevention, and abuse detection |
| Marketing preferences | Consent | Sending promotional emails (you can unsubscribe at any time) |
| Conversion event data (pseudonymous browser ID) | Consent | Sent to X (Twitter) when a creator publishes a course — only if marketing cookies are accepted |
We do not sell personal data to third parties. We share data only with service providers necessary to operate the platform:
Creator earnings data is visible only to the creator and to Lesso staff for payout processing. Affiliates can see which creators they referred and aggregated revenue data — they cannot see individual learner data.
You have the following rights regarding your personal data. To exercise any of them, email privacy@lesso.app. We will respond within one calendar month.
Some of our service providers (including Stripe and Vercel) may process data outside the UK. Where this occurs, we rely on Standard Contractual Clauses or UK adequacy decisions to ensure appropriate safeguards are in place.
The platform is not directed at children under 16. If we become aware that a child under 16 has provided personal data without appropriate consent, we will delete it promptly.
We implement appropriate technical and organisational measures to protect your data, including: TLS encryption in transit; secure credential storage (we use magic link authentication — no passwords stored); access controls on internal systems; and regular security reviews.
Card payment data never touches our servers — it is handled directly by Stripe.
We will notify you and the ICO of any data breach that poses a risk to your rights and freedoms within 72 hours of becoming aware of it.
See our Cookie Policy for full details on the cookies we use and how to manage your preferences.
Data protection queries: privacy@lesso.app
ICO complaints: ico.org.uk