Legal & policies
Legal information for ClassTycoon.
Terms, privacy information, operator details, refunds, and browser storage.
Version: 2026-08-21-3 · Effective date: 21 August 2026
Using ClassTycoon
Terms
1. Service and users
ClassTycoon is a higher-education classroom simulation for instructors, teaching staff, institutions, and their students. It is not knowingly directed to children. An instructor must be authorized to run each class and provide accurate student access instructions.
2. Accounts and acceptable use
Instructors use verified WordPress accounts. Students use private Student Access Links and are not WordPress users. Users must keep passwords, links, tokens, access codes, and Team join codes private. Users must not bypass security, access another class or Team Company, disrupt a Round, submit unlawful material, or impersonate another person.
3. Plans and payment
The plan, price, currency, quantity, and access shown before purchase form part of the order. Paid seats are credited after Stripe confirms payment. A reserved seat is consumed when Round 1 opens. The Refund Policy applies to purchases.
4. Service, ownership, and responsibility
Hufflelab Sàrl owns ClassTycoon software, scenarios, text, design, and branding except for identified third-party material. Access is limited and non-transferable. We may suspend access to protect users, classrooms, payments, or the service, investigate misuse, or comply with law. We work to keep the service available, but users should keep a backup teaching plan. To the extent permitted by law, Hufflelab Sàrl is not liable for indirect loss, lost profit, or teaching outcomes. Mandatory rights remain unchanged.
5. Law
Swiss law governs these Terms. Mandatory customer and consumer rights, including mandatory rules about where a customer may bring a claim, remain preserved.
Personal data
Privacy Policy
1. Controller and scope
Hufflelab Sàrl is the controller for personal data processed by the ClassTycoon website, classroom application, forms, and purchase fulfilment. Its contact details are in the Legal Notice. An instructor or institution may separately be responsible for the student roster it provides.
2. Data, sources, and purposes
- Accounts and forms: name, email, institution, password hash, account activity, form fields, request category, message, and short-term IP data, supplied by the person or WordPress. We use this data for registration, authentication, support, privacy requests, and abuse prevention.
- Classroom data: session settings, staff links, roster details, Team Company, Round decisions, results, notes, and audit activity, supplied by instructors and students or calculated by ClassTycoon. We use it to operate, explain, secure, recover, and export the class.
- Student access and security: hashed credentials, browser token, IP and browser-signature hashes, expiry, activity, and revocation state, generated from links and requests. We use it to authorize the correct Team Company and prevent misuse.
- Purchases: purchaser details, Forminator entry, Stripe references and status, quantity, amount, currency, receipt, fulfilment, grant, licence, membership, and seat-allocation evidence, supplied by the purchaser, Forminator, Stripe, and ClassTycoon. We use it to process, prove, fulfil, reconcile, and refund purchases.
- Operations: request times, errors, audit events, security signals, logs, and backups, generated by ClassTycoon, WordPress, and WPMU DEV. We use it to secure and recover the service and meet legal duties.
We do not sell personal data.
3. Recipients and countries
Authorized Hufflelab staff and class staff receive only the data needed for their work. WPMU DEV processes website, database, Forminator, email, security, log, and backup data in Frankfurt, Germany, with backups in the same general EU region. Stripe processes payment data through its responsible entities in Switzerland and Ireland and may use providers in the United States and other countries in its current service-provider list. Where required, Stripe relies on the Swiss-U.S. Data Privacy Framework or adapted Standard Contractual Clauses. Data may also be disclosed to professional advisers or public authorities where lawfully required.
4. Retention
- Registration, support, and public contact submissions: 24 months; Forminator IP data: 30 days. Login submissions are not saved.
- Completed or archived classrooms: 24 months from their first completion or archive date. Abandoned drafts: 24 months after the last update. Active classrooms are not automatically deleted.
- Student IP and browser-signature hashes: 90 days. Expired or revoked credential hashes are cleared.
- Purchase, payment, fulfilment, grant, licence, membership, and consumed-allocation evidence: 10 years after the transaction or entitlement ends, or longer for an active entitlement, dispute, or legal hold.
- WPMU DEV host logs: 7 days. Daily and manual backups: up to 30 days. A restored backup must have any prior deletion applied again.
5. Your rights
You may request information, access, correction, delivery, or deletion where Swiss law provides it. Use the contact form and choose the matching privacy category. We verify identity and normally respond within 30 days. We will explain any data retained for an active class, payment, entitlement, dispute, legal hold, security, or accounting requirement.
Operator
Legal Notice
- Operator and data controller
- Hufflelab Sàrl, Société à responsabilité limitée
- Postal address
- Case postale 663
Avenue du Général-Guisan 4
1800 Vevey 1
Switzerland - Swiss UID
- CHE-423.645.552
- VAT
- Not subject to VAT under article 10 of the Swiss VAT Act
Payments
Refund Policy
Swiss law does not provide a general change-of-mind right for online purchases. ClassTycoon voluntarily refunds a purchase when the request is received within 14 calendar days after Stripe’s recorded payment time and no seat from that purchase has been consumed by opening Round 1. Reserved seats may first be released. This policy does not limit mandatory rights concerning a defective service, incorrect charge, fraud, or another right that cannot be excluded.
Use the contact form and choose “Refund or purchase question.” Use the purchaser’s email address and include the order date and receipt reference. Never send card details.
Questions and privacy requests
Contact
Use this form for a privacy, refund, purchase, or legal question. We will reply to the email address you provide. Do not include passwords, Student Access Links, bearer tokens, Team join codes, card details, or identity documents in the first message.