Privacy notice
Last updated: 4 September 2026
Morrow Finance, a sole-trader business established in the United Kingdom, is the data controller. Its legal operator is identified in Morrow's Terms of Use. Privacy questions, complaints and rights requests can be sent to privacy@morrowfinance.co.uk or through the privacy enquiry form.
Scope and applicable law
This notice applies to the Morrow website, accounts, learning services, certificates, organisation workspaces, enquiries and, once enabled, paid subscriptions. Morrow handles personal information under the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and applicable amendments, including the Data (Use and Access) Act 2025.
Information we collect
- Account details: first and last name, email address and date of birth.
- Learning records: lesson progress, quiz answers, scores, course status and certificates.
- Organisation records: invitations, organisation name, role, membership, seat allocation and activity available to approved managers.
- Payment records after paid launch: subscription status, plan, renewal information and Stripe customer and subscription references. Morrow does not receive or store full card details.
- Enquiries: name, email address, organisation, enquiry type, message and later correspondence.
- Technical and security records: authentication events, session information, essential cookie values, request timestamps, errors and records reasonably needed to operate, diagnose and protect the service.
Please do not include health information, criminal-offence information or other sensitive personal information in free-text enquiry fields unless Morrow has specifically asked for it and explained why it is needed.
Children and age assurance
Accounts are available from age 13. A self-declared date of birth is used to provide age-appropriate access: under-18 users can use Learn and basic Money but cannot access Markets or analyst-style analysis. Anonymous Markets visitors make an 18-or-over declaration stored in an essential cookie. Morrow does not routinely request identity documents, use children's information for advertising or sell it.
Morrow applies data minimisation, privacy-protective defaults and age-appropriate explanations. A shorter privacy explanation for young people is available. A parent, carer or young person can contact Morrow using the details above.
School, college, university and employer access
If you join an organisation using an authorised invitation, its approved managers can see your name, membership role, lessons completed, quiz scores, course status and last learning activity. They cannot see information entered into private Money tools, your date of birth, password or payment information.
The organisation will normally be a separate data controller for its decision to invite you and use progress reports. Ask it how it uses its copy of that information. Morrow remains responsible for operating the platform and for its own handling of information under this notice. Contract terms with each organisation will document the parties' roles and responsibilities before a live programme begins.
Why we use information and our lawful bases
Where Morrow relies on legitimate interests, those interests are operating a useful and secure educational service, protecting users and Morrow, administering programmes and improving the service. Morrow considers necessity and balances these interests against your rights. You can object as explained below.
Morrow does not currently send direct-marketing emails. If that changes, Morrow will explain the lawful basis and provide an easy opt-out.
Where information comes from
Most information comes directly from you when you register, learn, update an account, join an organisation or enquire. Learning, subscription and security records are created as you use the service. An organisation may provide your email address and intended role when it creates an invitation. Stripe supplies payment and subscription status after paid launch. Morrow does not buy personal profiles or enrich learner accounts with data from brokers or social networks.
Who receives information
Morrow shares only what is necessary with:
- Supabase, for authentication, database storage and account administration.
- Netlify, for production hosting, delivery, logs and service security.
- Resend, for sending website-enquiry notifications, and Zoho Mail, where Morrow receives and answers those messages.
- Stripe, only after payments are enabled, for checkout, subscriptions, fraud prevention and payment administration.
- Your school, college, university, employer or other organisation, if you accept its invitation, as described above.
- Professional advisers, insurers, regulators, courts, law enforcement or public authorities where reasonably necessary or legally required.
- A buyer or successor if Morrow is reorganised, sold or transferred, subject to confidentiality and data-protection requirements.
Morrow does not sell personal information.
International transfers
Some providers may process information outside the UK. Where UK adequacy regulations do not cover a destination, Morrow requires an applicable safeguard, such as the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another lawful transfer mechanism, together with any risk assessment and supplementary measures required. You may ask for more information about relevant safeguards through the privacy enquiry form.
How long we keep information
- Account, learning, organisation membership and certificate records: while the account is active, unless a longer period is needed to provide a verifiable certificate or meet a legal requirement.
- Unused or expired organisation invitations: deleted or anonymised when no longer needed to administer and secure the programme.
- Enquiries and correspondence: normally up to 24 months after the last substantive contact.
- Payment, invoice and transaction records: normally up to six years after the relevant financial year or longer if required for tax, disputes or fraud prevention.
- Security and diagnostic records: only for the period reasonably needed to investigate, protect and maintain the service.
Account deletion removes associated information from the active service, subject to legal exceptions and the certificate choice explained at deletion. Residual encrypted backups are isolated from normal use and expire on the relevant provider's backup cycle. Morrow may retain minimal suppression or legal-claim records where necessary.
Cookies and similar technologies
Morrow currently uses cookies required for authentication, security and the Markets age declaration. It does not currently use advertising or optional analytics cookies. See the Cookie Policy for details and controls.
Automated decisions and profiling
Morrow uses the date of birth or adult declaration to apply access rules and uses quiz answers to calculate learning scores. These functions do not make solely automated decisions that produce legal or similarly significant effects. Morrow does not profile users for targeted advertising.
Your data-protection rights
Depending on the circumstances, you may have rights to be informed; access a copy; correct inaccurate information; erase information; restrict or object to processing; receive portable information; and challenge qualifying automated decisions. You may withdraw consent at any time where consent is the lawful basis, without affecting earlier lawful processing. Some rights have legal exceptions.
You may object to processing based on legitimate interests. Morrow will stop unless it demonstrates compelling legitimate grounds or needs the information for legal claims. You can always object to direct marketing.
You can update details or delete your account through Account Settings, email privacy@morrowfinance.co.uk, or use the privacy enquiry form. Morrow may need to verify your identity and will normally respond within one month. Rights requests are ordinarily free.
Complaints
Please contact Morrow first so the concern can be investigated. Morrow will acknowledge a data-protection complaint and respond without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or telephone 0303 123 1113.
Whether you must provide information
Name, email address, date of birth and a password are needed to create and secure an account and provide age-appropriate access. Without them, Morrow cannot provide an account. Information required at checkout is needed to enter and administer a paid subscription. Enquiries are optional, but a name, reply address and meaningful message are needed for a response. Organisation data is needed only if you use an organisation workspace.
Security and personal-data breaches
Morrow uses access controls, row-level database security, protected server credentials, encrypted connections, restricted administrative access and service monitoring. No online service can promise absolute security. If a personal-data breach requires notification, Morrow will notify the ICO and affected people within the periods required by law.
Changes to this notice
Morrow will update this notice when its services, providers or legal obligations change. The date above shows the latest revision. Material changes will be highlighted on the website or communicated directly where appropriate. Earlier versions may be requested using the privacy contact details.