Privacy and choices
MathHill provides one-to-one online math tutoring and free practice activities. This page explains information handling on this website.
MathHill is an independently operated tutoring service based in Texas, USA. Misha Deen is our public teaching name. This notice covers mathhill.com. You can send privacy questions to hello@mathhill.com or call (832) 852-0403.
Enquiries and contact
Our contact form asks for your name, email, your child's grade, a message, and an optional phone number. We send these details through Resend to the MathHill inbox so we can respond. Please use a parent or guardian's contact details and avoid sensitive information or unnecessary details about a child.
The website does not save a separate database of submissions. Email copies remain with Resend and our Gmail inbox. Calling, texting or emailing us directly also sends information through your communications provider and ours.
The form uses a hidden spam field, a signed form timestamp, and a temporary limit on repeated requests. For that limit, the server holds a salted representation of an IP address with a count and expiry time. The limit expires after ten minutes; expired entries are removed when another request is handled, or when that server instance ends. We do not send these values to our analytics service.
Resend privacy policyGoogle privacy policyBooking a session
The booking page loads a calendar from Cal.com. Loading or using it connects your browser to Cal.com, which receives connection information and the details you enter, and may use its own cookies or storage. MathHill receives booking information to arrange your session. Cal.com's privacy policy applies to its service.
Our available meeting services are Cal Video (powered by Daily), Google Meet and Zoom. The current free-assessment calendar offers Zoom Video. The service used for your booking processes the connection and meeting information needed to provide the call; your booking details identify which service to use. Calendar invitations and notifications can create separate copies of booking information.
You can contact us by email or phone if you prefer to arrange a session that way. Our analytics preference controls MathHill's optional analytics; it does not control the Cal.com calendar.
Cal.com privacy policyDaily privacy policyGoogle privacy policyZoom privacy statement
Optional website analytics
When enabled, optional analytics run on our home, booking, contact and privacy pages unless you refuse or Global Privacy Control is on. We use PostHog's US service to understand how our parent-facing tutoring website is found and used, improve its content and reliability, and measure enquiries and browser-observed booking steps. You can use the website with analytics refused.
We collect the page path, event time, fixed link/control and section labels, scroll milestones, estimated foreground activity time, form steps and fixed field/error categories, calendar readiness and fallback, and bounded page, calendar and form timings. We also collect supported web-performance measures and fixed application-failure categories, without error messages, stack traces or console contents.
For five named booking/contact links, we record an exposure when at least half the control is visible for one continuous second while the page is in the foreground. We also detect three clicks within one second on those links or the contact submit button, sending at most one repeated-click record per control per page. This is a heuristic that may suggest difficulty, not proof of frustration. Detection stays on reviewed parent-page controls and excludes editable fields, typed values, the calendar's contents and playgrounds. We do not automatically treat slow loading as a dead click or send individual click timestamps, pointer coordinates or DOM text.
Technology fields include window-width class, estimated mobile/tablet/desktop device type, browser and operating-system family and major version when available, and a broad browser-language code. These are estimates: a narrow desktop window remains a desktop estimate, and some devices or versions are unknown. We do not include raw user-agent strings, device models or fingerprinting identifiers.
A small first-party request obtains approximate country, state/region and city from Vercel's connection metadata. Vercel derives this from the connection's IP address. It can be wrong because of VPNs, mobile networks and routing; it does not establish your home or physical location. Unavailable or invalid information is unknown. We do not request GPS permission or collect coordinates, postcode or a street address for analytics. The result stays in document memory before being included in parent events; responses cannot be shared through a cache. Refusal/GPC prevents this lookup, and leaving eligible pages or withdrawal cancels pending work.
Acquisition fields use a reviewed referring-site category, root domain or fixed service domain and approved campaign source, medium, name and content labels. Reviewed sources include search engines, social sites such as Reddit, TikTok and Nextdoor, and recognized AI-assistant referral domains when the browser supplies them. We exclude full referrer URLs, personal or unapproved campaign text, ad click IDs, unrelated query parameters and fragments. Missing referral information is labelled direct or unknown, because a browser may hide it; we do not guess which service was used.
On parent pages, we store a random first-party browser ID for repeat-visit estimates and a random session ID to connect pageviews and actions. We stop reusing the browser ID after 90 days from creation. A session ends after 30 minutes without recorded activity or after 24 hours. First observed attribution is kept within the browser ID's lifetime; entry and latest attribution describe the current session's entry, including a direct or unknown source. IDs, visit counts and these limited attribution fields use browser local storage. If storage is blocked, estimates are limited to the current document. We do not connect devices, use your contact details as analytics IDs, or create PostHog person profiles. The events remain pseudonymous, not legally anonymous.
When our email provider accepts a genuine contact message, a separate total uses a fresh random record ID with no browser/session or device/location fields. If parent analytics are allowed, an additional acceptance event uses validated random browser, session and submission IDs to connect that acceptance to the parent journey. No typed form values enter either event. Acceptance is not proof of delivery, a qualified enquiry or a sale. The unlinked total cannot support a device/country conversion funnel.
Supported calendar callbacks can report booking creation, cancellation or rescheduling in an open embedded calendar. A created booking can still be pending confirmation; we retain only fixed status/payment-required categories, not attendee details, booking answers or meeting links. These observations are incomplete if a callback is blocked or the calendar is closed. We do not infer attendance, payment or enrolment from them.
When the separate server booking integration is enabled, Cal.com sends signed booking notifications to MathHill. We validate them and send PostHog only fixed creation, request, status, cancellation or rescheduling categories, notification time, and protected booking-record keys for duplicate detection and status changes. We do not forward attendees, answers, appointment times, meeting links or the raw notification. These operational totals are unattributed: they do not contain parent browser/session IDs, devices, location or campaign fields and are not joined to parent journeys. A browser preference is not available in these server notifications, so the website analytics choice does not control these separate booking-service totals. Contact us about booking information or privacy requests.
Reports describe observed events, sessions and estimated browsers, not verified people or exact attention. Shared devices, cleared storage, refusal, blockers and failed delivery affect coverage. We use fixed scroll/section milestones rather than continuous mouse or scroll records. We do not enable session recordings, heatmaps, unrestricted autocapture, surveys, experiments or advertising profiles.
Enquiry conversion reports match genuine email-provider acceptance to observed parent attempts and show their sample counts and observation windows. Time-to-enquiry reports use the first visit we can observe within a bounded history, not a verified person's first visit. Engagement and performance comparisons show associations and do not establish that one caused an enquiry. CTA reports use matching observed visibility where available; missing attribution or exposure stays unknown.
Parent-page requests expose a network IP address to PostHog before its storage controls apply. Our project is configured to discard client IPs and disable PostHog's GeoIP enrichment; location estimates instead come from Vercel. We have opted out of PostHog's optional Product and Model Development use of our customer content and restrict access to authorized people.
Refusal or GPC stops new optional browser events, linked and unlinked contact analytics, and playground counts, and clears the parent analytics IDs. It discards pending browser work but cannot recall a request already sent or delete historical events. The controls below apply to this browser and remain available through every page's Analytics preferences link.
PostHog privacy policyChildren and practice activities
Our home, booking and contact pages are intended for parents and guardians. Children are encouraged to use the practice activities at Playgrounds. We do not load the PostHog browser SDK on those pages or collect answers, scores, questions, hints or other practice actions.
When enabled, we count openings of the playground index and fractions activity to understand usage volume and operate the existing activities. A small request sends only a fixed page label to MathHill's server. Our server sends PostHog a count of one, the page label, a date rounded to the UTC day, and a new random record identifier for each count. It does not forward the visitor's IP address, browser details, cookies, referrer, URL query or a visitor identifier. PostHog also receives server-library and delivery metadata. These are approximate opening counts, not counts of individual children or learning progress.
These counts are kept separate from parent enquiry analytics and are not used for marketing attribution, advertising, profiling or measuring learning outcomes. Playground pages do not read parent analytics IDs, perform the analytics location lookup, or add technology, location or campaign fields to their counts. The analytics preference above also controls them. Parent-page analytics excludes detected journeys arriving from the playground and history restores that cross that boundary. Parent-only reloads and history navigation can remain in the same session.
Ordinary hosting and security processing still occurs when a page or image is requested. Parents may give us information about a child in an enquiry or booking. If you believe a child has sent personal information that should be removed, please contact us. An analytics choice is not age verification or parental consent.
Hosting, security and sharing
Our hosting service processes connection and request information to deliver the website and protect it from abuse. This can include an IP address, browser information, requested address and request time, including on playground pages. Avoid putting personal information into website addresses.
Our current deployment uses Vercel, with no Vercel log drains configured. Fonts are served as website files; visiting the site does not request them from Google. Our application does not log contact-form contents, country-lookup payloads, playground counter payloads or provider error messages.
The providers described here receive information to deliver their services. This analytics setup does not send information to advertising networks or use it to build advertising profiles.
Vercel privacy noticeStorage and privacy requests
We stop using a remembered browser ID after 90 days and a session ID after 30 minutes of inactivity or a 24-hour maximum. Expired local-storage records are replaced or removed on a later eligible visit; browser storage has no automatic physical-expiry mechanism. Refusal/reset or clearing site data removes these local IDs. This does not delete events already sent to PostHog. The preference cookie lasts up to one year. Emails, booking records, provider logs and analytics events have separate storage and deletion arrangements with their respective services.
- PostHog: our Free plan has a documented one-year event-query window where PostHog enforces it. This is not a guarantee that stored events are physically erased after one year. We have not verified selective deletion for our events without person profiles. If you request deletion, we assess what we can locate and use available provider processes; we do not promise removal that we cannot confirm.
- Contact emails: our policy is to review closed enquiries monthly and delete those more than 12 months past the last interaction. Deleted Gmail messages can remain in Trash for up to 30 days unless removed sooner.
- Resend: standard email-data retention is 30 days. Resend separately describes a 30-day backup period. We use its routine retention process and can request earlier removal through its support team.
- Cal.com: its published default keeps account and booking data while the account is active. We use available deletion controls or contact its privacy team for removal requests. Deleting a booking there does not necessarily delete copies in connected calendars or other services.
- Hosting: our Vercel Pro runtime logs have a one-day retention window. This is not a promise that every security record or provider backup is erased within one day. Exceptional deletion requests are raised with Vercel.
Gmail deletionResend retentionResend backupsVercel runtime logsPostHog retention
For questions about those arrangements, access, corrections or deletion, email hello@mathhill.com or call (832) 852-0403. Please describe your request without sending unnecessary sensitive information. We may need information to locate a record and verify the request. Random browser IDs may help locate parent events while available, but we may be unable to connect older or unlinked records to you. We do not ask for identity documents or a child's birthdate as a routine analytics shortcut.
We will update this page when our website's information practices change.
Contact MathHill