Last updated: 10 February 2026
This policy explains how Nightingale Notes (“we”) collects and uses your personal data when you visit the site or buy a study guide. It is written to meet the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Nightingale Notes is the data controller for personal data collected through this site. Contact: privacy@nightingalenotes.co.uk.
We do not sell your data, and we do not run behavioural advertising.
Payments are processed by Stripe Payments UK Ltd. Card data is submitted directly to Stripe on their PCI-DSS-compliant systems. We receive only a token and status. Stripe processes your data under its own privacy policy: stripe.com/privacy.
Receipt and service emails are sent via Resend. Resend processes your email address and message content on our behalf under our instructions: resend.com/legal/privacy-policy.
We use a small number of strictly-necessary cookies to keep you signed in (a session token cookie for Google logins) and to remember your basket in local storage. We do not use advertising or analytics cookies.
Under UK GDPR you have the right to:
To exercise any right, email privacy@nightingalenotes.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
Some of our processors (including Stripe and Resend) may transfer data outside the UK. Where they do, they rely on the UK International Data Transfer Agreement or an adequacy decision to protect your data.
We use HTTPS across the site, hashed passwords, tokenised sessions, and access controls on our backend and database. No online service can be 100% secure — if you suspect misuse of your account, contact us straight away.
We will post updates to this page with a new “Last updated” date. Material changes will also be communicated by email where reasonable.