Privacy Policy
Last updated: August 2026
1. Who We Are
Classroots ("we," "our," or "the Service") is a multi-tenant platform for community religious and cultural weekend schools. Your organization ("School") uses Classroots to manage student records, attendance, grades, and communication.
2. Information We Collect
Account Information
When you create an account we collect your name, email address, and optional phone number.
Student Records
Administrators and teachers enter student attendance, grades, conduct notes, and assignments. Parents may also provide custom registration information requested by their school.
Usage Data
We collect standard server logs (IP address, browser, pages visited) to operate the service and detect abuse. For certain administrative actions (e.g. approving a registration, exporting data, suspending an account), we also record an audit log entry containing the acting user, the action taken, a timestamp, and the IP address and browser used — this audit trail is visible to other administrators within the same organization, so they can see who took a given action.
Cookies
The web application uses a strictly-necessary session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.
Push Notification Tokens
With your permission, we store device tokens to send attendance alerts, grade notifications, and messages.
3. How We Use Information
- To provide, operate, and improve the Service
- To send you notifications you have opted into
- To generate attendance reports and report cards
- To respond to support requests
- To comply with legal obligations
We do not sell your personal information to third parties.
4. Data Isolation
Each organization's data is fully isolated. Users in one organization cannot access data from another. All database queries are enforced at the row level by Supabase Row Level Security policies.
5. Children's Privacy
Classroots is a platform for educational institutions that serve minors. Children do not create their own accounts or enter their own data — all student records are entered and managed by verified parents, guardians, or school administrators. We do not knowingly collect personal information directly from a child.
Because Classroots operates in multiple countries, "child" and the applicable consent requirements depend on where your school is located:
- United States (COPPA): we comply with the Children's Online Privacy Protection Act for children under 13. We do not knowingly allow a child under 13 to create their own account.
- India (Digital Personal Data Protection Act, 2023): the DPDP Act defines a child as anyone under 18 and requires verifiable parental consent for processing a child's personal data. For schools operating in India, we treat every student record as belonging to a child under this standard, and rely on the parent/guardian's consent given at registration as that verifiable consent.
For every school, regardless of country:
- Parental consent is obtained at the time a parent registers their child or links to a student account, either via the registration form, invite code, or direct admin linking.
- Parents may review all information held about their child by contacting their school administrator or emailing privacy@getclassroots.com.
- Parents may request deletion of their child's data at any time by contacting their school administrator or emailing privacy@getclassroots.com. Deletion requests will be processed within 30 days.
- School administrators are responsible for ensuring that only verified parents and guardians are granted access to student records.
6. Data Retention
Account and student data is retained for the lifetime of the organization's subscription. After an account is deleted, personally identifying information is anonymized within 30 days. Backups may retain data for up to 90 days.
7. Your Rights (GDPR / CCPA)
Depending on your jurisdiction you may have rights to access, correct, export, or delete your personal data. To exercise these rights, contact your school administrator or email us at privacy@getclassroots.com.
8. Security
All data is transmitted over HTTPS. Passwords are hashed by Supabase Auth. We use Cloudflare for DDoS protection and global CDN delivery of files.
9. Third-Party Services
- Vercel — web application hosting
- Supabase — database hosting and authentication
- Cloudflare R2 — file storage
- Firebase / FCM / APNs — push notifications
- Resend — transactional email
- Sentry — error monitoring (no PII in error reports)
- PostHog — product usage analytics (no PII, session recording disabled)
10. Changes to This Policy
We will notify organization administrators of material changes by email at least 14 days before they take effect.
11. Contact
Questions? Email us at privacy@getclassroots.com.