Privacy Policy
Last updated: August 13, 2026 · Effective: August 13, 2026
Classrin is built for K-12 schools, and student privacy is a design requirement, not an afterthought. This policy explains what we collect, how we use it, how we protect it, and the rights available to students, parents, and school administrators.
1.Introduction & Scope
Classrin ("Classrin," "we," "our," or "us") provides academic scheduling, communication, and school-support software for students, teachers, and school districts. We are committed to protecting the privacy and security of every user, with heightened protections for students and minors.
This Privacy Policy applies to the Classrin websites, applications, and services (collectively, the "Services"). By using the Services, you acknowledge the practices described here. Where a school or district has a separate written agreement or Data Privacy Agreement (DPA) with us, that agreement governs student data and controls if it conflicts with this policy.
2.Our Role & Legal Basis for Processing
When Classrin is used in a school setting, the school or district is the owner and controller of student education records, and Classrin acts as a "school official" with a legitimate educational interest under FERPA and as a service provider processing data solely on the school's behalf and under its direction.
We process personal information on these bases: (a) to perform our agreement with the school or user; (b) with school authorization or verifiable parental consent for students; (c) to meet legal obligations; and (d) for limited legitimate interests such as securing the Services, that never override student protections.
3.Information We Collect
A. Information you or your school provides
- Identity & contact: name, email address, and (optionally) phone number
- Academic information: student or staff ID, schedule and course data, class preferences, and related selections
- Roster data: identity, role, school, and enrollment details provided through district rostering (e.g., ClassLink or OneRoster)
- Content you create: messages, posts, club/board activity, support requests, and feedback
- Account credentials: login email and authentication identifiers (we support district single sign-on, so no separate password is required for SSO users)
B. Information collected automatically
- Device and browser information
- Log and diagnostic data (e.g., IP address, timestamps, error logs)
- Usage data (features accessed, time spent, interaction patterns) for operating and improving the Services
- Strictly necessary cookies and similar technologies (see Section 15)
We practice data minimization: we request only the fields needed to deliver the Services, and we support privacy-masking of non-essential fields where a district's rostering provider offers it.
4.How We Use Information
We use information only for educational, operational, and service-related purposes, including to:
- Provide, maintain, and secure the Services
- Personalize scheduling and school-related features
- Support school-authorized educational activities
- Monitor performance, debug, and improve functionality
- Detect, prevent, and respond to security incidents, fraud, or misuse
- Provide customer and technical support
- Comply with legal obligations and enforce our Terms
5.What We Never Do
We never sell, rent, or trade student data.
- We do not use student data for targeted advertising or to build advertising or commercial profiles.
- We do not use student data for any non-educational commercial purpose.
- We do not retain, use, or disclose student data beyond what the school authorizes or the law permits.
- We do not use automated decision-making to profile students for advertising.
These commitments reflect the principles of the Student Privacy Pledge and the requirements of SOPIPA-style state laws.
6.Compliance & Commitments
We design the Services to align with the leading federal and state student-privacy frameworks, including:
- FERPA — the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g)
- COPPA — the Children's Online Privacy Protection Act, for users under 13
- PPRA — the Protection of Pupil Rights Amendment
- SOPIPA and the 100+ comparable state student-data-privacy laws adopted across the U.S.
- Applicable state consumer-privacy laws (e.g., the CCPA/CPRA in California) for non-student, adult users
Classrin is an independent product and describes its commitments and alignment with these frameworks. Where we hold a formal third-party certification or have signed a district's DPA, we will state so specifically in that agreement.
7.How We Share Information
We share personal information only in these limited situations:
A. Service providers (subprocessors)
Trusted vendors who host, secure, and operate the Services under contract. Each is bound to confidentiality and to protect data consistent with FERPA and COPPA, and may use data only to provide services to us. See Section 8.
B. At your school's direction
If a school or district instructs us to access, export, transfer, or delete data, we act on that instruction.
C. Legal compliance & safety
To comply with applicable law, lawful requests, or legal process, and to protect the rights, safety, and security of users, the public, or Classrin.
D. Business transfers
If Classrin is involved in a merger, acquisition, or asset sale, affected schools will be notified, student data will remain subject to this policy and any DPA, and districts retain all FERPA rights.
8.Subprocessors
We rely on a small set of vetted infrastructure providers. The current list is:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, storage, and backend hosting | United States |
| Vercel | Website and application hosting / content delivery | United States |
| Stripe | Payment processing for optional school commerce features | United States |
| ClassLink / OneRoster providers | Single sign-on and district rostering (at the district's direction) | United States |
We maintain agreements with each subprocessor requiring appropriate security and privacy protections. We update this list as our providers change; material changes affecting student data are communicated to schools under their DPA.
9.Data Security
We apply administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption in transit (TLS) and at rest
- Row-level access controls and the principle of least privilege
- Authentication via district SSO and scoped access tokens
- Audit logging and monitoring of sensitive operations
- Secure, reputable data-center and cloud partners
- Content moderation and safety controls on user-generated content
- Regular review of access, dependencies, and configuration
No method of transmission or storage is 100% secure, but we work to meet or exceed industry-standard practices and to improve continuously.
10.Data Breach Notification
If we discover a security incident that compromises personal information, we will investigate promptly, take steps to contain and remediate it, and notify affected schools or districts without undue delay and consistent with our contractual obligations and applicable law. For students, we notify the school so it can fulfill its notification duties to parents and authorities.
11.Data Retention & Deletion
- We retain personal information only as long as necessary to provide the Services or as required by a school agreement or law.
- A school may request access, export, or deletion of its data at any time. We will complete deletion requests within 30 days unless a longer period is legally required.
- Residual copies may persist in secure backups for up to 90 days and are not used for any operational purpose before being purged.
- On termination, student data is deleted or returned per the school's instruction and any DPA.
12.Your Rights
Students, parents, and school administrators may request to:
- Access the personal information we hold
- Correct inaccurate information
- Delete information
- Export information (portability)
- Restrict processing for non-educational purposes
Because schools control student records, student and parent requests are generally directed through the school administrator, who may act on the student's behalf. You can also contact us at grant@classrin.com and we will coordinate with your school. We do not discriminate against anyone for exercising these rights.
13.Children Under 13
For students under 13, Classrin collects personal information only with school authorization (acting under COPPA's school-consent provisions) or with verifiable parental consent. We do not knowingly collect personal information from children under 13 outside of these authorized channels. If you believe a child provided information without proper authorization, contact us and we will delete it.
14.California & State Privacy Rights
For student data, we comply with SOPIPA and comparable state laws: we do not sell student data, do not use it for targeted advertising, and do not create non-educational profiles. For adult, non-student users in California, the CCPA/CPRA gives rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information — and we do not sell or share personal information as those terms are defined. Residents of other states with similar laws have comparable rights. Submit requests to grant@classrin.com.
15.Cookies & Tracking
We use strictly necessary cookies and similar technologies to keep you signed in, maintain security, and operate core features. We do not use third-party advertising or cross-site tracking cookies for students. Schools and users may restrict cookies through browser or device policies, though some features may not function without them.
16.Data Location
Classrin and its subprocessors store and process data in the United States. If we ever process data elsewhere, we will apply appropriate safeguards and update this policy.
17.Changes to This Policy
We may update this policy to reflect changes in our practices, technology, or the law. Material changes affecting student data will be communicated to schools. Updated versions carry a new "Last updated" date, and continued use of the Services after an update constitutes acceptance of the revised policy.
18.Contact Us
Questions, requests, or privacy concerns:
Classrin — Privacy
Email: grant@classrin.com
Address: Charleston, SC, USA