Privacy Policy
Effective Date: 1 March 2026
SchoolRails ("we", "us", or "our") is committed to protecting the privacy of parents, students, and educational institutions using our platform. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the laws of Pakistan.
1. Information We Collect
1.1 Information Provided by Schools
Schools register parents and students on the platform. This includes:
- Parent name, email address, and/or phone number
- Student name, date of birth, class, and registration number
- Parent-student relationship linkage
1.2 Information Provided by Parents
When using the app, parents provide:
- PIN (stored in encrypted/hashed form)
- Payment proof images (bank transfer receipts)
- Reference notes for payment submissions
1.3 Automatically Collected Information
We automatically collect:
- Device information (device type, operating system, app version)
- Push notification tokens for sending messages
- Timestamps of app usage and payment submissions
2. How We Use Your Information
We use collected information to:
- Enable parents to view and submit fee payments
- Allow schools to communicate with parents through announcements and messages
- Send push notifications about important updates, fees, and messages
- Verify payment submissions and maintain payment history
- Ensure security and prevent unauthorized access
- Improve our services and user experience
3. Information Sharing
We do not sell your personal information. We share information only as follows:
- With Your School: Schools can view their registered parents, students, payment submissions, and communication history
- Service Providers: We use trusted third-party services for:
- Cloud hosting (DigitalOcean)
- Push notifications (Firebase Cloud Messaging)
- File storage (DigitalOcean Spaces)
- Legal Requirements: We may disclose information if required by law or in response to valid legal requests by Pakistani authorities
4. Data Security
We implement appropriate security measures including:
- Encryption of data in transit (HTTPS/TLS)
- Secure hashing of PINs (never stored in plain text)
- Access controls and authentication
- Regular security reviews
- Isolated data per school (multi-tenant architecture)
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. If you request account deletion (through your school), we will delete your data within 90 days, except where we are required to retain it for legal or audit purposes.
6. Your Rights
You have the right to:
- Access: Request information about what data we hold about you
- Correction: Request correction of inaccurate information through your school
- Deletion: Request deletion of your account by contacting your school
- Portability: Request a copy of your data in a common format
Since schools manage parent and student accounts, most requests should be directed to your school. For general inquiries, contact us at the email below.
7. Children's Privacy
Student information is provided by schools with parental/guardian consent as part of the enrollment process. We do not collect information directly from children. Parents/guardians control their children's information through the school.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or via email. The "Effective Date" at the top indicates when the policy was last revised.
9. Contact Us
For privacy-related questions or concerns, contact us at:
SchoolRails
10. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of Pakistan. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in Pakistan.