1. Overview
School Ledger ("we", "our", "us") is committed to protecting the privacy and security of data entrusted to us by the schools and institutions ("Tenants") that use our platform. This Privacy Policy describes how we collect, process, store, and safeguard personal and institutional data in connection with our school management software-as-a-service platform.
By subscribing to and using School Ledger, you (the Tenant — typically a school or educational institution) and your authorised users agree to the practices described in this policy. If you do not agree, please discontinue use of the platform.
This policy applies to all users of the School Ledger platform, including school administrators, bursars, teachers, staff members, and driver-kiosk users operating under a Tenant subscription.
2. Who We Are
School Ledger is a cloud-based school management platform that provides tools for student management, fee collection and billing, staff and attendance tracking, transport management, and reporting. The platform is provided as a multi-tenant software-as-a-service (SaaS).
For purposes of data protection, School Ledger acts as the data processor on behalf of each Tenant. Each Tenant school is the data controller for all personal data relating to their students, staff, and parents that they input into the platform.
3. Data We Collect
We collect only the data necessary to deliver and improve our services. This falls into two categories:
3.1 Data You Provide (Tenant-Supplied Data)
As a Tenant administrator or authorised user, you may input the following data into the platform:
- Student records: full name, date of birth, gender, class, enrollment status, admission number, address, contact information, and academic history.
- Staff records: full name, employee ID, department, role, contact details, employment status, and attendance records.
- Financial data: fee structures, billing records, payment amounts, payment methods, receipts, outstanding balances, and ledger adjustments.
- Transport data: route assignments, vehicle information, driver details, student stop assignments, and transport billing records.
- Attendance data: daily student attendance, class attendance registers, staff check-in/check-out times, and leave records.
- Account information: names, email addresses, and roles of all users invited to the Tenant's account.
3.2 Data We Collect Automatically
- Authentication tokens: JWT tokens generated upon login, used to maintain secure sessions.
- Usage logs: API request logs including timestamps, endpoint paths, HTTP status codes, and IP addresses — retained for security monitoring and troubleshooting.
- Audit trails: a record of key actions (e.g., payment recorded, student status changed, charge voided) tied to the user who performed them, used for accountability and dispute resolution.
- Technical metadata: browser type, device type, and operating system, collected to optimise compatibility and performance.
4. How We Use Your Data
We use collected data solely for the following purposes:
- Delivering the platform's core features — student records, billing, attendance, transport, and reporting — to your school.
- Authenticating users and enforcing role-based access controls to ensure only authorised personnel access your data.
- Generating receipts, financial summaries, and reports on your behalf.
- Maintaining platform security, detecting fraud, and preventing unauthorised access.
- Providing customer support, including diagnosing technical issues you report to us.
- Improving platform reliability, performance, and features using aggregated, anonymised usage patterns — never individual student records.
- Sending transactional communications such as account invitations, password resets, subscription notifications, and critical service alerts.
We do not use your data for advertising, profiling, or selling to third parties under any circumstances.
5. Data Sharing
We do not sell, rent, or trade your personal or institutional data. Data may only be shared in the following limited circumstances:
- Infrastructure providers: We use reputable cloud hosting and database providers to store and serve your data. These providers act as sub-processors under strict data processing agreements and are not permitted to access or use your data for their own purposes.
- Email delivery services: Transactional emails (e.g., account invitations, password resets) are sent via a third-party email delivery provider. Only the recipient address and message content necessary for delivery are shared.
- Payment processors: Where integrated payment gateways are used (e.g., for online fee collection), only the data required to complete the transaction is shared with the payment processor. We do not store full card numbers on our servers.
6. Data Security
We implement industry-standard technical and organisational security measures to protect your data:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). Unencrypted HTTP connections are rejected.
- Encryption at rest: Sensitive data stored in our databases is encrypted at rest using AES-256 or equivalent standards.
- Role-based access control: Users only access data within their assigned role and Tenant. Cross-tenant data access is architecturally prevented.
- Audit logging: All significant data mutations are logged with user ID, timestamp, and action type.
- Access controls: Production database access is restricted to authorised personnel only and requires multi-factor authentication.
- Regular backups: Data is backed up regularly to geographically redundant storage.
9. Student Data
We recognise that student data is particularly sensitive, as it often relates to minors. The following specific commitments apply:
- Student personal data is used exclusively to provide the school management services subscribed to by the Tenant school. It is never used for advertising, profiling, or any purpose outside the scope of delivering those services.
- Student data is never sold, shared with third parties for commercial purposes, or used to build profiles outside of the platform.
- The Tenant school, as data controller, is responsible for obtaining any consents required from parents or guardians under applicable law before inputting student data into the platform.
- Access to student records is restricted by role: administrators and bursars have broad access; teachers have access only to their assigned classes; driver-kiosk users see only route-relevant student names and payment status.
10. Your Rights
As a Tenant or authorised user, you have the following rights with respect to your data:
- Access: You may request a copy of all data we hold relating to your school at any time.
- Correction: You may update or correct inaccurate data directly within the platform or by contacting support.
- Portability: You may export your data in a machine-readable format (CSV/JSON) at any time via the platform's export tools, or by requesting a full export from our support team.
- Erasure: You may request deletion of your Tenant data and all associated records at any time. See Section 7 for details.
- Restriction: You may request that we restrict processing of your data while a dispute is being resolved.
- Objection: You may object to specific processing activities where you believe there is no lawful basis.
To exercise any of these rights, contact privacy@schoolledger.co.zw. We will respond within 14 business days.
12. Third-Party Services
We may integrate with the following categories of third-party services. All integrations are governed by data processing agreements:
- Cloud infrastructure: Our platform runs on cloud infrastructure providers who provide compute, storage, and networking services under strict data processing agreements.
- Email delivery: Transactional emails are delivered via an email API provider. Recipient addresses and email content are transmitted to them solely for delivery purposes.
- Payment gateways: Schools may optionally connect payment gateway integrations (e.g., Paynow). Transaction data is passed directly between the payer and the gateway; we record confirmation references only.
We do not integrate with social media platforms, advertising networks, or data brokers.
13. Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do:
- The "Last updated" date at the top of this page will be revised.
- For material changes, we will notify all active Tenant administrators via email and an in-platform notice at least 14 days before the changes take effect.
- Your continued use of the platform after the effective date constitutes acceptance of the revised policy.
We encourage you to review this policy periodically. Previous versions are available upon request.
14. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or the handling of your data, please contact us:
If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.