Privacy Policy
ClassCheckpoint ("we," "us"), operated by Double H Ventures LLC, provides check-in/check-out and management software to learning centers. This policy explains what data we handle and how. The short version: your center's data belongs to your center, student data is handled only on your center's instructions, and we never sell data or use it for advertising.
1. Two kinds of data
We handle data in two distinct roles:
- Data we process for centers. Student and family records that a center puts into the service. Here the center is the data's owner and decision-maker; we're the service provider acting on its instructions.
- Data we collect ourselves. Center staff account details, billing information, website inquiries, and service logs. Here we're the decision-maker.
2. Data we process for centers
Depending on how a center uses the service, this can include:
- Student records: name, grade level, enrollment dates, subjects, and a center-assigned ID.
- Attendance: check-in and check-out times and session history.
- Session feedback: brief responses students give at the kiosk (for example, how homework felt today).
- Parent/guardian contact details the center enters, and prospective-family (lead) records if the center uses lead management.
- Staff notes and tasks about students and follow-ups.
We use this data only to provide the service to that center: running the kiosk and dashboards, producing the center's reports and summaries, and flagging attendance patterns for the center's own staff. We do not use it for advertising, do not sell it, do not combine it across centers in identifiable form, and do not contact a center's families for our own purposes. Each center's data is isolated from every other center's at the database level.
3. Children's privacy
Students (including children under 13) interact with the kiosk to check in, check out, and answer brief session-feedback questions. We collect this information solely on behalf of and at the direction of the student's center, which uses it for attendance and instruction, never for marketing. Each center is responsible for obtaining parental or guardian consent before adding a student, as required by our terms. We do not knowingly collect information from children except through a center in this way, never advertise to children, and never sell children's information. Parents: your center controls these records: contact your center to review, correct, or delete your child's information, and we'll support the center in honoring the request.
4. Data we collect ourselves
- Account data: staff names, email addresses, roles, and login records for the people a center authorizes.
- Billing: handled by Stripe. We receive subscription status and receipts. We never see or store full card numbers.
- Service logs: technical logs (such as sign-ins and errors) kept for security and troubleshooting.
- Website: our marketing site doesn't use advertising trackers. If you email us, we keep the correspondence.
5. Who we share data with
Only the infrastructure providers needed to run the service ("subprocessors"), each bound to use the data solely to provide their service to us:
| Provider | What they do |
|---|---|
| Supabase | Database and application hosting (where center data lives) |
| Vercel | Web application hosting |
| Stripe | Payment processing |
| Resend | Sending the service's emails (e.g., a center's daily report) |
| Anthropic | Generating a center's AI session summaries. API data is not used to train AI models. |
Beyond that, we disclose data only if the law requires it (we'll notify the affected center unless legally barred) or as part of a sale or reorganization of the business, in which case this policy continues to apply to the data. We never sell personal information, anyone's, and we don't share it for cross-context advertising.
6. Security
Data is encrypted in transit and at rest. Every center's records are isolated by row-level security enforced in the database itself, access is role-based (a kiosk login can't read what a staff login can), and access to production systems is limited to those who operate the service.
7. Retention and deletion
- While subscribed: attendance records are retained for the life of the subscription, preserving at least two years of history to support centers' record-keeping obligations. Centers can export everything at any time.
- After a subscription ends: the center has 60 days to export its data; we then delete it from live systems within 90 days, with backups aging out on our normal cycle.
- Our own records: billing and correspondence are kept as long as legal and tax obligations require.
8. Your rights
Centers control their data: export, correction, and deletion are available in-app or by emailing us. Parents and students should contact their center, which owns the records; we support centers in honoring these requests. California residents: we act as a service provider to centers under the CCPA, we do not sell or share personal information as those terms are defined there, and you may contact us with any privacy request or question.
9. Changes
If we make material changes to this policy (especially anything affecting student data), we'll email center account contacts at least 30 days before the change takes effect.
10. Contact
Privacy questions or requests: support@classcheckpoint.com.