Privacy Policy
Last updated: 24 March 2026
1. Introduction
MySchoolSathi (“we”, “our”, or “us”) operates the school management platform available at myschoolsathi.in. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. By using MySchoolSathi, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, school name, and role (admin, teacher, student, parent, staff).
- Student Data: Student names, admission numbers, dates of birth, parent/guardian details, class/section information, attendance records, fee records, exam marks, and custom fields (e.g., Aadhaar number) as entered by the school.
- Payment Information: Subscription plan details, billing dates, and payment amounts. We do not directly store credit card or bank account numbers.
- Inquiry Data: Name, school name, mobile number, and plan preference submitted through our contact forms.
2.2 Information Collected Automatically
- Log Data: IP address, browser type, pages visited, time and date of visit, and other diagnostic data.
- Cookies: We use authentication cookies (JWT-based) to maintain your login session. These are essential cookies required for the platform to function.
3. How We Use Your Information
- To provide, operate, and maintain the MySchoolSathi platform.
- To manage user accounts and authentication.
- To process subscription payments and manage billing.
- To send notifications related to attendance, fees, exams, and results.
- To generate PDF documents (marksheets, fee receipts, ID cards, hall tickets, transfer certificates).
- To respond to inquiries and provide customer support.
- To improve our platform and develop new features.
- To comply with legal obligations.
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share data only in the following circumstances:
- Within the School: Data is shared between authorized roles within the same school (e.g., a parent can see their child's attendance and fees).
- Service Providers: We may use third-party services for hosting, email delivery, and analytics. These providers are contractually obligated to protect your data.
- Legal Requirements: We may disclose information if required by law, court order, or government regulation.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity.
5. Data Security
We implement industry-standard security measures to protect your data:
- JWT cookie-based authentication with secure, HTTP-only cookies.
- Rate limiting: 10 login attempts per 15 minutes, 100 API calls per minute per user.
- Input sanitization with regex validation to prevent injection attacks (including ReDoS protection).
- Data encrypted in transit using HTTPS/TLS.
- Role-based access control ensuring users only access data relevant to their role.
While we strive to use commercially acceptable means to protect your data, no method of electronic transmission or storage is 100% secure.
6. Data Retention
- Active Accounts: Data is retained as long as your subscription is active.
- After Cancellation: Data is retained in read-only mode for 30 days. You may export your data (CSV format) during this period.
- After 30 Days: Data is permanently and securely deleted from our servers.
- Inquiry Data: Contact form submissions are retained for up to 12 months for follow-up purposes.
7. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your data (subject to legal and contractual obligations).
- Export: Export your data in standard formats (CSV).
- Objection: Object to processing of your data for specific purposes.
To exercise any of these rights, contact us at support@myschoolsathi.in.
8. Children's Data
MySchoolSathi processes student data on behalf of schools. Schools are the data controllers for student information and are responsible for obtaining necessary consents from parents/guardians. We process children's data solely as directed by the school and in accordance with applicable laws.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. Continued use of the platform after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy, contact us at:
- Email: support@myschoolsathi.in
- Phone: +91-8511926953
- Website: myschoolsathi.in