Data practices
Data practices
Legal
Data Policy
Effective: July 17, 2026
Overview
This Data Policy describes how SchoolBoardHQ handles, stores, and protects the data entrusted to us by school board members across the United States. It supplements our Privacy Policy with detailed information about data flows, retention controls, incident response, and compliance practices.
Data handling principles
SchoolBoardHQ applies the following principles to all data processing:
• Purpose limitation — data is collected and used only for specified, legitimate purposes.
• Data minimization — we collect only the data necessary to provide the service.
• Accuracy — we take reasonable steps to keep data current and correct.
• Storage limitation — data is retained only as long as needed for its purpose.
• Integrity and confidentiality — data is protected with appropriate technical and organizational measures.
• Transparency — our practices are documented in plain language.
Data categories
We process the following categories of data:
• Account credentials — email address, password hash, multi-factor authentication tokens.
• Profile information — display name, bio, avatar image, phone number, preferred contact method.
• Optional affinity and identity attributes — self-reported race/ethnicity, tribal or Indigenous affiliation, religion or spiritual identity, LGBTQIA2S+ identity, gender identity, disability identity, military/veteran status, parent/caregiver status, socioeconomic background, education status, immigrant/refugee status, language, cultural identity, board interests, and self-descriptions used for consent-based peer matching.
• Official board records — name, role, seat, district, term dates, and public contact information sourced from official school board websites.
• Messaging content — if member-to-member messaging is enabled in the future, this category would include the text of messages exchanged between verified board members.
• Device and session data — device type, browser and operating system, IP address, session identifiers.
• Product analytics — identifiable product analytics events that record screens viewed, features used, and sign-up funnel steps, linked to your account identifier in Supabase or a PostHog distinct ID when PostHog capture is enabled. These events are stored in our managed Supabase database and processed by our analytics provider, PostHog. Session replay is not captured.
Data flow overview
Your data flows through the following systems:
1. Web build — collects input, displays content, and stores session credentials in browser local storage (with an in-memory fallback). Hosted on Vercel.
2. API and database — Supabase provides PostgreSQL with row-level security, authentication, consent records, optional affinity/identity attributes, and realtime subscriptions for messages and presence.
3. File storage — Supabase Storage securely stores uploaded media (avatars, attachments) with access controls.
4. Records verification service — a read-only table within the Supabase database holding publicly available school board member information, refreshed periodically from official sources.
5. Email — Resend delivers transactional email (verification, invites, support correspondence).
6. Product analytics — identifiable event-level analytics linked to your account identifier in Supabase or a PostHog distinct ID when PostHog capture is enabled are stored in a dedicated table in our managed Supabase database and also sent to PostHog, our product-analytics vendor, for funnel and retention analysis. Feature flags are stored in the Supabase database and read at app start.
7. Payments — Stripe processes payment information for the voluntary Founding Pro offer; we do not store card details ourselves.
All data in transit is encrypted with TLS 1.2+. All data at rest is encrypted with AES-256.
Directory data provenance
SchoolBoardHQ maintains a national directory of K-12 school board members sourced exclusively from publicly available records — official district websites, board rosters, and state education agency listings. We do not purchase data from brokers, social media platforms, or commercial data aggregators.
Each directory record carries a provenance tier that indicates how the data was obtained:
• Scraper — machine-collected from a public source without human confirmation.
• Official document — sourced from an official district or governance artifact.
• Member verified — the linked member reviewed, confirmed, or corrected the value.
• Peer reported — submitted by another user and pending stronger confirmation.
Directory data is refreshed periodically via automated crawls. When a verified member claims their profile, they may review and correct any value, promoting it to the highest trust tier. Automated updates never silently overwrite a member-verified value. If you believe a directory record is inaccurate, contact support@schoolboardhq.com or use the 'Report a roster error' link in any member profile.
Retention schedule
Data retention periods are set to the minimum necessary for each category:
• Account credentials — retained while your account is active; deleted immediately upon closure.
• Profile information — retained while active; deleted immediately upon closure.
• Optional affinity and identity attributes — retained while active or until consent is withdrawn; deleted immediately upon account closure or an approved deletion request, unless legal retention requires otherwise.
• Official board records — retained as long as the source record exists in public records; updated with each crawl cycle.
• Messaging content — if member-to-member messaging is enabled in the future, message content would be retained indefinitely so other participants can still access their conversation, with a deleted sender's attribution replaced by "Deleted account."
• Device and session data — retained for 90 days after last use.
• Security and audit logs — retained for 1 year.
• Aggregate statistics — retained indefinitely only after they no longer identify a person or account.
You may request earlier deletion of your personal data, subject to legal retention obligations.
Prohibited data
Do not upload highly sensitive records to SchoolBoardHQ, including:
• Family Educational Rights and Privacy Act (FERPA)-protected student education records.
• Health Insurance Portability and Accountability Act (HIPAA)-protected health information.
• Social Security numbers or government-issued ID numbers.
• Confidential personnel files or employment records.
• Attorney-client privileged communications.
Exceptions apply only where your district's policy and applicable law explicitly authorize such use. You are responsible for ensuring compliance with your district's data governance policies.
Your data rights
You have the right to:
• Access — obtain a copy of the personal data we hold about you.
• Correction — request correction of inaccurate or incomplete data.
• Deletion — request deletion of your personal data.
• Portability — receive your data in a structured, machine-readable export of your account data and profile data in JSON or CSV format.
• Restriction — request that we limit processing of your data.
• Objection — object to processing based on legitimate interests.
Rights request workflow
To exercise any data right:
1. Submit your request — email privacy@schoolboardhq.com with your full name, account email, district, and the right you wish to exercise.
2. Identity verification — we verify your identity within 3 business days using your account email and, if needed, additional verification.
3. Scope confirmation — we confirm what data is covered and any limitations.
4. Fulfillment — we process your request within 30 calendar days. Complex requests may take up to 90 days, and we will notify you of any extension.
5. Completion — you receive a confirmation email with the outcome.
If we cannot fulfill part of a request due to a legal obligation (e.g., public records retention), we will explain the specific reason in plain language and fulfill all other aspects of the request.
Institutional sponsor controls
SchoolBoardHQ member accounts, profiles, and communications belong to the individual board member — not any institution that helps fund network access. No sponsor of any kind receives message content, message exports, peer-graph/connection data, individual member activity, or audits of a specific member's data.
• A district that sponsors member seats (for example, under a pilot seat-sponsorship program) receives only a seat-consumption count — how many sponsored seats are active. No admin console, no per-member analytics, no SSO control.
• A state school board association, NSBA, or similar partner that funds network access or co-branded learning may receive broader aggregate, de-identified reporting — adoption counts, participation counts, and cohort completion counts for programming a member opted into — but never member-level activity or individually identifying detail.
This is a firewall commitment, not a configurable setting — no plan grants any sponsor institutional access, monitoring, or export of member content. To request the reporting available under a sponsored plan, contact privacy@schoolboardhq.com with the sponsoring organization's name and the name and title of the authorized representative.