Privacy policy
Privacy policy
Legal
Privacy Policy
Effective: July 17, 2026
Overview
SchoolBoardHQ is built for America's K-12 school board members. This Privacy Policy explains what information we collect, why we collect it, how we protect it, and what rights you have. We are committed to handling your data transparently and responsibly.
Information categories
We collect and process data in the following categories:
• Account credentials — email address, password hash, multi-factor authentication tokens.
• Profile information — display name, bio, avatar image, phone number, preferred contact method.
• Optional affinity and identity attributes — self-reported race/ethnicity, tribal or Indigenous affiliation, religion or spiritual identity, LGBTQIA2S+ identity, gender identity, disability identity, military/veteran status, parent/caregiver status, socioeconomic background, education status, immigrant/refugee status, language, cultural identity, board interests, and self-descriptions used for consent-based peer matching.
• Official board records — name, role, seat, district, term dates, and public contact information sourced from official school board websites.
• Messaging content — if member-to-member messaging is enabled in the future, this category would include the text of messages exchanged between verified board members.
• Device and session data — device type, browser and operating system, IP address, and session identifiers.
• Product analytics — identifiable product analytics events that record screens viewed, features used, and sign-up funnel steps, linked to your account identifier in Supabase or a PostHog distinct ID when PostHog capture is enabled. These events are stored in our managed Supabase database and processed by our analytics provider, PostHog. We do not capture session replay (video-style screen recordings).
How we use data
We use your data for the following purposes:
• Authentication and account security.
• Board-member identity verification against official board records.
• Facilitating peer networking, affinity matching, messaging, and collaboration.
• Sending push notifications and service communications.
• Providing customer support and resolving reports.
• Detecting and preventing abuse, fraud, and security incidents.
• Improving the platform through product analytics that record which features you use and where you encounter friction. These analytics are linked to your account identifier (not anonymized).
We do not sell personal data. We do not use your data for advertising, marketing profiling, or cross-app or cross-site tracking.
Lawful basis for processing
We process your data based on:
(a) Consent — when you create an account and agree to these terms.
(b) Contractual necessity — to provide the core service you signed up for.
(c) Legitimate interests — platform security, abuse prevention, and service improvement, balanced against your privacy rights.
(d) Legal obligations — record retention, law enforcement requests, and compliance with applicable state and federal laws.
Data retention schedule
We retain data for the minimum period necessary for its purpose:
• Account credentials — retained while your account is active; deleted immediately upon account closure.
• Profile information — retained while active; deleted immediately upon closure.
• Optional affinity and identity attributes — retained while active or until consent is withdrawn; deleted immediately upon account closure or an approved deletion request, unless legal retention requires otherwise.
• Official board records — retained as long as the source record exists in public records.
• Messaging content — if member-to-member messaging is enabled in the future, message content would be retained indefinitely so other participants can still access their conversation, with a deleted sender's attribution replaced by "Deleted account."
• Device and session data — retained for 90 days after last use.
• Security and audit logs — retained for 1 year.
• Aggregate statistics — retained indefinitely only after they no longer identify a person or account.
You may request earlier deletion of your personal data, subject to legal retention requirements.
Your rights
Depending on your jurisdiction, you may have the right to:
• Access — obtain a copy of the personal data we hold about you.
• Correction — request correction of inaccurate or incomplete data.
• Deletion — request deletion of your personal data.
• Portability — receive your personal data in a structured, machine-readable export in JSON or CSV format.
• Restriction — request that we limit processing of your data.
• Objection — object to processing based on legitimate interests.
• Withdraw consent — withdraw previously given consent at any time.
How to exercise your rights
To submit a data rights request:
1. Email privacy@schoolboardhq.com with your full name, account email, district name, and the right you wish to exercise.
2. We will verify your identity within 3 business days.
3. We will confirm the scope of your request and begin processing.
4. We will fulfill your request within 30 calendar days, or notify you if an extension is needed (up to 60 additional days for complex requests). If you request portability, we will provide the export in JSON or CSV unless a different legally available format is required.
5. You will receive a confirmation email when your request is complete.
If we cannot fulfill part of a request due to a legal obligation, we will explain the specific reason in plain language.
Data sharing and third parties
We share data only when necessary to operate the service:
• Supabase — managed PostgreSQL database, authentication, file storage, realtime infrastructure, and product-analytics-event storage (United States data centers).
• PostHog — product analytics (United States data center).
• Vercel — hosting and content delivery for the web build (United States data centers).
• Sentry — application error monitoring and performance tracking (United States data centers).
• Resend — transactional email delivery (account verification, founding-member invites, and support correspondence).
• Stripe — payment processing for the Founding Pro offer.
• Legal obligations — law enforcement requests, court orders, or regulatory requirements.
All third-party providers are bound by data processing agreements that limit their use of your data to the services they provide to us. We do not share data with advertisers, data brokers, or social media platforms.
Subprocessors and vendors
Our current subprocessors are:
• Supabase — managed database, authentication, file storage, realtime, and analytics-event storage.
• PostHog — product analytics.
• Vercel — web hosting and content delivery.
• Sentry — application error monitoring and performance tracking.
• Resend — transactional email.
• Stripe — payment processing for the Founding Pro offer.
Each subprocessor processes data only under our written instructions and is reviewed for security practices and contractual safeguards before engagement and during periodic compliance audits. We will update this list when we add or change a subprocessor, and notify users of material changes via in-app notification at least 14 days before the change takes effect, or as soon as possible if we cannot provide advance notice.
Data transfers
Your data is processed and stored in the United States. If you access SchoolBoardHQ from outside the US, your data will be transferred to and processed in the US. We rely on standard contractual clauses and other applicable legal mechanisms to ensure adequate protection for any cross-border data transfers.