Privacy Policy
What we collect, why, and your rights·Source: docs/legal/PRIVACY.md
Draft — pending final legal review. Text marked {{PLACEHOLDER}}is filled in by counsel before publication. Content shown here is a good- faith draft + reflects HallPal's current operational posture, but is not a substitute for legal advice.
HallPal Privacy Policy
Effective: {{EFFECTIVE_DATE}} Last updated: 2026-08-08
1. Who we are
{{COMPANY_LEGAL_NAME}} ("HallPal", "we", "us", "our") operates the HallPal hallpass management service (the "Service") for K-12 schools. Our registered address is {{COMPANY_ADDRESS}}. You can reach us at privacy@hallpal.divz.io for any question about this policy or your data.
2. Scope of this policy
This policy covers information we collect when you (or your school) use the HallPal admin dashboard, the Homebase kiosk, the Pass wearable device, or any of our other software. It applies to information about:
- School administrators, teachers, and support staff who sign in to the dashboard.
- Students whose pass activity is recorded by the Homebase + Pass devices in their school.
- Website visitors to any public HallPal page.
Some of the data we hold about students is treated as a student education record under the US Family Educational Rights and Privacy Act (FERPA). See §7 for how we handle those specifically.
3. What we collect
3.1 Information the school provides
- Roster data: student names, school-assigned student IDs, grade year, classroom / period assignments.
- Staff account data: email address, display name, role (school admin / teacher), assigned classrooms.
- School configuration: school name, timezone, maintenance PIN, time-limit presets, destination list, join code.
3.2 Information generated by using the service
- Hallpass records: which student left, from which classroom, at what time, when they returned, optional destination. Kept as an audit trail of the student's use of the hall pass.
- Device telemetry: heartbeat timestamps, firmware version, radio signal strength (RSSI), free heap memory, battery level (Pass), charge state. Used to keep the fleet healthy.
- RFID card pairings: the mapping of a card's factory hardware UID to a student. The physical card itself carries only its UID; all meaning lives on our servers.
- Audit log: who did what and when, per school. Every mutation (create / edit / delete / rotate / invite / unpair / etc.) writes an audit entry with the actor's identity.
- Chat transcripts (when used): if a staff member uses the in-dashboard AI assistant, we retain the conversation to render it back to the same user + to debug problems. See §6 for how the AI provider handles this.
- Cookies + session data: authentication session cookies (from Supabase Auth), a theme preference, a bot-protection token from Cloudflare Turnstile (§5).
3.3 Information we do NOT collect
We do not collect location data, contact-book data, health data, financial data, browsing history outside HallPal, or third-party tracking-ad identifiers. We do not use HallPal to serve targeted advertising and we do not sell personal information.
4. How we use it
We use the information above to:
- Provide + operate the Service (open + close hallpass records, authenticate users, sync devices, render analytics).
- Keep student rosters + classrooms accurate.
- Investigate + respond to security incidents.
- Send transactional email (magic-link sign-in, invitations, device-provisioning confirmations, incident-response notices).
- Maintain an audit trail so a school can investigate misuse of the system.
- Improve the Service by measuring aggregate use patterns (e.g. which features are used, which errors occur). We do not use student personally-identifiable information for product improvement.
We do NOT use hallpass data or student data to train any machine learning model — ours or a third party's. See §6 for the specific data-flow around the AI chat feature.
5. Cloudflare Turnstile (bot protection)
Our sign-in page uses Cloudflare Turnstile to distinguish real users from automated bots without asking you to solve a puzzle.
When you visit the sign-in page, Cloudflare receives certain information about your browser to make that determination — including IP address, browser + operating-system version, minor timing characteristics, and a small script-generated token. Cloudflare states that Turnstile is designed to be a privacy-preserving alternative to CAPTCHA + does not use cookies for cross-site tracking or advertising.
We do not receive the raw data Cloudflare inspects. We receive only Cloudflare's yes/no verdict + a verification token. For details on what Cloudflare specifically collects, retains, and does with that data, please see Cloudflare's own Turnstile privacy statement: https://www.cloudflare.com/en-gb/turnstile-privacy-policy/.
Cloudflare's role here is that of a subprocessor operating on our behalf under a signed data-processing addendum.
6. Artificial intelligence — the chat assistant
HallPal's dashboard includes an optional AI-powered chat assistant that can answer questions about your school's data. In line with the US Federal Trade Commission's guidance on AI transparency, we want you to know:
You are talking to an AI, not a human. The assistant is a large language model operated by our subprocessor, Anthropic, PBC (the Claude family of models). Its responses are generated automatically based on your prompt + the data you have permission to see.
What we send to Anthropic: the text of your message, your current school's public metadata (school name, current period, roster count) needed to answer your question, and a system prompt describing what the assistant is allowed to do. We do NOT send:
- Any student's full name in a way that isn't already public within your school. (First names + last initials are used in-context.)
- Any authentication credential or API key.
- Any student data from a school you don't have access to.
What Anthropic does with the data: under our commercial agreement, Anthropic processes your messages solely to generate a response and does not use your inputs or outputs to train its models. Anthropic's own commercial terms describe this arrangement: https://www.anthropic.com/legal/commercial-terms.
What the AI is NOT. It is not a source of legal, medical, disciplinary, or safety advice. It may make mistakes ("hallucinate"). It should not be used to make decisions about a student that have lasting consequences without human review. We display a clear label on the chat panel identifying its output as AI-generated.
Retention. Chat transcripts are kept in your school's database for {{CHAT_RETENTION_DAYS}} days so you can review past conversations. Delete individual conversations from the chat panel any time; deleted conversations are removed from our systems on the next scheduled purge (up to 30 days) and are not retained by Anthropic beyond their transient processing.
Opt-out. School administrators can disable the AI assistant for their school from the settings page. When disabled, no chat data leaves our systems to Anthropic.
7. Student education records + FERPA
When HallPal is used inside a US K-12 school under a contract with the school or school district, we operate as a "school official" with a legitimate educational interest under the US Family Educational Rights and Privacy Act (FERPA), 34 C.F.R. § 99.31(a)(1).
That means:
- The school (not HallPal) is the legal custodian of the student education records HallPal stores on its behalf.
- We use student data only to perform the service the school contracted us to provide.
- We are under the school's direct control with respect to that data.
- We do not disclose student data to any third party except a subprocessor (§8) operating on our behalf, and only in ways consistent with FERPA's provisions.
- Parents + eligible students have the same rights of access, amendment, and consent to disclosure that FERPA provides — the school is the correct point of contact to exercise those rights; we will assist the school in fulfilling them.
If your child's school uses HallPal + you would like to review the records HallPal holds about your child, please contact the school's administrator. We can support the school in fulfilling that request but the request must originate through the school.
8. Children under 13 (COPPA)
HallPal's Service is designed for use INSIDE a school by school staff
- (via the Homebase kiosk) by students. Under the US Children's Online Privacy Protection Act (COPPA), when a school authorizes an online service on behalf of students under 13 for a school-authorized educational purpose, the school may act as the parent for the purpose of providing COPPA consent. HallPal relies on the school for that authorization.
We collect the minimum information required to operate the hallpass service. We do not collect from children:
- Contact information beyond the school-assigned student ID + name.
- Persistent identifiers used for behavioural advertising.
- Content the child creates outside the hallpass workflow (there is no student-authored content in HallPal).
- Geolocation.
Parents of children under 13 who wish to review, delete, or refuse further collection of their child's information can do so through their school's administrator. See §7 above; the school is the correct point of contact.
9. Subprocessors
We use the following third-party services ("subprocessors") to operate HallPal. Each processes data only under contract with us, only to provide the specific service listed, and each is bound by data-protection terms substantively equivalent to ours.
| Subprocessor | Purpose | Data categories |
|---|---|---|
| Vercel Inc. | Web application hosting (US regions) | All data in transit; short-lived logs |
| Supabase (self-hosted on our infrastructure) | Database, authentication, real-time, storage | All data at rest |
| Anthropic, PBC | AI chat assistant (Claude) | Chat prompts + minimal school context (§6) |
| Cloudflare, Inc. | Bot protection (Turnstile), CDN, tunneling | IP + browser fingerprint for Turnstile; TLS-encrypted traffic |
| Resend, Inc. | Transactional email delivery | Recipient email + message contents |
| Google LLC | OAuth sign-in (optional) | Email + display name of admins who choose Google sign-in |
We publish material changes to this list before they take effect (§14). A current machine-readable list is maintained at https://hallpal.divz.io/subprocessors.
10. Data retention
- Roster + classroom + configuration data: retained for as long as your school has an active HallPal contract, plus a {{POST_TERM_RETENTION_DAYS}}-day post-termination window during which you can export.
- Hallpass records: retained per your school's configured retention policy. Your school chooses the window; where none is set, records are retained until your school sets one or your account is terminated. Once a window is configured, records older than it are permanently deleted by a nightly job.
- Audit log: retained for the life of the account. We do not currently expire audit entries, because they are the record of who did what to student data and several retention obligations set a minimum rather than a maximum.
- Device telemetry (heartbeats): rolling 90-day window.
- Chat transcripts: {{CHAT_RETENTION_DAYS}} days (see §6).
- Backups: rolling {{BACKUP_RETENTION_DAYS}}-day encrypted offsite backups. Deletion from live systems takes up to {{BACKUP_RETENTION_DAYS}} days to propagate through backups.
Post-termination, we retain the minimum information required to comply with our legal obligations, resolve disputes, and enforce agreements.
11. Your rights
Depending on where you (or the person the data is about) live, you may have rights to:
- Access — request a copy of the data we hold about you.
- Correct — ask us to fix inaccurate data.
- Delete — ask us to erase your data (subject to §7 for student data + §10 for legally-required retention).
- Restrict / object — limit how we process your data.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — where processing is based on consent.
- Complain — to your local data protection authority (in the EU / UK) or the FTC (in the US).
To exercise any of these rights, email privacy@hallpal.divz.io. We will respond within 30 days. For student data specifically, see §7 — the school is the correct point of contact.
We will not discriminate against you for exercising these rights.
12. Security
We take security seriously. Concrete measures include:
- All data in transit encrypted with TLS 1.2+ (HSTS enforced with
1-year
preload). - All authentication tokens rotated automatically; sessions auto-expire after 120 minutes of inactivity.
- Row-Level Security enforced at the database layer so a request can only reach data the requester's school allows.
- Every mutation writes an immutable audit-log entry.
- Rate limiting on every sensitive route to blunt credential-stuffing
- card-brute-force.
- Content-Security-Policy + a suite of related security headers on every response.
- Regular automated + manual accessibility + security testing.
Despite these measures, no system is perfectly secure. If a security incident occurs that affects your data, we will notify you as required by law (in most cases within 72 hours of confirmed detection).
13. International transfers
HallPal's infrastructure is located in {{INFRA_REGION}}. If you access the Service from outside {{INFRA_REGION}}, your data will necessarily be transferred to + processed in {{INFRA_REGION}}. Where required, transfers rely on Standard Contractual Clauses or an equivalent adequacy mechanism.
14. Changes to this policy
If we make material changes to this policy, we will:
- Update the "Last updated" + "Effective" dates at the top of this page.
- Notify signed-in school administrators via in-app banner + email before the change takes effect.
- Provide at least 30 days' notice before the change becomes effective, unless the change is required by law to take effect sooner.
15. Contact
Privacy questions: privacy@hallpal.divz.io Postal: {{COMPANY_ADDRESS}} Data Protection Officer: {{DPO_NAME_OR_TBD}}