Student Section ("we," "our," or "us") operates the website mystudentsection.com and the Student Section fundraising platform (the "Service"). We are committed to protecting the privacy of school administrators, coaches, parents, and student participants.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service. Because our Service is used by K-12 schools, teams, and activities, we design our data practices to comply with the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and applicable state student data privacy laws, including the Michigan Student Online Personal Protection Act (SOPPA).
1. Information We Collect
A. Roster & Account Information Provided by Schools/Coaches
To initiate a fundraising campaign, authorized school personnel, athletic directors, or coaches upload or input roster information for participants. This information is strictly limited to:
- First and Last Name
- Team/Activity Affinity (e.g., "Varsity Boys Basketball")
- Phone Number (for receiving campaign magic links)
- Parent/Guardian Email or Phone Number (where applicable or required for consent)
B. Supporter & Donor Information
When a member of the public donates to a campaign, we collect:
- Name
- Email Address
- Payment Card Information (processed securely via Stripe; we do not store raw payment card data on our servers)
- Optional words of encouragement/comments
C. Automatically Collected Information
We collect minimal technical logs necessary to maintain platform security, prevent fraud, and ensure operational stability (e.g., IP addresses and device type). We do not use tracking cookies for behavioral advertising.
2. Children's Privacy & COPPA Compliance
Our platform is built for K-12 school activities. We do not knowingly collect personal information directly from children under the age of 13 without appropriate school or parental consent.
- When a coach inputs a roster, the school or school district certifies that it has the legal authority to act as an agent for parents and provide consent for the collection of minimal student data for school-authorized fundraising purposes.
- If we learn that we have inadvertently collected personal information from a child under 13 without verifiable parental or school consent, we will delete that information within 48 hours.
3. How We Use Information
We use the collected information solely to facilitate, track, and process the school-authorized fundraising campaign.
We DO:
- Send transactional SMS messages containing secure magic links to participants so they can access and share their campaign page.
- Attribute donations to specific participants so teams can track progress toward fundraising goals.
- Provide school administrators with accounting reports of funds raised.
We do NOT:
- Sell, rent, or lease student, coach, or donor data to third parties.
- Direct targeted behavioral advertising at students or platform users.
- Engage in student profiling for non-educational commercial purposes.
- Build advertising profiles based on student data.
- Share mobile numbers or SMS opt-in consent data with third parties or affiliates for marketing or promotional purposes under any circumstances.
- Create or administer Individual Fundraising Accounts (IFAs) that credit funds to individual students' personal accounts, which could jeopardize the tax-exempt status of school booster organizations.
4. Sub-Processors and Data Sharing
We only share information with third-party service providers (sub-processors) strictly necessary to run the Service. Each sub-processor is bound by confidentiality obligations and data protection agreements:
- Stripe (stripe.com): Payment processing. Donor payment card data is transmitted directly to Stripe — we do not store raw card data. Stripe Privacy Policy.
- Twilio (twilio.com): Transactional SMS delivery (campaign magic links, parent consent requests, milestone updates). Participant phone numbers are transmitted only for message delivery. Twilio Privacy Policy.
- Resend (resend.com): Transactional email delivery (coach notifications, donation receipts). Resend Privacy Policy.
- Supabase (supabase.com): Managed PostgreSQL database hosting. All stored data is encrypted at rest (AES-256) and in transit (TLS 1.3). Supabase Privacy Policy.
- Vercel (vercel.com): Application hosting and serverless compute. Processes request data to serve the application. Vercel Privacy Policy.
- Cloudflare (cloudflare.com): CDN, DDoS protection, and DNS. Processes IP addresses and request metadata for security purposes. Cloudflare Privacy Policy.
We do not use student data for advertising networks, data brokers, or any purpose beyond operating the school-authorized fundraising campaign. Districts may request an executed Data Processing Agreement (DPA) by emailing [email protected].
5. FERPA & State Student Data Privacy Laws
Student Section acts as a "School Official" under FERPA (20 U.S.C. § 1232g) when providing fundraising services to schools. We operate under the direct control of the school or district regarding education records and maintain a legitimate educational interest strictly limited to executing the school-authorized fundraising activity.
In compliance with applicable state student data privacy statutes, including but not limited to:
- Michigan SOPPA (MCL 380.1278a): Student data is the property of the school/district. We will notify the district within 48 hours of any confirmed breach. We do not use student data for advertising or non-educational commercial purposes.
- Illinois SOPPA (105 ILCS 85): We do not knowingly engage in targeted advertising using student information, create profiles of students for non-educational purposes, sell student information, or disclose covered information except as required to provide the service.
- New York Education Law § 2-d: We maintain a data security and privacy plan, do not sell student data or use it for targeted advertising, and will report any breach of student PII to the district within 10 days.
- California SOPIPA/AB 1584: We do not sell student information, use it for behavioral targeting, or build profiles of students for purposes other than providing this service.
- Texas SCOPE (TEC § 32.151): We do not disclose covered information except as required to provide the service and do not use student data for commercial purposes unrelated to the authorized educational purpose.
These commitments apply regardless of which state a district is located in. For state-specific Data Processing Agreement templates or compliance documentation, contact [email protected].
6. SMS Messaging
Student Section sends SMS messages to school fundraising participants and their parents/guardians on behalf of schools. Messages include campaign invites, milestone updates, parent consent requests (for under-13 participants), and final-push reminders.
Your phone number is provided to Student Section by your school's coach or athletic director as part of the school roster. For participants under 13, no SMS is sent until a parent/guardian approves via a consent link.
Message frequency varies by campaign — typically 3–5 messages over 2–4 weeks per active campaign. Message and data rates may apply.
- STOP — reply STOP to any message to immediately unsubscribe. You will receive one confirmation message; no further messages will be sent to that number.
- HELP — reply HELP to receive support contact details: [email protected].
Full details of our SMS program, sample messages, and opt-in process: mystudentsection.com/sms.
7. Data Retention & Deletion
We retain participant and roster data only for the duration necessary to execute, audit, and finalize the school's fundraising campaign. All roster details, including names and phone numbers associated with a completed campaign, are automatically permanently deleted or anonymized within 90 days of the campaign's formal closure.
To request early deletion of your data, email [email protected]. We will complete the deletion within 7 days and email a confirmation.
8. Contact
If you have any questions, concerns, or data deletion requests regarding this Privacy Policy, please contact us at:
[email protected]
You may also reach our general support team at [email protected]