Last updated September 12, 2026
Overview
Asset Pilot EDU is an operational technology platform designed to support K–12 institutions in managing device programs, parent communications, repairs, forms, and administrative workflows.
This Privacy Policy describes how Asset Pilot EDU LLC ("Asset Pilot EDU," "we," "us") handles information when institutions and authorized users access the platform. Deploying institutions remain the custodians of student education records.
Institutional Data Ownership
Each deploying institution owns the student, staff, and operational data entered into Asset Pilot EDU. The institution determines account provisioning, data retention, and access policies. Asset Pilot EDU provides application hosting and operational tooling under institutional agreement.
Information We Process
Asset Pilot EDU processes information necessary to deliver platform services. Categories may include:
- Student identifiers: name, grade, homeroom, optional school email, device assignments, standing, and optional portrait photo
- Parent and guardian portal accounts linked to students (including co-guardian links)
- Signed form records including signer name, timestamp, and optional IP address for audit
- Repair tickets, loaner history, evidence photos, and payment metadata when enabled
- Parent wallet ledger balances used for school accounting (not card numbers)
- Staff activity and operational logs for accountability
- Authentication credentials (password hashes) and session metadata
How Information Is Used
Information is used solely to operate platform features requested by the deploying institution, including device lifecycle management, repair workflows, parent communications, compliance tracking, and executive reporting.
We do not sell personal information. We do not use student data for advertising or unrelated commercial purposes.
Access and Role Boundaries
Access is governed by role-based permissions configured by the institution:
- Parents — server-scoped to students linked to their account (devices, repairs, payments, and related records for those students)
- Teachers — homeroom-focused workflows in the interface; school-wide API scoping for teachers continues to harden
- Administrators — full operational access within the institution's deployment
- Leadership — analytics and reporting scoped to institutional configuration
Education Records
Asset Pilot EDU is designed to support legitimate educational and operational uses of student information consistent with the Family Educational Rights and Privacy Act (FERPA). Requests to inspect or amend education records are handled by the deploying institution, not the software vendor.
This policy describes platform practices and is not legal advice. Institutions should obtain counsel review for FERPA, COPPA, and related obligations.
Children and Parent Access
Asset Pilot EDU is an institutional platform for schools and authorized staff, parents, and guardians. It is not directed at children under 13 as a consumer product. Parent portal accounts are intended for parents and guardians; students typically do not hold independent consumer accounts for the platform.
Deploying schools remain responsible for providing required notices and obtaining any consents under applicable student privacy laws, including FERPA and, where applicable, COPPA-related obligations.
Payments
When online card payments are enabled, parents complete payment on Stripe-hosted Checkout pages. Asset Pilot stores payment metadata (amount, status, session identifiers) and does not store card number, CVV, or full PAN.
When Stripe is not configured, families pay at the school office and staff record payment in the application.
Infrastructure and Subprocessors
Production data is hosted in United States data centers. Current infrastructure partners include:
- Vercel — application hosting (United States)
- Supabase — PostgreSQL database (United States)
- Stripe (optional) — payment processing when enabled by the institution
Retention
Data retention schedules are determined by the deploying institution in accordance with district, diocesan, or state requirements. The platform supports inactive/archived student status and end-of-year grade workflows to help schools manage lifecycle. Export capabilities support institutional record management.
Security Measures
We implement operational security controls including HTTPS with HSTS, HTTP-only session cookies, bcrypt password hashing, role checks, parent data scoping on the main data API, login rate limiting, and audit logging for key actions. See our Security Policy and Trust Center for additional detail suitable for parents and schools.
Privacy Contact
Privacy inquiries may be directed to privacy@assetpilotedu.com. Institution-specific record requests should be directed to the deploying school's administration.