1. Introduction
Permission Please ("we," "our," or "us") is committed to protecting the privacy of students, parents, teachers, and school administrators who use our digital permission slip platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
We understand the sensitive nature of student data and have designed our platform with privacy and security as core principles.
2. Information We Collect
2.1 Information Provided by Schools
- School name and contact information
- Teacher names and email addresses
- Student names and grade levels
- Parent/guardian names and email addresses
2.2 Information Collected During Use
- Electronic signatures (stored securely)
- Form responses and consent records
- IP addresses (partially masked for privacy)
- Timestamps of actions for audit purposes
2.3 Technical Information
- Browser type and device information
- Usage patterns and access logs
3. How We Use Information
We use collected information solely for:
- Providing and operating the permission slip service
- Sending permission requests and confirmations to parents
- Enabling teachers to track form completion status
- Maintaining audit trails for compliance purposes
- Improving and securing our platform
- Communicating service updates and important notices
4. What We Do NOT Do
- ✓We do NOT sell student or parent data to third parties
- ✓We do NOT use student data for advertising or marketing
- ✓We do NOT build profiles on students for non-educational purposes
- ✓We do NOT share data with third parties except as needed to operate the service
5. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit (HTTPS/TLS)
- Invite-only sign-in (Google or a short-lived email link — no passwords)
- Role-based access controls
- IP addresses stored in masked form on signatures and audit logs
- Rate limiting to prevent abuse
6. Data Retention
We retain permission records and signatures for a period determined by your school's requirements, typically aligned with state record retention guidelines. Schools can request deletion of their data at any time.
Audit logs are retained until the school asks us to delete them. We do not currently run an automatic anonymization job.
7. Third-Party Services
We use the following third-party services:
- Email: Resend
- Hosting: Vercel
- Database and file storage: Supabase (PostgreSQL)
- Sign-in: Google OAuth when a school uses Google accounts
- Error monitoring: Sentry, when configured
We will sign a data processing agreement with a school that asks for one. A template is published at /dpa. We do not claim that every subprocessor relationship is already under a DPA.
8. Children's privacy
Schools import student names and grades so teachers can send permission slips. Parents then review and sign. This tool is built for schools acting as the data controller. We are not claiming COPPA "verifiable parental consent" for the platform itself, and we do not market to children.
- We collect only what a school needs to run permission slips
- Parents can email privacy@permissionplease.app or use the deletion request form to review or request deletion
- We do not sell student or parent data
9. Your Rights
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your data (subject to legal retention requirements) via the deletion request form
- Receive a copy of your data in a portable format
- Withdraw consent for optional data processing
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify schools of any material changes via email and update the "Last updated" date at the top of this page.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Permission Please
Email: privacy@permissionplease.app
For data deletion requests: /privacy/delete or privacy@permissionplease.app