Legal
Privacy Policy
Last updated: August 15, 2026
1. Introduction
This Privacy Policy describes how eSchoolSaaS ("we", "us", "our") handles personal information when you use our multi-school ERP platform, public websites, admin portals, and mobile applications (Parent, Teacher, and Student apps).
Schools that deploy eSchoolSaaS act as data controllers for their users. We provide the software platform and, on our public demo host, operate a sample environment for product evaluation.
By creating an account, signing in, or using our mobile apps, you acknowledge this policy. If you use eSchoolSaaS through your school, your institution may also provide its own privacy notice.
2. Information We Collect
Account and identity data: name, email address, phone number (if provided), school or institution code, user role (parent, teacher, student, or administrator), and authentication credentials stored in hashed form.
Academic and operational data: student profiles, class and section assignments, attendance records, examination results, fee balances and receipts, timetables, homework, notices, transport and hostel assignments, and related school records entered by authorized staff.
Mobile and device data: Firebase Cloud Messaging (FCM) device tokens used to deliver push notifications; basic device and app version metadata needed to register and manage notification delivery.
Usage and security data: login timestamps, session identifiers, audit logs, IP addresses, and actions taken in admin or mobile apps for security, troubleshooting, and compliance.
Communications: messages sent through in-app notification systems and support inquiries you submit to us or your school.
3. How We Use Information
Provide and operate the ERP, website CMS, and mobile apps, including authentication, role-based access, and school-specific branding.
Display academic, financial, and operational information to authorized parents, teachers, students, and school staff.
Send push notifications and in-app alerts about attendance, fees, results, notices, and other school communications when you enable notifications.
Maintain platform security, prevent fraud and unauthorized access, and investigate incidents.
Improve reliability and support, including demo and evaluation environments on our reference deployment.
4. Legal Bases and School Responsibility
Schools typically process student and parent data under contractual necessity, legitimate interests in education administration, and applicable local education and privacy laws.
On our demo reference host, we process limited sample data solely to demonstrate product functionality to prospective buyers and app store reviewers.
We do not sell personal information. We do not use student academic data for third-party advertising.
5. Sharing and Disclosure
Within a school: information is shared only with users who have appropriate roles and permissions (for example, a parent sees their linked children; a teacher sees assigned classes).
Service providers: we may use infrastructure providers (hosting, email delivery, push notification services such as Google Firebase) that process data on our behalf under contractual safeguards.
Legal requirements: we may disclose information if required by law, regulation, court order, or to protect the rights, safety, and security of users and the platform.
Business transfers: if ownership of the platform changes, user data may transfer subject to this policy or a successor notice.
6. Mobile Applications (Google Play & App Store)
Our Parent, Teacher, and Student apps connect to your school's eSchoolSaaS API over HTTPS. Each app validates the signed-in user's role and shows only data permitted for that role.
Push notifications: when you grant permission, the app registers an FCM device token with our API so your school can send alerts. You may disable notifications in device settings; logging out removes the registered token from active delivery.
Offline cache: mobile apps may temporarily cache read-only data on your device to improve performance. Cached data is scoped to your account and cleared on logout or expiry.
Demo builds: evaluation apps may display one-tap demo login buttons that still authenticate through the normal login API. Demo credentials must not be used in production deployments.
7. Data Retention
Schools control retention of academic and administrative records according to their policies and legal obligations.
Session tokens, audit logs, and notification history are retained for operational and security periods configured by the platform or school.
When a school account is deactivated or deleted, associated tenant data is handled according to the school's contract and backup procedures.
8. Security
We use industry-standard measures including encrypted transport (TLS), password hashing, tenant database isolation, role-based access control, and audit logging.
No method of transmission or storage is completely secure. Schools and users should protect passwords and report suspected unauthorized access promptly.
9. Children and Students
eSchoolSaaS is designed for use by schools that manage student records. Student mobile access is intended for students with school-provided accounts under institutional supervision.
Parents and schools are responsible for ensuring appropriate consent and use in compliance with applicable child privacy laws (including COPPA, GDPR, and local education regulations where applicable).
10. Your Choices and Rights
Access and correction: contact your school administrator to update profile or academic records held in the ERP.
Account deletion: submit a request at https://eschool.mysyva.net/delete-account or contact your school administrator for account removal.
Notifications: control push permissions in your device settings and notification preferences where available in the app.
Depending on your jurisdiction, you may have additional rights to access, export, restrict, or delete personal data. Submit requests to your school or, for platform-level inquiries, to the contact below.
11. International Transfers
Data may be processed in the country where your school or our hosting provider operates. Schools choosing self-hosted deployments control server location.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date below will reflect changes. Continued use after updates constitutes acceptance of the revised policy.
13. Contact
For questions about this policy or our reference demo environment, contact the platform operator through your CodeCanyon purchase support channel or your school's designated administrator.
For data held by your school, contact the school directly — they are the primary controller of student and staff records.