Information Security
Last updated: 27 August 2026
This document explains how SchoolVillage protects your data and the data of the children represented on the platform — across school classrooms and activity groups including clubs, Scouts, sports, dance and drama.
1. Overview
Security is central to our design. We apply the principle of least privilege, data minimisation, and defence in depth, with particular care for any data that relates to children.
2. Data storage & encryption
Data is stored in managed cloud databases with encryption at rest and in transit over TLS. Secrets, such as service keys, are kept in a dedicated secrets store and never exposed to the client or logged.
3. Access control
Access is authenticated and role-based. Row-level permissions restrict records so that one guardian, school or organisation cannot read or modify another's data. A member of a classroom or group can only see the aliases, posts and members of communities they belong to. Administrative access to data is limited to authorised personnel and logged. Profile information (such as guardian first names) is only disclosed to members who share a community or a co-guardian link, not to every user. Invite codes are generated cryptographically and attempts to validate or join with a code are rate-limited per account to prevent guessing. User-generated posts and replies are filtered for prohibited language and rate-limited to reduce abuse.
4. Verification of schools & organisations
Staff claiming a school must verify an email on the school's registered domain before gaining staff privileges, and each school must first be approved and verified by SchoolVillage before any staff claim is granted. Activity organisation leaders must register their organisation and have it verified by SchoolVillage before they can publish a listing or lead a group; we may request evidence of the leader's role and the organisation's safeguarding arrangements. Staff and leader access is tied to that verification and is removed if it can no longer be confirmed.
5. Authentication
Accounts use secure authentication including optional social sign-in. Passwords are never stored in plain text. Sessions are managed with short-lived tokens and can be revoked on sign-out. Push notification tokens, where used, are stored securely and used solely to deliver notifications to your device.
6. Network & infrastructure
The service runs on managed infrastructure with monitored ingress, patching, and dependency management. We rely on established cloud providers whose security posture we assess for suitability.
7. Backups & resilience
We maintain backups and recovery procedures to protect against data loss and to support continuity. Backups are access-controlled and encrypted.
8. Breach response
We monitor for security incidents. If a personal data breach occurs that is likely to result in a risk to individuals, we will assess and, where required, notify the relevant supervisory authority and affected users without undue delay, in line with UK GDPR.
9. Sub-processors
We use trusted sub-processors for hosting, payments (Stripe) and related services under contracts that require appropriate security and confidentiality. We keep a list of key sub-processors and review them periodically.
10. Your responsibilities
You play a part too: keep your login secure, don't share invite codes or screenshots that expose children's information, and flag posts that concern you. Avoid posting identifying details in any classroom or group. Organisation leaders are responsible for managing their own members' access and removing leavers promptly.
11. Continuous improvement
We review our controls, address findings, and update practices as the service evolves. Where security changes materially affect you, we will communicate them.