Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains what SchoolVillage collects, why, and the choices you have. We are committed to data minimisation, particularly when it comes to children's information. SchoolVillage covers the whole of a child's village — school classrooms and activity groups including clubs, Scouts, sports, dance and drama.
1. Who we are
SchoolVillage is the controller of the personal data processed through the service, responsible for it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data we collect
- Account data — your name, email address, and authentication details.
- Guardian profile — first name, last name, optional avatar, subscription tier, and (for staff) the school you have claimed.
- Organisation & leader data — for activity organisation leaders: organisation name, type, address, postcode, whether it is volunteer-run or commercial, evidence of your role, and the groups you lead.
- Child aliases — a child's first name and last initial only, linked to a classroom or group. We do not collect full names, dates of birth, photos, or addresses for children.
- School & organisation data — publicly available UK school information (names, addresses, postcodes, unique reference numbers) from official datasets, and details organisations provide for their public listing.
- Posts, notices & messages — noticeboard posts, party notices, replies and group messages you create.
- Attendance — for organisation leaders, attendance records (present/absent/late) recorded against child aliases within a group.
- Support & reports — messages you send via our support channels and details you provide when reporting a post, member or safeguarding concern.
- Notifications — limited content (such as a post title) and device tokens used to send you push notifications about community activity.
- Usage data — limited, aggregated analytics to improve the service.
3. How we use your data
We use your data to provide classrooms, groups, directories, noticeboards, party features, attendance and in-app search; to verify school staff and activity organisation leaders; to process subscriptions; to send you push notifications about new posts, party notices, calendar dates and session reminders; to keep the platform secure; and to meet legal obligations. We do not sell personal data and do not use it for advertising profiling of children. You can disable push notifications in your device settings at any time.
4. Legal basis
We process data on the basis of contract (providing the service), consent (where you opt in), legitimate interests (security and improvement), and legal obligation.
5. Children's data
SchoolVillage is built around child aliases. Children do not hold accounts and we do not knowingly collect more than a first name and last initial for any child, whether in a school classroom or an activity group. Where we learn that more identifying information has been added, we will remove it. See our Child Safeguarding Measures for the full design and operational safeguards.
6. Sharing
We share data only with processors that support the service (for example payment processing via Stripe and cloud hosting), under contract and with appropriate safeguards. We may disclose data where required by law. Within a classroom or group, the aliases and posts you create are visible to other members of that community by design. Communication within a community is visible to its members. Where direct guardian-to-guardian messaging is available, those messages are visible only to the sender and recipient (and, where necessary for a safeguarding or moderation investigation, to our staff).
7. International transfers
Where data is transferred outside the UK, we do so with appropriate safeguards such as UK adequacy decisions or standard contractual clauses.
8. Retention
We keep your data only for as long as needed to provide the service and meet legal obligations. You can request deletion at any time: we remove your profile, child aliases, co-guardian links, direct messages, join requests, attendance records, read receipts and notifications, anonymise your party RSVP details and any reports involving you, and anonymise the posts, replies and party notices you created (replacing your name with "A guardian") so that community conversations remain intact. Child safeguarding concern records are the one exception — they are retained even after deletion, because we are required to keep child-protection records and removing them would break the audit trail a school's designated safeguarding lead relies on. Specific retention periods: account and guardian profile data is kept while your account is active and removed/anonymised on deletion; child aliases are removed on deletion and when you leave a community; attendance records are kept while a group is active and removed when a child leaves the group; moderation logs (including original removed content) are retained for 12 months for accountability and dispute resolution; support tickets are retained for 6 months after resolution; and notification content is retained for 30 days. New guardians join a community in a "welcome" state — their details are hidden from the directory until an existing member welcomes them — to protect the community if an invite code is leaked.
9. Security
We apply access controls, encryption and role-based permissions. See our Information Security document for detail.
10. Your rights
Under UK GDPR you may request access, correction, deletion, restriction, portability, and objection. You may withdraw consent at any time. You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).
11. Cookies
We use essential cookies for authentication and session management. Analytics cookies, where used, are minimised and do not profile children.
12. Contact
To exercise your rights or ask about this policy, contact us through your account or Base44 support.