Legal

Privacy Policy

Last updated: April 24, 2026

This Privacy Policy explains how SMS collects, uses, stores, and protects personal information — with special care for student and child data. We comply with India's Digital Personal Data Protection Act (DPDP Act), 2023, the Information Technology Act, 2000, and applicable international privacy standards.

Contents
01

Overview

SMS ("we", "our", "us") is a school management platform designed for Indian educational institutions. We are committed to protecting the privacy and security of all individuals whose data is processed through our platform — including school owners, administrators, staff, teachers, parents, and students.

This Privacy Policy applies to all users of the SMS platform, whether accessed via our web application or mobile interface.

đŸŽ¯

Core Commitment: We do not sell, rent, or trade personal data to third parties for profit. Student data is used exclusively to deliver the SMS service to your school. No student is profiled for advertising purposes.

02

Data Controller & Data Fiduciary

Under the DPDP Act 2023 and applicable privacy law, the following roles apply:

Data Fiduciary (Primary)
The registered School — the institution that determines the purposes and means of collecting and processing student, staff, and parent data within the platform. The School Owner acts as the authorised representative of the School for data purposes.
Data Processor
SMS Platform — we process personal data on behalf of schools strictly in accordance with their instructions and this Policy. We do not determine the purpose of processing independently.
Data Principal
The individual whose data is being processed — students, parents/guardians, teachers, and other staff members.

By registering on SMS, the School Owner confirms that the School has obtained, or will obtain, all necessary consents and authorisations from parents, guardians, and staff before entering their personal data into the platform — as required by the DPDP Act 2023.

03

What We Collect

School & Administrator Data

  • School name, address, contact information, and school code.
  • Owner name, email address, phone number, and securely stored password credentials.
  • Payment verification information (payment reference number, payer name) for setup fee processing.

Staff & Teacher Data

  • Name, email address, phone number, date of birth, gender, and address.
  • Role, designation, department, and joining date.
  • Teaching qualifications and subject specialisation (for teachers).
  • Profile photo (optional, managed by school administrators).

Student Data (Sensitive — Highest Protection Level)

  • Name, email address, date of birth, and gender.
  • Admission date, roll number, academic year, class, and section.
  • Attendance records, examination marks, and assignment submissions.
  • Fee payment records and financial ledger entries.
  • Medical information, where voluntarily provided by the school.
  • Parent and guardian relationships and contact details.

Automatically Collected Technical Data

  • Authentication session tokens stored locally in your browser for session management.
  • Browser type and version, used only for compatibility diagnostics.
  • Anonymised error logs and performance metrics. No personally identifiable information (PII) is included in these logs.
  • For users on the free tier: anonymised, non-personalised contextual data used to display relevant educational advertisements (see Section 07 — Advertising).
â„šī¸

We do not collect location data, device fingerprints, social media profiles, biometric data, or any behavioural tracking data for advertising or profiling purposes.

04

How We Use Data

PurposeData UsedLegal Basis
Deliver the platform serviceAll user dataContractual necessity
Account authentication & securityEmail, credentials, session tokensLegitimate interest
Academic management (attendance, marks)Student academic dataSchool's lawful instructions
Fee management & recordsEnrolment, payment dataContractual / legal obligation
Transactional email notificationsName, email addressContractual necessity
Platform improvement (anonymised)Aggregated, de-identified usage dataLegitimate interest
Contextual educational advertising (free tier only)Page context only — no personal profileSchool consent via Terms agreement
Legal compliance & auditRelevant records as requiredLegal obligation
05

Legal Basis for Processing

We process personal data under the following legal bases as provided under the DPDP Act 2023 and the IT Act, 2000:

  • Contractual Necessity: Processing required to deliver the Service under the Terms of Service agreed to by the School at registration.
  • Legitimate Interests: Security monitoring, fraud prevention, abuse detection, and service improvement — balanced against individuals' rights.
  • Legal Obligation: Where required by Indian law, court order, government directive, or regulatory requirement.
  • Consent (via School Agreement): For student and minor data, the School provides institutional consent on behalf of its community at registration by agreeing to these Terms. The School, as Data Fiduciary, is responsible for ensuring underlying parental or guardian consent has been obtained as required by the DPDP Act 2023.
06

Data Sharing & Third Parties

We do not sell personal data to third parties. We share data only in these limited, necessary circumstances:

Cloud Infrastructure Providers
We use reputable, enterprise-grade cloud service providers for hosting, database storage, and global content delivery. Each school's data is stored in an isolated, dedicated data store. All providers are bound by data processing agreements and maintain industry-standard security certifications. We do not disclose specific vendor names in this public document to protect our infrastructure security posture.
Transactional Email Service
We use a third-party email delivery service to send transactional messages such as registration confirmations, password resets, and payment receipts. Only the recipient's name and email address are shared for this purpose. This provider does not use your data for its own marketing.
Advertising Partners (Free Tier Only)
Schools on the free tier may have contextual, non-personalised educational advertisements displayed on the platform. Ad partners receive only anonymised, non-personal contextual signals (e.g., general subject area of the page). No student PII, behavioural profiles, or tracking data is shared with advertisers. See Section 07 for full details.
Legal Authorities
We may disclose data to law enforcement agencies, courts, or regulatory authorities when legally required to do so under Indian law or a valid court order. We will notify affected schools unless prohibited by law or court order.
âš ī¸

All third-party service providers are contractually bound to process data only for the purposes we specify, to maintain appropriate security standards, and to comply with applicable data protection law.

07

Advertising on SMS

đŸ“ĸ
Transparency Notice — How SMS is Funded SMS is available free of charge to schools. To sustain the platform, schools on the free tier may see contextual educational advertisements. Schools that prefer an ad-free experience may upgrade to a Premium plan.

What Type of Ads We Show

SMS displays only contextual, non-behavioural advertisements. This means:

  • Ads are matched to the content context of the page being viewed (e.g., a mathematics-related page may show ads for educational stationery or course materials), not to a user's personal history or profile.
  • No user tracking, behavioural profiling, or cross-site data collection is performed for advertising purposes.
  • No personally identifiable information of students, teachers, or parents is shared with advertisers.

Ad Categories — What We Allow

  • Educational courses, tutoring services, and academic tools.
  • Educational stationery, books, and school supplies.
  • Career guidance, scholarship programmes, and vocational training.
  • Age-appropriate technology products for education.
  • Reputable educational institutions and learning platforms.

Ad Categories — What We Strictly Prohibit

  • Alcohol, tobacco, or any substance-related products.
  • Gambling, betting, or fantasy sports platforms.
  • Dating, adult, or age-inappropriate content.
  • Political advertising or advocacy.
  • Financial products such as loans, credit cards, or investment schemes.
  • Any content that undermines student well-being or academic values.

Where Ads Are Shown

  • Ads are displayed only in non-sensitive areas such as dashboards and informational pages.
  • Ads are never shown on examination pages, result pages, fee payment screens, medical information sections, or any other sensitive workflow.
  • Ads are clearly labelled as "Advertisement" or "Sponsored" at all times.
Feature
Free Plan
Premium Plan
Contextual educational ads
Shown
Hidden
Ad-free experience
No
Yes
Behavioural / targeted ads
Never
Never
Student PII shared with advertisers
Never
Never
08

Children's Privacy

🧒

Students are our most protected users. Their data receives our highest level of care, access control, and legal protection.

SMS is a school management platform and by nature processes data of minors. We take this responsibility seriously and comply with:

  • DPDP Act 2023 (Section 9): Processing of personal data of minors (persons under 18 years) requires verifiable parental or guardian consent. The School, as Data Fiduciary, is responsible for obtaining this consent before entering any minor's data into the platform.
  • IT Act, 2000 (Section 43A): We maintain reasonable security practices for protection of sensitive personal data, including that of minors.
  • International Standards: We align with COPPA (US) and GDPR Article 8 (EU) principles as best practice, even where not directly applicable.

Our specific protections for student data include:

  • Student accounts are created and managed entirely by the school — students do not self-register.
  • Student data is visible only to authorised school staff, and to the student's own linked parent or guardian accounts.
  • No student's personal data is used for advertising targeting, behavioural profiling, or any commercial purpose beyond delivering the platform.
  • Advertisements on the free tier are contextual only — matched to page content, not to any student identity, history, or profile.
  • Sensitive data such as medical information is protected by strict, role-based access controls within the platform.
09

Data Retention & Deletion

Data TypeRetention PeriodDeletion Trigger
Active school & user dataDuration of active subscriptionAccount termination + 30 days grace
Student academic recordsDuration of enrolment + school's retention policySchool request or account termination
Fee & financial records7 years (financial/tax legal obligation)After mandatory legal retention period
Session tokensShort-lived, auto-expiringOn logout or automatic expiry
Transactional email logs90 daysAutomatic rolling deletion
Anonymised error & performance logs30 daysAutomatic rolling deletion

Upon account termination, we will provide a complete data export within 7 business days upon request. After the 30-day grace period, all school data is permanently and irreversibly deleted from all systems, including backups.

10

Your Rights

Under the DPDP Act 2023 and other applicable laws, you and your school have the following rights:

đŸ‘ī¸

Right to Access

Request a summary of the personal data we hold about you or your school.

âœī¸

Right to Correction

Request correction of inaccurate or incomplete personal data.

đŸ—‘ī¸

Right to Erasure

Request deletion of your personal data, subject to legal retention obligations.

đŸ“Ļ

Right to Data Portability

Receive a structured export of your school's data in a usable format.

đŸšĢ

Right to Withdraw Consent

Withdraw consent for non-essential processing at any time.

📋

Right to Grievance Redressal

Lodge a complaint with our Grievance Officer or with India's Data Protection Board.

To exercise any of these rights, contact us at privacy@sms.app. We will respond within 30 calendar days. Identity verification may be required for certain requests.

11

Security Measures

For full details of our technical and organisational security measures, please refer to our Security Policy. A summary of key protections:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using industry-standard secure protocols.
  • Encryption at Rest: All stored data — including school databases — is encrypted at the storage layer.
  • Password Security: User passwords are processed using a cryptographically secure, industry-standard adaptive hashing algorithm. Passwords are never stored or logged in readable form.
  • Session Management: Authentication uses short-lived, rotating session tokens. Sessions can be terminated instantly by administrators.
  • Data Isolation: Each school's data is stored in a dedicated, isolated data store. No cross-school data access is architecturally possible.
  • Access Control: A fine-grained, permission-based access control system ensures users can only access data relevant to their assigned role.

In the event of a data breach that may affect your personal data, we will notify affected schools within 72 hours of discovery, in accordance with DPDP Act 2023 requirements.

12

Cookies & Local Storage

SMS uses browser local storage (not tracking cookies) to maintain your session and preferences. The data stored locally includes:

  • Authentication tokens — for maintaining your logged-in session. Cleared automatically on logout.
  • School theme configuration — for displaying your school's custom branding without delay on page load.
  • School code and user type — for session persistence across browser refreshes.
  • Dark mode preference — your selected display preference.

No locally stored data is transmitted to third parties or used for advertising profiling. You may clear this data at any time via your browser settings, which will end your session.

If advertising is active on your school's free tier, any ad-serving technology used is configured to operate without behavioural cookies or cross-site tracking in compliance with our contextual-only advertising commitment.

13

Policy Changes

We may update this Privacy Policy periodically. When material changes are made, we will:

  • Update the "Last Updated" date displayed at the top of this page.
  • Send an email notification to all registered School Owners at least 14 days before material changes take effect.
  • Display a prominent in-platform notice for a minimum of 14 days following any material update.

Continued use of the Service following the effective date of any changes constitutes acceptance of the revised Policy. If you do not agree with material changes, you have the right to terminate your account and request a full data export before deletion.

14

Contact & Grievance Officer

In accordance with the DPDP Act 2023 and the IT Act 2000, we have designated a Grievance Officer to address data-related concerns. You may contact us for any privacy queries, requests, or complaints:

đŸ›Ąī¸ Privacy & Grievance Officerprivacy@sms.app
🔒 Security Incidentssecurity@sms.app
âš–ī¸ Legal & Compliancelegal@sms.app
đŸ’Ŧ General Supportsupport@sms.app

We aim to acknowledge all grievances within 48 hours and resolve them within 30 calendar days. If you are unsatisfied with our response, you have the right to lodge a complaint with India's Data Protection Board of India, once constituted under the DPDP Act 2023.

← Terms & ConditionsSecurity Policy →