PickupPass

Privacy

PickupPass Privacy Notice

This notice explains how PickupPass handles information when schools use the public beta. The participating school or district controls its student and pickup records; PickupPass processes those records to provide the service.

Effective August 15, 2026

Information we handle

School-provided roster and authorization data may include student name, school identifier, grade, teacher, authorized adult name, email, relationship, authorization status, and safety instructions. Operational records include pickup or drop-off location, time, vehicle note, queue status, staff action, and audit history. We also process staff email, role, sessions, waitlist contact details, and limited device and journey metadata.

How we use it

We use information only to authenticate users, operate pickup and drop-off workflows, enforce safety holds, maintain an audit trail, support schools, prevent abuse, and improve reliability. PickupPass does not sell personal information, serve behavioral advertising, or create advertising profiles.

Service providers

Cloudflare provides hosting, security, and database infrastructure. Brevo delivers staff sign-in emails. These providers process information only to provide their contracted services. A school or district may also authorize its personnel and service providers to access its records.

Retention and deletion

Short-lived sign-in links, expired sessions, remembered devices, rate-limit records, and beta journey events are removed on defined schedules. Schools control roster, safety, pickup, drop-off, and audit retention under their approved records policy. Legal holds and incident records may require longer retention.

Parent and school choices

Parents should contact their school to inspect, correct, or restrict school records and pickup authorizations. A school administrator can revoke remembered devices, suspend an authorized adult, rotate a PIN, disable staff access, and request export or deletion under the school's policy.

Children

PickupPass is a school-managed operational service, not a consumer service for children to create independent accounts. We do not knowingly ask children to submit personal information for marketing. Schools remain responsible for required notices, consent, and authorization decisions.

Security

Controls include hashed PINs and tokens, short-lived one-time staff links, secure cookies, role-based access, tenant-scoped queries, rate limits, safety holds, encrypted transport, backups, and audit records. No system can guarantee absolute security.

Contact

Questions or privacy requests may be sent to [email protected]. Parents should include the school name but should not email custody documents, student PINs, or detailed safety information.