Privacy
PickupPass Privacy Notice
This notice explains how PickupPass handles information when schools use the public beta. The participating school or district controls its student and pickup records; PickupPass processes those records to provide the service.
Effective August 15, 2026
Information we handle
School-provided roster and authorization data may include student name, school identifier, grade, teacher, authorized adult name, email, relationship, authorization status, and safety instructions. Operational records include pickup or drop-off location, time, vehicle note, queue status, staff action, and audit history. We also process staff email, role, sessions, waitlist contact details, and limited device and journey metadata.
How we use it
We use information only to authenticate users, operate pickup and drop-off workflows, enforce safety holds, maintain an audit trail, support schools, prevent abuse, and improve reliability. PickupPass does not sell personal information, serve behavioral advertising, or create advertising profiles.
Service providers
Cloudflare provides hosting, security, and database infrastructure. Brevo delivers staff sign-in emails. These providers process information only to provide their contracted services. A school or district may also authorize its personnel and service providers to access its records.
Retention and deletion
Short-lived sign-in links, expired sessions, remembered devices, rate-limit records, and beta journey events are removed on defined schedules. Schools control roster, safety, pickup, drop-off, and audit retention under their approved records policy. Legal holds and incident records may require longer retention.
Parent and school choices
Parents should contact their school to inspect, correct, or restrict school records and pickup authorizations. A school administrator can revoke remembered devices, suspend an authorized adult, rotate a PIN, disable staff access, and request export or deletion under the school's policy.
Children
PickupPass is a school-managed operational service, not a consumer service for children to create independent accounts. We do not knowingly ask children to submit personal information for marketing. Schools remain responsible for required notices, consent, and authorization decisions.
Security
Controls include hashed PINs and tokens, short-lived one-time staff links, secure cookies, role-based access, tenant-scoped queries, rate limits, safety holds, encrypted transport, backups, and audit records. No system can guarantee absolute security.
Contact
Questions or privacy requests may be sent to [email protected]. Parents should include the school name but should not email custody documents, student PINs, or detailed safety information.