Privacy Policy
Last updated: 21 July 2026
Schome is a school attendance and student-safety platform operated by [LEGAL ENTITY NAME] (“we”, “us”). This policy explains what personal data the platform handles, why, who it is shared with, and the choices available to you.
1. Who controls your data
Your child’s school decides what data is entered into Schome and who may see it. The school is the data fiduciary (controller). We operate the platform on the school’s instructions as its processor.
Requests to see, correct or delete a student’s records should go to the school first. We will assist the school in answering them.
2. Data we handle
Student and family details, entered by the school: name, admission number, class, date of birth, gender, blood group, home address, transport mode, medical notes, guardian name and phone number, and emergency contacts.
Attendance and presence: check-ins and check-outs recorded by ID card or beacon, gate crossings, class attendance marked by teachers, and leave requests.
Location data, for students on a Safety or Shield plan: the position of the student’s tracking device, journey history, and the safe-zones (geo-fences) a parent has configured, including entry and exit events.
School activity: homework and submissions, teacher diary and daily status notes (behaviour, meals, water, grooming), incidents, circulars and messages.
Emergency records: SOS alerts raised from a student’s card or by a parent, including the time, the device and any note added.
Technical data: account email and role, device identifiers of issued hardware, beacon identifiers, notification tokens, and an audit log of significant actions taken in the system.
3. Why we handle it
To record attendance; to let schools and parents see whether a child arrived safely; to raise and deliver emergency alerts; to carry communication between school and home; to operate subscriptions; and to keep the service secure and auditable.
We do not sell personal data, and we do not use it for advertising or profiling.
4. Children's data
Schome exists to record information about children, including their location where a school and family have chosen a safety plan. Access is limited to the child’s school staff and the parent or guardian account the school has linked to that child.
[LEGAL REVIEW REQUIRED] — the lawful basis for processing children’s data, the mechanism for obtaining verifiable parental consent, and the position on tracking and behavioural monitoring of children under the Digital Personal Data Protection Act 2023 must be settled and stated here before this policy is published.
5. Who else receives data
We use a small number of service providers. Each receives only what its function requires:
- Google (Firebase Cloud Messaging) — delivers push notifications to phones. Receives the device notification token and the notification text, which for an emergency includes the child’s name (for example, “SOS from [name]”).
- Google (Places API) — powers address search and autocomplete. When someone types into an address field — a parent setting a safe-zone, or school staff recording a student’s or school’s address — the text entered is sent to Google to return matching addresses and their map coordinates. Where a key is not configured, this falls back to the OpenStreetMap Foundation’s Nominatim service, which receives the same search text.
- Anthropic — powers the assisted message composer used by school staff. Receives the draft text a staff member submits for rewriting. Do not enter information in that box you would not wish to send to a third-party service.
- [HOSTING PROVIDER] — hosts the servers and database on which the platform runs.
We may also disclose data where the law requires it, or to protect the safety of a child.
6. Retention
Records are kept while the school’s account is active and for [RETENTION PERIOD] afterwards, unless the school asks us to delete them sooner or the law requires us to keep them longer.
7. Security
Data is transmitted over encrypted connections and access is restricted by role, with each school’s records separated from every other school’s. No system is perfectly secure; we will notify the affected school without undue delay if a breach affects its data.
8. Your rights
Subject to applicable law, you may request access to the personal data held about you or your child, correction of anything inaccurate, deletion, and information about how it has been shared. Contact your school first; it holds the decision over its own records.
Grievance Officer: [NAME], [EMAIL], [POSTAL ADDRESS].
9. Changes
We will update the date at the top of this page when this policy changes, and notify schools of material changes.
10. Contact
[LEGAL ENTITY NAME], [POSTAL ADDRESS] — [CONTACT EMAIL].
