Trust
Security & data protection
SchoolerHub holds information about children. This page describes the controls we actually operate — no certifications we don't hold, no claims we can't stand behind.
Per-school separation
Every record belongs to exactly one school. The application scopes each request to the signed-in user's school, so one school's staff cannot reach another school's data.
Role-based access
School administrator, staff, teacher and parent roles each reach only the modules and records their role requires. Authorisation is checked per action, not just per page.
Private document storage
Uploaded certificates and documents are stored on a private disk outside the public web root. They are served only through authenticated routes that verify the requester may see that specific record.
Encryption in transit
All traffic to schoolerhub.com and app.schoolerhub.com is served over HTTPS/TLS. Backups are stored encrypted at rest.
Secure authentication
Passwords are stored as salted one-way hashes — neither we nor your administrator can read them. Sessions are protected against fixation and forms against cross-site request forgery.
Activity logging
Significant actions are recorded with the acting user and timestamp, giving schools an audit trail of who did what.
Reversible deletion
Most records use soft deletion, so a record removed by mistake can be restored rather than lost.
Data residency
Application data is hosted in India. The exceptions are WhatsApp delivery, handled by Meta, and transactional email — both limited to the data described in our privacy policy.
What we send to messaging providers
When a school sends a fee reminder or absence alert, only the variables the approved template needs leave our systems — the recipient's mobile number, the student's name and class, and the amount or date concerned. Student documents, Aadhaar numbers, addresses, marks and medical information are never shared with messaging providers.
What we do not claim
We would rather be accurate than impressive. We do not hold, and do not claim to hold:
- ISO 27001 certification
- SOC 2 attestation
- Any guarantee that the platform is “100% secure”
No system can be guaranteed completely secure. If we obtain a formal certification in future, we will say so here and provide evidence on request.
If something goes wrong
If we become aware of a personal data breach affecting a school's data, we will notify that school without undue delay, tell it what we know, and support its own notification obligations under the Digital Personal Data Protection Act, 2023.
Reporting a vulnerability
Found something? Email [email protected] with enough detail to reproduce it. We acknowledge reports within 3 working days and will not pursue action against anyone reporting in good faith. Full terms are in the Acceptable Use Policy.
What your school controls
Some of the most important controls sit with the school, not with us:
- Deciding who gets an account and what role they are given
- Removing accounts promptly when staff leave
- Ensuring staff do not share credentials
- Deciding what information is recorded about students in the first place
- Obtaining the consents required to hold and use that information
We are happy to walk your team through these during implementation.
Related: Privacy Policy · Terms & Conditions · Acceptable Use Policy