Skip to content
← Trust & compliance

Student data privacy

A school is trusting us with its families and its students. Here is what that means for their data: what we collect, what we never do, how long we keep it, and how it aligns with the laws that protect students.

What we collect

  • Adult contact details for organizers and families: name, email, and phone.
  • Students' names, entered by their family or the school, so the trip knows who is travelling. A school can choose to keep only a first name and last initial ("Jane S."), which our database then enforces for the names on its rosters, member list, payment records, chat, polls, date votes and safety check-ins.
  • Coordination facts: who is going, who is a chaperone and whether staff have recorded their background-check clearance, who has returned a permission form, rooming, and payment status.
  • Group assignments: which students and chaperones staff put in each group. A draft changes nothing; chaperones see their group only after staff publish the plan.
  • Personal invitations: when staff invite a family to a trip by email, the invitation record keeps a one-way fingerprint of the link and of the invited address, when it expires (after 7 days), and whether it was used.
  • Account setup: if a school chooses to create families' accounts itself, we keep that account record and a one-time setup code, stored only as a one-way fingerprint. Staff see the code once, when they issue it. Families choose their own password, which staff never see.
  • Pickup lists: up to six people a guardian says may collect their student at the end of a trip, with each person's name, relationship and phone, and whether the guardian lets the student leave on their own. Staff can enter or change a list when a family asks.
  • Day-of records: headcount taps (who was counted at each check, by which staff member or chaperone, and when), and marks staff make for a student who is not travelling that day, which apply to that day's counts only.
  • Dismissal records: who released each student at the end of the trip, to whom, how and when. A release to someone not on the list also records the reason and the second staff member who confirmed it.
  • What people type into the trip: messages, announcements, questions to the organizer, written poll answers, and schedule notes. Organizers' notes on a family's financial aid are stored too, until the retention step below.
  • Electronic signatures: when a family signs a permission form in Jettova, we keep the typed name, the time, the IP address and the browser, so the signature can be checked later.
  • Payment records: amounts, currency, and the payment processor's references. Card numbers are entered directly into the processor's secure fields and never reach Jettova.
  • Uploaded permission forms: the document a family uploads, stored privately. We don't ask for medical or health records, but if a school's own permission form asks for health, allergy or emergency-contact details, the signed copy holds them. Our automatic form check is switched off; if we ever switch it on, our AI reads the uploaded form to check that it looks signed.

What we never do

  • We don't ask families for students' medical or health records. The optional emergency and medical layer is off, so no medical record is collected through it.
  • No advertising runs on any school page or trip. We never sell students' or families' data from a school trip, and never use it for advertising.
  • We do not use student data to build a profile of a student unrelated to their trip.
  • We do not share data with third parties except the sub-processors that run the service, each listed with what it receives and when it is used.

Who sees what

Every new school program has these seats. This table is generated from the same permissions reference staff see in the console, which we check against the code that enforces each rule. Our servers check every rule on every request.

AllowedLimited, within the scope notedNot allowed

  • See trips

    Family
    Limited: Only trips they were invited to by that trip's link, or are on the roster of.
    Coach
    Limited: Only trips they created or were added to.
    Principal
    Allowed: Every trip in the program.
    Program administrator
    Allowed: Every trip in the program.
    Finance
    Limited: Every trip's basics and money, not its families' details.
  • See families and their names

    Family
    Limited: Only their own family.
    Coach
    Limited: Only families on their trips.
    Principal
    Allowed: Every family.
    Program administrator
    Allowed: Every family.
    Finance
    Limited: Anonymous family labels, never names.
  • See guardian phone numbers

    Family
    Limited: Only their own.
    Coach
    Limited: Only families on their trips.
    Principal
    Allowed: Every family.
    Program administrator
    Allowed
    Finance
    Not allowed
  • See a trip while waitlisted

    Family
    Limited: Trip basics and what they would owe, until they have a place.
    Coach
    Not allowed: Staff never take a seat, unless they are a parent on the trip.
    Principal
    Not allowed: Staff never take a seat.
    Program administrator
    Not allowed: Staff never take a seat.
    Finance
    Not allowed: Staff never take a seat.
  • Send, resend and revoke personal roster invitations

    Family
    Not allowed: They accept their own invitation only.
    Coach
    Limited: Only trips they created or were added to.
    Principal
    Allowed: Every trip in the program.
    Program administrator
    Allowed
    Finance
    Not allowed: Sends none. May accept an invitation for their own child, as a family on that trip.
  • Create family accounts and issue or revoke setup codes

    Family
    Not allowed: They set their own password through the link emailed to them, or keep the one they already have. Staff never see a password.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • Build, publish and stop participant groups

    Family
    Limited: A chaperone sees only their published group on the day-of headcount.
    Coach
    Limited: Only trips they created or were added to.
    Principal
    Allowed: Every trip in the program.
    Program administrator
    Allowed
    Finance
    Not allowed
  • See the payments ledger

    Family
    Limited: Only what their own family owes and paid.
    Coach
    Limited: Only their trips, with family names.
    Principal
    Allowed: Every trip, with family names.
    Program administrator
    Allowed: Every trip, with family names.
    Finance
    Limited: Every trip, with anonymous family labels.
  • See permission-form progress

    Family
    Limited: Only their own students.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Who has returned a form and when, not the form itself.
    Program administrator
    Allowed
    Finance
    Not allowed
  • Open and download signed permission forms

    Family
    Limited: Only their own.
    Coach
    Limited: Only trips they run.
    Principal
    Not allowed
    Program administrator
    Allowed: One trip at a time, or every trip at once from Settings.
    Finance
    Not allowed
  • See medical records and legal identities

    Family
    Limited: Only their own students.
    Coach
    Limited: Only students on trips they run.
    Principal
    Not allowed
    Program administrator
    Allowed
    Finance
    Not allowed
  • Answer families' questions and see poll answers

    Family
    Limited: They ask questions and vote on their own trips.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • Download the offline departure pack (roster, guardian phones, rooms)

    Family
    Not allowed
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip. No medical records, legal identities or signed forms.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • Take the day-of headcount (who has been counted, and by whom)

    Family
    Limited: A cleared chaperone counts only their own group. Families never see the count.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • Mark a student not travelling today on the day-of headcount

    Family
    Limited: A cleared chaperone sees who on their own team is not travelling, and cannot change it.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • Tap-to-call phones on the day-of headcount and departure pack

    Family
    Limited: Every family on the trip sees the number staff set for families on the day. A cleared chaperone in a published group can also call their own group's guardians, and gets the staff day-of number. Never another group's phones.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • See and edit who may collect each student

    Family
    Limited: Their own students only, and only the guardian can allow a student to leave on their own. A cleared chaperone sees their published group's lists on the day.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip. Not in the export.
    Program administrator
    Allowed: Every trip. Staff can remove, but never grant, permission to leave alone. Also in the program administrator's export.
    Finance
    Not allowed
  • Run dismissal at the end of a trip (who collected each student)

    Family
    Limited: A cleared chaperone, for their published group only. Someone not on the list needs a second staff member.
    Coach
    Limited: Only trips they run.
    Principal
    Allowed: Every trip.
    Program administrator
    Allowed: Every trip.
    Finance
    Not allowed
  • See who opened student records

    Family
    Not allowed
    Coach
    Not allowed
    Principal
    Allowed
    Program administrator
    Allowed
    Finance
    Not allowed
  • Audit log and whole-program export

    Family
    Not allowed
    Coach
    Not allowed
    Principal
    Limited: The export, without signed forms or the audit log.
    Program administrator
    Allowed
    Finance
    Not allowed
  • Students don't have accounts. Their families act for them.
  • A coach who is also a parent is a family on their own child's trip: they see and pay for that trip like any family.
  • A chaperone sees nothing about anyone until staff record their clearance. Then, on the day, they see the first names of the students in their own group and who in it is not travelling. Once staff publish groups, they also see their own group's pickup lists and can call their own group's guardians, and no one else's.
  • Hiding a button is never the safeguard. Every one of these rules is checked again on our servers.
  • The tour-operator page a school can share carries dates, headcounts, rooms and the itinerary, with no roster and no names from student records.
  • Some older programs have a separate approver seat. An older principal seat that approves or denies trips. Sees what the Principal sees: every trip, families' names and contact details, aid notes, the money and the departure pack; not medical records, legal identities or signed forms. Can't run trips or change settings. New programs seat the Principal instead.
  • Every program starts with a Jettova administrator in the program administrator seat, because we set programs up with you. That person can see everything the program administrator column shows, including signed forms. When you are ready, we seat your own administrator and step out of the seat; tell us when.

How families are protected

Families see only their own trip

A family sees only the trips it was invited to. When a trip's roster lists parents' email addresses and someone joins through a forwarded link with an email that isn't on it, they see the trip's basics only until the organizers confirm them, and the organizers are told.

A waitlist shows basics only

A waitlisted family sees the trip's basics: where, when, and what it would cost them. The itinerary, meeting points, chat and polls open only once they have a place.

Families see only what they owe

A family sees what it owes and what it has paid, never the trip's budget, vendor costs or another family's payments.

Chaperones see their own group

A chaperone sees nothing about anyone until staff record their background-check clearance. Then, on the day, they see the first names of the students in their own group and who in it is not travelling. Once staff publish groups, they also see that group's pickup lists and can call that group's guardians (or an adult participant's own number), and no one else. Families never see headcounts, pickup lists or dismissal records, except their own students' pickup lists.

Invitation-only enrollment

Staff can switch a trip to personal invitations only. A new family then needs the invitation sent to the address on the trip's roster, opened in an account with that verified address, plus their student's first name. Families already on the trip keep their place.

Setup codes can't set a password alone

When a school creates a family's account, the setup code staff can see cannot set a password by itself. Choosing the password needs the link we email to the address on the roster, and a guardian also enters their student's first name. Codes expire after 7 days and stop working after 5 wrong tries.

Two staff for anyone not on the list

A student can go home with someone not on their pickup list only with a written reason and a second staff member confirming on their own signed-in account. A chaperone can ask, but only staff confirm, and an unconfirmed request lapses after 15 minutes.

Every release is recorded

Each release records who released the student, to whom and when. Undoing one is allowed for 10 minutes and is recorded too. Recording a release needs a connection, so two offline phones can never hand the same student to two people.

No direct database access

Every table that holds school data refuses direct access from a browser. Every read and write goes through our server, or through a short-lived link our server issues, and the server checks the person's current role first.

Short-lived file links

Uploaded forms and documents sit in private storage. Staff open them through links that expire after five minutes.

Access is logged

Opening a student record and downloading a trip's offline departure pack are logged with who and when. Logging never blocks the person doing their job, so if an entry cannot be written we try to record the gap and show the school the log is incomplete. The program administrator and the Principal can see it. Opening or downloading a signed permission form is recorded on the program's audit log, which only the program administrator can see. The Principal sees whether each form has come back and when, never the form itself.

Retention runs on its own

One year after a trip returns, a nightly job removes the names and contact details families entered, signatures and uploaded forms from it. Messages, announcements, questions, poll answers and schedule notes people typed are kept as written, as the trip's record. Organizers' private notes on a family's financial aid are removed; the aid amount stays with the payment records. Copies already taken offline, such as a printed departure pack or a downloaded form, are outside its reach. A family's own account and program membership stay until they delete them or leave the program, and a family can delete their own account themselves at any time.

No push notifications on school trips

School trips reach families by email and on the trip page only, so no app-store push service receives school trip content.

First name and last initial, if you want it

A school can switch on a setting that keeps every student's name to a first name and last initial ("Jane S."). The database shortens every copy of a student's name the product keeps for running the trip (roster, payments, chat and poll labels). Legal names a school collects for a ticketed booking, the guardian's signature and uploaded forms are kept as entered, and names people type into messages are left as written.

The vendors that run the service, what each receives and when, are on our school sub-processors list.

Built to align with the laws that protect students

Jettova for Schools is built to help a school meet its obligations under the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and applicable state student-privacy laws (for example SOPIPA). We support the school as the controller and act only on its instructions.

The full commitments, including security measures, breach notification, and retention, are set out in our Data Processing Addendum, which your counsel can review before you sign up. The current list of sub-processors is our school sub-processors list.

Your data, your control

The data belongs to the school

The school is the controller; Jettova is a processor acting on the school's instructions. When the platform is used with K-12 students, Jettova acts as a school official performing an institutional service, and uses covered data only for that.

Access, correction, deletion

Jettova helps the school respond to requests to access, correct, or delete a family's data, and to meet the school's obligations under applicable law.

Retention and auto-deletion

One year after a trip's return date, a nightly job removes the names and contact details families entered (students' names included), home locations, signature details and uploaded forms, and keeps the trip's payment records with each family shown as "Former member". Uploaded itineraries are deleted 30 days after the return date. Messages, announcements, questions, poll answers and schedule notes people typed are kept as written, as the trip's record. Organizers' private notes on a family's financial aid are removed; the aid amount stays with the payment records. The same job deletes every pickup list and removes the names, relationships and reasons from dismissal records, keeping only that a student was released, how and when. It also deletes the not-travelling marks. Headcount taps, invitation records and setup codes hold no names; they stay with the trip and go when it is deleted, and an invitation or setup code stops working after 7 days. A school can ask us to remove its data sooner. On termination, we delete or return the school's data at the school's choice.

Export any time

It is your data. A school can request an export of its roster and records at any time, and request deletion, without penalty. The program administrator's export includes pickup lists and dismissal records; the Principal's export, and every other seat's, does not.

Privacy questions and requests

For a parent or guardian. You can see and correct your own family's details, your students' names and your students' pickup lists on the trip page at any time, and see what you owe and have paid. Only you can let your student leave on their own; staff can remove that permission, never grant it. You can delete your own account yourself. Payments you made stay with the school as its financial record, with your name removed. Deleting your account, or leaving a trip, also deletes your students' pickup lists and not-travelling marks, and removes the names of the people who collected them from the trip's dismissal records.

Your school controls its trip records, so a request to see, correct or delete records the school holds goes to the school, usually the trip's organizer. We help the school answer it. If you are not sure who to ask, or want to ask us directly, email support@jettova.com and name your school and trip, and we will help your school answer it.

For a school. Your program administrator or Principal can export your records, and either can ask us to delete them at any time, using the same address or your usual contact with us.

This page describes how the product works and is not a substitute for the executed agreement and DPA between your school and Jettova, Inc., which govern.