Skip to content
Jettova for Schools

For your administration, business office, and IT reviewer

Check us before you trust us

Most vendor trust pages ask you to believe a list of assurances. This one starts with three things you can confirm yourself, in a few minutes, without calling us. The promises come after, and we have marked which is which.

Three things you can verify without asking us

Each of these is checkable by you, with no cooperation from Jettova. That is why they are first.

  1. No advertising or marketing tracker runs on any page a family or student touches.

    Jettova's consumer travel pages carry an affiliate attribution tag, which is how free trip planning gets paid for. That tag is switched off on every school surface: the school console, the nonprofit pages, and every trip room, including the pages where a family signs a permission form and pays. This is not a policy we follow, it is a rule in the code, with an automated test that fails if anyone removes a surface from the list.

    No ad network, no marketing pixel, no retargeting, no session recorder, and no data broker runs on a school surface. We never sell students' or families' data from a school trip, and never use it for advertising.

    The same rule switches off the third-party page-view and performance analytics products we use elsewhere, so none of those runs on a school surface either. And a booking search link a staff member follows now carries only the channel it came from, never the trip's room code.

    How to check this: Open a trip room, open your browser's network tab, and filter for requests leaving our domain. You will not find an ad network. The next section lists everything you will find, so you can match it against what you see.

  2. Your school is the merchant of record. The money never sits with us.

    Family payments go into your school's own Stripe account as a direct charge. Your school is the merchant on the transaction, your school's name appears on the family's statement, and the funds settle to your bank on your schedule. Jettova is not in the funds flow and cannot hold, delay, or redirect your money. There is no Jettova balance a school's trip money can sit in, and no Jettova failure that can strand it.

    The school receives 100% of the trip cost. A service fee is added at checkout on top of the trip cost, and it covers payment processing plus our platform fee. On smaller payments card and bank transfer cost a family the same, so we say so rather than imply a discount that is not there. Above $324.00 the bank transfer costs less, because everything added to a bank payment is capped at $15, and checkout shows the exact saving for that payment before a family commits. If you would rather collect cash or checks, an organizer marks the payment received in Jettova and no fee applies at all.

    How to check this: The Stripe account is created in your school's name and your business office completes the verification directly with Stripe. Open your own Stripe dashboard and the charges are there, under your account, before Jettova tells you anything.

  3. We sign your district's data privacy agreement, not ours.

    Most vendors hand a district their own contract. We do the reverse: send us your district's data privacy agreement and we sign it. If your district uses the Student Data Privacy Consortium's National Data Privacy Agreement, we sign your state's version with the standard clauses unmodified, plus the General Offer of Privacy Terms (Exhibit E) so other districts in your state can adopt the same agreement without renegotiating it.

    Your counsel reviews a document they already know, on paper they already approved, instead of a startup's custom contract.

    How to check this: The NDPA for your state is public at the SDPC's site. Nothing in it is ours, so there is nothing for you to take on faith about the terms. Ask us for the completed exhibits (description of services, schedule of data, data security requirements) and compare them against the data the product actually collects, which is listed on the student data privacy page.

Exactly what runs on a school page

We would rather you find this list here than find it yourself and wonder what else we left out. Every network request from a school page goes to one of these, and nothing else.

WhatWhy it runsWhat it receives
Jettova's own app and APIServing the product, and counting page views for our own product metricsThe trip data you put in
Our database and sign-in providerSigning in, a live signal on an open trip page, and opening an uploaded form or documentYour sign-in session, the trip's change signal and who is online, and a file you open through a five-minute link. Nothing else about the trip
Google or AppleOnly if someone chooses to sign in with Google or AppleThe sign-in itself. Nothing about the trip
Our hosting and content delivery providerServing the pagesRequest metadata and IP address, page paths
Our error monitoring providerTelling us when something breaks so we can fix itDiagnostic data, which can include limited request context. Payment links and a family's device credential are stripped out before anything is sent
StripeOnly on a payment screen, only when a family paysCard or bank details, entered directly with Stripe. Jettova never receives or stores card numbers
Map tiles and destination photographyShowing a map or a destination imageThe location being displayed. No account or student identifier

Our own page-view counts do run on school pages. They go to Jettova's own API, they count page views and performance so we know whether the product works, they are not an advertising product, and they are not shared with an ad network. The third-party analytics products we use on the consumer site are switched off here by the same rule that blocks the affiliate tag. Session replay is not enabled, so no recording of a family's screen exists to be shared.

Every provider above is named, with what it receives and when it is used, on our school sub-processors list (opens in a new tab), the one list we keep for Jettova for Schools. If your district needs any of them removed or substituted, tell us and we will tell you honestly whether we can.

You own your data

The school is the controller of its data. Jettova is a processor acting on the school's instructions. You can export your roster and records, or ask for their deletion, at any time and without penalty.

We collect what a trip needs: adult contact details for organizers and families, students' names, and coordination facts like who is going, who is a chaperone, who has returned a permission form, and who has paid. On the day of the trip it adds headcounts, the people each guardian says may collect their student, and a record of who collected each student and when. The student data privacy page lists everything we keep, including signatures and what people write in a trip, and shows who sees what. We never use student data for advertising.

The optional student emergency and medical layer is off. It stays off for a school unless that school asks for it and the applicable education-privacy terms are agreed first, in writing, with an amended schedule of data.

Retention, stated plainly

One year after a trip's return date, a nightly job removes the names and contact details families entered (students' names included), signatures and uploaded forms. Messages, announcements, questions, poll answers and schedule notes people typed are kept as written, as the trip's record. Organizers' private notes on a family's financial aid are removed; the aid amount stays with the payment records. The trip and its payment records stay, with each family shown as “Former member”, so the school's financial records remain complete. The same step deletes every pickup list and removes the name and relationship of whoever collected each student, and any reason staff typed, from the dismissal records, keeping only that a student was released, how and when.

A school can remove a family or delete a trip that has no payment records at any time, or ask us to remove its data sooner. The security summary lists every window.

The documents

Everything your administration, counsel, and IT team will ask for.

New York schools: Education Law 2-d

For New York districts we support Ed Law 2-d contracting, including a Parents' Bill of Rights supplement. Our standing commitments:

  • Student data is used only to provide the trip coordination service the school engaged us for, and for no other purpose.
  • We never sell students' or families' data from a school trip, and never use it for marketing or advertising.
  • Sub-processors that touch school data are bound in writing to protections no less strict than ours.
  • Data is encrypted in transit and at rest. Our database and the application servers that read and write it are in the United States. Other providers on our sub-processor list may process or store limited data outside the United States. The database runs in Amazon Web Services' Ohio region (us-east-2) and the application servers that read and write it run in Vercel's Washington, D.C. region (iad1). We publish the regions rather than the word “domestic” so the claim is one you can check instead of accept. What we do NOT have is a contractual residency guarantee: neither provider is under a term with us that pins those regions, and we hold no certified residency region. So this is where your data is today, verified, not a promise about where it will always be. The components that run at the edge, meaning they may execute nearer to whoever is asking, are the social preview images, the small pictures that appear when a link is pasted into a message. One of them covers a trip room. For a school trip it shows only a generic invite, with no trip name, destination or headcount, because a trip link is often forwarded and a preview is shown to whoever sees it. It reads no student record, no family contact, no permission form and no payment. The request router is not one of them. In this version of our framework it runs on the Node.js runtime and that is not configurable. Separately, our travel search provider may process lodging searches in the EU under data-protection terms, and that path carries no student data. If your district requires a strict United States-only guarantee, raise it as a contract term and we will scope it rather than assert it generally.
  • Parents can see their own child's information in the product at any time, and can raise questions with the school or directly with us.
  • The school is the controller and Jettova is a processor acting on its instructions. The limited coordination data a trip needs is collected by the school through Jettova and lives with the trip.
  • On contract end, we delete or return the school's data at the school's choice.
  • If a breach affects school data, we notify the school promptly with what it needs to meet its own notification duties.

What we are not

We would rather you learn this here than in week three of a procurement review.

  • We are not SOC 2 certified.

    A SOC 2 Type II examination is something we intend to complete. We will not claim it until an auditor has signed it.

  • We do not hold ISO 27001 or PCI DSS certification.

    Card handling is delegated entirely to Stripe, which is PCI compliant. Jettova never receives card numbers.

  • We have not commissioned an independent accessibility audit.

    We test the surfaces schools and families use, fix what we find, and treat reported barriers as bugs.

  • We are early.

    Jettova for Schools is new and we are not going to show you a logo wall we have not earned. If being an early school matters to your district's risk assessment, that is a fair question and we would rather answer it directly than have you discover it later.

If your procurement process needs an attestation we do not have, ask. We will tell you what we can and cannot provide today rather than let it surface late.

Accessibility and reporting a problem

Jettova aims to conform to WCAG 2.1 AA on the surfaces schools and families use. We test these surfaces as we build them and treat reported barriers as bugs. Our current conformance status and how to report an issue are on the accessibility statement. Security researchers can reach us through security.txt.

For your business office

We'll provide the vendor paperwork your district needs to onboard us:

  • DPAWe sign your district's data privacy agreement. Send us yours, or use the SDPC National Data Privacy Agreement for your state.
  • W-9So your business office can set Jettova up as a vendor.
  • Security summaryA written overview of our security posture for your IT or procurement team. Published, and printable.Read the security summary
Request the documents