StudentAid
HomeFor schoolsFor driversFor parentsBook a demo
HomeFor schoolsFor driversFor parentsBook a demo

Privacy Policy

StudentAid helps schools run their transport safely: a live view of where a van is, a verified record of who boarded it, and a verified record of who collected a child at the end of the day. Doing that means handling information about children. This page explains exactly what we hold, why, who can see it, and what you can ask us to do about it.

Last updated: 23 July 2026

On this page

  1. Who this covers
  2. Our role, and your school's
  3. What we collect
  4. Location information
  5. Children's information
  6. How we use it
  7. Who can see what
  8. Service providers
  9. How long we keep it
  10. How we protect it
  11. Your choices and rights
  12. Cookies
  13. Changes
  14. Contact us

1. Who this covers

This policy applies to the StudentAid platform, operated by StudentAid INC. ("StudentAid", "we", "us"), an Ontario corporation of 27 New Hampshire Court, Brampton, Ontario L6S 0B9, Canada. It covers:

  • the school portal at app.studentaid.io and the platform console at admin.studentaid.io;
  • the Parent app and the Driver app;
  • the API at api.studentaid.io that those apps talk to;
  • this website, studentaid.io.

It does not cover a school's own systems, or any other app or website you reach by a link from ours.

2. Our role, and your school's

Almost all the personal information on StudentAid is entered by, or on behalf of, a school or a transport operator — the student roster, guardian phone numbers, driver records, routes. Those organisations decide what to collect and why. We hold and process it on their instructions, to provide the service they have signed up for.

In practice that means:

  • If you are a parent or guardian, your school is the first place to go to correct your child's record, change who may collect them, or ask what is held. We will help, but we generally act through the school.
  • If you are a driver, the operator who employs you and the schools they serve control your record. Your national ID is a special case and is described in section 9.
  • We do not sell personal information. We do not use it to advertise, and there is no advertising of any kind in the Parent or Driver apps.

Who answers your request. The school or operator decides what is collected and why, so they are the first point of contact and the party that can change a record directly. We hold the information on their behalf.

That split is about responsibility, not about sending you away. If you write to us at info@studentaid.io we will acknowledge within 7 days and answer within 30 days, working with your school to do it. If your school does not respond to you, or has stopped using StudentAid, we will answer you directly rather than leave you without a route. We will not refuse a request solely on the basis that you should have asked someone else.

3. What we collect

We collect only what the service needs to work. Grouped by whose information it is:

Students

WhatWhy
Name, school-issued student ID, classTo identify the child on a van manifest and at the school gate.
Photograph (optional)So a driver or gate staff member can confirm they have the right child. If no photo is provided, the app shows the child's initials instead.
Home address areaUsed to suggest a suitable route. Suggestions are confirmed by school staff, not applied automatically.
Transport method, route and van assignment, enrolment datesTo build the daily manifest and to reconstruct historical records accurately.
Boarding and drop-off times, attendance, absence and self-drop flagsThe record of each journey — the core of the service.
Collection records at dismissal: who collected the child, by what method, and whenA verified custody trail, so it is always known who took a child home.

Parents and guardians

WhatWhy
Name, relationship to the child, mobile number, email (if given)To link you to your child, to sign you in, and to send alerts.
One-time passcodes sent to your phoneTo verify it is you. Codes are stored hashed and expire in minutes.
Device push token, app version, platformTo deliver notifications to the right device. Removed when you sign out.
People you authorise to collect your child, and any short-lived collection passes you issueSo someone other than you can collect your child safely.
Consent recordsTo evidence that consent for data and photographs was given, and to let you withdraw it.

Drivers

WhatWhy
Name, mobile number, licence number, years of experienceIdentity and eligibility to drive.
National ID number and supporting documentsRequired for driver verification and for transport compliance records. Stored encrypted; displayed only as the last four digits; the full number can be revealed only once, deliberately, and every reveal is logged. See section 9 for deletion.
Approval, rejection and revocation historyTo show a school that the person driving their children has been checked.
Location while a trip is runningSee section 4.

School and operator staff

Name, email, mobile number, role, and a log of significant actions taken in the portal — who approved a driver, who released a child, who changed a setting. That log exists so a school can answer questions about its own records, and it is not used to monitor staff productivity.

This website

If you submit the pilot-demo form, it opens WhatsApp with your details so you can send them to us — nothing is submitted to our servers by the form itself. Our web server keeps ordinary access logs (IP address, page requested, time).

4. Location information

Location is the most sensitive thing we handle, so it is worth being precise.

The Driver app

While a trip is running, the Driver app sends the van's position periodically so the school and the waiting parents can see where it is. This is the vehicle's location during a working trip. It starts when the driver starts the trip and stops when the trip is completed.

The Parent app

The Parent app does not track you. It asks for location only when you tap to check in at pickup, and then it takes a single reading at that moment to confirm you are at the gate. There is no continuous tracking, no location history, and the app does not request background-location permission — so it cannot read your location when it is closed.

What parents can see

A parent sees the van carrying their own child. They do not see other routes, other schools, or other families' children.

We are changing this to be narrower still: van position will be visible to a parent only during the window their own child is actually riding, rather than for as long as the van's trip is running. Until that change ships, a parent may still see the van for the remainder of a trip after their child has been dropped off.

5. Children's information

Most of what StudentAid holds is about children, and we treat it accordingly.

  • Children are not our users. The apps are for parents, drivers and school staff. We do not create accounts for children and do not market to them.
  • No advertising, no profiling, no sale. There is no advertising SDK in either app. We do not build behavioural profiles and we do not sell or rent personal information to anyone.
  • Consent is recorded, and revocable. A school records consent for a child's data and separately for their photograph, and either can be withdrawn. Withdrawing photo consent removes the photo; the app falls back to initials.
  • Least exposure. A driver sees only the children on their own manifest for the trip they are running. Where one van serves two schools, each school sees only its own children.

6. How we use it

  • To show a live view of a van and to send alerts — that a van is approaching, that a child boarded, that a child was dropped off, that a child was not on the van as expected.
  • To verify boarding: a child's pass is scanned at the van, rather than a name being ticked off a paper list.
  • To run dismissal safely and record who collected each child.
  • To raise and route emergency alerts to the school's escalation contacts and to the guardians of affected children.
  • To produce the compliance and route records a school must keep.
  • To sign you in, keep your session secure, and support you when you contact us.
  • To keep the service working — diagnosing faults, preventing abuse, and maintaining security.

We do not use personal information to train machine-learning models, and we do not make automated decisions that have a legal or similarly significant effect on anyone.

7. Who can see what

WhoSees
A parentTheir own children only — the child's plan, journey events, and the van carrying them.
A driverThe manifest for the trip they are running, and the identity checks needed to board a child safely.
School staffTheir own school's students, guardians, drivers serving them, routes and records — limited further by their role. Not another school's data.
A transport operatorTheir own vehicles, drivers and trips.
StudentAid staffOnly what is necessary to operate and support the service. Access to a school's data is restricted and logged.

These boundaries are enforced by the system itself, not by convention: a request for data outside your boundary fails rather than returning a filtered result.

8. Service providers

We use a small number of providers to deliver parts of the service. They act on our instructions and are not permitted to use the information for their own purposes.

ProviderWhat it handles
SMS and WhatsApp gatewayDelivering one-time passcodes and alerts to your phone.
Google (Firebase)Delivering push notifications to your device, and — where enabled — verifying your phone number at sign-in.
Google MapsDisplaying the map inside the apps.
Cloud hostingRunning the servers and databases. Data is hosted on infrastructure operated by our hosting provider.

Some of these providers operate outside your country, which means information may be processed internationally, including in Canada and in the region where your school's data is hosted. We may also disclose information where the law requires it, or where it is necessary to protect the safety of a child.

9. How long we keep it

Our default is 30 days. Information that exists to run a journey is deleted 30 days after it stops being useful. This is enforced by scheduled jobs that run every night, not by anyone remembering to do it.

WhatHow long
Location history — where a van was, minute by minute30 days, then permanently deleted.
Driver national ID numbers and ID scans30 days after a driver is rejected or revoked. Only the last four digits survive, for the audit record.
Collection-pass national IDs30 days after the pass expires or is revoked.
One-time passcodesMinutes. Stored hashed, never in readable form.
Device tokens for notificationsRemoved when you sign out or the device stops responding.

What we keep for longer, and why

Two things cannot be on a 30-day clock without breaking the service or the school's own obligations, so we are explicit about them rather than burying them:

  • Your child's record and their journey history — enrolment, route, and the record of which days they travelled — are kept while the child is enrolled in transport at the school, and afterwards for as long as the school must keep them. A school has to be able to answer a question about a journey that happened last term, and to produce transport records for the authorities. The school decides how long, and can ask us to delete them.
  • Custody records — who collected a child, by what method, and when — are append-only. They cannot be edited, and they are not deleted on a timer. The entire value of that record is that it is still trustworthy long after the day it was written; a custody trail that quietly erased itself after a month would be worth nothing in the one situation it exists for.

When a school stops using StudentAid, its data is made available for export and then deleted, except where the law requires us to keep it.

10. How we protect it

  • All traffic to our websites and apps is encrypted in transit (HTTPS).
  • National ID numbers are encrypted at rest, hidden by default, and shown in full only through a single deliberate action that is logged.
  • Access is controlled by role. Boundaries between schools and between operators are enforced by the data layer and fail closed.
  • Sign-in is by one-time passcode to a verified phone number; app sessions use scoped tokens that can be revoked.
  • Boarding passes and collection passes are cryptographically signed and time-limited, and can be revoked immediately.
  • Significant actions are written to an audit log.

No system is perfectly secure. If a breach affects your information we will act to contain it and inform the affected schools, and you, without undue delay.

11. Your choices and rights

You can ask us, or your school, to:

  • tell you what information is held about you or your child;
  • correct anything inaccurate — a misspelled name, a wrong phone number, a wrong class;
  • remove a photograph, or withdraw consent for it;
  • remove a person you previously authorised to collect your child;
  • delete information, where we are not required to keep it for safety or compliance reasons.

You can also turn off non-essential notifications in the app. Emergency alerts cannot be switched off — an SOS is not a preference, and the apps deliberately provide no setting that could suppress one.

Because your school controls most of this information, the fastest route is usually to ask the school directly. If you would rather come to us, contact us at info@studentaid.io and we will work with your school to answer. We may need to verify your identity first.

12. Cookies

The school portal and platform console use a single session cookie to keep you signed in. It is necessary for the service to function and is not used for tracking or advertising. Fonts and map tiles are loaded from Google, which may log the request.

This marketing website — and only this website — uses Google Analytics to count visits and see which pages people read, so we know what to explain better. It sets analytics cookies and sends Google your approximate location, device and browser type, and the pages you viewed; your full IP address is not stored. We do not use it for advertising and we do not sell what it collects.

Analytics stops at this website. There is no analytics or advertising tracking inside the parent app, the driver app, the school portal or the platform console — no child's name, photo, location or trip is ever sent to Google Analytics. If you would rather not be counted here, any browser setting or extension that blocks analytics cookies will stop it, and nothing on this site will break.

13. Changes

If we change this policy we will update the date at the top. Where a change materially affects how information about you or your child is handled, we will tell the school and, where appropriate, notify you in the app.

14. Contact us

Questions about this policy, or about information held about you:

  • Email: info@studentaid.io
  • WhatsApp: +1 917 569 6137
  • Post: StudentAid INC., 27 New Hampshire Court, Brampton, Ontario L6S 0B9, Canada

See also our Terms of Service.

StudentAid

The trust layer for school transport — live tracking, verified boarding, and a custody record you can stand behind.

Every journey accounted for.

Product

School portal Driver app Parent app Safety by design

Contact

WhatsApp +1 917 569 6137 info@studentaid.io

StudentAid INC.
27 New Hampshire Court,
Brampton, Ontario L6S 0B9, Canada

Legal

Privacy Policy Terms of Service Security standards Data retention
© 2026 StudentAid INC.