1. Who this is for
This statement is for school, district, and program staff who are asked about a BandWagon community used by families in their program. It explains how student information is handled. It is a plain-language summary. The Privacy Policy is the full policy.
2. The design choice: no school records needed
BandWagon is designed so a community can run without the school. Parents opt in and set up their own household. Adult volunteers offer rides. The school does not need to share a roster or take part in the ride arrangement. Because of this, BandWagon is designed to avoid needing school education records at all.
We are not making a claim of formal certification under FERPA, COPPA, Texas education privacy laws, or any similar law. Whether a law applies depends on facts such as who sets up the community and what data is shared. We are happy to answer a reviewer's questions about how the design fits your requirements.
3. What BandWagon does not collect about students
- No school roster, student ID number, or district account.
- No grades, attendance, discipline, IEP, 504, or health records.
- No full date of birth. Accounts use birth month and year only to tell adults from minors.
- No live GPS tracking and no background location collection.
- No photos of students, and no social profiles or public ratings.
- No advertising profiles and no ad trackers.
4. What BandWagon may hold about a student
Only what a parent or guardian chooses to enter so rides can be arranged:
- The student's name or display name, and which household and community they belong to.
- Birth month and year, or an age group, so minors get guardian protections.
- Which guardians may manage the student and approve rides.
- Ride requests for the student, such as the event, direction, and pickup or drop-off location.
- If the organization turns on student sign-in and a guardian sets it up, a student email used for sign-in codes.
5. Guardian control
- A parent or guardian creates and manages any student profile. Students do not need their own account.
- Guardians can require their approval before a student requests a ride. Students default to needing approval.
- Student sign-in is off unless the organization turns it on, and a guardian must set it up and give consent. Turning it off or withdrawing consent ends the student's active sessions right away.
- Children under 13 cannot create their own account. A parent manages their profile.
- Guardians can review, correct, export, or delete their student's information.
6. Who can see student information
Only people with a reason to see it: the student's guardians, the community's admins within their role, and, for a confirmed ride, the matched driver. Other families see a general area instead of an exact address until a ride is confirmed. Exact addresses are encrypted, and each view of one is recorded.
7. No selling, no ads, no sponsor access
We never sell personal information, including student information. We do not use it for targeted advertising or to build profiles. Donors and sponsors get no participant data. Our service providers are listed on the Subprocessors page and receive only what their job requires.
8. Retention and deletion
- Exact pickup and drop-off locations for completed or cancelled rides are deleted after 30 days by default. The organization can set 1 to 365 days.
- When a guardian deletes an account, there is a seven-day safety grace period, then eligible personal information is removed.
- When a community is closed, data tied only to that community is deleted after a holding period (30 days by default).
- A small amount of restricted safety, consent, security, or audit information may be kept when needed for safety or the law.
- Encrypted backups expire on their normal schedule.
9. How to request access or deletion
A signed-in guardian can export data or schedule deletion from Privacy & Data. Anyone can also use the Privacy Request topic in the Help Center, email [email protected], or contact [email protected]. We may confirm identity and guardian authority before acting. A school or district that believes a student's information was added without a guardian's permission can report it the same way, and we will act quickly.
10. Security
Data is encrypted in transit and at rest, and sensitive fields have extra encryption. Each community's data is kept separate. Access is limited by role and logged. Report a security concern through the Security page.