Privacy Policy
How allcadets.com collects, uses, and protects personal information about Cadets and instructors, including our COPPA, FERPA, and state privacy law commitments.
Last updated
Pending review. DRAFT DOCUMENT - NOT PRODUCTION READY. This document is under review and may change before publication. Please check back later for the final version.
1. Scope of this policy#
This policy explains how {{LEGAL_ENTITY}} collects, uses, discloses, and protects personal information through the allcadets.com Cadet-management service (the “Service”). It applies to platform administrators, instructors, and Cadets, and to parents and guardians who interact with us about a Cadet’s record.
The Service is provided to United States school-based JROTC and ROTC programs. A school or district (the “Unit”) decides what information is entered about its students and for what purpose. For student records, the Unit is the controlling party and we act on its documented instructions; this policy describes our practices and is supplemented by the written agreement between us and each Unit’s school. Where that agreement is more protective, it prevails.
This policy is read together with our Terms of Service.
2. What we collect#
We collect only what is needed to run a school’s program. We do not ask Cadets for home addresses, dates of birth, government identifiers, biometric data, precise location, or health information, and no such fields exist in the Service.
| Category | Source | Purpose | Basis |
|---|---|---|---|
| Identity — first and last name | Entered by the Unit’s instructor, or by the Cadet at registration | Identify the Cadet on the roster, in the structure view, and on task records | School direction under the FERPA school official exception; verifiable parental consent where the Cadet is under 13 |
| Contact — personal email address | Cadet, instructor, or the Unit | Account creation, sign-in, password reset, and service notices | Necessary to provide the Service requested by the Unit; parental consent where under 13 |
| Program assignment — unit, battalion, company | Instructor | Organise the roster and control which records each account can see | School direction; legitimate operation of the Service |
| Cadet rank and Cadet leadership position | Instructor | Reflect the program’s student leadership structure | School direction |
| Task and requirement completion | Instructor and Cadet activity in the Service | Track progress against program requirements and report to the instructor | School direction; education record processing under FERPA |
| Payment status | Stripe, and instructor entry | Show whether a Cadet or Unit fee has been paid, and manage access to paid features | Performance of the subscription agreement; legal obligation to keep financial records |
| Account and security logs — sign-in events, IP address, timestamps, device/browser | Generated automatically | Authenticate users, detect abuse, investigate incidents, and maintain audit trails | Legitimate interest in securing the Service; legal obligation |
| Support correspondence | The person who contacts us | Answer questions and handle privacy or safeguarding requests | Legitimate interest; legal obligation for rights requests |
Cardholder data is not collected by us. Card numbers, expiry dates, and security codes are submitted directly to Stripe.
3. How we use personal information#
We use personal information to:
- create and authenticate accounts and enforce role-based access between admin, instructor, and Cadet;
- display the Unit roster, structure, ranks, and Cadet leadership positions to authorised users;
- assign, track, and report task completion;
- process subscription payments and display payment status;
- send transactional messages such as sign-in, password reset, and account notices;
- provide support, investigate reported problems, and respond to safeguarding or security concerns;
- maintain the security, availability, and integrity of the Service, including backups and audit logs; and
- comply with legal obligations and enforce our Terms.
We do not use student personal information for advertising, for building advertising or marketing profiles, or to train third-party machine learning models. We do not send marketing email to Cadets.
4. Children under 13 and COPPA#
Some Cadets in a JROTC or ROTC program are under 13, which brings their personal information within the Children’s Online Privacy Protection Act (COPPA). We treat every account flagged as under 13 as requiring consent before any personal information is collected.
How consent is obtained
Under COPPA, a school may provide consent on a parent’s behalf where the information is used solely for an educational purpose and for no commercial purpose. Our school agreement requires the Unit to give parents direct notice of what we collect, how it is used, and that it is not disclosed for any other purpose, and to obtain or relay parental authorisation before an account is created. A parent may instead give consent to us directly, and we will accept a signed consent form returned by post, email with a verified signature, or another method permitted by the COPPA rule.
Parental rights
A parent or guardian of a Cadet under 13 may at any time:
- review the personal information we hold about their child;
- ask that it be corrected;
- refuse to allow further collection or use of it; and
- require that it be deleted, which will normally mean deactivating the Cadet’s account.
Requests can be made to privacy@allcadets.com or through the Cadet’s instructor. We will verify that the requester is the child’s parent or guardian, in coordination with the school, before acting. Exercising these rights may end the Cadet’s ability to use the Service, since the Service cannot function without a name and a sign-in identifier.
No conditioning
We do not condition a child’s participation in any activity on disclosing more personal information than is reasonably necessary for that activity. There are no optional profile fields, no photograph uploads, no free-text public profiles, and no social features for Cadet accounts.
5. Education records and FERPA#
Records held in the Service about a student — roster membership, unit assignment, Cadet rank and position, and task completion — are generally education records under the Family Educational Rights and Privacy Act (FERPA) once maintained by or for the school.
We operate as a school official with a legitimate educational interest under 34 CFR § 99.31(a)(1). That relies on four commitments, which we accept contractually with each Unit’s school:
- we perform an institutional service the school would otherwise perform using its own employees;
- we are under the direct control of the school with respect to the use and maintenance of education records;
- we use education records only for the purposes for which the disclosure was made and do not redisclose them without authorisation; and
- we comply with the school’s instructions on access, correction, retention, and deletion.
This exception requires a written agreement with each Unit’s school or district. Where no such agreement is in place, the Unit must not enter student records into the Service.
Directory information
We do not designate any field as directory information and we do not publish student information. A school may separately treat certain fields as directory information under its own annual notice; that decision, and any opt-outs, belong to the school.
Access and correction
Parents and eligible students exercise FERPA rights of inspection and correction through the school, not through us. If a request reaches us directly, we will refer it to the Unit and support the school in responding within FERPA’s timelines.
6. Disclosure to third parties#
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:
| Recipient | Role | What they receive |
|---|---|---|
| Stripe, Inc. | Payment processor acting on our instructions | Cardholder data submitted directly by the payer, plus the identifiers needed to match a payment to a Unit or Cadet place. Stripe does not receive task records or program structure. |
| Google LLC (Firebase) | Infrastructure provider — authentication, database, and hosting | Stored account and program data, processed on our instructions under Google’s data processing terms. Firebase does not use the data for its own purposes. |
| The Cadet’s own school or district | Controlling institution | Its own students’ records, at any time and in full. |
| Legal and safety recipients | Courts, regulators, law enforcement, child protection agencies | Only what is required by valid legal process, or what is necessary to prevent serious harm to a child or other person. |
| A successor entity | Acquirer in a merger, acquisition, or asset sale | Personal information may transfer, subject to this policy and to advance notice to Units so they can object or export and delete. |
Every processor is bound by contract to use personal information only for the purpose we specify, to protect it appropriately, and to delete or return it at the end of the engagement.
7. Retention#
We keep personal information no longer than needed, subject always to the school’s instructions:
| Data | Retention |
|---|---|
| Active Cadet and instructor account records | For as long as the account is active within a subscribing Unit. |
| Deactivated Cadet records | Deleted or de-identified within 12 months of deactivation, or sooner on the school’s instruction. |
| Records of a Unit that ends its subscription | Available for export for 30 days, then deleted within 90 days of termination. |
| Task completion history | Retained with the Cadet record and deleted with it. |
| Payment and transaction records | Retained for 7 years to meet financial and tax record-keeping obligations. |
| Security and access logs | Typically 12 months, longer where needed for an active investigation. |
| Backups | Rolling backups expire within 35 days; deleted records disappear from backups as those cycles complete. |
Where a parent or school requires deletion of an under-13 Cadet’s data, we act promptly rather than waiting for the schedule above.
8. Security#
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of student data, including:
- encryption in transit (TLS) and at rest for stored records;
- role-based access control enforced server-side, so a Cadet account cannot read another Unit’s records regardless of what the client requests;
- least-privilege access for platform staff, with administrative access to Cadet records logged and reviewed;
- authentication managed by Firebase Authentication, with no password material stored by us;
- payment isolation, so cardholder data never touches our systems;
- routine backups and tested restoration; and
- an incident response process, under which we notify affected Units without undue delay and support their own notification duties under state breach-notification law.
No system is perfectly secure. Report a suspected vulnerability or breach to security@allcadets.com.
9. State privacy rights#
Residents of California and of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others as they take effect — have rights over their personal information. Depending on the state, these include the right to:
- Know and access the categories and specific pieces of personal information we hold, and obtain a portable copy;
- Correct inaccurate personal information;
- Delete personal information, subject to legal and contractual exceptions;
- Opt out of sale, sharing for cross-context behavioural advertising, and profiling with legal or similarly significant effects; and
- Non-discrimination for exercising any of these rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including personal information of consumers under 16. There is therefore no opt-out to exercise, but the right to submit one remains available.
How to exercise your rights
Submit a request at Data rights & removal, or email privacy@allcadets.com. We will verify your identity in proportion to the sensitivity of the request, and we may work with the relevant school to do so. We respond within 45 days, extendable once by a further 45 days with notice. An authorised agent may submit a request on your behalf with written permission that we can verify.
Where the information is an education record held on behalf of a school, we will route the request to that school, which is the party responsible for responding, and support it in doing so.
10. Children’s data minimisation#
Our design principle is to hold the least information that lets a program function. In practice this means:
- Cadet records carry a name, an email address, a unit/battalion/company assignment, a rank, a position, task status, and payment status — and nothing else;
- there are no analytics or advertising trackers in Cadet-facing pages, and no third-party advertising SDKs anywhere in the Service;
- Cadets cannot upload photographs, files, or free-text public profiles;
- Cadet leadership titles such as Company Commander describe a student role and do not grant access to other students’ personal information beyond what an instructor has enabled; and
- new fields affecting Cadet data are assessed for necessity before release, and material additions are notified to Units in advance.
11. International transfers#
The Service is intended for use by schools in the United States, and personal information is stored and processed in the United States on infrastructure operated by Google Cloud/Firebase.
Where a support request or a vendor’s operations involve access from outside the United States, we require appropriate contractual safeguards and equivalent protection. We do not routinely transfer student records outside the United States, and a Unit may require in its school agreement that its records remain within US data centres.
12. Changes to this policy#
We may update this policy as the Service, our vendors, or the law changes. The “last updated” date above always reflects the current version, and we keep prior versions available on request.
For material changes affecting student data, we notify Unit instructor accounts at least 30 days in advance. Where a change would materially expand how we use personal information already collected from a child under 13, we will obtain fresh verifiable parental consent, through the school where appropriate, before the change applies to that child’s data.
13. Contact#
Privacy questions, rights requests, and parental review or deletion requests should go to privacy@allcadets.com, or be submitted at Data rights & removal.
- General and billing support — support@allcadets.com
- Child safety and safeguarding — safeguarding@allcadets.com
- Security vulnerabilities — security@allcadets.com
Postal requests may be sent to {{LEGAL_ENTITY}}, {{POSTAL_ADDRESS}}.
See also our Terms of Service.
