Privacy Policy

How allcadets.com collects, uses, and protects personal information about Cadets and instructors, including our COPPA, FERPA, and state privacy law commitments.

Last updated

Pending review. DRAFT DOCUMENT - NOT PRODUCTION READY. This document is under review and may change before publication. Please check back later for the final version.

allcadets.com is an independent commercial product and is not affiliated with, sponsored by, or endorsed by the U.S. Department of Defense or any of its components.

1. Scope of this policy#

This policy explains how {{LEGAL_ENTITY}} collects, uses, discloses, and protects personal information through the allcadets.com Cadet-management service (the “Service”). It applies to platform administrators, instructors, and Cadets, and to parents and guardians who interact with us about a Cadet’s record.

The Service is provided to United States school-based JROTC and ROTC programs. A school or district (the “Unit”) decides what information is entered about its students and for what purpose. For student records, the Unit is the controlling party and we act on its documented instructions; this policy describes our practices and is supplemented by the written agreement between us and each Unit’s school. Where that agreement is more protective, it prevails.

This policy is read together with our Terms of Service.

2. What we collect#

We collect only what is needed to run a school’s program. We do not ask Cadets for home addresses, dates of birth, government identifiers, biometric data, precise location, or health information, and no such fields exist in the Service.

CategorySourcePurposeBasis
Identity — first and last nameEntered by the Unit’s instructor, or by the Cadet at registrationIdentify the Cadet on the roster, in the structure view, and on task recordsSchool direction under the FERPA school official exception; verifiable parental consent where the Cadet is under 13
Contact — personal email addressCadet, instructor, or the UnitAccount creation, sign-in, password reset, and service noticesNecessary to provide the Service requested by the Unit; parental consent where under 13
Program assignment — unit, battalion, companyInstructorOrganise the roster and control which records each account can seeSchool direction; legitimate operation of the Service
Cadet rank and Cadet leadership positionInstructorReflect the program’s student leadership structureSchool direction
Task and requirement completionInstructor and Cadet activity in the ServiceTrack progress against program requirements and report to the instructorSchool direction; education record processing under FERPA
Payment statusStripe, and instructor entryShow whether a Cadet or Unit fee has been paid, and manage access to paid featuresPerformance of the subscription agreement; legal obligation to keep financial records
Account and security logs — sign-in events, IP address, timestamps, device/browserGenerated automaticallyAuthenticate users, detect abuse, investigate incidents, and maintain audit trailsLegitimate interest in securing the Service; legal obligation
Support correspondenceThe person who contacts usAnswer questions and handle privacy or safeguarding requestsLegitimate interest; legal obligation for rights requests

Cardholder data is not collected by us. Card numbers, expiry dates, and security codes are submitted directly to Stripe.

3. How we use personal information#

We use personal information to:

  • create and authenticate accounts and enforce role-based access between admin, instructor, and Cadet;
  • display the Unit roster, structure, ranks, and Cadet leadership positions to authorised users;
  • assign, track, and report task completion;
  • process subscription payments and display payment status;
  • send transactional messages such as sign-in, password reset, and account notices;
  • provide support, investigate reported problems, and respond to safeguarding or security concerns;
  • maintain the security, availability, and integrity of the Service, including backups and audit logs; and
  • comply with legal obligations and enforce our Terms.

We do not use student personal information for advertising, for building advertising or marketing profiles, or to train third-party machine learning models. We do not send marketing email to Cadets.

4. Children under 13 and COPPA#

Some Cadets in a JROTC or ROTC program are under 13, which brings their personal information within the Children’s Online Privacy Protection Act (COPPA). We treat every account flagged as under 13 as requiring consent before any personal information is collected.

Consent must come first. Verifiable parental consent must be obtained before an under-13 Cadet account collects any personal information — including the Cadet’s name and email address at registration. This depends on the written school agreement being in place, because that agreement is what authorises the school to give or relay consent on the parent’s behalf. Where no signed agreement exists for a Unit, under-13 Cadet accounts must not be created.

How consent is obtained

Under COPPA, a school may provide consent on a parent’s behalf where the information is used solely for an educational purpose and for no commercial purpose. Our school agreement requires the Unit to give parents direct notice of what we collect, how it is used, and that it is not disclosed for any other purpose, and to obtain or relay parental authorisation before an account is created. A parent may instead give consent to us directly, and we will accept a signed consent form returned by post, email with a verified signature, or another method permitted by the COPPA rule.

Parental rights

A parent or guardian of a Cadet under 13 may at any time:

  • review the personal information we hold about their child;
  • ask that it be corrected;
  • refuse to allow further collection or use of it; and
  • require that it be deleted, which will normally mean deactivating the Cadet’s account.

Requests can be made to privacy@allcadets.com or through the Cadet’s instructor. We will verify that the requester is the child’s parent or guardian, in coordination with the school, before acting. Exercising these rights may end the Cadet’s ability to use the Service, since the Service cannot function without a name and a sign-in identifier.

No conditioning

We do not condition a child’s participation in any activity on disclosing more personal information than is reasonably necessary for that activity. There are no optional profile fields, no photograph uploads, no free-text public profiles, and no social features for Cadet accounts.

5. Education records and FERPA#

Records held in the Service about a student — roster membership, unit assignment, Cadet rank and position, and task completion — are generally education records under the Family Educational Rights and Privacy Act (FERPA) once maintained by or for the school.

We operate as a school official with a legitimate educational interest under 34 CFR § 99.31(a)(1). That relies on four commitments, which we accept contractually with each Unit’s school:

  • we perform an institutional service the school would otherwise perform using its own employees;
  • we are under the direct control of the school with respect to the use and maintenance of education records;
  • we use education records only for the purposes for which the disclosure was made and do not redisclose them without authorisation; and
  • we comply with the school’s instructions on access, correction, retention, and deletion.

This exception requires a written agreement with each Unit’s school or district. Where no such agreement is in place, the Unit must not enter student records into the Service.

Directory information

We do not designate any field as directory information and we do not publish student information. A school may separately treat certain fields as directory information under its own annual notice; that decision, and any opt-outs, belong to the school.

Access and correction

Parents and eligible students exercise FERPA rights of inspection and correction through the school, not through us. If a request reaches us directly, we will refer it to the Unit and support the school in responding within FERPA’s timelines.

6. Disclosure to third parties#

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:

RecipientRoleWhat they receive
Stripe, Inc.Payment processor acting on our instructionsCardholder data submitted directly by the payer, plus the identifiers needed to match a payment to a Unit or Cadet place. Stripe does not receive task records or program structure.
Google LLC (Firebase)Infrastructure provider — authentication, database, and hostingStored account and program data, processed on our instructions under Google’s data processing terms. Firebase does not use the data for its own purposes.
The Cadet’s own school or districtControlling institutionIts own students’ records, at any time and in full.
Legal and safety recipientsCourts, regulators, law enforcement, child protection agenciesOnly what is required by valid legal process, or what is necessary to prevent serious harm to a child or other person.
A successor entityAcquirer in a merger, acquisition, or asset salePersonal information may transfer, subject to this policy and to advance notice to Units so they can object or export and delete.

Every processor is bound by contract to use personal information only for the purpose we specify, to protect it appropriately, and to delete or return it at the end of the engagement.

7. Retention#

We keep personal information no longer than needed, subject always to the school’s instructions:

DataRetention
Active Cadet and instructor account recordsFor as long as the account is active within a subscribing Unit.
Deactivated Cadet recordsDeleted or de-identified within 12 months of deactivation, or sooner on the school’s instruction.
Records of a Unit that ends its subscriptionAvailable for export for 30 days, then deleted within 90 days of termination.
Task completion historyRetained with the Cadet record and deleted with it.
Payment and transaction recordsRetained for 7 years to meet financial and tax record-keeping obligations.
Security and access logsTypically 12 months, longer where needed for an active investigation.
BackupsRolling backups expire within 35 days; deleted records disappear from backups as those cycles complete.

Where a parent or school requires deletion of an under-13 Cadet’s data, we act promptly rather than waiting for the schedule above.

8. Security#

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of student data, including:

  • encryption in transit (TLS) and at rest for stored records;
  • role-based access control enforced server-side, so a Cadet account cannot read another Unit’s records regardless of what the client requests;
  • least-privilege access for platform staff, with administrative access to Cadet records logged and reviewed;
  • authentication managed by Firebase Authentication, with no password material stored by us;
  • payment isolation, so cardholder data never touches our systems;
  • routine backups and tested restoration; and
  • an incident response process, under which we notify affected Units without undue delay and support their own notification duties under state breach-notification law.

No system is perfectly secure. Report a suspected vulnerability or breach to security@allcadets.com.

9. State privacy rights#

Residents of California and of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others as they take effect — have rights over their personal information. Depending on the state, these include the right to:

  • Know and access the categories and specific pieces of personal information we hold, and obtain a portable copy;
  • Correct inaccurate personal information;
  • Delete personal information, subject to legal and contractual exceptions;
  • Opt out of sale, sharing for cross-context behavioural advertising, and profiling with legal or similarly significant effects; and
  • Non-discrimination for exercising any of these rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including personal information of consumers under 16. There is therefore no opt-out to exercise, but the right to submit one remains available.

How to exercise your rights

Submit a request at Data rights & removal, or email privacy@allcadets.com. We will verify your identity in proportion to the sensitivity of the request, and we may work with the relevant school to do so. We respond within 45 days, extendable once by a further 45 days with notice. An authorised agent may submit a request on your behalf with written permission that we can verify.

Where the information is an education record held on behalf of a school, we will route the request to that school, which is the party responsible for responding, and support it in doing so.

10. Children’s data minimisation#

Our design principle is to hold the least information that lets a program function. In practice this means:

  • Cadet records carry a name, an email address, a unit/battalion/company assignment, a rank, a position, task status, and payment status — and nothing else;
  • there are no analytics or advertising trackers in Cadet-facing pages, and no third-party advertising SDKs anywhere in the Service;
  • Cadets cannot upload photographs, files, or free-text public profiles;
  • Cadet leadership titles such as Company Commander describe a student role and do not grant access to other students’ personal information beyond what an instructor has enabled; and
  • new fields affecting Cadet data are assessed for necessity before release, and material additions are notified to Units in advance.

11. International transfers#

The Service is intended for use by schools in the United States, and personal information is stored and processed in the United States on infrastructure operated by Google Cloud/Firebase.

Where a support request or a vendor’s operations involve access from outside the United States, we require appropriate contractual safeguards and equivalent protection. We do not routinely transfer student records outside the United States, and a Unit may require in its school agreement that its records remain within US data centres.

12. Changes to this policy#

We may update this policy as the Service, our vendors, or the law changes. The “last updated” date above always reflects the current version, and we keep prior versions available on request.

For material changes affecting student data, we notify Unit instructor accounts at least 30 days in advance. Where a change would materially expand how we use personal information already collected from a child under 13, we will obtain fresh verifiable parental consent, through the school where appropriate, before the change applies to that child’s data.

13. Contact#

Privacy questions, rights requests, and parental review or deletion requests should go to privacy@allcadets.com, or be submitted at Data rights & removal.

Postal requests may be sent to {{LEGAL_ENTITY}}, {{POSTAL_ADDRESS}}.

See also our Terms of Service.