OnStaffOnStaff

Privacy Policy

Last updated: 1.0

1. Information We Collect

We collect information you provide directly: account details (name, email, role), professional credentials (license numbers, certifications), district affiliation, tax documentation required for contractor payments, and content you post on the platform (profiles, messages, hours logs).

We also collect technical information automatically, including log data, device information, and cookies necessary for authentication and platform operation.

2. How We Use Information

We use your information to operate the platform (match SLPs and Districts, process payments, send transactional communications), verify credentials, prevent fraud, comply with legal obligations, and improve the Service.

3. Data Sharing

We share information with service providers who help us operate the platform (payment processor Stripe, email delivery Resend, error monitoring Sentry, hosting Vercel and Supabase). We do not sell your personal information. We may disclose information when legally required or to protect the rights, property, or safety of OnStaff, our users, or the public.

4. Data Retention

We retain account data for as long as your account is active and for a reasonable period afterward to comply with legal, accounting, and tax obligations. Soft-deleted records may persist in backups for up to 90 days.

5. FERPA Compliance

OnStaff is designed to avoid handling student Personally Identifiable Information (PII) under the Family Educational Rights and Privacy Act (FERPA). The platform does not store student names, IEPs, evaluations, or individualized service records. SLPs and Districts are responsible for keeping student-level information off the platform and within district-owned systems.

6. Cookies and Tracking

We use only essential cookies required for authentication and session management. We do not use third-party advertising or analytics trackers.

7. Children's Privacy

The Service is intended for use by adult professionals and district administrators. We do not knowingly collect information from children under 13. If we learn that we have collected such information, we will delete it promptly.

8. Your Rights

You may access, update, or delete your personal information at any time via your account settings. Residents of certain jurisdictions (California, EU, etc.) may have additional rights under applicable law; contact us to exercise those rights.

9. Security

We use industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access controls, and regular security reviews. No system is perfectly secure; notify us immediately if you suspect unauthorized access to your account.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email and in-app notification.

11. Contact

Privacy questions? Email support@onstaffsped.com.