Student Data & FERPA
How VolTrack handles student education records. Effective date: September 26, 2026.
Our role under FERPA
VolTrack acts as a “school official” with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)), processing student education records solely on the school's behalf and under its direction. We do not own the data, do not sell it, and do not use it for advertising. Schools remain the data controller and decide who may access records. VolTrack is operated by VolTrack LLC, a New York limited liability company.
Where FERPA does not apply to a school (many private and parochial schools are not subject to it), we still act as the school's service provider under our agreement and applicable state student-privacy laws, and apply the same practices.
What we collect
- Identity: name (incl. optional middle name), email, graduation year, role.
- Service records: logged hours, descriptions, verifier decisions, and any proof files (images or short videos) the student uploads.
- Account/security metadata: hashed password, timestamps, audit events.
We do not request SSNs, government IDs, or payment data from students.
Who can see a student's records
- The student — their own records.
- School staff (admins and verifying teachers) at the student's organization, as school officials.
- Parents/guardians — only when the school enables the Parent Portal and a link is created. Parents can view hours and progress, message school staff, and manage SMS consent for their child; they cannot edit records. Access is scoped to their own student and revocable at any time by the student or the school. At colleges, only the (adult) student may grant parent access.
Access records & disclosures
Sensitive actions are recorded in a per-school audit log — actions by the school's own users (logins, exports, role changes, parent invitations, activations and revocations) and parent access to records. Platform (VolTrack staff) actions are logged centrally. This supports FERPA's expectation that schools can account for disclosures of education records.
De-identified case studies
We never share identifiable student data externally. Separately, a school's administrator may grant explicit, revocable consent to share a de-identified, rounded aggregate of the organization — a participation percentage and an approximate hours total — in case studies shown to other schools. This contains no individual records, names, or exact figures; aggregates for small cohorts are suppressed entirely; and consent can be withdrawn at any time from the school's Participation page. It is off by default.
Student/parent rights
Through the school, individuals can request to access or correct records, and request erasure. Admins can export a student's full data — profile, memberships, service hours, opportunity sign-ups, parent links, consent records, message counts, audit-log entries, and product events — and permanently delete an account and its records from the people list.
Security
- Encryption in transit (HTTPS); passwords hashed with bcrypt.
- Strict tenant isolation and role-based access between organizations.
- Uploaded proof files served via short-lived signed URLs, not public links.
- Two-factor authentication available to all users and required for school administrators.
- Staff sessions expire after inactivity.
- Login, export and access events are logged with IP address.
- We will notify the affected school within 72 hours of confirming a security breach involving its data, and no later than any period required by law (including the 7-day requirement of New York Education Law §2-d where it applies).
Sub-processors
We use a small, vetted set of vendors to operate the service, each under contract. The named list is on our Subprocessors page. For high-school, college and nonprofit organizations, opportunity maps and address lookup use Google Maps Platform: your browser's IP address and browser information go directly to Google, which acts as an independent controller. Google Maps is never loaded for K-8 organizations.
- Hosting & database — application hosting and the PostgreSQL database (incl. encrypted file storage for proof uploads).
- Transactional email — account verification, approvals, and reminder emails.
- Payments — subscription billing (card data is handled by the processor; VolTrack never stores it).
- SMS — currently unavailable. If offered, texts would go only to opted-in recipients; texting a student would additionally require a verified parent/guardian's recorded consent, and any recipient could reply STOP to opt out.
- Error monitoring — configured to redact emails, tokens, request bodies and search parameters; names appearing in error text may still reach our monitoring vendor, which is bound by contract.
- AI data-import assistant — when an administrator uses the optional data-migration importer, only the uploaded file's column headers and shape-preserving placeholder values (no real names, IDs, emails, dates or notes) are sent to our AI provider to suggest how columns map to VolTrack fields. No real cell values are sent; the AI is not used to make decisions about individuals, and the provider does not train on this data.
The current sub-processor list is also incorporated in the Data Processing Agreement; we notify schools of changes. Request the DPA at [email protected].
Data retention
| Data | How long we keep it |
|---|---|
| Education records & proof files | Kept for the duration of the school's subscription; permanently deleted 60 days after a paid subscription ends (administrators are notified with an export link when the countdown starts), within 30 days of a written request, or, for organizations on the free plan, 60 days after 12 months with no administrator sign-in (administrators are emailed first, and signing in cancels the deletion). |
| Unverified signups & pending join requests | Purged automatically after 30 days. |
| Product analytics events | 365 days. |
| Audit logs | Retained for security and FERPA accountability; names are anonymized when a user is deleted. |
| Data-import upload rows | Until the school deletes the import or its account. |
| Demo requests & waitlist | Until fulfilled, or 24 months. |
| Backups | Encrypted provider backups may retain deleted data for up to 30 additional days. |
Longer periods apply only where required by law. Schools may direct earlier deletion of individual records at any time.
Contact
Questions or to request a DPA: [email protected] · VolTrack LLC, VolTrack LLC, Fresh Meadows, NY.