GuardianFlow Systems LLC · Privacy Policy · v1.0

Privacy Policy

1. Introduction and Scope

1.1 Who We Are

This Privacy Policy ("Policy") describes how GuardianFlow Systems LLC, a Florida limited liability company ("GuardianFlow," the "Company," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information in connection with:

  • (a) the GuardianFlow mobile applications for iOS and Android (the "App");
  • (b) the GuardianFlow web-based administrative console (the "Console");
  • (c) the website located at https://guardianflow.up.railway.app/ (the "Site"); and
  • (d) any related services, features, or communications (collectively with the App, Console, and Site, the "Services").

GuardianFlow is a school dismissal and student release management platform used by schools, districts, and other educational organizations ("Schools") to coordinate the safe release of students to parents, legal guardians, and other authorized pickup persons.

1.2 Who This Policy Applies To

This Policy applies to:

  • Parents and Guardians — parents, legal guardians, and other adults authorized by a parent or guardian to pick up a student ("Authorized Pickup Persons");
  • School Users — teachers, staff, administrators, and other personnel authorized by a School to use the Services;
  • Site Visitors — individuals who visit the Site; and
  • Prospective Customers — individuals who contact us about the Services on behalf of a School or district.

1.3 The Services Are Not For Children

GuardianFlow is designed for and directed exclusively to adults. Students do not create accounts, do not log in, and do not use the Services. Information about students (such as name, grade, and dismissal records) is provided to us by Schools and by parents or guardians — never collected directly from children. Section 13 (Children's Privacy) explains this in detail.

1.4 Our Role: Service Provider / Processor for Student Data

For student information and education records, GuardianFlow acts as a service provider and data processor on behalf of the School. The School (not GuardianFlow) determines which students appear in the roster, who is authorized to pick up each student, and how long dismissal records are retained under applicable education-records law. Where this Policy conflicts with a written agreement between GuardianFlow and a School (a "School Services Agreement"), the School Services Agreement controls with respect to student data.

For account information of adult users (e.g., a parent's own contact details) and for Site visitor data, GuardianFlow acts as a data controller / business as those terms are defined under applicable law.

2. Information We Collect

2.1 Information You Provide Directly

Depending on your role, we may collect:

(a) Parent / Guardian / Authorized Pickup Account Information

  • Full name
  • Email address
  • Phone number
  • Profile photograph (optional or required per School configuration; used for visual identity verification at dismissal)
  • Relationship to the student(s) (e.g., mother, father, guardian, grandparent, caregiver)
  • Government-issued ID verification data, only if the School enables enhanced identity verification: [DESCRIBE — e.g., ID scan, last 4 characters of ID number, or verification result only]

(b) Vehicle Information (provided by parents/guardians for carline check-in)

  • Vehicle make, model, and color
  • License plate number

(c) Authorized Pickup Designations

  • Names and contact details of individuals a parent or guardian designates as authorized to pick up a student
  • Any pickup restrictions or notes entered by the parent, guardian, or School (e.g., custody-related restrictions entered by the School)

(d) School User Account Information

  • Name, work email address, phone number
  • Role and permissions (e.g., teacher, front office, administrator)
  • School and classroom assignment
  • Profile photograph (if enabled by the School for staff identity verification)

(e) Communications

  • Messages you send to our support team, and related correspondence records

2.2 Information Provided by Schools (Including Student Roster Data)

Schools provide, upload, or sync the following information to operate the Services:

  • Student name
  • Student grade level
  • Assigned teacher and classroom
  • Student photograph, only if the School elects to include photos for release verification
  • Student ID number assigned by the School [IF APPLICABLE]
  • Associations between students and their parents, guardians, and Authorized Pickup Persons
  • Dismissal method and schedule information (e.g., carline, walker, bus, after-care)
  • Custody or release restrictions entered by the School
  • School information (name, address, campus configuration, dismissal zones)

Student roster data is education-record information maintained on behalf of the School. See Sections 13 and 14.

2.3 Information Generated Through Use of the Services

  • Check-in and dismissal events: parent check-in records, dismissal queue entries, student release verifications, release confirmations, and associated timestamps
  • Pickup history and audit logs: who requested, approved, and completed each student release, and when
  • Emergency dismissal records: records generated during emergency or off-schedule dismissal events initiated by the School
  • Notification records: which push notifications, SMS messages, or emails were sent, delivered, and opened

2.4 Information Collected Automatically

When you use the App, Console, or Site, we and our service providers automatically collect:

  • Device information: device model, operating system and version, app version, language, time zone, and device identifiers (e.g., a randomly generated installation ID)
  • Push notification tokens (e.g., Firebase Cloud Messaging registration tokens, Apple Push Notification service tokens)
  • Log and security data: IP address, authentication events (logins, failed logins, password resets), access logs, and security event logs
  • Usage analytics: screens viewed, features used, session duration, and interaction events, collected in aggregated or pseudonymous form to improve the Services
  • Crash and diagnostic data: crash logs, error traces, and performance metrics
  • Cookies and similar technologies on the Site and Console (see Section 6)

2.5 Location Information

The App collects precise device location only if location features are enabled by the parent/guardian on their own device or configured by the School (for example, geofenced carline check-in that detects arrival on campus). You can disable location access at any time in your device settings; doing so may limit location-dependent features (such as automatic check-in), but manual check-in remains available. We do not track your location continuously in the background except as required for an enabled check-in feature, and only as disclosed at the time you grant the permission.

2.6 Information We Do NOT Collect

  • We do not knowingly collect any information directly from children. Students do not use, register for, or log into the Services.
  • We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
  • We do not collect biometric identifiers or biometric information as defined under applicable biometric privacy laws. Profile photographs are stored as images for human visual verification and are not used to create biometric templates. We do not serve third-party advertising in the Services and do not use advertising SDKs.

3. How We Collect Information

We collect information:

  • (a) Directly from you, when you register, complete your profile, add vehicle details, designate Authorized Pickup Persons, check in for pickup, or contact support;
  • (b) From Schools, which provide student rosters, staff accounts, dismissal configurations, and release restrictions;
  • (c) From parents and guardians about others, when a parent or guardian designates an Authorized Pickup Person (the designating parent/guardian is responsible for having authority to share that individual's information — see Section 15.2);
  • (d) Automatically, through the App, Console, and Site as described in Sections 2.4–2.5; and
  • (e) From service providers, such as cloud infrastructure, analytics, and communications providers acting on our behalf.

4. Why We Collect Information (Purposes of Processing)

We use personal information to:

  • (a) Operate the dismissal platform: verify the identity of parents, guardians, Authorized Pickup Persons, and staff; manage dismissal queues; confirm that students are released only to authorized individuals; and record each release event;
  • (b) Maintain safety and accountability: generate audit logs, pickup history, and release verifications that Schools rely on for student safety and record-keeping;
  • (c) Provide notifications: send push notifications, and where enabled, SMS or email notifications, about check-in status, dismissal events, schedule changes, and emergencies;
  • (d) Administer accounts: create and manage accounts, authenticate users, enforce role-based permissions, and provide customer support;
  • (e) Secure the Services: detect, investigate, and prevent unauthorized access, fraud, misuse, and security incidents; maintain authentication and security logs;
  • (f) Maintain and improve the Services: diagnose crashes, monitor performance, analyze aggregate usage patterns, and develop new features;
  • (g) Communicate with Schools and account holders: service announcements, policy updates, and (for School administrative contacts only) account and billing communications;
  • (h) Comply with law: satisfy legal obligations, respond to lawful requests, enforce our agreements, and protect the rights, property, and safety of students, users, Schools, and the Company.

We do not use personal information — and in particular we do not use student information — for targeted advertising, for building profiles unrelated to the Services, or for selling to third parties. We use student data solely to provide the Services to the School, consistent with FERPA's school-official requirements and Florida's student data privacy laws (including § 1002.222, Florida Statutes).

6. Cookies and Similar Technologies

6.1 What We Use

The Site and Console use:

  • (a) Strictly necessary cookies — session, authentication, security (e.g., CSRF protection), and load-balancing cookies required for the Services to function;
  • (b) Functional cookies — remembering preferences such as language and selected school/campus;
  • (c) Analytics cookies and SDKs — first-party or service-provider analytics used to understand usage in aggregate (see Section 7).

We do not use advertising or cross-site tracking cookies.

6.2 Your Choices

Most browsers allow you to refuse or delete cookies. Blocking strictly necessary cookies will prevent the Console and authenticated areas of the Site from working. Where required by law, we present a cookie banner allowing you to accept or decline non-essential cookies.

6.3 Do Not Track and Global Privacy Control

Because we do not track users across third-party websites, the Services respond to "Do Not Track" signals by continuing not to track you. Where the Global Privacy Control (GPC) signal is legally recognized as an opt-out of sale/sharing, we honor it; note, however, that we do not sell or share personal information as defined under the CCPA.

7. Analytics, Crash Reporting, and Push Notifications

7.1 Analytics and Crash Reporting

We use service providers to collect app analytics and crash diagnostics so we can fix bugs and improve reliability. These currently include:

  • Google Firebase (Google LLC), including Firebase Analytics [CONFIRM], Firebase Crashlytics [CONFIRM], Firebase Authentication [CONFIRM], Firebase Cloud Messaging, and related Firebase services. Google processes this data as our service provider under the Google data processing terms. Information about Firebase privacy and security is available at https://firebase.google.com/support/privacy.
  • [LIST ANY OTHER ANALYTICS/CRASH SDKS, e.g., Sentry, Datadog — OR DELETE]

Analytics are configured to avoid collecting student personal information. Analytics events describe app usage by adult users (e.g., "check-in completed"), not student identities.

7.2 Push Notifications

With your permission (iOS) or by default subject to system settings (Android), we send push notifications about dismissal events, check-in confirmations, schedule changes, and School announcements, using Firebase Cloud Messaging and Apple Push Notification service. You can disable push notifications in your device settings; doing so may delay your awareness of time-sensitive dismissal information. Push notification tokens are stored to route notifications to your device.

8. How We Disclose Information

We disclose personal information only as follows:

8.1 To Schools

The School and its authorized personnel can view information relevant to their students and dismissal operations, including parent/guardian and Authorized Pickup Person profiles and photos, vehicle information, check-in events, release records, pickup history, and audit logs for their School. Schools control access within their organization through role-based permissions.

8.2 To Parents, Guardians, and Authorized Pickup Persons

Parents and guardians can view their own students' dismissal status, their designated Authorized Pickup Persons, and their own pickup history. Authorized Pickup Persons see only the information needed to complete authorized pickups.

8.3 To Service Providers (Sub-processors)

We use vetted service providers who process data on our behalf under written contracts limiting their use of the data to providing services to us, including:

  • Cloud hosting and storage: [Google Cloud Platform / Railway]
  • Firebase services (Google LLC) — authentication, push messaging, analytics, crash reporting
  • Email delivery: SendGrid
  • SMS delivery: [PROVIDER — e.g., Twilio — CONFIRM OR DELETE]
  • Payment processing (School billing contacts only): Stripe
  • Customer support tooling: [CONFIRM OR DELETE]

A current list of sub-processors is available upon request to legal@guardianflowsystems.com [OR AT A HOSTED SUBPROCESSOR PAGE — CONFIRM].

We may disclose information: (a) to comply with applicable law, regulation, subpoena, court order, or other legal process; (b) to enforce our agreements; (c) to detect, prevent, or address fraud, security, or technical issues; or (d) to protect the rights, property, or safety of students, users, Schools, the public, or the Company, including in emergencies involving imminent risk of harm. Where a request seeks student education records maintained for a School, we will (unless legally prohibited) redirect the requester to the School and/or notify the School before responding, consistent with FERPA and our School Services Agreements.

8.5 Business Transfers

If GuardianFlow is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy's commitments. Student data will remain subject to the same protections and to the applicable School Services Agreement, and Schools will be notified as required by law and contract. We will not permit a successor to use student data in a manner inconsistent with the promises made in this Policy without notice and, where required, consent or School approval.

8.6 What We Never Do

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not disclose student information to data brokers, advertisers, or marketing partners.

9. Data Retention

9.1 General Approach

We retain personal information only as long as needed for the purposes described in this Policy, to comply with legal obligations, to resolve disputes, and to enforce agreements. Retention of student data and dismissal records is directed by the School: because release and audit records may constitute education records and safety documentation, Schools typically require retention for the duration of the contract plus a defined archival period.

9.2 Indicative Retention Periods

Data CategoryIndicative RetentionNotes
Parent/guardian/staff account profilesLife of account + [90] days after deletion requestSubject to legal holds
Student roster dataTerm of School Services Agreement; deleted or returned within [60–90] days of contract terminationSchool-directed
Dismissal, release, and audit recordsAs configured by the School; default [X years]Safety/audit records; School may require longer under state records schedules
Vehicle informationLife of account or until removed by userUser-editable
Push tokensUntil token invalidated or account deletedRotated by platform
Security and authentication logs[12–24] monthsSecurity and incident investigation
Crash/diagnostic logs[90–180] days
Analytics data[14–26] months, then aggregated
Support correspondence[3] years
Billing records (School contacts)[7] yearsTax/accounting requirements

9.3 Deletion and De-identification

When retention periods end, we delete or de-identify personal information. Residual copies may persist in encrypted backups for up to [35] days before being overwritten in the ordinary backup cycle. See our separate Data Deletion Policy for request procedures.

10. Your Rights and Choices

10.1 All Users

Regardless of where you live, you may:

  • Access and update your profile information in the App;
  • Delete your vehicle information and profile photo in the App;
  • Request account deletion in the App ([Settings → Account → Delete Account]);
  • Control device permissions (location, camera, notifications) in your device settings;
  • Opt out of non-essential communications using unsubscribe links or notification settings (service and safety notifications may still be sent while your account is active).

Important — student and School-managed data: If your request concerns student roster data, release restrictions, custody notes, or dismissal/audit records maintained for a School, we will refer the request to the School, which controls that data as the education-record custodian. Parents seeking to inspect, amend, or delete education records should contact the School directly; we will support the School in fulfilling verified requests.

10.2 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to: (a) know/access the categories and specific pieces of personal information we collect, the sources, purposes, and categories of recipients; (b) delete personal information, subject to exceptions; (c) correct inaccurate personal information; (d) opt out of "sale" or "sharing" of personal information — we do not sell or share personal information as defined by the CCPA; (e) limit use of sensitive personal information — we use sensitive personal information (e.g., account login credentials, precise geolocation if enabled) only for purposes permitted under the CCPA regulations (providing the Services, security, and quality); and (f) non-discrimination for exercising your rights.

To exercise these rights, email support@guardianflowsystems.com with the subject line "California Privacy Request" or [INSERT WEB FORM / TOLL-FREE NUMBER IF REQUIRED BASED ON CCPA APPLICABILITY ANALYSIS]. We will verify your identity (typically by matching account credentials and confirming via your registered email) and respond within 45 days, extendable by 45 days with notice. You may use an authorized agent with written authorization.

Categories disclosure (Cal. Civ. Code § 1798.130): In the preceding 12 months we have collected the categories of personal information described in Section 2 (identifiers; customer records such as name, phone, vehicle and license plate; audio/visual data in the form of profile photos; geolocation if enabled; internet/electronic activity; professional information for School staff; and inferences limited to service operation). Sources, purposes, and disclosures are as described in Sections 3, 4, and 8. We disclose information for business purposes to the recipients in Section 8; we have not sold or shared personal information.

Note for Schools and parents: to the extent GuardianFlow processes student information as a service provider to a School, requests concerning that information should be directed to the School.

10.3 EEA, UK, and Swiss Users (GDPR)

You may have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent (without affecting prior processing). Contact legal@guardianflowsystems.com. You also have the right to lodge a complaint with your supervisory authority. Where GuardianFlow acts as processor for a School, we will refer your request to the School (the controller) and assist as required by Art. 28 GDPR. [IF THE COMPANY ACTIVELY OFFERS SERVICES IN THE EEA/UK, COUNSEL SHOULD COMPLETE THIS SECTION BEFORE PUBLICATION.]

10.4 Other U.S. State Privacy Laws

Residents of states with comprehensive privacy laws (including Florida's Digital Bill of Rights (§§ 501.701–501.722, Fla. Stat.), and the laws of Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others, to the extent applicable to us) may have similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, or profiling. We do not engage in targeted advertising, sale, or profiling producing legal or similarly significant effects. To exercise applicable rights, contact support@guardianflowsystems.com. If we decline your request, you may appeal by replying to our decision email with "Appeal" in the subject line; we will respond within the period required by your state's law.

10.5 Florida Residents

In addition to any rights under the Florida Digital Bill of Rights (to the extent applicable), Florida users should note: (a) student data is protected under § 1002.222, Florida Statutes, and related State Board of Education rules, which prohibit certain collection and uses of student information — GuardianFlow's handling of student data is limited accordingly; and (b) in the event of a breach of security involving your personal information, we will provide notice as required by the Florida Information Protection Act, § 501.171, Florida Statutes.

11. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest;
  • Role-based access controls and least-privilege permissions for both School users and internal personnel;
  • School-level data isolation (each School's data is logically segregated);
  • Multi-factor authentication for administrative access;
  • Audit logging of access to student release records;
  • Secure cloud infrastructure with vendor security certifications [e.g., SOC 2 / ISO 27001 at the infrastructure level];
  • Personnel confidentiality obligations and security training;
  • Vulnerability management and [PENETRATION TESTING CADENCE];
  • A documented incident response plan.

No system is perfectly secure, and we cannot guarantee absolute security. If we determine that a breach of security has occurred affecting your personal information, we will notify affected individuals, Schools, and regulators as required by applicable law, including § 501.171, Florida Statutes, and our contractual commitments to Schools.

12. International Users and Data Transfers

The Services are operated from the United States, and information is stored and processed in the United States [CONFIRM REGION(S)]. If you access the Services from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where privacy laws may differ from those of your jurisdiction. Where GDPR or similar law applies to a transfer, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, for applicable providers, the EU–U.S. Data Privacy Framework together with supplementary measures as appropriate. You may request more information about transfer safeguards at legal@guardianflowsystems.com.

13. Children's Privacy (COPPA)

13.1 Not Directed to Children

The Services are not directed to children under 13 (or to minors of any age). GuardianFlow is a tool for adults — parents, guardians, Authorized Pickup Persons, and School personnel. Children cannot create accounts, cannot log in, and are not permitted to use the Services. We do not knowingly collect personal information from any child.

13.2 Information About Students Is Different From Information From Children

The Services necessarily process information about students — such as name, grade, teacher, dismissal status, and release records — because student safety is the purpose of the platform. This information is provided to us by Schools and by parents/guardians, not by children, and it is used solely to operate the dismissal platform on the School's behalf. The Children's Online Privacy Protection Act ("COPPA") governs operators that collect personal information from children through online services directed to children or with actual knowledge of collection from children; because students do not interact with the Services, GuardianFlow does not collect information from children within the meaning of COPPA. To the extent any School use of the Services were deemed to involve collection from children, the School would provide the required consent on parents' behalf in the educational context consistent with FTC guidance, and GuardianFlow would use the information solely for the School's educational/safety purposes and for no commercial purpose.

13.3 If We Learn a Child Has Provided Information

If we learn that a child under 13 has provided personal information to us directly (for example, by creating an account in violation of our Terms), we will delete that information and terminate the account promptly. Parents who believe a child has provided information to us may contact support@guardianflowsystems.com.

13.4 No Advertising, Profiling, or Sale of Student Data

We never use student information for advertising or marketing, never build student profiles for non-educational purposes, and never sell student information. See our Child Safety & Education Privacy Policy for a full statement of our student-data commitments.

14. FERPA and School Responsibilities

14.1 Schools Remain the Custodians of Education Records

Student information in GuardianFlow — including roster data and dismissal/release records — may constitute "education records" under the Family Educational Rights and Privacy Act ("FERPA," 20 U.S.C. § 1232g; 34 C.F.R. Part 99) and equivalent state law. The School remains the custodian of those records and is responsible for FERPA compliance, including responding to parents' requests to inspect, review, and seek amendment of education records.

14.2 GuardianFlow as a "School Official"

GuardianFlow receives education-record information under FERPA's "school official" exception (34 C.F.R. § 99.31(a)(1)), pursuant to which GuardianFlow: (a) performs an institutional service or function for which the School would otherwise use employees; (b) is under the direct control of the School with respect to the use and maintenance of education records, as set out in the School Services Agreement; (c) uses education records only for the purposes for which the disclosure was made (operating the dismissal platform); and (d) does not re-disclose education records except as directed by the School or required by law.

14.3 School Obligations

Each School is responsible for: (a) having authority to disclose roster and release information to GuardianFlow (whether under the school-official exception, its annual FERPA notification, directory-information designations, or parental consent, as the School determines); (b) accurately maintaining release authorizations and custody restrictions in the platform; (c) managing its users' access and promptly deactivating departed staff; and (d) providing any notices to parents required by applicable law or district policy.

14.4 Florida Student Data Law

For Florida public Schools, GuardianFlow's collection and use of student data is limited consistent with § 1002.222, Florida Statutes (prohibiting collection of biometric, political-affiliation, religious, and similar data), and district data-governance policies. GuardianFlow does not collect any category of student information prohibited by that statute.

15. Parent and User Responsibilities

15.1 Accuracy

Parents, guardians, and School users are responsible for keeping their profile, vehicle, and contact information accurate and current. Inaccurate information (for example, an outdated vehicle description) can delay or complicate dismissal.

15.2 Designating Authorized Pickup Persons

When you designate an Authorized Pickup Person, you represent that: (a) you have legal authority to authorize that individual to pick up the student; (b) you have that individual's permission to share their name and contact information with GuardianFlow and the School; and (c) you will promptly remove any individual who is no longer authorized. Custody-related restrictions must also be communicated directly to the School, which controls release restrictions in the platform.

15.3 Account Security

Keep your credentials confidential and notify us immediately of any suspected unauthorized use. Do not allow others to check in or claim students under your account.

16. Third-Party Links and Services

The Site or Services may link to third-party websites or services (for example, a School's own website). We are not responsible for the privacy practices of third parties, and this Policy does not apply to them. App marketplace providers (Apple, Google) process certain data (e.g., downloads, purchases) under their own privacy policies.

17. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice through the App, by email to account holders, and/or by prominent notice on the Site at least [30] days before the changes take effect. Material changes affecting student data handling will also be communicated to Schools in accordance with our School Services Agreements, and we will not materially change our student-data practices without providing Schools the notice and choices required by law and contract. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy to the extent permitted by law.

18. Contact Us

Privacy questions and rights requests:

GuardianFlow Systems LLC

Florida Limited Liability Company

Florida, United States

Attn: Privacy

Email: support@guardianflowsystems.com (support and rights requests)

Email: legal@guardianflowsystems.com (legal notices and privacy officer)

If you have an unresolved privacy concern that we have not addressed satisfactorily, you may contact your state Attorney General or, for EEA/UK users, your data protection supervisory authority.