Legal
Privacy Policy
Last updated: July 2026
CommPartHS, LLC (“CommPart,” “we,” “us”) provides a multi-tenant software platform that helps school districts and career-technical centers approve, track, and report on community-partner engagement, workforce and career-technical activity, and family communication. This policy explains what information we handle, how we use it, and the choices and protections that apply. It covers our marketing site, our administrative and tenant web applications, and our mobile applications (together, the “Services”).
Our customers are educational institutions. When a district or center uses the Services, it is the controller of the information in its account. We act as its service provider and process that information only to provide the Services and on the institution’s behalf.
Student data and FERPA
Some features process education records that identify students. With respect to those records, we act as a “school official” with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA), performing a service the institution would otherwise perform itself, under its direct control. Specifically:
- We use student data only to provide the Services to the institution that provided it.
- We do not sell student data, and we do not use it for advertising or to build advertising profiles.
- We do not use student data to train third-party or general-purpose AI models.
- The institution retains ownership and control of its student data and may access, correct, export, or delete it.
- Student data is disclosed only to the institution, to users the institution authorizes, or to the sub-processors listed below strictly to operate the Services.
Where a feature is used with students under 13, the institution provides any consent required under the Children’s Online Privacy Protection Act (COPPA) on the parent’s behalf, consistent with the school-consent exception, and we collect from those students only what is needed to provide the Services. Where the Services are used to run surveys that touch protected topics, we support the institution’s obligations under the Protection of Pupil Rights Amendment (PPRA).
For institutions in Ohio, our handling is built to support their obligations under Ohio’s student-records confidentiality law (Ohio Rev. Code § 3319.321) and data-breach notification law (Ohio Rev. Code § 1349.19), and we use the state student identifier (SSID) rather than Social Security numbers for reporting. We will enter into a data protection agreement with each institution — the institution’s own required agreement, or the Student Data Privacy Consortium (SDPC) National Data Privacy Agreement with its Ohio exhibit.
Information we handle
- Account and staff information — names, work email, role, and authentication data for district staff and administrators.
- Community-partner information — organizations and contacts a district engages with, approval and engagement history, and contributions.
- Student and family information (where those features are used) — student names, identifiers (SSID), date of birth, grade, demographic elements used for state reporting, enrollment and program participation, work-based-learning hours, credentials, guardian contact details, and form submissions.
- Uploaded files — logos, images, documents, and attachments submitted through the Services.
- Usage and device data — log data, IP address, and technical event data used to secure and operate the Services.
The ClockIn student app
Most information above reaches us froma school. The ClockIn mobile app is different, and we describe it separately because the student enters information themselves: a high-school student (grades 9–12) creates a login with their name and email, connects to their school using a code the school issues, and from there may record work-based-learning hours, apply to job postings, and send a message to their own counselor or instructor.
A student only ever sees content from a school that has verifiedthey are one of its students, and only their own records. Hours a student records are marked unverified until a staff member confirms them. Messages a student sends are delivered to that school’s staff and are not private between students. Students choose a preset avatar rather than uploading a photo, so we do not collect student photographs. We do not use any of this for advertising, we do not sell it, and there is no third-party advertising or tracking SDK in the app.
How we use information
We use information to provide, secure, support, and improve the Services; to authenticate users and enforce tenant isolation; to send transactional messages (such as approvals, reminders, and password resets); to generate the reports and exports an institution requests; and to comply with law. We do not sell personal information.
Sub-processors and sharing
We share information only with vendors that help us run the Services, under contracts that require them to protect it and use it only for that purpose:
- Amazon Web Services — cloud hosting and the primary database (United States).
- Cloudflare — content delivery, network security, and media storage.
- Resend — delivery of transactional email.
- Stripe — subscription billing (payment-card data is handled by Stripe, not stored by us).
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (subject to this policy). We do not otherwise share personal information with third parties.
Security
We protect information with encryption in transit, database-level tenant isolation (row-level security so one institution’s data cannot be served to another), role-based access controls, attested and immutable audit logging of approvals and status changes, least-privilege administrative access, and regular backups. No system is perfectly secure, but security is a core design principle of the Services.
Data incidents and notification
If we confirm a security incident affecting personal information, we notify the affected institution’s designated contact without undue delay and no later than 72 hours after confirmation, with the nature and scope, the data involved, and the steps taken. We cooperate with the institution’s own notification obligations under FERPA and applicable state law (including Ohio Rev. Code § 1349.19). We maintain a written information-security program with administrative, technical, and physical safeguards aligned to a recognized framework.
Retention and deletion
We retain information for as long as an institution’s account is active and as needed to provide the Services. Records are soft-deleted (retained with a deletion marker) to preserve audit history and support recovery. On written request or on termination, we will export an institution’s data in a usable format and delete it from active systems within a commercially reasonable period, subject to legal retention obligations and routine backup cycles.
Your choices and rights
Because institutions control the data in their accounts, parents, students, and staff should direct requests to access, correct, or delete information to their district or center, which can act on them directly in the Services. We assist our customers in responding to such requests.
Where the Services are used
The Services are operated in the United States and intended for use by U.S. educational institutions. We do not knowingly collect information directly from children except through, and at the direction of, a school that has provided the required consent.
Changes to this policy
We may update this policy to reflect changes to the Services or the law. Material changes will be posted here with an updated date and, where appropriate, communicated to customers.
Contact
Questions about this policy or our data practices can be sent through our contact form.
See also our Terms of Service.