Privacy Policy
Privacy Policy
This Privacy Policy describes how CommonCentsIP (“we”) handles information in Beacon School & Family. Beacon is a school operations product. Each participating school has its own code, roster, and records. Last updated 10 September 2026.
Operator: CommonCentsIP, operated by Chad Berg. Contact: chad.berg@commoncentsip.com. Atlanta, Georgia, USA.
Accounts: schools provision staff and family logins. There is no public self-serve signup. To close an account or request deletion of school records, ask your school office or email the address above. We do not sell personal information.
This page is Beacon’s Privacy Policy for the website and the iPhone app. It is not a data processing agreement, FERPA/COPPA certification, or substitute for a school’s own counsel.
Information Beacon can handle
The exact categories depend on the modules a school enables and the information it enters.
Product inquiries
Name, work email, role, school and workflow notes submitted through the design-partner form.
Identity & contact
Names, dates of birth, photos, family links, contact and emergency information.
Learning records
Classes, enrollment, assignments, grades, attendance, report cards and teacher notes.
Student support
Allergies, medical notes, discipline records and whole-child check-ins when a school uses them.
School operations
Announcements, communications, aftercare, badge scans and room events when enabled.
Product activity
Coarse authenticated product activity by school, person, role, workflow category and UTC date. The pilot activity ledger does not include student identity, URL, IP address, user agent or arbitrary payload.
Parent feedback
Weekly parent helpfulness responses and optional comments.
Billing
Products, invoices, payment records and accounting connection status when enabled.
Who can access school data
Parents
Students explicitly linked to their account, including the linked child’s family-facing records.
Teachers
Classes assigned to them and students enrolled in those classes.
School staff
School-wide operational records within their own school; not billing or QuickBooks credentials.
Principal / admin
School-wide administration, including billing and configured accounting connections.
Database row-level policies enforce these role and school boundaries. Parent links also require the parent profile and student to belong to the same school. School leadership can see aggregated pilot evidence and parent feedback for its school.
Public, account and token access
- The public school site shows school-provided brand and contact information.
- The public campus tour uses fictional student identities, not live roster records.
- Staff tools, role-scoped student records and the school’s campus twin use account sign-in.
- Kiosks, device scans and family payment portals can use bearer-token links without an account login. A valid token limits the view or action to that specific workflow.
- Schools should treat token links as secrets, rotate exposed kiosk/device links and share family payment links only with the intended recipient.
Implemented safeguards
- School and role boundaries are enforced in the database, not only in page code.
- Production authentication is required. Durable rate limiting is required before public or multi-instance production traffic; the explicitly labeled in-memory break-glass mode is only for controlled, non-public pilots.
- Email and accounting connections show live, log-only or demo status.
- Go-live health checks, access review and leadership approval are tracked separately.
Service providers and optional integrations
Core platform
CoreSupabase for database and authentication; Vercel for application hosting.
Communication
ConditionalResend or school SMTP for email; Twilio and Slack only when configured.
Payments & accounting
ConditionalSquare for Snack Shack top-ups; Stripe for family invoices; QuickBooks for accounting, only when the school enables those modules.
Optional AI grading
ConditionalxAI or the configured model through Vercel AI Gateway receives assignment details, student first names, answer-key and work photos, optional handwriting samples, and recent teacher corrections when a teacher runs AutoGrade. Photos can contain additional personal information.
Operations
ConditionalUpstash for production rate limiting and Sentry for error monitoring when configured.
This is a product-level provider overview, not a contractual or complete subprocessor list.
School responsibilities
- Use unique staff and family accounts; do not share generic passwords.
- Verify parent–student links and remove access when relationships change.
- Complete migration, login, phone, email and access-review checks before launch.
- Enable only the integrations the school intends to use and test their mode.
Before production procurement
A signed data processing agreement, named incident SLAs, and an accessibility conformance statement are separate from this Privacy Policy. A school should require those in writing before treating Beacon as an approved production vendor.
Children, retention, and your choices
- Beacon is a school and family product, not an Apple Kids Category app. Classroom games at /games need no account and do not attach to a student roster.
- School records are kept while the school uses Beacon and for a reasonable backup period after. Ask the school office or chad.berg@commoncentsip.com to correct or delete an account.
- Optional payments (Snack Shack top-ups, family invoices) run only when a school enables Square or Stripe. Those processors receive the payment details they need to charge the card.