Legal
Privacy Policy
Last updated August 28, 2026
This is a plain-language starting point that Simply Shepherd will finalize with counsel before general availability. It reflects how we intend to operate.
This policy explains how Simply Shepherd handles information in the Shepherd platform (the “Service”). For most data in Shepherd — applicant, student, and family records — your school is the controller and Simply Shepherd is a processor acting on your instructions.
What we collect
- Account information — the name, email, and password of staff who sign in, and your school's name and settings.
- School data you enter — applicants, students, households, applications, attendance, classes and grades, calendar events, and financial ledger entries. You decide what goes in.
- Payment data — handled by Stripe. We store identifiers and amounts needed to reconcile the ledger; we do not store full card numbers.
- Usage and device data — logs, IP address, and basic analytics needed to run, secure, and debug the Service.
How we use it
- to provide, maintain, secure, and support the Service;
- to process payments your school initiates, through Stripe;
- to communicate with account admins about the Service; and
- to comply with law and enforce our Terms.
We do not sell personal information, we do not use student data for advertising, and we do not use your school's data to train machine-learning models.
Messaging
Emails and messages Shepherd helps your school send — decision letters, family updates, announcements — are written and sent by your staff. Shepherd does not generate or send outbound communications on your behalf.
Subprocessors
We rely on a small number of vendors to run the Service:
- Stripe — payment processing for application fees, tuition, and giving;
- Cloud hosting and database — infrastructure the Service runs on;
- Transactional email — delivery of the messages your staff send and our own account notices.
Each is bound by contract to protect data and use it only to provide their service to us.
Security
- Tenant isolation — every table that holds school data has PostgreSQL row-level security enabled from the migration that creates it. Isolation is enforced by the database, not just by application code.
- Append-only finance — financial records cannot be updated or deleted in place; corrections are new offsetting entries, preserving a complete audit trail.
- Encryption — data is encrypted in transit (TLS) and at rest.
- Access — staff see only what their role allows; Simply Shepherd staff access tenant data only when needed for support or to keep the Service running.
To report a vulnerability, email security@simplyshepherd.com.
Students and families (FERPA)
Where a school is subject to FERPA or similar rules, Simply Shepherd acts as a “school official” with a legitimate educational interest, using education records only to provide the Service and under your school's direction. Requests from students or families to access or correct their records go to the school, which controls the data.
Your choices and rights
- Admins can export school data as CSV at any time and request deletion of the tenant.
- Individuals should contact their school to exercise rights over their records; we will assist the school in responding.
- For account-holder data (staff logins), email hello@simplyshepherd.com.
Retention
We keep school data for as long as your account is active. After closure we delete or anonymize it within 90 days, except where law requires longer retention (for example, financial records).
Cookies
We use only the cookies needed to keep you signed in and to run the Service. We don't use third-party advertising or cross-site tracking cookies.
Changes
If we make a material change to this policy, we'll notify account admins before it takes effect.
Contact
Privacy questions: hello@simplyshepherd.com.