Privacy Policy.
What we collect, how we use it, the subprocessors who touch it, and the rights you have under US state privacy laws.
Effective June 8, 2026
Effective date: June 8, 2026. Last reviewed: June 14, 2026.
1. Who we are
CohortLedger is software operated by Ravencord Inc., a Delaware C-corporation headquartered in Brentwood, Tennessee. We provide operations and ESA-compliance software for independent microschools, learning pods, and homeschool co-ops in the United States. This Privacy Policy describes how we collect, use, share, and protect personal information when you use CohortLedger.
For purposes of US state privacy laws, Ravencord Inc. is the business (California), controller (Virginia, Colorado, Connecticut, Utah, Texas) for operator account information, and the service provider / processor for family and student data the school enters into the dashboard. The school is the business / controller for that family and student data and is responsible for parental notice and any required consent.
2. What we collect
2.1 Operator account information
The person running the school provides: name, email, school name and address, the US state the school operates in, payment method (handled by Stripe), authentication credentials, and any documents the operator uploads to support ESA vendor registration or quarterly state reporting.
2.2 Family information
For each enrolled family the operator records: family name, primary contact name, email, phone number, the ESA program the family is enrolled in, and the payment platform that program uses (for example ClassWallet, Odyssey, Step Up For Students, Student First Technologies, or EMA).
2.3 Student records
For each student the operator records: first and last name, grade level, family relationship, enrollment date, attendance entries, the ESA program assigned to that student, and per-quarter funding amounts and statuses. We do not collect or store: child photos, biometric data, social security numbers, health records, geolocation data, or device identifiers tied to a child.
2.4 Technical information
When you use the dashboard, our systems automatically record standard server log information: IP address, browser user agent, timestamp, and the URL of the page you accessed. This information is used for security, abuse prevention, and aggregated usage measurement. It is not sold or shared with advertisers.
2.5 Data minimization
We collect only the information needed to run the ESA money flow, attendance, and per-state compliance for your school. We do not collect data we do not need to provide the service, and we never ask for child photos, biometrics, social security numbers, health records, or location data.
3. How we use it
We use this information solely to deliver the service you are paying for. Specifically:
- Service delivery: rendering the dashboard, generating invoices, tracking attendance, and surfacing compliance deadlines.
- Billing: charging the operator’s subscription through Stripe and recording family payments the operator marks as received.
- Compliance reporting: producing dated records you can hand to a state ESA program reviewer or attach to a quarterly state report.
- Support: responding when you write to us.
- Security: detecting and preventing fraud, abuse, and unauthorized access.
- Product improvement, aggregated only: measuring how operators use the product, exclusively from de-identified and aggregated data that cannot reasonably be linked to any individual, family, or school.
We do not use student records for advertising. We do not use student records to train AI models, ours or any third party’s. We do not sell any personal information to anyone. We do not share personal information for cross-context behavioral advertising. We do not engage in any automated decision-making that produces legal or similarly significant effects on operators, families, or students.
4. Subprocessors
We share information only with the limited set of named service providers required to operate CohortLedger. Each subprocessor is contractually bound to use information only for the purpose we specify and only on our instructions. The complete, current list is published at cohortledger.com/subprocessors. Today the list includes:
- Vercel Inc. (United States): frontend hosting and edge network for the marketing site and operator dashboard.
- Supabase Inc. (United States): primary database, authentication, file storage, and edge functions for the operator dashboard.
- Stripe, Inc. (United States): subscription billing and out-of-pocket family balance processing.
- Resend, Inc. (United States): transactional email and the SMTP backend for authentication emails.
We will notify operators in writing at least 30 days in advance of adding a new subprocessor or activating a Planned subprocessor. Operators entitled to advance notice under the Data Processing Addendum may object on reasonable grounds, and if we cannot resolve the objection, the operator may terminate the affected portion of the service. State ESA payment platforms (ClassWallet, Odyssey, Step Up For Students, Student First Technologies, EMA) receive only what the operator actively submits to them; we do not push data to those platforms automatically and they are not our subprocessors.
5. How we store and protect it
Data is encrypted in transit using TLS 1.2 or higher. Data is encrypted at rest in our production database (AES-256 or equivalent). Infrastructure is hosted in the United States. Production access is limited to a small number of authorized Ravencord personnel through audited role-based access controls and multi-factor authentication. Our written information security program is reviewed annually and is summarized in the Security page. The contractual controls available to schools are set out in the Data Processing Addendum.
6. Data retention
We retain information for as long as needed to provide the service and to comply with our legal obligations. Specifically:
- Operator account, family, and student records: retained for the duration of the subscription and for ninety (90) days after cancellation, during which the operator may export records. After 90 days we delete or anonymize the records, subject to legal hold and any state record-retention rule that requires longer retention (typically 4 to 7 years for ESA-funded tuition records).
- Billing and tax records: retained for 7 years after the end of the tax year, as required by US tax law.
- Server logs: retained for 90 days.
- Email transaction logs: retained for 30 days by our email subprocessor.
- Backup snapshots: retained for 30 days, then purged.
7. Your privacy rights under US state law
We honor the rights US state privacy laws give to residents, without making you prove residency to exercise them. To make a request, email privacy@cohortledger.com with the subject line “Privacy Request” and identify the right you are exercising. We respond within forty-five (45) days of a verified request, extendable by an additional 45 days where reasonably necessary, with notice to you. We will not discriminate against you for exercising these rights.
7.1 California residents (CCPA / CPRA)
California residents have the right to: (a) know what personal information we collect, use, and disclose; (b) request deletion of personal information; (c) request correction of inaccurate personal information; (d) opt out of the sale or sharing of personal information; (e) limit the use of sensitive personal information; and (f) be free from discrimination for exercising these rights. We do not sell personal information and do not share personal information for cross-context behavioral advertising. We honor valid Global Privacy Control (GPC) signals as an opt-out request under California Civil Code § 1798.135(b). Because we do not sell or share personal information, receipt of a GPC signal does not change our data practices.
7.2 Virginia (VA CDPA), Colorado (CO CPA), Connecticut (CT CTDPA), Utah (UT UCPA), Texas (TX DPDSA)
Residents of these states have the right to: (a) confirm whether we process their personal data and access it; (b) correct inaccurate personal data; (c) delete personal data we hold; (d) obtain a copy of their personal data in a portable format; and (e) opt out of targeted advertising, the sale of personal data, and certain profiling. We do not engage in targeted advertising, personal-data sales, or profiling that produces legal or similarly significant effects.
7.3 Submitting and appealing
Email privacy@cohortledger.com. If we deny a request, you may appeal by replying to our denial email; we will reconsider and respond within 60 days. Where state law provides, you may also contact your state attorney general.
8. Student data, FERPA, and state student data privacy laws
CohortLedger acts as a service provider on behalf of the school. The school is the controller of student records. We perform an institutional service or function for which the school would otherwise use its own employees, under the direct control of the school, consistent with the FERPA school official exception described in 34 CFR § 99.31(a)(1)(i)(B) and its state-law analogs.
For operators in states with specific student data privacy statutes (including New York Education Law § 2-d, Illinois SOPPA, California SOPIPA, Connecticut student data privacy law, Colorado student data privacy law), the Data Processing Addendum provides additional contractual terms. New York operators must execute the New York Parents Bill of Rights Addendum before transmitting NY student records. See our Children’s Privacy page for details specific to children under 13.
9. Cookies and analytics
We use only the cookies strictly necessary for authentication, security, and the operator’s saved UI preferences. We do not use behavioral advertising cookies. We do not currently use a third-party analytics vendor. If we begin using one, we will (a) add it to our subprocessor list, (b) update the Cookies Policy, and (c) notify operators by email. See the full list at Cookies Policy.
10. Breach notification
If we confirm a security event affecting personal information CohortLedger holds, we will notify the affected operator in writing within seventy-two (72) hours of confirmation, providing the facts the operator needs to fulfill notification obligations to the families they serve and to satisfy any applicable state breach notice law. Where state law sets a shorter deadline, we will comply with that shorter deadline.
11. Children
CohortLedger is not directed to children and we do not knowingly collect personal information directly from a child under 13. The operator (the school) is responsible for any parental notice or consent required to enter a child’s record into the dashboard. See Children’s Privacy.
12. International transfers
CohortLedger is a US-only service. Personal information is processed in the United States. We do not market the service to individuals outside the United States and do not transfer personal information outside the United States as part of normal service operations.
13. Changes to this Policy
We will publish changes on this page with a revised effective date and a plain-English summary of what changed. Material changes will be announced by email to active operators at least 30 days before they take effect.
14. Contact
Privacy contact: privacy@cohortledger.com.
Postal contact:
Privacy & Data Protection
Ravencord Inc.
6688 Nolensville Rd, Ste 108 #2225
Brentwood, TN 37027, United States
