KudoTapper

Privacy Policy

KudoTapper is a classroom recognition tool for K-12 schools. Protecting students is the core of how it's built — we collect the least data possible and never sell it or use it for advertising.

Last updated: July 18, 2026

The short version

  • We collect the minimum student data needed to run a classroom points program — a first name, last initial, an optional class/grade, a school-assigned ID, and a points balance.
  • Students never create accounts and never log in. They tap an NFC card that carries only a random ID.
  • We never sell student data, never use it for targeted advertising, and never build advertising profiles of students.
  • The school or district owns and controls its data. Parents exercise their rights through the school.
  • We run no third-party advertising or analytics on student data.

Who this covers, and who does what

KudoTapper is operated by Arrington Innovative Solutions, LLC (“AIS,” “we,” “us”). A school or district (“School”) subscribes to KudoTapper and decides what information to enter.

For student information, the School is the data controller and KudoTapper acts as its service provider — a “school official” with a legitimate educational interest under FERPA, processing student data only on the School’s behalf and under its direction. The School retains direct control over the use and maintenance of student records; we act only on the School’s instructions and do not use student data for our own purposes.

What we collect

Student records (entered by school staff): first name, last initial, an optional grade and class/homeroom, an optional school-assigned student reference number, the random ID (UID) of an NFC card or fob issued to the student, and the student’s points balance and points history (awards and store purchases).

We do not collect student email addresses, dates of birth, home addresses, phone numbers, photographs, government identifiers, biometric data, or precise location. Students do not have logins or passwords.

Staff accounts: for teachers and administrators we store a name, work email, role, and school assignment. Staff sign in with a password or magic link; we store passwords only as salted hashes, never in plain text.

Technical data: standard server logs and security records (e.g. rate-limiting and audit logs) needed to operate the service securely. We do not run behavioral tracking or advertising cookies (see Cookies).

How we use data

We use information solely to provide and secure the service the School asked for: recording and displaying points, running the store kiosk, letting staff award and manage points, keeping accounts and access secure, and providing support to the School.

An optional, staff-only AI assistant (“Tally”) can help teachers draft point awards. It processes limited classroom roster information (first name, last initial, and class/homeroom) to do so, is never available to students, and always requires a teacher to confirm any action. That information is used only to generate the teacher’s suggested award — it is not used to train any AI model and is not used for any other purpose. See Subprocessors for the provider that powers it.

Children's privacy — FERPA, COPPA & state student-privacy laws

KudoTapper is designed for use in schools with students who may be under 13. We handle student data in line with the Family Educational Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA), and state student-data-privacy laws (such as SOPIPA-style statutes).

School-authorized consent. Where COPPA applies, the School provides consent on behalf of parents for the limited, educational use of student data within KudoTapper, consistent with FERPA’s school-official exception. We only collect what the School enters for classroom recognition. On request, we will give the School a description of the categories of student data we collect, how it is used, and the means to review or delete it. Student data is used only for the educational purpose the School authorizes — never for any commercial purpose.

Our binding commitments regarding student data:

  • We do not sell or rent student data.
  • We do not use student data for targeted advertising, and we do not allow third parties to do so.
  • We do not build a personal profile of a student except to provide the school service.
  • We collect and retain only the minimum data needed, and delete or return it on request (see Retention).
  • We do not run third-party advertising or analytics trackers on student data.

How data is shared

We do not sell data or share it for advertising, and we do not redisclose student data to any third party except as described here — at the School’s direction, to the subprocessors below under contract (bound to these same restrictions), or as required by law. Specifically, we share information only:

  • Within the School’s own tenant — a school’s data is isolated from every other school and district, and is visible only to authorized staff of that school (and its district administrators).
  • With service providers (subprocessors) that operate the platform under contract and only to provide their service to us, listed below.
  • When required by law. Where we are compelled by legal process to disclose student data, we will notify the affected School before disclosing, unless the law prohibits it, so the School can respond.
  • At the School’s direction. In a merger, acquisition, or sale, any successor will be bound by these same commitments, and any transfer of student data remains subject to the School’s rights and our Data Privacy Agreement.

Subprocessors

We use a small set of vetted providers to run KudoTapper. Each is bound by contract to protect data and use it only to provide their service to us:

  • Supabase — database, authentication, and hosting of application data.
  • Vercel — application hosting and delivery.
  • Resend — transactional email to staff (e.g. invitations). No student email is ever sent or stored.
  • Anthropic — powers the optional staff-only AI assistant, when a school enables it. Roster information sent to power the assistant is not used to train AI models.

We will give subscribing Schools advance notice of any new or replacement subprocessor that will handle student data, and a reasonable opportunity to object.

Data retention & deletion

We keep student data only for as long as the School uses KudoTapper, or as the School instructs. School staff can archive a student at any time (reversible — it keeps the record but hides it), or delete a student to remove their identity. A deleted student is recoverable for a short grace window (a district-configurable period, 30 days by default) and is then permanently de-identified; for a parent or district erasure request, an administrator can remove the data immediately. Deletion completes no later than 30 days, or within the timeframe set out in our Data Privacy Agreement, except where limited records must be retained by law.

When a student’s data is deleted, we remove the student’s name, ID, grade, homeroom, card, and any free-text notes. The points ledger keeps only an internal reference for transaction integrity — it does not retain a deleted student’s identity. Data is removed from production immediately on purge and ages out of routine backups within our backup-retention cycle.

Parent & student rights

Because the School controls student records, parents and eligible students exercise their rights — access, correction, and deletion — through their school or district. If you are a parent and contact us directly, we will refer you to your School and assist the School in responding.

How we protect data

KudoTapper encrypts data in transit and at rest, isolates each school’s data with database-level access controls, minimizes the data it holds, and keeps audit logs of sensitive actions. Student data is stored on infrastructure located in the United States. For more detail, see our Security page.

Security incidents

If we confirm a security breach affecting a School’s student data, we will notify the affected School without undue delay and no later than 72 hours after confirmation, describe what happened and what data was involved, and cooperate with the School’s investigation and its own notification obligations. Where a Data Privacy Agreement sets a specific timeframe or process, that agreement controls.

Data privacy agreements

We will enter into a Data Privacy Agreement (DPA) with a School on request — including the Student Data Privacy Consortium (SDPC) National Data Privacy Agreement where a district uses it — and will provide reasonable security documentation to support a School’s due diligence.

Accessibility

We aim to meet WCAG 2.1 AA accessibility standards across KudoTapper. If you need an accommodation or encounter an accessibility barrier, contact us at privacy@arringtonis.com.

Cookies

KudoTapper uses only essential cookies — to keep staff signed in, to enforce kiosk mode on a shared tablet, and to remember a light/dark theme preference. We do not use advertising cookies or third-party tracking cookies, and we do not track students across sites.

Changes & contact

We may update this policy as the service evolves; we will revise the “last updated” date and, for material changes affecting student data, notify subscribing Schools.

Questions about privacy or a student-data request? Contact us at privacy@arringtonis.com, or reach out through your school administrator.