Effective Date: September 5, 2026Last Updated: September 22, 2026
1. Introduction
MCS-App is a school management and communication platform that provides tools for managing student enrollment, attendance, academic records, fees and payments, staff payroll, chat and messaging, file sharing, and related educational and administrative functions. The platform is available through a web application and a mobile application for iOS and Android.
This Privacy Policy applies to all users of the platform, including school administrators and management staff, teachers, students, and other authorized personnel. By accessing or using the platform, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy describes how we collect, use, store, protect, and share personal and educational information. It should be read alongside our Terms of Use, which govern your use of the platform.
The platform is operated by [LEGAL ENTITY NAME]. References to "we", "us", or "our" in this policy refer to the entity responsible for processing your information.
2. Information We Collect
We collect different categories of information depending on your role and how you use the platform. The sections below describe each category.
2.1 Account and Identity Information
When an account is created for you or when you register, we collect:
Full name
Username and email address (where provided)
Phone number (where provided)
Gender and date of birth (where provided)
Physical address (where provided)
Role (administrator, management, teacher, student, staff member)
Branch or school association
Profile photo (if uploaded)
Login credentials (passwords are stored in hashed form using bcrypt; plain-text passwords are never stored)
Account status (active, inactive, suspended)
Login timestamps and last-seen activity
Account creation is managed by authorized school administrators. You are responsible for ensuring that the information associated with your account is accurate and current.
2.2 Student Information
Student information is entered and managed by authorized school personnel as part of school administration. This may include:
Student name, admission number, and enrollment records
Class or group assignment and academic year placement
Date of birth, gender, religion, nationality, blood group
National identity number (B-Form / CNIC)
Contact information (phone, email, WhatsApp)
Home address, city, postal code, country
Previous school and transfer certificate details
Family association and parent/guardian linkage
Emergency contacts and their phone numbers
Health records (blood group, chronic conditions, allergies, disability, medical notes, doctor name and phone)
Attendance records (daily status: present, absent, late, leave, holiday, function)
Academic results, marks, examination records, and report cards
Fee records, payment history, receipts, and concessions
Profile photo and uploaded documents
Class movements and transfer records
Credential lifecycle tracking (generation, delivery, first login)
Students have individual accounts on the platform. There is no separate parent portal or account switcher; each student logs in independently to view their own permitted information.
2.3 Teacher and Staff Information
Information about teachers, staff, and management profiles is collected as part of employment and branch membership:
Employee ID, job title or work role, department
Educational qualifications, specialization, work experience
Joining date and employment history
Salary information (where applicable)
Phone number, emergency contact, home address
Date of birth, gender, blood group, father's name, national ID number
Medical information (severe disease, if provided)
Portal access level and module permissions
Branch membership and role assignment
Attendance records
Payroll records and salary payment history
Profile photo and uploaded documents
2.4 Financial and Payment Information
The platform records financial information related to school fees and payments. We do not store raw credit card numbers, bank account details, or payment credentials. Financial data includes:
Fee structures, categories, and amounts
Student fee records (monthly, term, annual, one-time)
Payment amounts, dates, and methods (cash, cheque, bank transfer)
Receipt numbers and reference identifiers (cheque numbers, transaction IDs)
Payment allocation records and balance history
Concessions, late fees, and extra charges
Family payment records and multi-student allocation
Outgoing payment vouchers (payroll, utilities)
Payroll records including salary amounts and attendance-derived pay
Payment processing for school fees is handled through approved school channels. The platform records payment information but is not itself a payment processor and does not handle credit card or bank transactions directly.
2.5 Academic Information
Subjects, classes, and group assignments
Examination sessions, types, and schedules
Marks entries (per student, per subject, per exam)
Users may upload files through the platform, including profile photos, chat attachments, documents, receipts, voice notes, and videos. For each uploaded file, we store:
Original filename and file type (MIME type)
File size and dimensions (for images)
Storage location and access path
Upload status and processing status
Entity association (which student, teacher, or chat message the file is linked to)
Upload session data (for resumable uploads: byte offset, checksum, state)
Uploaded files are stored in cloud object storage (Cloudflare R2) or local filesystem depending on the deployment configuration. Files are subject to security validation before storage. Dangerous file types are blocked or reclassified to prevent security risks.
2.9 Device and Technical Information
We collect limited technical information necessary to operate the platform:
Device type, operating system, and application version (mobile app)
IP address and access timestamps (for authentication and security logging)
Push notification device tokens (for mobile notifications)
Session and authentication tokens
Error logs and diagnostic information (for debugging and reliability)
We do not use third-party analytics services such as Google Analytics, Mixpanel, or similar tracking tools. We do not place tracking cookies or use behavioral analytics.
2.10 Local and Offline Data (Mobile App)
The mobile application may temporarily store certain information locally on your device to support offline functionality. This includes:
Cached dashboard and bootstrap data (expires after 24 hours)
Recently viewed chat messages (up to 200 per room, retained for 30 days)
Pending outgoing messages (queued for sending when connectivity is restored)
Upload tasks in progress (for resumable uploads)
Active branch and academic year selection
Local cached data is associated with your user account. When you log out, all user-specific local data is cleared. If the application is closed unexpectedly, cached data may remain temporarily until the next login or cache expiry. You should protect access to your device to prevent unauthorized viewing of locally stored information.
3. How We Use Information
We use the information we collect for the following purposes:
Providing the platform: Operating, maintaining, and delivering the features and functionality of the platform
Authentication and access: Verifying your identity, managing your account, and controlling access based on your role and permissions
School administration: Managing student enrollment, class assignments, attendance tracking, academic records, and staff management
Financial management: Recording fee structures, processing payments, generating receipts, and maintaining financial records
Communication: Facilitating chat messaging, announcements, and direct messages between authorized users
Notifications: Sending attendance alerts, payment notifications, result notifications, payroll alerts, and school announcements
File management: Storing, processing, and delivering uploaded files and media to authorized recipients
Offline functionality: Caching data locally on mobile devices to support use when internet connectivity is unavailable
Security and fraud prevention: Detecting unauthorized access, preventing misuse, and maintaining audit trails
Debugging and reliability: Investigating errors, improving performance, and ensuring system stability
Backup and recovery: Maintaining database backups for disaster recovery and data integrity
Legal compliance: Meeting regulatory, record-keeping, and reporting obligations as required by applicable law
4. Legal Basis for Processing
We process your information on the following bases, depending on the context:
Service provision: Processing necessary to provide the platform and fulfill our obligations to the school organization
Legitimate interests: Processing necessary for legitimate operational and security purposes, including fraud prevention and system integrity
Legal obligations: Processing required to comply with applicable laws, regulations, and record-keeping requirements
Consent: Where you have given specific consent for a particular processing activity
If you have questions about the legal basis for processing your information, please contact us using the details provided in Section 17.
5. How Information Is Shared
We do not sell, rent, or trade personal information. Information may be shared in the following circumstances:
School and Organization Administrators
Authorized school personnel may access information necessary for their responsibilities. Branch administrators and management staff can view and manage records within their branch according to their assigned permissions.
Teachers and Academic Staff
Teachers may access information appropriate to their assigned classes, groups, and subjects, including student attendance, academic results, and communication channels.
Students
Students can access their own permitted information, including their academic records, attendance, fee status, and results, through their individual accounts.
Service Providers
We share information with third-party service providers who assist in operating the platform. These providers process data on our behalf under contractual obligations. Current service providers include:
Cloudflare R2 — cloud object storage for files and database backups
Firebase (Google) — push notification delivery via Firebase Cloud Messaging
Upstash — Redis-based rate limiting and session management
Resend — transactional email delivery
Sentry — error monitoring and diagnostics
Legal Requirements
We may disclose information when required by applicable law, court order, lawful government request, or to protect the rights, safety, or property of the platform, its users, or the public.
6. Third-Party Services
The platform integrates with third-party services that may independently collect or process information. We encourage you to review each provider's own privacy policy for details on their data practices.
Provider
Purpose
Information Involved
Cloudflare
Cloud object storage (files, backups)
Uploaded files, database backup files
Google Firebase
Push notification delivery (FCM)
Device tokens, notification content (encrypted)
Upstash
Redis rate limiting, JWT blacklist
Rate limit counters, token identifiers
Resend
Transactional email (admin invitations)
Email address, invitation content
Sentry
Error monitoring (optional)
Server-side error reports, HTTP metadata
7. Notifications
The platform may send you notifications related to your activity on the platform. These include:
Attendance notifications:Alerts when a student's attendance status is recorded (absent, late, leave)
Payment notifications: Alerts when fees are recorded, partially paid, or when payments are processed
Result notifications: Alerts when marks are entered or report cards are published
Teacher attendance and payroll notifications: Alerts related to teacher attendance and salary payments
Chat messages: New messages in chat rooms and direct messages
Announcements: School-wide or class-specific notices
Notifications may be delivered through the platform's internal notification system, push notifications on mobile devices, or both. Push notification content may contain limited information necessary to identify the event. You can disable push notifications through your device settings, though this may limit your ability to receive timely updates.
8. Cookies and Similar Technologies
The web application uses the following storage technologies:
Essential Cookies
Session cookie (token): An httpOnly cookie used to maintain your authenticated session. This cookie is essential for the platform to function and is set when you log in. It expires after 7 days. In production, this cookie is marked as Secure (HTTPS only).
Local Storage
JWT token: A fallback copy of your session token
Active branch and academic year: Your current branch and year selection for the session
Session Storage
Pending payment forms: Temporary in-progress payment form data that is cleared when the form is submitted or closed
We do not use tracking cookies, analytics cookies, advertising cookies, or any third-party cookies. We do not use Google Analytics, Google Tag Manager, or similar tracking services on the web application.
9. Data Security
We implement reasonable technical and organizational safeguards designed to protect your information. These measures include:
Password hashing: Passwords are hashed using bcrypt with 12 salt rounds; plain-text passwords are never stored
Encryption in transit: All communication between clients and the server is encrypted using TLS/HTTPS
Secure session storage: JWT tokens are stored in httpOnly cookies on the web and in hardware-backed secure storage on mobile devices
Role-based access control: Access to data and functionality is limited based on user role, branch membership, and module permissions
Branch isolation: Data is scoped by branch to prevent cross-tenant access
Upload validation: Uploaded files are validated for type, size, and security before storage
Encrypted push payloads: Push notification payloads are encrypted using AES-256-GCM with per-user cryptographic keys
Audit logging: Sensitive operations including data changes, payment events, and access events are logged for audit purposes
Rate limiting: API endpoints are protected by rate limiting to prevent abuse
Private object storage: Files are stored in private cloud storage with access controlled through signed URLs or direct service access
Account lockout: Accounts are temporarily locked after multiple failed login attempts
While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
10. Data Retention
We retain your information for as long as necessary to provide the platform and fulfill the purposes described in this policy. Specific retention practices include:
Student academic records:Retained for the duration required by educational regulations and the school's record-keeping policy, which may extend beyond the student's enrollment period
Financial records: Retained as required for accounting, audit, and legal compliance obligations
Chat messages: Retained while the associated chat room and user account are active; message read states and metadata are retained for operational purposes
Attendance records: Retained as part of academic and staff administration records
Uploaded files: Retained as long as the associated records (student profiles, chat messages, receipts) are retained
Database backups: Backups are retained for a limited period for disaster recovery purposes; backup data may persist after primary data changes
Audit logs: Retained for security and compliance purposes for a period consistent with operational needs
Account information: Retained while the account is active and for a reasonable period after account deactivation to support reactivation requests and audit requirements
Exact retention schedules are subject to the school organization's policies and applicable legal requirements.
11. Data Deletion
You may request deletion of your personal information by contacting the school administration. Please note:
Account deletion requests are processed by school administrators
Student academic and financial records may be subject to legal or regulatory retention requirements that prevent immediate deletion
Records that are part of a school's official academic or financial documentation may be retained in accordance with applicable laws and the school's record-keeping policy
Database backups may retain information for a limited period after primary data changes; backup data is subject to the backup retention cycle
Audit logs may be retained for security and compliance purposes
Uploaded files linked to retained records may also be retained
We do not promise immediate permanent deletion of all data, as certain records may be subject to legitimate retention requirements.
12. User Rights and Choices
Depending on applicable law, you may have the following rights regarding your personal information:
Access: Request a copy of the personal information we hold about you
Correction: Request correction of inaccurate or incomplete information
Deletion: Request deletion of your personal information, subject to applicable retention requirements
Restriction: Request restriction of processing in certain circumstances
Objection: Object to processing of your information for specific purposes
Withdrawal of consent: Where processing is based on consent, you may withdraw consent at any time
Notification preferences: Manage your notification preferences through your device settings
To exercise any of these rights, please contact the school administration through the platform or through the contact details provided in Section 17. We will respond to requests in accordance with applicable law.
13. Children's and Student Information
Student and Minor Information
This platform is used in an educational context that may involve the processing of information about students who are minors. The information described in this policy is collected and processed as part of school administration.
The platform may process personal information about students, including minors, as part of school enrollment and administration
Student accounts may be created by authorized school administrators as part of the enrollment process
Student information is accessed and processed by authorized school administrators and teachers as part of their educational and administrative responsibilities
Student access to the platform is controlled according to the platform's role and permission system
The platform is not designed to collect personal information from children beyond what is necessary for school administration
Parents or guardians may review their child's information by contacting the school administration through the platform.
14. International Data Processing
Your information may be processed in countries other than your own, as the third-party services we use (cloud hosting, push notifications, email, messaging) may operate data centers in various locations. These transfers are subject to the terms and security practices of the respective service providers.
We do not make representations regarding the data protection laws of specific jurisdictions. You should be aware that data protection laws may vary depending on where your information is processed.
15. Security Incidents
In the event of a security incident that affects your personal information, we will:
Investigate the incident promptly
Take appropriate steps to contain and remediate the issue
Notify affected users and relevant authorities where required by applicable law
We are committed to addressing security incidents responsibly and in accordance with applicable legal requirements.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, communicate the changes through the platform. Your continued use of the platform after the effective date of any updated policy constitutes your acknowledgment of the changes.
17. Contact
For privacy-related inquiries, data requests, or complaints, please contact: