← Back to Home

Privacy Policy

Effective Date: September 5, 2026Last Updated: September 22, 2026

1. Introduction

MCS-App is a school management and communication platform that provides tools for managing student enrollment, attendance, academic records, fees and payments, staff payroll, chat and messaging, file sharing, and related educational and administrative functions. The platform is available through a web application and a mobile application for iOS and Android.

This Privacy Policy applies to all users of the platform, including school administrators and management staff, teachers, students, and other authorized personnel. By accessing or using the platform, you acknowledge that you have read and understood this Privacy Policy.

This Privacy Policy describes how we collect, use, store, protect, and share personal and educational information. It should be read alongside our Terms of Use, which govern your use of the platform.

The platform is operated by [LEGAL ENTITY NAME]. References to "we", "us", or "our" in this policy refer to the entity responsible for processing your information.


2. Information We Collect

We collect different categories of information depending on your role and how you use the platform. The sections below describe each category.

2.1 Account and Identity Information

When an account is created for you or when you register, we collect:

  • Full name
  • Username and email address (where provided)
  • Phone number (where provided)
  • Gender and date of birth (where provided)
  • Physical address (where provided)
  • Role (administrator, management, teacher, student, staff member)
  • Branch or school association
  • Profile photo (if uploaded)
  • Login credentials (passwords are stored in hashed form using bcrypt; plain-text passwords are never stored)
  • Account status (active, inactive, suspended)
  • Login timestamps and last-seen activity

Account creation is managed by authorized school administrators. You are responsible for ensuring that the information associated with your account is accurate and current.

2.2 Student Information

Student information is entered and managed by authorized school personnel as part of school administration. This may include:

  • Student name, admission number, and enrollment records
  • Class or group assignment and academic year placement
  • Date of birth, gender, religion, nationality, blood group
  • National identity number (B-Form / CNIC)
  • Contact information (phone, email, WhatsApp)
  • Home address, city, postal code, country
  • Previous school and transfer certificate details
  • Family association and parent/guardian linkage
  • Emergency contacts and their phone numbers
  • Health records (blood group, chronic conditions, allergies, disability, medical notes, doctor name and phone)
  • Attendance records (daily status: present, absent, late, leave, holiday, function)
  • Academic results, marks, examination records, and report cards
  • Fee records, payment history, receipts, and concessions
  • Profile photo and uploaded documents
  • Class movements and transfer records
  • Credential lifecycle tracking (generation, delivery, first login)

Students have individual accounts on the platform. There is no separate parent portal or account switcher; each student logs in independently to view their own permitted information.

2.3 Teacher and Staff Information

Information about teachers, staff, and management profiles is collected as part of employment and branch membership:

  • Employee ID, job title or work role, department
  • Educational qualifications, specialization, work experience
  • Joining date and employment history
  • Salary information (where applicable)
  • Phone number, emergency contact, home address
  • Date of birth, gender, blood group, father's name, national ID number
  • Medical information (severe disease, if provided)
  • Portal access level and module permissions
  • Branch membership and role assignment
  • Attendance records
  • Payroll records and salary payment history
  • Profile photo and uploaded documents

2.4 Financial and Payment Information

The platform records financial information related to school fees and payments. We do not store raw credit card numbers, bank account details, or payment credentials. Financial data includes:

  • Fee structures, categories, and amounts
  • Student fee records (monthly, term, annual, one-time)
  • Payment amounts, dates, and methods (cash, cheque, bank transfer)
  • Receipt numbers and reference identifiers (cheque numbers, transaction IDs)
  • Payment allocation records and balance history
  • Concessions, late fees, and extra charges
  • Family payment records and multi-student allocation
  • Outgoing payment vouchers (payroll, utilities)
  • Payroll records including salary amounts and attendance-derived pay
  • Financial audit logs (creation, reversal, reprint, download events)

Payment processing for school fees is handled through approved school channels. The platform records payment information but is not itself a payment processor and does not handle credit card or bank transactions directly.

2.5 Academic Information

  • Subjects, classes, and group assignments
  • Examination sessions, types, and schedules
  • Marks entries (per student, per subject, per exam)
  • Grade scales and grade bands
  • Subject results and overall percentages
  • Report cards (draft and published status)
  • Class ranks and academic performance data

2.6 Attendance Information

  • Student daily attendance (present, absent, late, leave, holiday, function)
  • Teacher attendance records
  • Staff attendance records
  • Date, time, and note associated with each attendance entry
  • Who marked the attendance

2.7 Communication Information

The platform provides chat and messaging features. Information collected in connection with communications includes:

  • Chat messages (text content, images, videos, audio, voice notes, documents)
  • Announcements and school-wide notices
  • Direct messages between authorized users
  • Group and class communications
  • System-generated messages (attendance alerts, payment notifications, result notifications)
  • Message metadata (sender, recipient, room, timestamp, type)
  • Attachment file records and media metadata
  • Read receipts and message delivery status

2.8 Uploaded Files and Media

Users may upload files through the platform, including profile photos, chat attachments, documents, receipts, voice notes, and videos. For each uploaded file, we store:

  • Original filename and file type (MIME type)
  • File size and dimensions (for images)
  • Storage location and access path
  • Upload status and processing status
  • Entity association (which student, teacher, or chat message the file is linked to)
  • Upload session data (for resumable uploads: byte offset, checksum, state)

Uploaded files are stored in cloud object storage (Cloudflare R2) or local filesystem depending on the deployment configuration. Files are subject to security validation before storage. Dangerous file types are blocked or reclassified to prevent security risks.

2.9 Device and Technical Information

We collect limited technical information necessary to operate the platform:

  • Device type, operating system, and application version (mobile app)
  • IP address and access timestamps (for authentication and security logging)
  • Push notification device tokens (for mobile notifications)
  • Session and authentication tokens
  • Error logs and diagnostic information (for debugging and reliability)

We do not use third-party analytics services such as Google Analytics, Mixpanel, or similar tracking tools. We do not place tracking cookies or use behavioral analytics.

2.10 Local and Offline Data (Mobile App)

The mobile application may temporarily store certain information locally on your device to support offline functionality. This includes:

  • Cached dashboard and bootstrap data (expires after 24 hours)
  • Recently viewed chat messages (up to 200 per room, retained for 30 days)
  • Pending outgoing messages (queued for sending when connectivity is restored)
  • Upload tasks in progress (for resumable uploads)
  • Active branch and academic year selection

Local cached data is associated with your user account. When you log out, all user-specific local data is cleared. If the application is closed unexpectedly, cached data may remain temporarily until the next login or cache expiry. You should protect access to your device to prevent unauthorized viewing of locally stored information.


3. How We Use Information

We use the information we collect for the following purposes:

  • Providing the platform: Operating, maintaining, and delivering the features and functionality of the platform
  • Authentication and access: Verifying your identity, managing your account, and controlling access based on your role and permissions
  • School administration: Managing student enrollment, class assignments, attendance tracking, academic records, and staff management
  • Financial management: Recording fee structures, processing payments, generating receipts, and maintaining financial records
  • Communication: Facilitating chat messaging, announcements, and direct messages between authorized users
  • Notifications: Sending attendance alerts, payment notifications, result notifications, payroll alerts, and school announcements
  • File management: Storing, processing, and delivering uploaded files and media to authorized recipients
  • Offline functionality: Caching data locally on mobile devices to support use when internet connectivity is unavailable
  • Security and fraud prevention: Detecting unauthorized access, preventing misuse, and maintaining audit trails
  • Debugging and reliability: Investigating errors, improving performance, and ensuring system stability
  • Backup and recovery: Maintaining database backups for disaster recovery and data integrity
  • Legal compliance: Meeting regulatory, record-keeping, and reporting obligations as required by applicable law


5. How Information Is Shared

We do not sell, rent, or trade personal information. Information may be shared in the following circumstances:

School and Organization Administrators

Authorized school personnel may access information necessary for their responsibilities. Branch administrators and management staff can view and manage records within their branch according to their assigned permissions.

Teachers and Academic Staff

Teachers may access information appropriate to their assigned classes, groups, and subjects, including student attendance, academic results, and communication channels.

Students

Students can access their own permitted information, including their academic records, attendance, fee status, and results, through their individual accounts.

Service Providers

We share information with third-party service providers who assist in operating the platform. These providers process data on our behalf under contractual obligations. Current service providers include:

  • Cloudflare R2 — cloud object storage for files and database backups
  • Firebase (Google) — push notification delivery via Firebase Cloud Messaging
  • Upstash — Redis-based rate limiting and session management
  • Resend — transactional email delivery
  • Sentry — error monitoring and diagnostics

Legal Requirements

We may disclose information when required by applicable law, court order, lawful government request, or to protect the rights, safety, or property of the platform, its users, or the public.


6. Third-Party Services

The platform integrates with third-party services that may independently collect or process information. We encourage you to review each provider's own privacy policy for details on their data practices.

ProviderPurposeInformation Involved
CloudflareCloud object storage (files, backups)Uploaded files, database backup files
Google FirebasePush notification delivery (FCM)Device tokens, notification content (encrypted)
UpstashRedis rate limiting, JWT blacklistRate limit counters, token identifiers
ResendTransactional email (admin invitations)Email address, invitation content
SentryError monitoring (optional)Server-side error reports, HTTP metadata

7. Notifications

The platform may send you notifications related to your activity on the platform. These include:

  • Attendance notifications:Alerts when a student's attendance status is recorded (absent, late, leave)
  • Payment notifications: Alerts when fees are recorded, partially paid, or when payments are processed
  • Result notifications: Alerts when marks are entered or report cards are published
  • Teacher attendance and payroll notifications: Alerts related to teacher attendance and salary payments
  • Chat messages: New messages in chat rooms and direct messages
  • Announcements: School-wide or class-specific notices

Notifications may be delivered through the platform's internal notification system, push notifications on mobile devices, or both. Push notification content may contain limited information necessary to identify the event. You can disable push notifications through your device settings, though this may limit your ability to receive timely updates.


8. Cookies and Similar Technologies

The web application uses the following storage technologies:

Essential Cookies

  • Session cookie (token): An httpOnly cookie used to maintain your authenticated session. This cookie is essential for the platform to function and is set when you log in. It expires after 7 days. In production, this cookie is marked as Secure (HTTPS only).

Local Storage

  • JWT token: A fallback copy of your session token
  • Active branch and academic year: Your current branch and year selection for the session

Session Storage

  • Pending payment forms: Temporary in-progress payment form data that is cleared when the form is submitted or closed

We do not use tracking cookies, analytics cookies, advertising cookies, or any third-party cookies. We do not use Google Analytics, Google Tag Manager, or similar tracking services on the web application.


9. Data Security

We implement reasonable technical and organizational safeguards designed to protect your information. These measures include:

  • Password hashing: Passwords are hashed using bcrypt with 12 salt rounds; plain-text passwords are never stored
  • Encryption in transit: All communication between clients and the server is encrypted using TLS/HTTPS
  • Secure session storage: JWT tokens are stored in httpOnly cookies on the web and in hardware-backed secure storage on mobile devices
  • Role-based access control: Access to data and functionality is limited based on user role, branch membership, and module permissions
  • Branch isolation: Data is scoped by branch to prevent cross-tenant access
  • Upload validation: Uploaded files are validated for type, size, and security before storage
  • Encrypted push payloads: Push notification payloads are encrypted using AES-256-GCM with per-user cryptographic keys
  • Audit logging: Sensitive operations including data changes, payment events, and access events are logged for audit purposes
  • Rate limiting: API endpoints are protected by rate limiting to prevent abuse
  • Private object storage: Files are stored in private cloud storage with access controlled through signed URLs or direct service access
  • Account lockout: Accounts are temporarily locked after multiple failed login attempts

While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security.


10. Data Retention

We retain your information for as long as necessary to provide the platform and fulfill the purposes described in this policy. Specific retention practices include:

  • Student academic records:Retained for the duration required by educational regulations and the school's record-keeping policy, which may extend beyond the student's enrollment period
  • Financial records: Retained as required for accounting, audit, and legal compliance obligations
  • Chat messages: Retained while the associated chat room and user account are active; message read states and metadata are retained for operational purposes
  • Attendance records: Retained as part of academic and staff administration records
  • Uploaded files: Retained as long as the associated records (student profiles, chat messages, receipts) are retained
  • Database backups: Backups are retained for a limited period for disaster recovery purposes; backup data may persist after primary data changes
  • Audit logs: Retained for security and compliance purposes for a period consistent with operational needs
  • Account information: Retained while the account is active and for a reasonable period after account deactivation to support reactivation requests and audit requirements

Exact retention schedules are subject to the school organization's policies and applicable legal requirements.


11. Data Deletion

You may request deletion of your personal information by contacting the school administration. Please note:

  • Account deletion requests are processed by school administrators
  • Student academic and financial records may be subject to legal or regulatory retention requirements that prevent immediate deletion
  • Records that are part of a school's official academic or financial documentation may be retained in accordance with applicable laws and the school's record-keeping policy
  • Database backups may retain information for a limited period after primary data changes; backup data is subject to the backup retention cycle
  • Audit logs may be retained for security and compliance purposes
  • Uploaded files linked to retained records may also be retained

We do not promise immediate permanent deletion of all data, as certain records may be subject to legitimate retention requirements.


12. User Rights and Choices

Depending on applicable law, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information, subject to applicable retention requirements
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing of your information for specific purposes
  • Withdrawal of consent: Where processing is based on consent, you may withdraw consent at any time
  • Notification preferences: Manage your notification preferences through your device settings

To exercise any of these rights, please contact the school administration through the platform or through the contact details provided in Section 17. We will respond to requests in accordance with applicable law.


13. Children's and Student Information

Student and Minor Information

This platform is used in an educational context that may involve the processing of information about students who are minors. The information described in this policy is collected and processed as part of school administration.

  • The platform may process personal information about students, including minors, as part of school enrollment and administration
  • Student accounts may be created by authorized school administrators as part of the enrollment process
  • Student information is accessed and processed by authorized school administrators and teachers as part of their educational and administrative responsibilities
  • Student access to the platform is controlled according to the platform's role and permission system
  • The platform is not designed to collect personal information from children beyond what is necessary for school administration

Parents or guardians may review their child's information by contacting the school administration through the platform.


14. International Data Processing

Your information may be processed in countries other than your own, as the third-party services we use (cloud hosting, push notifications, email, messaging) may operate data centers in various locations. These transfers are subject to the terms and security practices of the respective service providers.

We do not make representations regarding the data protection laws of specific jurisdictions. You should be aware that data protection laws may vary depending on where your information is processed.


15. Security Incidents

In the event of a security incident that affects your personal information, we will:

  • Investigate the incident promptly
  • Take appropriate steps to contain and remediate the issue
  • Notify affected users and relevant authorities where required by applicable law

We are committed to addressing security incidents responsibly and in accordance with applicable legal requirements.


16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, communicate the changes through the platform. Your continued use of the platform after the effective date of any updated policy constitutes your acknowledgment of the changes.


17. Contact

For privacy-related inquiries, data requests, or complaints, please contact:

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[PRIVACY CONTACT EMAIL]

You may also contact the school administration through the platform's built-in communication features.