Who this policy applies to
This policy applies to the School Track IT company website, hosted School Track IT platform, Android mobile app, Chromebook extension, Windows inventory agent and related download pages.
Where School Track IT is used by a school, trust, business or other customer, that organisation will normally decide why the data is used and who can access it. In those cases, the customer is normally the data controller and School Track IT acts as a service provider or data processor. This policy explains the platform behaviour, but customer agreements and each organisation's own privacy notices may also apply.
Information entered into School Track IT
Users and administrators may enter information such as staff names, usernames, school email addresses, rooms, departments, asset records, serial numbers, asset tags, assignments, PAT testing records, fire call point checks, fire door checks, first aid kit checks, training records, policy records, report data, support notes and audit comments.
The platform may also keep history showing when records were created, edited, moved, deleted, assigned, audited, marked as seen, marked as missing or included in a report.
Account, login and security data
School Track IT may process account details such as username, staff identifier, role, permissions, account status and login session information.
Security logs may include login time, logout time, session expiry, token identifier, device identifier, app version, IP address, browser or app user agent, and whether a login was successful or failed. These records help administrators investigate account use, revoke sessions and protect the system.
Android app data
The Android app connects to a School Track IT site using the API. It can show, search and update asset and site-check information according to the user's permissions.
The app may send or receive asset identifiers, scanned QR code values, room movements, asset assignments, audit status, PAT test results, site-check results, report requests, username, device identifier, app version, IP address and API session details.
If the user chooses Keep me signed in, the app stores an API session token using Android secure storage. The app does not need to store the user's password for this feature.
Chromebook extension data
The managed Chromebook extension is intended for authorised deployment through Google Admin. It may collect Chromebook inventory and usage check-in data including directory device ID, serial number, annotated asset ID, hostname, annotated location, current profile email, Google account ID, manufacturer, model, CPU, memory, storage basics, Chrome version, platform details, extension version, idle state, battery status, diagnostics, check-in time and approximate session duration.
The extension uses a managed site URL and enrolment token, then stores a per-device token and runtime status locally in extension storage.
Windows inventory agent data
The Windows inventory agent is intended for authorised deployment by the customer organisation. It may collect device identity and inventory data including device GUID, hostname, domain name, asset tag, BIOS serial, manufacturer, model, agent version, hardware details, operating system details, disk and volume details, installed software, last logged-in user, uptime, pending reboot status, CPU usage and memory usage.
The platform stores the submitted inventory payload and normalised reporting records so administrators can view inventory, software and device health information.
Website, cookies and similar technologies
The website and hosted platform may use cookies or similar storage for essential purposes such as logging in, maintaining a secure session, remembering security state and protecting against misuse. These are required for the service to work correctly.
Server logs may record IP address, browser user agent, requested pages, timestamps, error details and security events. If analytics or non-essential cookies are added later, the site should provide a clear choice before setting them.
Why we use the information
- To provide the School Track IT platform and related apps.
- To authenticate users, apply permissions and keep accounts secure.
- To track assets, rooms, assignments, compliance checks and inventory.
- To create reports, audit history and operational records.
- To diagnose faults, improve reliability and support customers.
- To meet legal, contractual, safeguarding, security or audit requirements where applicable.
Sharing information
Customer data is not sold. It is shared only where needed to operate School Track IT, support a customer, comply with law, protect the service, or work with approved hosting, infrastructure, email, monitoring, backup or support providers.
Customer administrators may export or report on data from their own School Track IT instance according to their permissions and responsibilities.
Where data is stored
School Track IT stores customer platform data, logs and backups within the United Kingdom. Support and administration access is controlled so that data is only accessed where needed to operate, secure or support the service.
If a customer chooses to export data, integrate with another service, deploy device management tools, or share reports outside School Track IT, that onward handling is controlled by the customer and may be covered by their own policies and supplier agreements.
Retention
Different data has different retention periods. Account sessions, API tokens, inventory snapshots, Chromebook check-ins, audit logs, reports, backups and security logs may be retained for the period configured by the customer, required by the service, or needed for audit and security purposes.
Where a customer asks for data deletion or contract termination, data is removed or returned according to the customer agreement, backup process and any legal or operational retention requirements.
Security
School Track IT uses role-based permissions, API bearer sessions, hashed server-side tokens where supported, session expiry, audit logging and administrator-controlled access. Customers should ensure that user accounts, mobile devices, managed extensions and Windows agents are deployed only to authorised users and devices.
Your rights and contact
People may have rights to access, correct, delete or restrict the use of their personal data. For data held in a customer School Track IT site, requests should normally be raised with the school or organisation that controls that site.
For questions about the School Track IT company website or this policy, contact School Track IT using the contact details provided on the company website.