All documents

Privacy Policy

What Desk Dollars collects, why it is used, who can see it, and how to exercise privacy choices.

Version:
2026-08-14-v1
Effective August 15, 2026
Effective August 15, 2026

This is the controlling English (United States) version. The en-US text controls if a convenience translation differs.

1. Who we are and our roles

Desk Dollars is operated by Andrew Hall, an individual/sole proprietor located in Florida, United States. Privacy questions and verified requests may be sent to [email protected]. No public street address is provided in this policy.

Andrew Hall/Desk Dollars is controller for teacher identity, account, product support, security, legal acceptance, and entitlement information. Where applicable to student education data, the school or educator is the controller and Desk Dollars is its processor or service provider. Sold through Link, LLC/Stripe has independent merchant-of-record and controller responsibilities for Managed Payments.

The en-US text controls; translations are convenience copies. Which law and role apply depends on the user, school, transaction, and jurisdiction.

2. Information we process

Teacher and account information can include teacher identity and login data, name, email, school, district, country, locale, password hash, verification and reset state, legal acceptance, subscription and entitlement state, support messages, security events, and owner audit history.

Student data can include student username, first name and last initial, display name, enrollments, account number, simulated balance, immutable transactions, jobs and payroll, rent, store orders and fulfillment, goals, pets, onboarding, class settings, and related activity. Educators may author class, job, store, image, reason, and settings content.

Technical information can include signed-session and preference cookies, request and coarse abuse-prevention signals, rate-limit state, Turnstile results and browser signals when enabled, email-delivery status, audit and error records, and privacy-focused self-hosted aggregate analytics. Analytics can include a page path, sanitized referrer, browser, device, country, session, and an allowlisted product event name. Desk Dollars does not add custom student, teacher, class, balance, transaction-content, search, or authored-text fields to analytics events, and does not use analytics cookies, cross-site advertising identifiers, or advertising profiles.

For Managed Payments, Desk Dollars receives limited subscription and transaction status, product, price, currency, tax, customer, refund, and paid-through identifiers needed to project access and reconcile support. Desk Dollars does not receive or store full card details. Stripe and Link collect payment details in their hosted experience.

3. Purpose, source, and legal basis

We receive teacher data from the teacher, school, product use, support, security tools, and payment status returned by Stripe/Link. Teachers and students supply or generate classroom data under educator direction. Technical records arise from devices, requests, configured vendors, and service operations.

We use data to create and authenticate accounts; deliver the classroom ledger, jobs, payroll, rent, store, goals, pets, cards, reports, and exports; process subscriptions; provide support; prevent abuse; preserve record integrity; improve aggregate reliability; meet legal duties; and respond to verified requests. Depending on the context, processing rests on contract, school instructions, legitimate security and operational interests, consent, or legal obligation.

4. Student data protections and visibility

Student data is used only to deliver, secure, support, and legally operate this educational service. It is not sold, rented, or traded; used for behavioral advertising; used to create unrelated commercial profiles; or disclosed for unrelated marketing. Logged-in student pages contain no third-party advertising or social widgets.

Teachers create student identities and control enrollment. Student pages show first name and last initial and the authenticated student's own information. There are no public student profiles, no classmate balances, no leaderboards, and no public rankings. Teachers with authorized class access and the service owner may access records only for classroom operations, support, security, privacy, and legal administration.

5. COPPA, FERPA, schools, and families

For US students under 13, a school may authorize collection in the educational context only for the school's educational purpose where COPPA permits that approach. The teacher or school must have authority and provide required notice. Desk Dollars provides direct notice, limits collection, supports review/deletion and stopping further collection, protects the information, and retains its operator duties; COPPA is not solely the school's responsibility.

Where FERPA applies and a school uses an applicable exception, Desk Dollars processes education records for the limited school-directed purpose, uses access controls, does not use or redisclose records for unauthorized purposes, and supports access, return, or deletion. Each school must evaluate its own FERPA exception, annual notice, approval, and contract requirements.

Parents and eligible students should normally start with the school or educator, who can review, export, correct, stop collection, archive, or request deletion. They may also email [email protected]; we verify identity and authority without revealing whether another person has an account.

6. Recipients and subprocessors

Data is shared only with authorized teachers/schools, the affected user, Andrew Hall for service operations, configured subprocessors that need it, Stripe/Link for Managed Payments, or recipients required for safety, legal process, rights protection, or a business transfer. A successor must receive data subject to this policy or give appropriate notice.

The public Subprocessor and Vendor List identifies enabled vendors, their service, data categories, purpose, known processing location, privacy link, and affected users. Required hosting, email, backup, monitoring, and support facts must be resolved before they process production data or before public signup relies on them.

7. Cookies, analytics, and anti-abuse

Signed session cookies keep users authenticated; locale and theme cookies remember choices. Required cookies are not advertising cookies. Process-local rate limits and security logs help detect misuse. Cloudflare Turnstile is used only when configured on public account forms and may process challenge and browser signals under Cloudflare's own privacy terms.

Production app pages use Desk Dollars-operated Umami for aggregate page and product-use analytics. Page query strings and hashes are excluded; dynamic account, class, student, run, token, and upload path segments and referrers are removed or templated by the privacy guard; and the configured script honors Do Not Track. Standard aggregate facts may include page path, sanitized referrer, browser, device, country, and session.

Allowlisted product event names include student_purchase_submitted, student_job_interest_submitted, reward_redeemed, pet_care_completed, and user_login_success; aggregate reports also cover account exports through allowlisted export event names. These names show that a kind of product action occurred, but Desk Dollars sends no custom student, teacher, class, balance, transaction-content, search, or authored-text data with them. Unexpected custom analytics data is dropped before sending.

8. Retention, recovery, and deletion

A verified teacher receives a 14-day trial. After trial or complimentary access ends, a 30-day recovery window applies; after paid access ends, a 90-day recovery window applies. Earlier verified deletion can begin immediately. Recovery keeps classroom data restricted while account export, privacy deletion, support, legal, and subscription recovery remain available.

Cleanup removes or anonymizes teacher and student identifiers, mutable class/order/goal/payroll/rent content covered by the cleanup service, and uploads while preserving immutable transaction and necessary accounting history under anonymized account and student identifiers. Because ledger history is not rewritten, teacher-authored transaction descriptions and student-visible reasons may remain. Educators should not put unnecessary personal information in ledger reasons. Pet names and historical pet or accounting records may also remain linked to anonymized identity where the current cleanup does not delete them. Retained raw authored text is not described as privacy-safe.

Trial-abuse fingerprints are keyed, non-reversible risk signals retained only to prevent repeat trial abuse. Backups age out under the configured rotation rather than being selectively rewritten, and restored data must be re-subjected to deletion controls. Stripe/Link independently retains transaction records under its own obligations.

See the Retention, Deletion, and Business Closure Policy for category-specific events, actions, backup treatment, and exceptions.

9. Security and incidents

Desk Dollars uses password hashing, signed sessions, server-side authorization, class scoping, immutable ledger history, same-origin checks, rate limits, security headers, production HTTPS requirements, environment secret handling, minimal logs, and configured backups. Security risk cannot be eliminated.

Suspected incidents are investigated and contained, evidence is preserved, affected vendors are coordinated, sessions or credentials are revoked where appropriate, and service is safely restored. Andrew Hall assesses notice duties by affected data, people, contracts, and jurisdiction; breach communication and timing are jurisdiction-specific rather than governed by one global deadline.

10. International transfers and regional rights

Data is primarily administered from the United States and may be processed in configured vendor locations. Any international transfer must use a lawful basis and appropriate safeguard when required. EU Standard Contractual Clauses, a UK transfer addendum or IDTA, a representative, DPIA, Brazilian mechanism, or registration is treated as active only after the applicable parties, annexes, and deployment facts are completed. If an affected region requires unresolved steps, signup for that region stays disabled.

Depending on scope and residence, California and other US law may provide notice, access, correction, deletion, portability, or limits on use; COPPA and FERPA may provide child or education-record protections. GDPR and UK GDPR may provide access, correction, erasure, restriction, objection, portability, withdrawal of consent, and regulator complaint rights. Canada privacy principles may provide informed consent, access, and correction. Brazil's LGPD may provide confirmation, access, correction, portability, deletion or anonymization, information about sharing, consent choices, and ANPD petition rights.

These descriptions do not claim that every law applies to every user. Non-waivable local rights remain available.

11. Requests, complaints, and policy changes

Email [email protected] with the account email, school/class context, request, and relationship to the user. Do not send a password. We may request proportionate verification and school or parent authority. Teachers can also use account export and verified privacy deletion tools while eligible.

You may complain to an applicable privacy or education authority. We will post updated versions and provide additional notice or seek renewed acceptance when a material change requires it. Questions about a translation are resolved against the controlling en-US version.

Privacy Policy | Desk Dollars | Desk Dollars