Privacy Policy

Privacy Policy

Effective: 2026-05-13 · Last updated: 2026-05-21

Campus Care is school operations software built for K-12 districts. This policy explains what data we collect from the people who use the app, why we collect it, and what protections we put around it. If you are signing up on behalf of a district, this policy is the agreement between Campus Care and your organization regarding data we process on your behalf.

1. Who runs Campus Care

Campus Care is operated by NexGen AI Automations. References to “we,” “us,” and “our” mean NexGen AI Automations. References to “you” mean either the district that contracts with us or the individual staff member using the app.

Contact: nexgen.aiautomations@gmail.com

2. What we collect

We collect only what is necessary to run the operations features you use.

Account information

  • Name, email address, hashed password (bcrypt, never stored in plaintext)
  • Role assignment (Head Admin, Department Head, Accountant, Teacher, Employee)
  • Organization (district) you belong to

Operational data your district enters

  • Buildings, rooms, equipment, and vehicles
  • Work orders, inspection records, recurring maintenance schedules
  • Budget categories, planned and actual spending; 10-year capital plan entries
  • Time clock events, break records, PTO entries, timesheet approvals
  • Vehicle trip logs, mileage, and state-mandated compliance records (SISBO)
  • Teacher work-order requests and end-of-year capital requests
  • In-app messages (direct, group, and head-admin broadcasts) sent between staff in your district
  • Notifications generated by the app (work-order assignments, message alerts, request status changes)
  • UI preferences saved on each user’s device (accent color, compact layout, last department) — stored in browser localStorage, not on our servers

Limited student information

The transportation trip log records the count of students on a route for state compliance reporting. We do not collect student names, ages, demographics, grades, discipline records, or any other student-identifying data. Campus Care is not designed as a student information system and should not be used to store student PII.

Automatically collected

  • Session cookies (HTTP-only, secure) for authentication. Sessions persist for up to 30 days of inactivity.
  • Password reset tokens (single-use, expire in 60 minutes) when a user clicks “Forgot password.”
  • Server-side audit logs of sensitive actions (role changes, budget edits, etc.)
  • Standard web access logs (IP, user-agent, timestamps) for security investigation

Progressive Web App (PWA) install

Campus Care can be installed as a home-screen app on phones, tablets, and desktops. Installing the PWA does not give us any extra data — it just packages the same web app for offline-friendly use. A small service worker caches static assets and the last-viewed pages on the user's device to speed up load times when network is poor.

3. Why we collect it

  • Provide the service — the data is the product. Without it, the planner is empty.
  • Authenticate users and enforce role-based access control.
  • Send transactional emails (invitations, password resets, work-order updates, dept-lead assignments, request status changes).
  • Route messages and notifications within your district’s organization.
  • Bill your district via Stripe based on the staff-count tier you select (currently four tiers from $200/mo for districts up to 40 staff through $899/mo for 151–300 staff, with a $50/mo Early School Access discount available on every tier for the first 12 months; an Enterprise tier is available for 300+ staff). Head Admin and Accountant accounts are unlimited at no extra cost regardless of tier.
  • Maintain audit trail for actions a school board or auditor may need to review.

We do not sell, rent, or trade personal information. We do not use your data to train machine learning models. We do not display ads.

4. FERPA & student data

Campus Care does not function as an “educational record” system under FERPA. The only student-related data we touch is aggregate ridership counts for transportation reporting. If your district configures Campus Care in a way that records additional student information (e.g. in a free-text notes field), you, the district, remain the data controller and are responsible for FERPA compliance. We recommend against entering student PII into free-text fields.

5. Where data lives

  • Database — PostgreSQL hosted on Neon (US region).
  • File uploads (photos on requests, attachments) — Vercel Blob storage.
  • Application hosting — Vercel (US edge + serverless).
  • Email — transactional only, via Resend.
  • Payments — processed by Stripe; we never see your full card number.

These sub-processors have their own privacy commitments. We rely on their certifications (SOC 2, PCI DSS where applicable) and contractual data-processing terms.

6. How we protect it

  • TLS in transit for every request
  • Encryption at rest at the database layer
  • Passwords hashed with bcrypt (cost 12)
  • Role-based access control enforced server-side on every mutation
  • Multi-tenant scoping: every query filters by organizationId
  • Audit log entries for sensitive actions

No system is perfect. If you discover a vulnerability, please email nexgen.aiautomations@gmail.com before disclosing publicly.

7. How long we keep it

  • Active districts: data is retained for as long as your subscription is active.
  • Cancelled districts: data is retained for 90 days after cancellation, then deleted. A district admin can request earlier deletion.
  • Audit log records: kept for two years from creation.
  • Email transactional logs at Resend: 14 days.

8. Your rights

A district admin can export or delete their organization's data on request. Individual users can request their own account data via their district admin or by emailing us directly. We respond to verified requests within 30 days.

Residents of jurisdictions with stronger statutory rights (CCPA, GDPR, etc.) have those rights honored regardless of district contract terms.

9. Children

Campus Care is a tool for school staff. Accounts are not created for children. The teacher-request portal can be used by certified teachers but not by students. Do not create accounts for users under 13.

10. Changes

If we materially change this policy, district admins will receive an email notification and have 30 days to review before the new terms take effect.

11. Contact

Questions about this policy? Email nexgen.aiautomations@gmail.com.


See also: Terms of Service