Student Data Privacy



Schools and districts evaluating a scheduling vendor — often as part of a FERPA or state student-privacy review — ask the same set of questions. This page answers them factually. It describes how pickAtime handles the data a district imports, so that your team can assess it against your own obligations.

See also our Data Security and Privacy statement for infrastructure, encryption, and breach-notification detail.

What data pickAtime receives

For a typical K-12 parent teacher conference setup, a district imports:
  • Student name
  • Parent or guardian name and email address
  • Teacher, class, or grade level
  • Student ID number, commonly used as the matching key on import
The district decides what to import. pickAtime does not request, require, or collect student records beyond what the customer chooses to provide, and uses that data solely for the events the customer has set up.

Where it is stored

All customer data is stored in the United States, in a Tier II/III dedicated data center monitored 24/7 with card-key access control. This applies to every customer, including those located outside the US. No customer data is stored or processed outside the United States.

Data is encrypted in transit using TLS and at rest using AES-256. Backups are taken daily and kept both locally and in cloud storage. Backup copies are encrypted before they leave our systems, and encrypted again by the storage provider.

Who can access it

  • Preapproved individuals on the customer's own team, each with a unique username and password. Access levels are configurable, and every login attempt is logged.
  • pickAtime technical and support staff, only where needed to resolve a technical problem or provide support. Access is limited to the small number of employees who provide that support.
Customer data is never sold. It is not shared with any third party. pickAtime does not permit behaviorally targeted advertising on any customer's scheduling site.

Third parties

No third party processes student or parent data. pickAtime uses an external payment processor for billing schools and districts; student and parent records are never sent to it.

Where a district uses an integration such as Clever, ClassLink, Blackbaud, Finalsite, or MySchoolBucks, data flows from that system into pickAtime at the district's direction. Those are sources the district already controls, not onward recipients of pickAtime data.

How long it is kept

pickAtime applies published retention limits:
  • Cancelled appointments: deleted after 2 years
  • Confirmed appointments: retained up to 5 years
  • Appointment logs: retained 2 years
  • Appointment slots and events: removed after 5 years
  • Contact records: eligible for deletion after 5 years with no appointment in the last 3
A customer can delete their information at any time, without waiting for these limits.

Backups that cannot be tampered with

pickAtime's cloud backups are retention-locked. Once written, a backup cannot be altered or deleted until it expires - not by a mistake on our side, and not by pickAtime itself. This is deliberate. It means a backup is still there and still intact after a security or cyber incident - ransomware, a virus, or similar - as well as after a hardware failure or a mistake, which is what makes a complete recovery possible rather than a partial one.

One consequence is worth knowing for a privacy review. Deleting your data removes it from everything in use promptly; the encrypted backup copies then age out on their own within 60 days. Nothing stays in service, and the backup window simply has to close.

Ending your contract

On request, pickAtime deletes a departing customer's data. If no request is made, the retention limits above apply and the data ages out on that schedule.

Getting your data back

Administrators can export their own appointment and contact data directly from their account, without needing to contact pickAtime.

Who uses the scheduler

In K-12 parent teacher conference scheduling, the people booking are parents, guardians, and school staff. Other pickAtime products are used in settings where the individual books for themselves, such as higher education advising and office hours.

Because a customer sets up its own schedules and decides who to invite, pickAtime does not determine, and is not in a position to know, the age of every person who books an appointment. Determining whether a given use is appropriate for the audience a customer invites, and what consent that requires, is the customer's decision.

Data privacy agreements

Many districts require a vendor to sign their own data privacy agreement or state-specific rider. pickAtime reviews and executes district agreements; please send yours to info@pickatime.com and we will respond.

Security incidents

If pickAtime determines a security breach has occurred, every customer whose data was affected is notified in a timely manner, with the scope of the breach as understood at that time and further updates as more is learned. pickAtime cooperates fully with law enforcement, and will delay notification only if requested to do so by them.

Suitability and agreements

The descriptions on this page are general and provided for informational purposes. Customers are ultimately responsible for determining whether pickAtime meets the specific requirements of their intended use, including any obligations under FERPA, state student privacy law, or district policy.

pickAtime makes no representation, warranty, or claim of suitability for any particular purpose except as expressly set out in the written agreement between pickAtime and the customer. Nothing on this page forms part of, is incorporated by reference into, or modifies that agreement. Where this page and a customer agreement differ, the agreement controls.

Questions about any of the above: contact us.