Privacy program version: 2026-07-25
Retention Schedule
The current operational retention and deletion schedule for student and related records.
| Record category | Retention and deletion rule |
|---|---|
| Student identity, enrollment, household, guardian, profile, lunch card, and authorized account access | While the documented school-authorized purpose remains active; after verified termination or deletion instruction, review begins within 30 days and approved deletion or anonymization completes within 90 days unless a contract, legal hold, or nonwaivable duty requires otherwise. |
| Cafeteria, wallet, payment, refund, dispute, and reconciliation records | While operationally needed; qualifying financial, accounting, legal, and reconciliation evidence may be retained for up to seven years, with child-identifying fields removed sooner where feasible. |
| Invitations and terminated authentication sessions | Approximately 30 days after expiration or termination. |
| Family access requests and unanswered guardian consent requests | Family access requests: approximately 90 days. Unanswered consent requests expire after seven days and are deleted 90 days after expiry when no evidence or legal hold applies. |
| Privacy exports, archived notifications, and sanitized payment-webhook summaries | Privacy exports: seven days; archived notifications: approximately 180 days; sanitized payment webhook summaries: approximately 400 days. |
| Authorization, consent, notice, security-audit, and legal evidence | Up to seven years under manual legal review, subject to a shorter school agreement, approved deletion decision, or longer legal hold. |
Browser-storage inventory
Authentication cookies
Supabase session identifiers and refresh material. Keep the user signed in and rotate authenticated sessions. Provider-configured session lifetime or earlier sign-out/expiration. Cleared by: Sign-out, session expiration, or clearing site data.
Active-school cookie
The current school identifier. Scope authenticated requests to the selected school. Until replaced, expired, or cleared. Cleared by: Cleared on sign-out or site-data clearing; replaced on school switch.
Language, timezone, and functional preferences
Locale, timezone, and display preferences. Present localized dates, language, and interface settings. Until changed or site data is cleared. Cleared by: Preference reset or clearing site data.
Guided-tour, checklist, and onboarding state
Minimized-checklist markers and a resumable school-onboarding draft; the draft may include administrator and school setup fields but excludes passwords. Resume setup and avoid repeating completed guidance. Until completion/expiry cleanup or site-data clearing. Cleared by: Completion, expiry cleanup, school switch/sign-out where applicable, or clearing site data.
Short-lived read and authorization-context caches
Audit-view results and minimized staff, dashboard, and family read-context tokens. Avoid duplicate authorized requests and support reliable reads. Current tab with bounded expirations, generally five minutes or less. Cleared by: Physical removal on expiry/read, school switch, tab close, sign-out, or clearing site data.
Cafeteria catalog session cache
School menus, menu slots, item categories, items, prices, styles, and update timestamps. Avoid an immediate duplicate catalog request. Current tab for approximately two minutes. Cleared by: Physical removal on expiry/read, school switch, tab close, sign-out, or clearing site data.
Country and state option cache
Public country and state names and codes; no student records. Populate address-option lists without repeated requests. Current tab for up to 24 hours. Cleared by: Physical removal on expiry/read, tab close, or clearing site data.
Point-of-sale and line state
Selected serving line and in-progress operational state. Keep the authorized POS workflow on the selected line. Current tab/session until reset, sign-out, or configured expiry. Cleared by: Workflow reset, school switch, sign-out, tab close, or clearing site data.
Authentication and checkout handoff flags
A password-recovery readiness flag and a safe local subscription-completion path; no password or payment credential. Complete the requested recovery or subscription workflow. Current tab; subscription handoff expires after approximately 30 minutes. Cleared by: Workflow completion, expiry/read cleanup, sign-out, tab close, or clearing site data.
Operational analytics deduplication flag
A one-bit marker that an approved event was sent in the tab; no student or event property is stored in the marker. Avoid sending the same approved operational metric twice in one tab. Current tab only. Cleared by: Sign-out, tab close, or clearing site data.
Stripe component storage
Provider-created anti-fraud, session, and payment-interface values. Securely present and operate Stripe payment components. Controlled by Stripe and browser/provider settings. Cleared by: Provider expiry or clearing browser/site data.