Privacy Policy

Your privacy matters to us

Last Updated: February 1, 2026

Introduction

Welcome to Klass Hero's Privacy Policy. At Klass Hero, we connect families with enriching afterschool programs, camps, and educational activities. We understand that when you entrust us with your family's information, you expect us to handle it responsibly and transparently.

This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data. We are committed to protecting your privacy and complying with data protection laws, including GDPR.

Last Updated: February 1, 2026

Information We Collect

To provide our platform services, we collect the following types of information:

Account Information:

  • Email address (for login and communication)
  • Password (encrypted and never stored in plain text using bcrypt)
  • Parent/guardian name

Child Information:

  • Child's first and last name (for enrollment and identification)
  • Date of birth (to match age-appropriate programs)
  • Emergency contact information
  • Optional: support needs and allergies — parent-controlled, shared with program providers only when you explicitly consent

Booking Information:

  • Program enrollments and preferences
  • Schedule selections
  • Communication history with instructors

Payment Information:

  • We accept credit card, direct transfer, and cash payments
  • For credit card payments, we use third-party payment processors
  • We do not store credit card numbers or banking details
  • We only retain transaction records for accounting purposes

Usage Information:

  • Pages visited on our platform
  • Device and browser information
  • Session data (essential for platform functionality)

How We Use Your Information

We use the information we collect for the following purposes:

  • Program Enrollment: To facilitate registration and enrollment in afterschool programs, camps, and activities
  • Communication: To send important updates about programs, bookings, and platform changes
  • Platform Improvement: To understand how our platform is used and improve functionality
  • Safety & Security: To verify instructor credentials and maintain secure facilities
  • Legal Compliance: To meet legal and regulatory requirements

Data Sharing

We take your privacy seriously and limit data sharing to what's necessary:

Program Providers:

Providers see enrolled children's names for program management. Optional safety information (support needs, allergies) is visible to providers only when a parent explicitly consents to share it. Behavioral notes written by providers about a child require parent approval before being displayed.

Payment Processors:

For credit card payments, we work with third-party payment processors who handle transaction processing securely. They only receive the information necessary to process payments.

What We Don't Do:

  • We never sell your personal data to third parties
  • We never share your data with advertisers or marketers
  • We never use your data for purposes other than those stated in this policy

Your Privacy Rights

Under GDPR and other data protection laws, you have the following rights:

Right to Access:

You can request a copy of all personal data we hold about you. Use the "Export My Data" feature in your Settings page to download your information as a JSON file.

Right to Deletion:

You can request deletion of your account at any time from your Settings page. When you delete your account, we immediately anonymize your email and name. Note that some information may be retained for legal or accounting purposes (such as completed booking records).

Right to Correction:

You can update your profile information at any time through the Settings page.

Right to Data Portability:

Your exported data is provided in a standard JSON format that can be used with other services.

Right to Object:

You can object to certain types of data processing. Contact us at [email protected] to discuss your concerns.

To exercise any of these rights: Visit your Settings page or contact us at [email protected]

Data Security

We take data security seriously and implement multiple layers of protection:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS
  • Password Security: Passwords are hashed using bcrypt and never stored in plain text
  • Access Controls: We limit access to personal data to authorized personnel only
  • Regular Updates: We keep our systems updated with the latest security patches
  • Monitoring: We actively monitor for security threats and suspicious activity

While we implement robust security measures, no system is 100% secure. We encourage you to use strong, unique passwords and contact us immediately if you suspect unauthorized access to your account.

Children's Privacy

Klass Hero is designed to help parents manage their children's activities. We prioritize protection for children's data, strict data minimization, role-based access, and explicit parental consent for any optional health-related notes shared solely for safety and participation purposes.

  • Parental Consent: Parents or legal guardians must create accounts and provide consent for their children's participation
  • Consent-Gated Sharing: Optional safety information (support needs, allergies) is shared with program providers only when a parent explicitly consents
  • Data Minimization: Only a child's name and date of birth are required; all health and safety notes are optional and parent-controlled
  • Behavioral Notes: Observations written by providers about a child require parent approval before they are displayed
  • COPPA Compliance: We comply with the Children's Online Privacy Protection Act (COPPA) for children under 13
  • Limited Collection: We only collect the minimum information necessary for program enrollment and safety
  • No Direct Marketing: We never market directly to children or collect information from them for marketing purposes

Important: Children should never create accounts or provide personal information without parental permission.

Cookies & Tracking

Klass Hero uses minimal tracking to provide essential functionality:

Essential Cookies:

We use session cookies that are necessary for authentication and platform functionality. These cookies do not track you across other websites and are automatically deleted when you close your browser or log out.

No Third-Party Tracking:

We do not currently use analytics, advertising, or other third-party tracking cookies. If this changes in the future, we will update this policy and request your consent before implementing such tracking.

Good News: Since we only use essential cookies, you don't need to worry about complex cookie consent or settings. Your privacy is protected by default.

Data Retention

We retain your personal data only as long as necessary:

  • Active Accounts: Information is retained while your account is active and you continue using our services
  • Deleted Accounts: When you delete your account, personal identifiers (email, name) are immediately anonymized
  • Booking Records: Transaction records may be retained for legal and accounting requirements (typically 7 years)
  • Anonymized Data: Anonymized data used for statistical purposes may be retained indefinitely as it cannot be linked back to you

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

How We Notify You:

  • We will update the "Last Updated" date at the top of this policy
  • For material changes, we will send an email notification to all active users
  • Continued use of Klass Hero after changes constitute acceptance of the updated policy

We encourage you to review this policy periodically to stay informed about how we protect your information.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Email: [email protected]

General Inquiries: [email protected]

You can also reach us through our Contact Page.

Questions About Privacy?

We're here to help with any privacy-related concerns.

Contact Us