Privacy Policy
Last updated: September 2026
ShuleTop ("we," "our," "the platform") is a school management and finance system used by schools in Kenya to manage students, staff, exams, attendance, timetables, fee collection, and communication with parents and guardians. This policy explains what information ShuleTop processes, why, and how a school can control or request deletion of it.
Information we collect
- School staff accounts: name, email address, phone number, role, and password (stored securely, never in plain text).
- Student records: name, admission number, class/stream, guardian contact details, attendance, exam results and grades, and fee balances โ entered by school staff as part of normal school administration.
- Guardian/parent contact details: phone numbers used to deliver SMS notifications (e.g. exam results, fee reminders) that the school chooses to send.
- Financial records: fee structures, payments received, and expense records for the school's own bookkeeping.
- Usage data: basic technical logs (e.g. login times, error logs) used to keep the platform secure and reliable.
How information is used
- To operate the core features of ShuleTop: student records, grading, attendance, timetables, fee tracking, and reporting.
- To deliver SMS messages the school itself initiates (e.g. results, fee reminders) to the phone numbers the school has on file for guardians.
- To maintain the security, integrity, and reliability of the platform.
We do not sell student, staff, or guardian data, and we do not use it for advertising.
Who we share information with
- Supabase โ our database and authentication infrastructure provider, which stores platform data securely on our behalf.
- Africa's Talking โ our SMS gateway provider, used only to deliver the text messages a school sends through the platform (e.g. results and fee reminders) to the phone numbers the school provides.
- Netlify โ our website hosting provider.
We do not share personal information with any other third party except where required by Kenyan law.
Data about children
ShuleTop stores academic and administrative records about students, some of whom are minors. This data is entered and controlled entirely by the student's own school, which acts as the data controller for its students' records. ShuleTop (and the ShuleTop app) is a tool used by adult school staff โ it is not directed at, marketed to, or intended for direct use by children.
Data security
Passwords are stored using industry-standard hashing (never in plain text). Data in transit is encrypted (HTTPS/TLS). Access to student and financial records is restricted by role โ for example, a teacher cannot see another class's fee records.
Data retention
We retain school data for as long as a school's account is active, so the school can continue to access its own historical records (e.g. past exam results). A school may request deletion of its account and associated data at any time โ see below.
Requesting account or data deletion
A school administrator can request deletion of their school's ShuleTop account and all associated data (staff accounts, student records, and financial records) at any time, either:
- In the app: open the user menu (top-right avatar) โ "Delete Account / Data", which explains the process and lets you submit a request.
- By email or web form: visit our Account & Data Deletion page for instructions.
We process deletion requests within 30 days and will confirm once complete.
Your rights
Depending on your role and applicable law (including Kenya's Data Protection Act, 2019), you may have the right to access, correct, or request deletion of personal data ShuleTop holds about you. School staff should contact their school's administrator; school administrators can contact us directly using the details below.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact us
Questions about this policy or your data: privacy@shuletop.com