📘 1. Introduction
Welcome to School App by Toyar (“the App”, “we”, “our”, or “us”). The App is operated by Toyar Pvt Ltd, a company registered in Sri Lanka.
School App by Toyar is a dedicated communication and management platform designed to strengthen the connection between schools, parents, and students. It facilitates instant notifications, attendance tracking, student growth monitoring, and seamless day-to-day school communication.
This Privacy Policy explains how we collect, use, protect, and share information when you use our App. By using the App, you agree to the practices described in this policy. We encourage you to read it carefully.
📋 2. Information We Collect
We collect information necessary to provide you with a safe and effective school communication experience.
2.1 Account Information
- Full name of parent, teacher, or school administrator
- Email address and phone number
- Role within the school (parent, teacher, administrator)
- School name and class/grade affiliation
- Profile photo (optional)
2.2 Student Data
- Student name, grade, and class section
- Attendance records (present, absent, late)
- Academic performance and growth tracking data
- Homework and assignment status
- Behavioral notes shared by teachers (when applicable)
2.3 Device & Technical Data
- Device type, operating system version, and unique device identifiers
- Push notification tokens (for delivering alerts)
- App version and crash/error logs
- IP address and general location (country/region level only)
- App usage analytics (screens visited, feature interactions)
2.4 Communications Data
- Messages sent between parents and teachers through the in-app messaging feature
- Announcements and notices created by school administrators
⚙️ 3. How We Use Your Data
We use the information we collect solely to operate and improve the App for the benefit of schools, parents, and students.
- Facilitate real-time communication between schools and families
- Send instant push notifications for attendance, announcements, and important updates
- Track and display student attendance and academic progress
- Enable teachers and administrators to manage class records efficiently
- Provide account authentication and maintain account security
- Diagnose technical issues and improve app performance
- Comply with applicable legal obligations
🔗 4. Data Sharing & Third Parties
We do not share your personal data with third parties for their own marketing or commercial purposes. We may share data only in the following limited circumstances:
- School Administrators: Student and parent data is shared within the school's designated account as required for school operations.
- Service Providers: We use trusted third-party providers (e.g., cloud hosting, push notification services) who process data strictly on our behalf under confidentiality agreements.
- Legal Requirements: We may disclose data if required by law, court order, or governmental authority.
- Safety: We may share data to protect the safety of students or others when required.
🧒 5. Children's Privacy (COPPA & GDPR)
School App by Toyar is designed for use within school environments and may involve the data of students who are under the age of 13 (or under 16 in certain jurisdictions). We take children's privacy extremely seriously.
- We rely on the school institution as the authorized entity to obtain and manage parental or guardian consent for student data.
- Schools are responsible for ensuring that parents or guardians have been informed about the App and have provided necessary consent before student accounts are created.
- We do not knowingly collect personal information directly from children without school-mediated consent.
- Student data is used solely for educational and communication purposes and is never used for advertising or profiling.
Parents and guardians have the right to request access to their child's data, correct inaccurate information, or request deletion. Please contact us or your school administrator to exercise these rights.
🔒 6. Data Security
We take data security seriously and implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
- Encryption in Transit: All data transmitted between the App and our servers is encrypted using TLS/SSL protocols.
- Encryption at Rest: Sensitive data stored in our databases is encrypted at rest.
- Secure Hosting: Our infrastructure is hosted on reputable cloud platforms with robust physical and network security controls.
- Access Controls: Only authorized personnel with a legitimate need can access user data, and access is controlled through role-based permissions.
- Regular Audits: We periodically review our security practices to identify and address potential vulnerabilities.
While we strive to use commercially acceptable means to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We encourage users to keep their login credentials confidential.
🗂️ 7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law.
- Active account data is retained while the account remains active within a school's subscription.
- When a school's subscription ends, data is retained for a brief transition period (up to 90 days) before being securely deleted.
- Communication logs and student records may be retained longer if required by applicable educational regulations.
- You may request earlier deletion by contacting us (see Section 9).
✅ 8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data (“right to be forgotten”).
- Right to Restriction: Request that we limit how we process your data in certain circumstances.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to certain types of data processing.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
🗑️ 9. Account & Data Deletion
You have the right to request the deletion of your account and all associated personal data at any time. This is a mandatory requirement under both Apple App Store and Google Play Store policies.
Request Account or Data Deletion
To request the deletion of your account or personal data, please send an email with your school name, registered email address, and the reason for deletion. We will process your request within 30 days and confirm once your data has been removed.
✉️ Request Data Deletion📝 10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or app features. When we make significant changes, we will notify users through the App or via email.
The “Last Updated” date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
📬 11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please do not hesitate to contact us:

