Privacy Policy
Last updated: 28 September 2026
This policy explains what personal information Akshara360 handles, why, who can see it, and the choices you have. We have kept it short and in plain language.
1. Who we are and what this policy covers
Akshara360 (“we”, “us”) provides the Akshara360 school management service used by schools in India (the “Service”). The Service is available on our website www.akshara360.com and through our Android app “akshara360”.
This policy applies to the website, the Android app and the public admission-enquiry form.
It covers everyone whose information is in the Service: school administrators and staff, teachers, parents and guardians, students, and people who send an admission enquiry.
Laws we follow: the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the “SPDI Rules”) apply now. India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the DPDP Rules, 2025 apply as their provisions come into force.
2. Your school’s role and ours
Your school decides whose information to record in the Service, what to record and why. For that information the school is the Data Fiduciary under the DPDP Act.
Akshara360 processes that information on the school’s behalf and on its instructions, as its Data Processor. We do not decide how the school uses its records.
- Questions about why your school holds certain information, and requests to see, correct or delete it, should go to your school first. We help the school respond.
- The school is responsible for telling you how it uses your information and for obtaining any consent the law requires, including a parent’s or guardian’s consent for a child.
- We are responsible for the information we need to run the Service itself, such as sign-in and security records, and for protecting all information we hold.
There is no self sign-up. Accounts are created only by the school — for administrators, teachers and other staff, parents and students — except a new school’s first administrator account, which we create when the school joins.
3. Information we process
Which of the details below are recorded depends on how your school uses the Service.
Everyone who signs in
- Name, login ID, school and role (for example teacher, parent or student).
- Mobile number and email address, if the school records them.
- Your password, stored only as a salted one-way hash — never in readable form.
- When you last signed in, and how you arranged your dashboard.
Students
- Identity and admission: name, admission number, class, section and roll number, date of birth, gender, photo, address, mother tongue, nationality, house, admission and leaving dates, previous school and transfer certificate number.
- Government identifiers: Aadhaar number, APAAR ID and PEN (UDISE+). Giving an Aadhaar number is optional; the Service never requires it.
- Sensitive details the school may record for admission and government reporting: social category and caste, religion, blood group, Right to Education (RTE) and EWS status, and whether the child has special needs (CWSN).
- School records: attendance (including arrival and leaving times on late or half days), marks, results, rank and remarks, co-scholastic grades, height and weight, homework and submissions, class register notes (for example about discipline, cleanliness or support given), leave requests and their reasons (which may mention health), library loans and fines, certificates issued, transport route and stop, and hostel room.
- Documents the school uploads, such as a birth certificate, transfer certificate, Aadhaar card, caste certificate and photos.
Parents and guardians
- Names, mobile numbers, email, occupation, relationship to the student, and an emergency contact.
- Fee dues, concessions, receipts and refunds for your children, and messages you exchange with the school.
Brothers and sisters at other schools
If a family shares them, the school may record siblings who study elsewhere (name, date of birth, gender and current school) so that it can contact the family about admission.
Staff
- Employee ID, name, designation, department, gender, date of birth, date of joining, qualifications, mobile number, email, photo and address.
- The last four digits of PAN. The Service has no fields for bank account numbers or full PAN.
- Attendance with in and out times, leave, salary structure and payslips (pay, deductions, and how and when salary was paid).
Transport
Names and mobile numbers of drivers and attendants, and vehicle registration numbers. The Service does not track vehicles or anyone’s location.
Admission enquiries
The public enquiry form collects the parent or guardian’s name, the child’s name, a mobile number, an optional email address, the class sought and any message. It goes to the school named on the form.
Payments and messages
- How each fee was paid and its reference (for example a UPI or bank-transfer reference, cheque details or the last four digits of a card) and, for online payments and refunds, the payment provider’s order, payment and refund IDs. We do not store full card numbers.
- Messages and attachments, notices and who has read them, and in-app notifications.
- In messaging: reports you make about a message (with your reason and how it was resolved), people you block, and when you accepted the messaging rules.
The school
Name, code, board, UDISE and affiliation numbers, address, contact details, logo and the principal’s name.
The Service has no fields for medical history, biometrics or location. Free-text fields, such as remarks or leave reasons, may still contain such details if someone types them in.
4. How information is collected
- From your school: school staff enter most information — at admission, when taking attendance, entering marks, collecting fees and so on — or import it from spreadsheets.
- From you: when you use your account, for example to send a message, submit homework, request leave, pay fees online or change your password.
- From the admission-enquiry form, which anyone can fill in without signing in.
- From our payment provider: whether an online payment succeeded or failed, with its reference IDs.
- Automatically:
- a cookie that keeps you signed in (see our Cookie Policy);
- the time of your last sign-in;
- your IP address, login ID or the enquiry form’s mobile number, used to limit repeated sign-in attempts and enquiry-form submissions (these entries are cleared out from time to time after they expire);
- a record of important changes — who changed what, when, and the values before and after — for example password resets, permission changes, fee cancellations and refunds;
- technical error logs on our servers, which may occasionally include details of the request that caused the error.
We do not use analytics, advertising or tracking tools on the website or in the app.
5. How information is used
Information is used to run the Service for your school:
- keeping student, staff, attendance, exam, fee, library, transport, hostel, payroll and other school records;
- producing report cards, receipts, certificates, ID cards, timetables and reports;
- letting staff, parents and students communicate through messages, notices and notifications;
- processing online fee payments and refunds, and sending SMS alerts (see SMS and notifications);
- signing you in, keeping accounts secure and preventing misuse;
- helping the school when it asks for support, and fixing problems;
- meeting legal obligations.
The school may also use admission enquiries and sibling details to contact families about admission. That is the school’s own use of its records.
We never:
- sell or rent personal information;
- show advertisements, or share information with advertisers;
- track students or other users across other websites or apps, or build profiles of them for advertising or marketing;
- use information for any purpose other than providing the Service, unless the law requires it.
6. Who can see your information
People at your school
Information is visible to people at your school according to their role and the permissions the school gives them. For example, a parent sees only their own children, a student sees only their own records, and a teacher sees the classes they teach. School administrators can see and manage the school’s records.
Staff whom the school allows to moderate messages can read a message and its attachment once someone has reported it, and can remove it.
Our service providers
We use a small number of providers to run the Service. Each receives only what it needs for its part of the work:
- Vercel — hosts the website and the application servers.
- Supabase — hosts the database where school records are stored.
- Razorpay — processes online fee payments and refunds, when online payment is switched on (see Online fee payments).
- MSG91 — delivers SMS to Indian mobile numbers, when SMS is switched on (see SMS and notifications).
Akshara360 staff
A small number of our people who run the Service have technical access to the systems that store school data. They use it only to operate, maintain and support the Service, when the school asks for help, or when the law requires.
When the law requires
We may disclose information when required by law, a court order or a lawful request from a government authority, or where needed to protect someone’s safety or the security of the Service.
We do not sell personal information or share it with anyone for their own marketing.
Links to other websites
The Service may link to other websites, such as Razorpay’s payment page. Their own privacy policies apply there.
7. Online fee payments
Online fee payment is switched on for the whole Service, not school by school. When it is on, payments are processed by Razorpay, through the Razorpay account set up for the Service.
- You enter card, UPI or net-banking details on Razorpay’s own payment screen, not in our forms. We never receive or store your full card number, CVV or UPI PIN.
- To start a payment we send Razorpay the amount and our own reference numbers, including internal IDs for the school and the student. Razorpay’s payment screen also receives the school’s name, a description with the student’s name (“Fees — student’s name”), and the name, mobile number and email of the signed-in person paying, to pre-fill the form. If that login has no mobile number, the father’s mobile number is used.
- Razorpay tells us whether the payment succeeded, with its order and payment IDs, which we keep with the receipt.
- When the school refunds an online payment, the refund is made through Razorpay: we send it the payment ID, the amount and internal IDs for the school and the payment.
- In the Android app, online payment (where available) opens in a browser tab rather than inside the app.
Razorpay handles payment information under its own privacy policy and terms.
8. SMS and notifications
SMS delivery is switched on for the whole Service, not school by school. When it is on, the Service sends text messages through MSG91 to the Indian mobile numbers the school has recorded:
- automatically: absence alerts to a parent or guardian (the student’s name, class and date), and fee receipts and refunds to a parent (the student’s name, the amount and the receipt number);
- automatically: a daily summary of fees collected and money spent, to school administrators;
- when staff choose to send them: fee reminders to a parent (the student’s name and the amount due), and short notice alerts (the school’s name and the notice title).
The Service does not send email, and we do not send promotional messages of our own.
Other updates appear as notifications inside the Service. The Android app does not send push notifications.
9. The Android app and its permissions
The Android app “akshara360” opens the same Service as the website. It asks Android for only two permissions:
- Internet access (“full network access”) — to connect to the Service.
- Network state (“view network connections”) — to know whether your device is online.
The app does not ask for access to your location, camera, microphone, contacts, photos, media or other files, phone, SMS, calendar or notifications. If a page inside the app asks for the camera or microphone, the app refuses.
- Uploading a file (for example a photo or document) opens Android’s own file picker. The app can read only the files you pick, and sends them to your school’s records in the Service.
- Downloading or exporting a file opens Android’s own save screen, so you choose where it goes. The app keeps no copy.
- Printing uses Android’s print service, including “Save as PDF”.
- Staying signed in: the app keeps your sign-in cookie in its private storage on your device until you sign out or the session expires. When you sign out, the app clears its browsing history and cache.
- The app’s data is excluded from Android cloud backup and device-to-device transfer.
- The app contains no advertising, analytics or crash-reporting software and does not collect advertising IDs.
The app shows the Service using Android System WebView, a part of your device’s operating system. Anything that component shares with its provider depends on your device settings and that provider’s policies.
An app for iPhone and iPad is not available yet. If we publish one, we will update this section before it is released.
10. Cookies
The Service uses a few cookies it needs to work — mainly one that keeps you signed in — and a few that remember your screen preferences. We do not use advertising or analytics cookies. See our Cookie Policy for the full list.
11. How we protect information
- Connections to the website and the app use HTTPS. The Android app refuses unencrypted connections.
- Passwords are stored only as salted one-way hashes. Temporary passwords given by the school must be changed at the first sign-in.
- The sign-in cookie cannot be read by scripts in the page and is sent only over secure connections. A session stops working after 30 days or when you sign out, and changing your password signs you out on your other devices.
- Repeated failed sign-in attempts are blocked for a while.
- Every record belongs to one school, and users can reach only their own school’s records; what they see is further limited by their role and permissions. An uploaded file opens only for signed-in users of the school that owns it; the school’s logo is also shown on its public enquiry form.
- Aadhaar numbers are shown masked (only the last four digits), except to staff editing the student’s record.
- Important changes, such as password resets, permission changes, fee cancellations and refunds, are recorded in an audit log the school can review.
- We never store full card numbers, CVV or UPI PIN; they are entered only on our payment provider’s screen.
- If a breach affects personal information, we inform the affected school without delay and report it to CERT-In and other authorities as the law requires.
No system is completely secure, and we cannot guarantee that information will never be accessed without permission. If you think your account has been misused, tell your school administrator and write to us at privacy@akshara360.com.
12. How long information is kept
- School records are kept for as long as the school uses the Service, unless the school deletes them sooner. The school decides how long to keep its records, in line with the laws that apply to it.
- Uploaded documents and photos (for example Aadhaar cards, certificates, photos and message attachments) are not removed automatically when a record is deleted or a photo is replaced. Ask us and we will delete them.
- When a student leaves, the school marks them as left or passed out. The student’s login is switched off, and their records stay with the school’s other records (for example for transfer certificates, results and fee history).
- When a staff member leaves, their login is switched off and their records stay with the school’s records. A staff login is never deleted, even when the staff record is; it stays switched off.
- Admission enquiries and messages are kept for as long as the school uses the Service. Notices and sibling details are kept until the school removes them.
- The audit log, including the values before and after each change, is kept for as long as the school uses the Service.
- Sign-in sessions stop working after 30 days. Entries used to limit repeated attempts are cleared out from time to time after they expire.
- Server error logs are kept for as long as our hosting provider keeps them.
- When a school stops using the Service, its access can be switched off so that nobody from the school can sign in. Its data is not deleted automatically: the school can ask us to delete it, and we will do so in line with our agreement with the school and the law.
Deleted information may remain in backup copies until those copies expire.
13. Your rights
Under the SPDI Rules, and the DPDP Act as its provisions come into force, you have the right to:
- get a summary of the personal information held about you and how it is used;
- have inaccurate or incomplete information corrected, completed or updated;
- have information erased when it is no longer needed, unless the law requires it to be kept;
- decline to give information that is optional, such as an Aadhaar number (some details are needed for admission, and without them the school may not be able to provide a service);
- withdraw consent where the school relies on your consent (this does not affect what was done before);
- have your grievances addressed;
- nominate another person to use these rights for you if you die or become unable to do so.
How to use them: your school controls its records, so please contact your school first. Many details can be corrected by the school’s administrator directly in the Service, and you can change your own password at any time. You can also write to us (see Contact); we will pass your request to your school and help it respond.
If you are not satisfied with the response, you can complain to the Data Protection Board of India once the DPDP Act’s provisions on complaints are in force.
14. Deleting your account and data
Accounts in the Service belong to your school, so there is no delete button in the app. You can ask for your account and its data to be deleted in either of these ways:
- Ask your school administrator. A staff login can be switched off straight away, which signs you out everywhere. A student’s login is switched off when the school marks the student as left. A parent’s login is switched off when the school issues a transfer certificate for the last of their children still at the school. For anything else, such as a parent login while a child is still at the school, email us.
- Email us at privacy@akshara360.com with the subject “Delete my account”, your name, your school’s name and school code, and your login ID. Never send your password. We will confirm the request with your school and arrange the deletion, including uploaded documents and photos. See Contact for how quickly we respond.
What may be kept:
- A student with fee receipts, refunds, certificates, marks or library books on loan cannot be deleted. The school marks the student as left instead: the whole student record stays (including the profile, parent details and uploaded documents) and the student’s login is switched off. The school can clear optional details, such as the Aadhaar number, religion or category, by editing the record; ask us to remove uploaded documents.
- A staff member with payslips, attendance or leave cannot be deleted: the record stays and the login is switched off. A staff login is never deleted; it stays switched off, even when the staff record is deleted.
- Uploaded documents and photos are not removed automatically when a record is deleted; ask us and we will delete them.
- A short note that a record was deleted (for example a student’s admission number and name) stays in the school’s audit log.
15. Children
- Most students using the Service are children (under 18). A school may give students their own login, including young children; the school decides from which class.
- The school is responsible for obtaining verifiable consent from a parent or lawful guardian, where the law requires it, before recording a child’s information.
- We use children’s information only to provide the Service to their school. We do not show advertisements, track children, or build behavioural or advertising profiles of them, and we never sell their information. Attendance, marks and conduct notes are records the school keeps for its own educational purposes.
- Student logins cannot send messages. Parents can see their child’s information through their own parent login.
If you believe a child’s information is in the Service without the right permission, contact the school or write to us.
16. Where information is stored
Our hosting and database providers (Vercel and Supabase) store information in the United States, so it is stored outside India. We transfer information outside India only as Indian law permits (Rule 7 of the SPDI Rules now; section 16 of the DPDP Act once in force), and use providers that protect it with appropriate security measures.
17. Changes to this policy
We may update this policy when the Service changes or the law requires. The date at the top shows when it last changed. For significant changes we will also tell schools or show a notice in the Service.
18. Contact and grievance officer
For questions, requests or complaints about this policy or your information, contact our Grievance Officer:
- Grievance Officer, Akshara360
- Email: privacy@akshara360.com
- Address: 93/3, 1st Cross, Thulasi Theater Road, Munnekolala, Marathahalli, Bengaluru, Karnataka 560037, India
- Website: www.akshara360.com
We acknowledge complaints within 24 hours and resolve them within 15 days of receipt. For questions about your school’s records, please also contact your school.