Introduction & commitments
Our Services are used by students and educational institutions in the United States, and we handle student records in line with the Family Educational Rights and Privacy Act (FERPA) and other applicable laws. Users of our platform may include minors under the authority of their schools, so we also adhere to the Children's Online Privacy Protection Act (COPPA) and relevant state laws. We do not sell personal data or share it with third parties for marketing purposes, except as described in this Policy. By using our Services, you agree to the practices described here. If you do not agree, please do not use the Services.
Key privacy commitments
- FERPA. We handle student education records in line with FERPA and act as a "School Official" to educational institutions, using student data only for authorized educational purposes.
- No sale of data. We do not sell your personal information, and we do not use student data for targeted advertising or marketing. Your information is used only to deliver and improve our Services.
- Limited sharing. We share data only with authorized parties — such as your school or service providers operating under strict contracts — and only as needed to operate our platform. We do not build personal profiles of students beyond educational requirements.
- Security. We employ industry-standard security measures, including encryption of data in transit and at rest, access controls, and regular privacy training, to protect your information.
- Parental consent for minors. If students under 13 use our Services through a school, we rely on schools to obtain any necessary parental consents in accordance with COPPA. We do not knowingly collect data from children under 13 for any independent commercial use.
Information we collect
We collect personal information and student data from and about users of our Services in order to provide and improve our platform. This includes:
- Identifying information. Name, email address, telephone number, postal address, username, and account login credentials. If you are a student, this may include your student ID number or other identifiers provided by your school.
- Educational records. Academic and enrollment information such as courses taken, grades, credits earned, transcripts, enrollment status, and other information that is part of your educational record. This can include information needed for verifying concurrent enrollment, high school articulation, or prior learning credits (e.g., course names, performance criteria).
- Uploaded documents. Documents or files you or your school upload to the platform — for example, proof of course completion, transcripts, certificates, or identification documents submitted when you claim credit. These may contain personal information and academic details.
- Payment information. If you make payments through our Services, we collect information necessary for payment processing, such as billing name and address and payment card details. Card information is processed via a secure third-party payment processor and is not stored on our servers in full. We keep records of transactions (date, amount, method) for accounting and compliance.
- Usage data. Technical information (IP address, device type, operating system, browser, unique device identifiers) and usage information (pages or features used, dates and times of visits, referring URLs, errors, and other analytics), collected through log files and cookies.
- Cookies and tracking technologies. We use cookies, web beacons, and similar technologies to remember preferences, keep you logged in, and gather usage analytics. See the Cookies section below.
- Communications. If you contact us for support, we collect the information you provide, including your contact details and the content of your communications.
- Information from schools or third parties. We may receive personal information about students or educators directly from the institutions we serve or other parties authorized by your school — for example, class rosters or academic data provided to set up and integrate their systems with our Services.
We collect this information directly from you, from your educational institution, or automatically through your use of the Service. We only collect information that is relevant and necessary for the purposes described in this Policy. You may choose not to provide certain information; however, this may limit your ability to use some of our Services.
How we use your information
Campus Credit uses the collected information for the following purposes:
- Providing and improving Services. Operating the platform's core functionality — processing credit articulation and concurrent enrollment requests, evaluating eligibility for credits, updating academic records, and facilitating the transfer of earned credits to student information systems or transcripts — and maintaining and improving our Services (fixing bugs, analyzing usage trends, developing new features).
- Account management and authentication. Creating and managing accounts, verifying identities during login, authenticating authorized users (students, teachers, counselors, administrators), and preventing unauthorized access.
- Communication. Using contact information and in-app notifications to communicate about the Service — status changes, reminders, support responses, and service-related announcements. We do not send promotional marketing emails to students, and informational emails to school staff comply with applicable law and provide an opt-out.
- Processing payments. Using payment information to process transactions and keep billing records, securely and only for those purposes.
- Compliance and legal obligations. Using and disclosing information as necessary to comply with law, regulation, legal process, or enforceable governmental requests, providing only the minimum necessary and, whenever feasible, notifying the affected institution or individual.
- Security and preventing misuse. Monitoring for suspicious activity, preventing fraud or misuse (including falsification of academic documents), and maintaining system integrity.
- Analytics and aggregated uses. Any analytics or research uses de-identified or aggregated data that does not personally identify individuals, solely for product improvement.
- Educational reporting. Generating reports and insights for authorized school officials, using only data under that institution's control and shared only with that institution.
We use personal information only for the purposes outlined above or compatible purposes. We do not use personal information for targeted advertising or profiling outside educational or operational purposes, and student data is never used to contact students for marketing, advertising, or non-educational purposes.
Cookies & tracking technologies
Like most websites, our platform uses cookies and similar technologies to enhance user experience and gather usage data. We use cookies to keep you logged in as you navigate secure areas of the site and to remember your preferences — often called "strictly necessary" or "functional" cookies.
We also use analytics services (such as Google Analytics) to understand how users interact with our Services — pages visited, time on page, actions taken, and general (city- or region-level, not precise) location. This data is typically aggregated and does not directly identify individual users.
We do not use cookies or tracking technologies for advertising or profiling of students. You will not see third-party advertising on our site, and we do not allow advertising networks to collect information through our platform. Any third-party tools we use are contractually bound to use information solely for providing services to us.
Your choices. Most browsers accept cookies automatically, but you can modify your settings to decline them or clear them at any time. Disabling cookies may affect login and account features. For Google Analytics, Google provides an opt-out browser add-on.
Do Not Track. Our site does not currently respond to "Do Not Track" signals. We do not track users across third-party sites, and we will revisit our approach if industry DNT standards become formalized.
How we share your information
We do not disclose or share your personal information with third parties except in the following circumstances, and always in compliance with FERPA and other privacy laws:
- With your educational institution. Your school and its authorized teachers, counselors, and administrators have access to your records on our platform, and we sync relevant data with the institution's systems (such as updating the college's SIS with awarded credits) as part of providing the service. We disclose student information only to the originating institution or as it directs.
- With service providers (processors). Trusted providers who perform services on our behalf — cloud hosting, databases, analytics, email and notifications, identity verification or single sign-on, and payment processing. They are contractually bound to keep information confidential and use it only for the services we request, never for their own purposes.
- For legal requirements and safety. Where we believe in good faith it is necessary to comply with law or legal process, protect rights or property, prevent fraud or security threats, or protect personal safety. For requests seeking student records, we will, whenever legally permissible, redirect the request to the appropriate institution and require a subpoena or court order as FERPA requires, disclosing only the minimum necessary.
- With your consent or at your direction. Where you (or your parent/guardian, if you are a minor) explicitly consent — for example, sending your credit attainment to a scholarship service or another college.
- Business transfers. In a merger, acquisition, sale of assets, or other corporate change, personal information may transfer to a successor, which must keep it subject to the same protections in this Policy. We will provide notice before information becomes subject to a different policy, and we will never sell student personal data as a standalone asset.
- De-identified or aggregated data. We may share data stripped of personal identifiers or aggregated so it cannot reasonably identify you — for example, a report of total credits earned across partner schools.
We do not sell, rent, or exchange your personal information for third-party marketing or advertising. Student data is only used for educational purposes and only shared with parties that have a legitimate educational interest or legal right to access, as permitted by FERPA. We treat all student data as strictly confidential.
Student data privacy (FERPA)
Campus Credit operates as a service provider to educational institutions and is committed to protecting student privacy. In handling Student Data (personal information from student education records), we adhere to FERPA and applicable state student-privacy laws.
- School Official under FERPA. When we provide our Services to a college, district, or educational agency, we are a "School Official" under FERPA § 99.31 with a legitimate educational interest in the records we receive, under the direct control of the institution — acting as an extension of the school's own staff for managing credit articulation, concurrent enrollment, and prior learning workflows.
- Authorized use only. We use student PII from education records only as needed to provide the Services on the institution's behalf, never for targeted advertising, marketing, or other commercial purposes. Any use for product improvement is done with de-identified data only.
- No re-disclosure without consent. We will not re-disclose student education records except (a) as the institution directs, (b) as permitted by law (such as a student's transfer to another institution, or a lawful subpoena), or (c) with consent of the eligible student or parent — consistent with FERPA's re-disclosure limits (34 CFR § 99.33).
- Ownership and control. Student records remain the property of and under the control of the institution. We do not own student data; we hold and process it on the school's behalf and assert no rights to it.
- Access and correction. Eligible students and the parents of minor students have rights to access and seek amendment of education records. Direct such requests to your institution, which is the primary custodian; we facilitate schools in fulfilling them.
- State student-privacy laws. We comply with applicable state laws — for example, California Education Code § 49073.1 governing ed-tech provider contracts — and align with the Student Privacy Pledge.
- FERPA and HIPAA. Health-related information that appears within an education record (e.g., a doctor's note in a prior-learning portfolio) is protected by FERPA, not HIPAA, and we treat it under FERPA's confidentiality rules.
- No advertising or profiling of students. We do not serve advertisements to students or create marketing profiles, and we do not allow advertising networks to target students through our platform.
Campus Credit maintains an architecture built to meet FERPA's requirements, and all employees and contractors with potential access to student records are trained on FERPA obligations.
For a fuller explanation of how the platform itself enforces these protections — role-based access, a complete decision log on every request, and integration without direct database access — see our FERPA page.
Children's privacy (COPPA)
Our Services are intended for use by students primarily at the direction of schools and colleges. Campus Credit does not knowingly allow children under 13 to use our Services without appropriate consent. In nearly all cases, student users under 13 (and often under 18) use the platform in a school context, with the school's involvement and consent.
- Role of schools for under-13 users. Where a student under 13 uses Campus Credit as part of a school's program, the school acts in place of the parent to provide consent, as permitted under COPPA. We require that any school enrolling students under 13 has obtained necessary parental consent or provided the required COPPA notice.
- Direct sign-up by minors. Our platform generally does not allow students to create an account without a school involved. If we ever offer direct sign-up to a child under 13, we will obtain verifiable parental consent first. If we learn we collected such information without consent or school authorization, we will delete it promptly.
- Parental rights. Parents and guardians may review information collected about their children, request deletion, and refuse further collection. Contact your child's school first, since the school is often best positioned to make changes; you may also contact us at support@mycampuscredit.com.
- Users ages 13–17. COPPA may not require parental consent here, but these users are typically under the authority of a school or parent. We handle teenage users' data with the same care and confidentiality described throughout this Policy.
- No child-directed advertising. We do not serve behavioral advertisements to any user, and certainly not to children, and we do not knowingly market to or solicit information from children.
- Teacher and school responsibility. Educators should provide only data relevant to credit and enrollment processes, and remain responsible for their own COPPA and FERPA notice and consent obligations. We provide tools and information to help facilitate transparency with parents.
If you believe we hold information about a child under 13 collected without proper consent, contact us immediately at support@mycampuscredit.com and we will investigate and address it promptly.
Data security
Campus Credit uses administrative, technical, and physical measures to protect personal information from unauthorized access, loss, misuse, or alteration. Because the data we handle — student academic records and payment details — is sensitive, we design our security program with that in mind.
- Encryption. We protect data in transit and at rest. Connections to our site are encrypted using TLS/SSL, so data moving between your device and our servers (such as login credentials or uploaded documents) is encrypted. We also encrypt sensitive data at rest — for example, stored transcripts and identification documents are kept in encrypted form.
- Secure hosting. Our Services run on Amazon Web Services (AWS), which maintains strong security certifications and physically secured data centers with access control, monitoring, and redundancy. Servers are kept patched and monitored for intrusions.
- Access controls. Access to personal information is restricted to employees and authorized contractors who need it to operate, develop, or support our Services. Personnel who handle student data undergo background checks where permitted and receive training on data-privacy and security requirements, including FERPA. Access follows least-privilege, uses unique credentials, and administrative access is logged and audited.
- Security testing and monitoring. We monitor our systems for vulnerabilities, use network protections and secure development practices (including code review and testing), and may engage third-party security experts to perform penetration testing or audits periodically.
- Payment security. Payments are processed by PCI-DSS compliant processors. We do not store full card numbers; such data is tokenized or held by the payment gateway.
- Backups and recovery. We perform regular, encrypted backups and maintain recovery procedures to restore availability and data integrity in the event of a system issue.
- Employee policies. All personnel agree to confidentiality obligations and follow internal data-handling policies — including a rule against using actual student data in testing environments.
No method of transmission or storage is completely secure, so while we strive to protect your information we cannot guarantee absolute security. We continuously update our practices to meet or exceed industry standards.
Security breach procedures
In the event of a breach affecting personal information, we act promptly to contain and investigate, and we notify affected institutions and individuals as required by law. Where student data is involved, we inform the relevant school officials as soon as possible (typically within the timeframe required by law or contract) so notifications to students or parents can be coordinated. Please use a strong password, do not share credentials, and notify us at support@mycampuscredit.com if you suspect unauthorized access.
Data retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Because our Services involve official academic records, we handle retention in coordination with our client institutions:
- Student accounts and records. Retained for as long as the institution authorizes — generally for the duration of the agreement and as needed to support educational purposes (e.g., until credit is awarded and transferred, plus a reasonable period for auditing). If a school ends its use of Campus Credit, we will, at the school's option, return all student data and/or delete it from our systems (except data we are legally required to retain), and certify deletion on request. Backups may persist briefly before being overwritten.
- User accounts (educators and others). Retained while the account is active or as needed to provide services. On verified deletion requests we delete or de-activate account data, keeping only minimal records where required by law or to prevent fraud.
- Payment and transaction data. Retained as required for financial reporting and audits — typically at least seven years — though full card numbers are not stored by us.
- Legal obligations and disputes. Retained longer where necessary to comply with law or where a dispute, investigation, or litigation is pending or reasonably anticipated.
- Backups and residual storage. Deleted data may persist briefly in secure backups until cycled out. Aggregated or anonymized data that no longer identifies you may be retained for statistical or product-improvement purposes.
- Account inactivity. Inactive accounts may be archived or deleted after a defined period of inactivity, set in consultation with the institution or by our internal policies. Archived data is restricted and not used for new purposes.
When personal information is no longer needed, we securely delete or anonymize it. For student data, we coordinate retention and deletion with our client institutions to honor both the letter and spirit of student-privacy regulations.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), subject to certain exceptions (for example, CCPA's education-related exemption may apply to data we handle on behalf of schools). These rights include:
- Right to know (access). Request the categories and specific pieces of personal information we collect, use, and disclose about you, along with sources, purposes, and the categories of third parties we share it with.
- Right to delete. Request deletion of personal information we collected from you, subject to legal exceptions (such as completing a service you requested or meeting a legal obligation).
- Right to correct. Request correction of inaccurate information. For student information from a school, we may coordinate with the school to verify and implement corrections at the source.
- Right to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, so no action is needed — by default we do not engage in these practices.
- Right to limit sensitive information. We already limit use of any sensitive information strictly to the educational purposes for which it was provided.
- Right of non-discrimination. We will not discriminate against you for exercising your rights.
Submitting requests
California residents (or an authorized agent) may submit access, deletion, or correction requests by emailing support@mycampuscredit.com or by mail at the address in Contact Us. We will verify your identity before fulfilling a request and, for student data we hold on behalf of a school, may direct the request to your school or work with them to fulfill it. We acknowledge requests within 10 business days and aim to respond within 45 calendar days (extendable up to a total of 90 days with notice).
We do not sell personal information, and we have not sold or shared (for behavioral advertising) any personal information of California residents, including minors, in the preceding 12 months. Accordingly, we do not provide a "Do Not Sell or Share My Personal Information" link, because it is not applicable.
International data & GDPR
Campus Credit is based in the United States and primarily serves U.S. institutions, but our Services may be accessible elsewhere, including the EEA and UK. If you use our Services from outside the U.S., please note:
- Data transfers. Information is stored and processed in the United States, which may not have the same data-protection laws as your country. By using our Services, you acknowledge this transfer. For the EEA/UK, we rely on mechanisms such as the European Commission's Standard Contractual Clauses (SCCs) or other appropriate safeguards.
- GDPR rights. To the extent GDPR or UK GDPR applies, you may have the following rights:
- Access — confirmation and a copy of your personal data and how we process it.
- Rectification — correction of inaccurate data.
- Erasure — deletion in certain circumstances, which may be limited by legal obligations to retain educational records.
- Restrict processing — in certain situations, such as while data is contested.
- Data portability — a copy of certain data in a machine-readable format where technically feasible.
- Object — to processing based on legitimate interests, and to any direct marketing at any time.
- No solely automated decisions — we do not make decisions producing legal or similarly significant effects by purely automated means.
- Withdraw consent — where we rely on consent, at any time, without affecting prior lawful processing.
- Complaint — to lodge a complaint with a supervisory authority, though we welcome the chance to resolve concerns directly first.
- Legal bases. We process personal data under one or more of: performance of a contract, legitimate interests, legal obligation, and consent.
- Processor vs. controller. For most student data received through school clients, the institution is the data controller and Campus Credit is a data processor acting on documented instructions under a Data Processing Addendum. For data such as marketing-website visitors or directly registering educators, we may act as a controller.
Even if you are not in California or the EU, if you contact us about your privacy preferences we will do our best to accommodate you in line with applicable laws.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. For minor updates, we post the revised Policy with a new effective date. For significant changes, we provide more prominent notice or seek consent as required by law. The effective date is listed at the top, and earlier versions are available on request. If you continue using our Services after an update takes effect, it signifies your acceptance of the updated terms to the extent permitted by law.
Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@mycampuscredit.com
Mail: Campus Credit LLC — Privacy Team, 3150 Hilltop Mall Rd, Suite 61, Richmond, CA 94806, USA
If you are an educational institution or enterprise customer, you may also reach out to your account representative or our support channel for assistance.