Last updated: ongoing · Compliant worldwide

Privacy Policy.

How Studyladder collects, uses, stores and protects information — written plainly, with the rights of every child, parent, teacher and school in mind.

Studyladder privacy policy

At Studyladder we recognize the need to protect information collected from the Studyladder websites. We are committed to keeping safe and secure any personal and identifiable information obtained about users and to provide a safe learning environment for children.

Studyladder and Privacy for U.S. & California Users

Studyladder is committed to protecting the privacy of our users and complying with:

  • COPPA – Children’s Online Privacy Protection Act
  • FERPA – Family Educational Rights and Privacy Act
  • SOPIPA – California Students Online Personal Information Protection Act
  • AB 1584 – California Assembly Bill 1584

Collection of Personal Information

  • We do not collect personal information directly from children under 13 without parental or guardian consent.
  • Personal information is collected through parents, legal guardians, or schools acting as the parent’s agent.
  • Data is limited to what is necessary for educational purposes (learning activities, tracking progress, reports).

Parental and School Consent

  • Schools may provide student information as a parent’s agent after obtaining verifiable parental consent.
  • Parents can view what information is collected and how it is used.
  • Parents may review, correct, or delete their child’s information at any time.

Use and Disclosure

  • Information is used only for educational purposes.
  • Studyladder does not sell or use student information for advertising or create profiles for non-educational purposes.

Parent and Eligible Student Rights

  • Access, correction, deletion, restriction, portability, objection, withdraw consent.
  • Requests processed within 30 days.

Data Retention

  • Retained only as necessary for educational purposes.

Data Security

  • Industry-standard measures (encryption, access controls) are used to protect personal information.

Data Breach Notification

  • Parents, guardians and schools will be notified of breaches involving children’s information.

California-Specific Protections

  • No sale of student information or behavioural advertising.
  • Student data is not used for non-educational profiling.
  • Schools may act as parent agents.
  • Data deletion requests fulfilled within 30 days.

Highlights of our policy

  • We do not collect any personal information directly from children and we do not communicate directly with children.

  • We only collect personal information about children under 13 with parent consent or from teachers that are authorised to act as agents for parents.

  • We only collect minimal personal information from Parents/Teachers.

  • We do not sell or pass on information to any third party.

  • We collect information for the purposes of providing access to the website.

  • We give registered users complete control and management of their personal information, including the right to erasure.


This policy explains how we collect and use information that is provided to us via our websites. Including;

Please read this policy carefully. Contact us if you have any questions at: privacy@studyladder.com.

What personal information does Studyladder collect?

We collect personal information about two groups.

Teachers/Parents (teachers, school administrators, tutors, parents and legal guardians) and Children. We collect personal information from these two groups differently.

Personal information from Teachers/Parents is collected when an account is created on our website. This information may include: email addresses, names, country and state, phone numbers, first name, surname, school name and address.

Studyladder does not collect personal information directly from children. Children are not able to register directly themselves. We do not collect children’s email addresses and do not communicate directly with them.

The personal information we collect about children may include: first name, surname, grade and school name (school-based users only).

Information about children comes from Teachers or Parents. Once registered Teachers or Parents may provide information about the child via their account.

How does Studyladder collect and process information?

  • Directly from Registering (Teachers/Parents) and Registered Users via our website.
  • When emails are sent to us.
  • For Children, a home-based Registered User (usually a parent or guardian) creates an account then creates and links a child account to their account OR
  • For Children, a school-based Registered User creates an account then creates and links a student account to their account.
  • IP Address, browser type and device type as sent from your device when accessing the Studyladder website.
  • Anonymous metrics, used to improve the website, collected by Google Analytics when accessing the Studyladder website.

Children are not able to create an account themselves and no personal information about themselves is collected from them.

How does Studyladder use your information?

The information collected may be used for the following purposes:

  • To send confirmation of successful registration by email.
  • To personalize usernames and provide access to restricted areas of the websites.
  • To communicate with Registered Users.
  • To enable Registered Users to manage accounts, including managing their own personal information and children/student accounts.
  • For school administration purposes.
  • To create personalized features such as reports and rewards.

Results data and how it is used

Results Data is limited to what is necessary for educational purposes (learning activities, tracking progress, reports).

Results data is used to inform Teachers/Parents about a student’s performance and to tailor educational programs for students. Results data is also used to better inform us about ways to improve our resources.

Studyladder does not share with any third party information about a student’s or school’s results or progress.

What Studyladder does not do with your information

We believe that it is essential that all information is kept confidential. We will not disclose information to third parties at any time unless required by law or with parental consent.

We will not:

  • Give, rent or lease any personal or identifying personal information that you have provided us to any individual, organization or company.
  • Disclose student information to third parties for behavioural advertising or marketing.
  • Share information about a student’s results with any third party.
  • Share information about a school’s results with any third party.
  • Build personal profiles of the student other than for supporting educational purposes.

For how long is your information held?

Information is kept to provide access to the site and to support educational purposes. Information is kept until the registered users account is deleted or deletion is requested by the Registered User.

For any Registered User that deletes their account, any children accounts that they listed will also be deleted after a 90 day grace period. Children can keep their account by linking to another Registered User (parent) during the grade period.

How do registered users manage or delete their information?

  • Registered Users can access, update, review, or amend theirs or their children’s/student’s personal information.
  • Registered Users can permanently delete their personal information (the right to erasure).
  • Home Registered Users can request that their children’s personal information be amended by contacting privacy@studyladder.com.
  • Teachers can request that their student’s personal information be amended by contacting privacy@studyladder.com.
  • Home Registered Users can have their children’s personal information permanently deleted by contacting privacy@studyladder.com (the right to erasure).
  • Teachers can have their student’s accounts deleted by contacting privacy@studyladder.com (the right to erasure). Linked student accounts are given a grace period of 90 days to link to an active parent account for supervision before deletion.
  • When a parent’s account is deleted their children’s personal information and account is also deleted.
  • When a teacher’s account is deleted their student’s personal information and account is also deleted after 90 days if the student account is not linked to a parent account.

Security of personal information

Studyladder is committed to implementing technical and organizational strategies to take every reasonable step to protect and keep safe from unauthorized access personal information held by us.

Studyladder staff and contractors with access to personal information (Authorized Studyladder Staff) are required to comply with this privacy policy and their obligation of confidentiality.

No third party has access or is given access to any User’s personal information.

Data storage and security

The Studyladder website and its data is hosted and stored on servers leased from Amazon Web Services in their US/Oregon data centre.

Amazon Web Services are one of the largest hosting companies in the world and are certified compliant with a wide range of security and data protection standards. More details here: http://aws.amazon.com/compliance/

Studyladder backups and all student result data is encrypted before storage using certified industry standards.

Access to the Studyladder systems for software maintenance is only available via secure and encrypted channels. Access is only available to Authorized Studyladder Staff.

Service providers, subprocessors and other recipients

Studyladder engages the organisations listed below to operate, secure, support and provide its websites, applications and services. A provider described as a processor processes personal information on Studyladder’s behalf and under its instructions. When Studyladder processes personal information on behalf of a school or other customer that is the data controller, a provider engaged to assist with that processing is also a subprocessor. When acting as a processor, a provider may use the information only to provide its contracted services to Studyladder and not for its own advertising or other independent purposes.

A provider described as an independent controller determines its own purposes and means of processing for the relevant service and is responsible for meeting its own legal obligations. Examples in the table include payment processing, identity and security services, analytics, advertising measurement, embedded media and social-sharing functionality. Some providers perform different roles depending on the service used and its configuration.

For each provider, the table identifies its role, links to relevant privacy or data-processing information, describes the personal information processed and its purpose, explains Studyladder’s reason for using the provider, and identifies principal or other stated processing locations.

The data categories shown describe the maximum categories of personal information that may be processed through each service or integration. A provider does not receive every listed category about every user. Depending on the provider and service, information may be processed automatically as part of operating Studyladder or only when a particular feature is selected, loaded or used. Information may be disclosed by Studyladder, collected directly by the provider or generated through the user’s interaction with the service.

Where the GDPR or UK GDPR applies and Studyladder acts as the controller, Studyladder relies, as appropriate, on performance of a contract, compliance with legal obligations, legitimate interests in providing and securing the service, or consent. The Reason for use column describes Studyladder’s operational reason for engaging each provider; it does not itself identify a GDPR lawful basis. Where Studyladder acts as a processor for a school or other customer, that customer determines the applicable lawful basis and Studyladder processes the information under its instructions.

For school-managed accounts, the school is responsible for having appropriate authority to provide student information to Studyladder and for giving any required privacy notices or obtaining consent where consent is legally required. Studyladder remains responsible for meeting its own obligations as a processor. For parent-managed accounts, the parent or guardian provides the information and authorises the child’s use of the service, subject to applicable law.

Amazon Web Services, Inc. (AWS)

Role: Processor / subprocessor – primary system hosting and infrastructure

Privacy information
AWS data privacy information
Data processed
Account, student, learning, results, submitted content, support, email, log and network data.
Purpose
Hosting, databases, encrypted backups, content delivery, transactional email, monitoring and service security.
Reason for use
Service provision and security
Locations
United States, principally US West (Oregon), with some legacy storage in US West (Northern California). CloudFront edge delivery, email and operational support may involve AWS locations worldwide.

Google Cloud Platform

Google LLC and the applicable Google Cloud contracting affiliate

Role: Processor / subprocessor – backup storage and cloud operations

Privacy information
Google Cloud
Data processed
Encrypted backups of account, student, learning, results, submitted content and related service data.
Purpose
Encrypted backup storage, disaster recovery and restoration of the Studyladder service.
Reason for use
Service provision, data backup and security
Locations
Primary backup storage: Australia. Support, security and operational data may be processed in other countries where Google or its subprocessors operate, including the United States.

Google Sign-In and reCAPTCHA

Google LLC and the applicable Google affiliate, including Google Ireland Limited

Role: Processor and independent controller, depending on the service and configuration

Privacy information
Google Privacy Policy
Data processed
Google account profile information when Google Sign-In is selected, including name, email address and account identifier. reCAPTCHA may process IP address, device/browser information, cookies, referring page and interaction data.
Purpose
Authenticate users, prevent automated abuse and protect accounts and the Studyladder service.
Reason for use
Authentication and security
Locations
Worldwide, including the United States. Google states that it maintains servers and uses service providers around the world.

Google Analytics and advertising services

Google LLC and the applicable Google affiliate, including Google Ireland Limited

Role: Processor and independent controller, depending on the service and configuration

Privacy information
Google Privacy Policy
Data processed
IP address, device/browser information, cookies and similar identifiers, referring page, pages viewed, events, pseudonymous account identifier and general user category.
Purpose
Measure website and service usage, understand performance, and measure advertising campaigns where those services are enabled.
Reason for use
Analytics and advertising measurement
Locations
Worldwide, including the United States. Google states that it maintains servers and uses service providers around the world.

YouTube and Google-hosted content

Google LLC and the applicable Google affiliate, including Google Ireland Limited

Role: Independent embedded-content controller

Privacy information
Google Privacy Policy
Data processed
IP address, device/browser information, cookies, referring page and interactions with Google-hosted videos, fonts, icons or other embedded content.
Purpose
Display educational videos and other Google-hosted website content or assets.
Reason for use
Delivery of educational media and website content
Locations
Worldwide, including the United States. Google states that it maintains servers and uses service providers around the world.

Mailchimp Transactional (Mandrill)

The Rocket Science Group LLC, an Intuit company

Role: Processor / subprocessor

Privacy information
Mailchimp Data Processing Addendum
Data processed
Recipient name and email address, message content, and delivery, bounce, open or click information where enabled.
Purpose
Send and manage transactional service emails.
Reason for use
Service provision and transactional communications
Locations
United States and other countries in which Mailchimp, its affiliates and subprocessors operate.

Stripe Payments Australia Pty Ltd and applicable Stripe affiliates

Role: Processor and independent payment controller

Privacy information
Stripe Privacy Centre
Data processed
Purchaser name, email, account/customer identifiers, billing, subscription and transaction data, plus IP, device and fraud-prevention data. Card details entered into Stripe components are collected directly by Stripe.
Purpose
Process payments, administer subscriptions, prevent fraud and meet financial obligations.
Reason for use
Service provision, payment processing and fraud prevention
Locations
United States, Ireland and Stripe or provider locations worldwide. Stripe states that some authentication and security data may also be stored in India.

Vimeo.com, Inc.

Role: Independent embedded-video controller

Privacy information
Vimeo Privacy Policy
Data processed
IP address, browser/device, cookies, referring page and viewing interactions when a Vimeo player is loaded.
Purpose
Display requested video content and operate the embedded player.
Reason for use
Service provision and delivery of educational video content
Locations
United States and other countries in which Vimeo and its service providers operate.

Meta Platforms, Inc. and Meta Platforms Ireland Limited

Role: Independent social-plugin controller

Privacy information
Meta Privacy Policy
Data processed
IP address, device/browser, cookies, referring page and interaction data when a Facebook social plugin is loaded or used.
Purpose
Provide social sharing and related Facebook functionality.
Reason for use
Social sharing functionality
Locations
United States, Ireland and other locations in Meta’s global infrastructure and provider network.

Breach Response Protocols

Studyladder maintains an incident and data breach response protocol that includes procedures for containment, remediation, and user notification.

This approach ensures Studyladder can respond effectively to security incidents while protecting user data and maintaining service integrity.

Data Breach Notification

In the event of a data or security breach involving personal information, Studyladder will notify affected users, schools, or school boards directly by email in a timely manner.

Where required, the notification will include information on the nature of the breach, the types of information affected, and the steps Studyladder has taken to contain, mitigate, and remediate the incident.

Use of cookies on our websites.

Studyladder uses cookies only for the purposes of managing users’ membership and enabling services provided by Studyladder website.

How will Studyladder notify changes to this policy?

Studyladder’s Privacy Policy may be amended at any time, including changes, additions and deletions to comply with applicable laws, to reflect changes in our processes or for any other reason. Any Significant changes will be communicated to registered users by email. Users are also encouraged to check this Privacy Policy periodically to keep abreast of any changes.

How to contact Studyladder?

All requests for further information, concerns or questions regarding this privacy policy should be directed to Studyladder’s Data Security Officer at privacy@studyladder.com.

Updates

  • 26 August 2026: Added a service-provider and subprocessor register.
  • 12 February 2026: Removed from Data Breach notification - 'and in accordance with applicable legal and regulatory requirements'.
  • 11 February 2026: Added a section outlining Breach Response Protocols.
  • 11 February 2026: Added a section addressing Data Breach Notification procedures.
  • 11 February 2026: Added clarification that users will be notified by email when changes to this Privacy Policy occur.
Cookie Consent