Privacy Policy

Effective: April 27, 2026 · Last updated: May 14, 2026

Cascade Software Solutions LLC, an Oregon limited liability company (“BellPlan,” “we,” or “us”) provides school-operations software to K-12 schools, districts, and their staff. This Privacy Policy describes the personal data we collect, how we use it, and the choices school administrators and staff have. It is written for school administrators and procurement reviewers as well as the staff and educators who use BellPlan day to day.

1. Data we collect

When a school onboards BellPlan, we collect basic operational data so the product can function: your school’s name, address, academic calendar dates, and the names + work email addresses of staff your school adds to the platform. We also collect content your staff creates in BellPlan — tasks, events, departments, comments, and uploaded attachments — in order to render and store that content.

We do not collect student records, education records as defined by FERPA, or any data covered by COPPA from children under 13. BellPlan is a staff-and-administrator-facing product. Schools may not upload student PII to BellPlan, and our terms prohibit that use.

2. How we use your data

We use the data your school provides only to:

  • Operate, maintain, and improve the BellPlan service;
  • Send transactional notifications (task assignments, kickoff reminders, overdue alerts) to staff who opt in;
  • Provide customer support to school administrators when they request it;
  • Detect and prevent fraud, abuse, and security incidents on the platform;
  • Comply with our legal obligations.

We do not sell personal data. We do not share your school’s data with advertising networks, data brokers, or any third party for marketing purposes.

3. Service providers (subprocessors)

We use a small set of vendors to run BellPlan. Each is contractually bound to use your data only to provide service to us and to maintain comparable security and confidentiality protections. The current list is:

  • Supabase (database + authentication hosting)
  • Vercel (web application hosting + edge delivery)
  • Resend (transactional email delivery)
  • Stripe (subscription billing; billing-contact data and payment tokens only, no access to school operational data)
  • Sentry (error reporting and diagnostics)
  • PostHog (product analytics on usage events; no PII beyond a hashed user identifier)

The canonical, always-current list — with the region and category of data each vendor processes — is published at bellplan.app/legal/subprocessors. We will provide thirty (30) days’ notice before adding or materially changing it. School administrators receive that notice by email and can object via the contact below.

4. Data residency and security

Production data is hosted in the United States (Supabase “East US” region). BellPlan is currently offered only to schools located in the United States; we do not market or design the service for schools in jurisdictions with cross-border data-transfer regimes (e.g., the European Union or United Kingdom). All traffic to BellPlan is encrypted via TLS 1.2 or higher. Data at rest is encrypted with AES-256. Access to production systems is limited to BellPlan personnel who require it to operate the service, and is logged.

5. Retention and deletion on request

We retain school data for as long as your school maintains an active BellPlan subscription. When a subscription ends, we retain data for up to ninety (90) days to allow for restoration if the school renews, after which we delete the data on a rolling basis.

A school administrator may request export or deletion of school data at any time. For verified requests, we will deliver a machine-readable export within five (5) business days and complete deletion from production systems within thirty (30) days, except where we are legally required to retain specific records. Encrypted backups containing deleted data cycle out within an additional thirty (30) days on the normal backup-retention schedule. We will confirm completion in writing.

6. Your rights

Depending on where you and your school operate, applicable law may give you rights to access, correct, port, or delete personal data we hold about you. The fastest path for staff is to ask your school administrator, who has direct access to your account in BellPlan and can fulfill most requests in-product. For requests that require our involvement, contact us at the address below.

7. FERPA + COPPA posture

BellPlan is designed for school operations — not student instruction. We do not knowingly collect or process FERPA-covered education records or COPPA-covered data from children. If a school believes it has inadvertently uploaded such data, please contact us immediately so we can purge it.

8. Cookies + tracking

BellPlan uses session cookies that are required for authentication and a small set of first-party analytics events that help us understand how the product is used (which pages are visited, which actions are triggered). We do not use third-party advertising cookies.

The cookies we set:

  • Authentication — session cookies issued by our authentication provider (Supabase). Required for the service to function. Cleared on sign out.
  • cookie_consent — remembers that you dismissed the cookie banner, so we do not show it on every page load. Set for one (1) year.
  • First-party analytics — PostHog uses a hashed per-user identifier and an anonymous device cookie to attribute page views and actions across a session. No other personal data is sent to PostHog and no cross-site tracking occurs.

9. Changes to this policy

We may update this policy from time to time. When we make material changes we’ll notify school administrators by email at least thirty (30) days before the changes take effect. The latest version will always live at this URL.

10. Contact

Questions, requests, or concerns about this policy should be directed to privacy@bellplan.app. We aim to respond within five (5) business days.