Privacy Policy

Who we are

The MicroSchool Lab is a Virginia-registered DBA of Create Business Solutions, LLC, a Virginia limited liability company. Create Business Solutions, LLC operates the service and is the controller of the personal information described below. In this policy, "MicroSchool Lab," "we," "us," and "our" mean Create Business Solutions, LLC doing business as The MicroSchool Lab.

What we collect

From founders and school administrators. Account information (name and email), your Supabase authentication id, your Stripe customer id, and your inputs to the planning, classifier, and operating tools (including business-plan and financial-projection data). We also collect AI chat inputs and outputs, telemetry such as page views and feature usage, and network/security metadata including IP address and user-agent for abuse prevention.

From parents. When a school invites you to use the parent portal, we collect your name, email address, phone number (if you provide it), the names of the students associated with your account, payment records related to tuition or fees, and your interactions with messages, events, and forms shared by the school.

From or about students (collected by schools on the students' behalf — see "Children and student data" below). Student name, grade level, photograph (if uploaded), academic records (assignments, grades), attendance, login credentials for the student portal where enabled by the school, and — where the school chooses to record them — health information including allergies, dietary restrictions, and medications, as well as designated emergency contacts and approved-pickup individuals.

Payment data. Payment-card data is processed and stored by Stripe. We do not store card numbers on our systems. We retain transaction metadata (amount, date, status, the last four digits of the card, the Stripe customer id) for accounting, support, and tax reporting purposes.

Subprocessors

We use the following named subprocessors to provide the service. Each subprocessor receives only the personal information necessary to perform its function and is contractually obligated to handle personal information consistent with this policy.

We will provide at least thirty (30) days' advance notice in this policy of changes to the list of subprocessors. Continued use of the service after the notice period constitutes acceptance.

Sharing with microschool networks and service providers

When you use the free operator model classifier on our website, you can tick a box that reads: "Also share my answers and email with microschool networks and service providers who may contact me about my program." The box is unticked unless you tick it, and your result does not depend on it.

If you tick it, we may share the answers you gave the classifier, the state you named, the result you received, your email address, and your name (if you gave one) with microschool networks, school-launch organizations, and service providers that work with microschool founders, such as insurance, curriculum, facilities, legal, and accounting providers. They may contact you about your program. Under the California Consumer Privacy Act and similar state laws, sharing with a third party that may use the information for its own purposes can count as a "sale" or "sharing" of personal information, so we do it only with your opt-in, and we record the time you gave it.

The form that emails you when a law changes in your state carries the same box, worded for what that form collects: "Also share my email and state with microschool networks and service providers who may contact me about my program." It is unticked unless you tick it, and your alerts do not depend on it. If you tick it, we may share your email address and the state you chose with the same kinds of recipients, and we record the time you gave it.

If you leave the box unticked, we do not share your classifier answers or contact details with anyone outside the subprocessors listed above. This section never applies to parent, student, or school-record information, which stays governed by "Children and student data" below.

Do not sell or share my information

You can withdraw your consent, or ask us not to sell or share your personal information, at any time by emailing privacy@themicroschoollab.com from the address you gave us with the subject "Do not sell or share". We will stop sharing within fifteen (15) business days and, where applicable law requires it, tell the recipients we have already shared with that you have opted out. Withdrawing consent does not affect any sharing that took place before we received your request.

CCPA rights (California residents)

California residents may request to know, delete, and correct personal information, and may opt out of the sale or sharing of personal information. The only sale or sharing we do is the opt-in described in "Sharing with microschool networks and service providers" above; to opt out, follow "Do not sell or share my information" above or contact privacy@themicroschoollab.com. We do not sell or share personal information in any other way.

VCDPA rights (Virginia residents)

Virginia residents may request to know, delete, and correct personal data, and may opt out of targeted processing where applicable. To exercise VCDPA rights, contact privacy@themicroschoollab.com.

Retention

We retain account data during your active subscription and for 2 years afterward. On a verified deletion request, we delete applicable personal data within 30 days, unless a longer period is required by law.

Cookies

We use essential cookies required for authentication session continuity and analytics cookies for product measurement. Analytics cookies include first-party product usage analytics. We do not use cross-site tracking cookies.

Children and student data

The MicroSchool Lab is a service provided to schools and microschool founders. Founders, parents, and school staff using our service must be at least 13 years old. We do not knowingly collect personal information directly from children under 13 through founder, parent, or staff accounts.

Student portal and student records. Schools using our service may invite students — including students under the age of 13 — to use a school-managed student portal and may upload student records (including academic records, health information, and emergency contacts) on those students' behalf. When schools do this, we act as a service provider operating under the school's direction and the school-consent exception under the Children's Online Privacy Protection Act ("COPPA") and its implementing regulations at 16 C.F.R. Part 312.

What this means in practice.

Parents. If you are a parent or guardian and believe your child's information has been collected outside the school-consent framework, or you wish to review or request deletion of your child's records held in our service, please contact your school first; the school is the records-management authority for your child's account. If the school is unable or unwilling to assist, you may contact us at privacy@themicroschoollab.com and we will work with the school to address your request.

Health information

Schools using our service may upload student health information including allergies, dietary restrictions, medications, and emergency-contact details. We collect and process this information solely on the school's behalf, for purposes of the school's classroom safety, meal planning, and emergency response.

The MicroSchool Lab is not a HIPAA covered entity or business associate, and the service is not designed for the storage of clinical or medical-records data. We treat student health information as Confidential Information and apply the same security controls (encryption in transit and at rest, access controls, audit logging) as we apply to other student records. The school is responsible for obtaining any consents required under applicable law before uploading student health information.

Security

We use encryption in transit and provider-managed encryption at rest, access controls, and authentication safeguards appropriate to the information we process. Password credentials are hashed through Supabase authentication systems. If we confirm a data breach affecting personal information, we will notify affected users as required by applicable law.

International transfers

Depending on your region and selected services, data may be processed or stored in the United States or the European Union through Supabase infrastructure and OpenAI processing systems. Where required, we apply appropriate contractual and technical safeguards for international data transfers.

Version history