EduOnTrack LLC uses the providers below to operate EduOnTrack, DeviceOnTrack, and ClassOnTrack. Each provider receives only the information reasonably needed for its listed function. This page does not list ordinary open-source libraries, development tools, or internal tools that do not receive production customer information. It also does not publish account credentials, project identifiers, or private system endpoints.
Cloudflare
Products: EduOnTrack, DeviceOnTrack, and ClassOnTrack.
Cloudflare provides website and application delivery, server execution, database services used by DeviceOnTrack, traffic security, rate limiting, scheduled processing, and operational request logging. Depending on the product and request, Cloudflare may process technical request information, account or organization identifiers, managed-device records, classroom session records, billing workflow records, and other information needed to run the requested application function.
Supabase
Product: ClassOnTrack.
Supabase provides teacher authentication, the ClassOnTrack application database, realtime classroom updates, and private storage for requested lesson snapshots. It processes teacher account and organization information, lesson and session records, participant display names and activity, scoped extension-session records, and snapshots requested during a session.
Google Services and Firebase
Products: DeviceOnTrack and ClassOnTrack.
DeviceOnTrack uses Firebase Authentication and Google sign-in for approved administrator access, Firebase Cloud Messaging for configured device-sync notifications, and Firebase Analytics for basic dashboard usage and technical measurement when supported by the administrator's browser. This may involve administrator identity, authentication identifiers, device-messaging identifiers, page views, browser or device properties, and automatically generated usage events. ClassOnTrack uses Google Identity Services when a teacher chooses optional Google sign-in. EduOnTrack products do not receive users' Google passwords.
Stripe
Products: DeviceOnTrack and ClassOnTrack.
Stripe provides customer, subscription, quote, invoice, payment, and tax-related billing functions. Stripe processes billing contacts, billing addresses, payment methods, transaction information, tax status, and the customer or subscription identifiers needed for billing. EduOnTrack products do not store complete payment-card numbers entered into Stripe.
Brevo
Products: DeviceOnTrack and ClassOnTrack.
Brevo delivers transactional email, including requested quotes, invoice notices, account communications, alerts, and renewal reminders. It processes the recipient's email address and name when available, delivery information, and the content needed for the applicable message.
OpenStreetMap Foundation Services
Product: DeviceOnTrack.
DeviceOnTrack currently loads base-map tiles directly from OpenStreetMap's public tile service. When an administrator views a map, the administrator's browser sends ordinary request information, including IP address, request headers, and the tile coordinates and zoom level for the visible map area. DeviceOnTrack draws device markers and device details separately, so serial numbers, asset tags, account emails, and other device records are not included in tile requests.
DeviceOnTrack also uses the public Nominatim reverse-geocoding service to convert a reported latitude and longitude into a nearest readable address. The lookup includes the coordinates and application-identifying request information, but not the device serial number, asset tag, account email, or organization name. OpenStreetMap Foundation operates these as public external services under its own terms and privacy policy, not as an EduOnTrack customer database.
Sentry
Product: DeviceOnTrack, when enabled.
Sentry receives application error and limited performance information used to diagnose failures and maintain reliability. DeviceOnTrack disables Sentry's default collection of personally identifying information in the web application. Error details may still contain technical context associated with the failed operation, so access is limited to troubleshooting and security purposes.
Upstash
Product: ClassOnTrack, only when the fallback is configured.
Upstash may provide distributed request rate limiting when the primary platform rate limiter is unavailable or not configured. It receives a scoped rate-limit key and counters needed to determine whether a request limit has been reached. It does not receive lesson content or snapshots through this function.
Changes and School Requests
Providers and product configurations may change as services are improved. We will update this page when a production provider begins or stops receiving information in a way that materially changes these descriptions. Schools and districts may contact us for the current list, product-specific privacy information, or available data-processing terms before deployment.
Contact
Questions about providers or product data practices may be sent to privacy@eduontrack.com.