Last updated August 2026. This is a starting template — have an attorney review before relying on it.
Privacy Policy
This policy explains what we collect and how we handle it, including the education records you store in GetESAPaid.
What we collect
- Account data: your name, email, and business details.
- Records you enter: student names, parent/account-holder names, services, dates, notes — used to generate and maintain your invoices and records.
- Payment workflow data: expected and received payout amounts, deposit dates/references, and an optional standardized invoice-rejection reason you record.
- Site usage: page and product-action events used to understand whether tools work and where users get stuck. We do not send student names, invoice content, payout references, or application selections as analytics event parameters.
- Billing data: handled by Dodo Payments; we store only a customer/subscription reference, never card numbers.
Children’s & education records
GetESAPaid may hold information about minors that you enter as part of your education records. We act as a processor of that data on your behalf. We do not sell it, use it for advertising, or share it except with the subprocessors needed to run the service (hosting, email, payments). You control this data and can export or delete it at any time.
Security
Data is encrypted in transit. Access is restricted to your account. You can permanently delete your account and all associated records from your profile settings, which removes your students and invoices.
Aggregate rejection benchmark
If you record a standardized invoice-rejection reason, we may count that category in the public ESA invoice rejection benchmark. The benchmark does not publish student, parent, provider, invoice, state, date, amount, payout reference, or free-text data. Nothing is published until the total sample reaches five reports, and each individual category is suppressed until it independently reaches five.
Your choices
Email us to access, correct, export, or delete your data. Marketing emails include an unsubscribe link; transactional emails (billing, security) are required for the service.