Last updated September 2026. This is a starting template — have an attorney review before relying on it.

Privacy Policy

This policy explains what we collect and how we handle it, including the education records you store in GetESAPaid.

What we collect

Optional invoice draft transfer

The free invoice tool keeps entries in the page until you request account saving. That action transfers an encrypted draft to GetESAPaid. It expires after 72 hours and expired drafts are removed by daily cleanup. Saving it as an invoice removes the temporary transfer copy. A payment interruption can temporarily preserve your unfinished form in your account session.

Children’s & education records

GetESAPaid may hold information about minors that you enter as part of your education records. We act as a processor of that data on your behalf. We do not sell it, use it for advertising, or share it except with the subprocessors needed to run the service (hosting, email, payments). You control this data and can export or delete it at any time.

Security

Data is encrypted in transit. Access is restricted to your account. You can permanently delete your account and all associated records from your profile settings, which removes your students and invoices.

Aggregate invoice outcome benchmark

If you record a standardized invoice-rejection reason, we may count that category in the public ESA invoice outcome benchmark. Nothing is published until the total sample reaches five reports, and each individual category is suppressed until it independently reaches five. If at least five valid invoices connect a recorded submission date to a payout date, we may publish only global calendar-day aggregates such as the median and 25th/75th percentiles. Invalid, negative, or over-365-day intervals are excluded. The benchmark does not publish student, parent, provider, invoice, state, rail, exact date, amount, payout reference, or free-text data.

Customer stories and publication consent

An authenticated customer may separately submit a display name, optional business name, provider type, state, quote, and outcome for possible publication on our customer stories page. Submission requires explicit written confirmation that the words are the customer’s own, contain no sensitive student or payment data, and may be published. A human reviews the story before publication. The customer can withdraw it from the submission page, which removes it from public display.

Your choices

Email us to access, correct, export, or delete your data. Marketing emails include an unsubscribe link; transactional emails (billing, security) are required for the service.

privacy@getesapaid.com