Last updated September 2026. This is a starting template — have an attorney review before relying on it.
Privacy Policy
This policy explains what we collect and how we handle it, including the education records you store in GetESAPaid.
What we collect
- Account data: your name, email, and business details.
- Records you enter: student names, parent/account-holder names, services, dates, notes — used to generate and maintain your invoices and records.
- Payment workflow data: expected and received payout amounts, deposit dates/references, and an optional standardized invoice-rejection reason you record.
- Site usage: page and product-action events used to understand whether tools work and where users get stuck. We do not send student names, invoice content, payout references, or application selections as analytics event parameters.
- Billing data: handled by Dodo Payments; we store customer, subscription and payment references, confirmed amounts, currencies and receipt timestamps, never card numbers.
Optional invoice draft transfer
The free invoice tool keeps entries in the page until you request account saving. That action transfers an encrypted draft to GetESAPaid. It expires after 72 hours and expired drafts are removed by daily cleanup. Saving it as an invoice removes the temporary transfer copy. A payment interruption can temporarily preserve your unfinished form in your account session.
Children’s & education records
GetESAPaid may hold information about minors that you enter as part of your education records. We act as a processor of that data on your behalf. We do not sell it, use it for advertising, or share it except with the subprocessors needed to run the service (hosting, email, payments). You control this data and can export or delete it at any time.
Security
Data is encrypted in transit. Access is restricted to your account. You can permanently delete your account and all associated records from your profile settings, which removes your students and invoices.
Aggregate invoice outcome benchmark
If you record a standardized invoice-rejection reason, we may count that category in the public ESA invoice outcome benchmark. Nothing is published until the total sample reaches five reports, and each individual category is suppressed until it independently reaches five. If at least five valid invoices connect a recorded submission date to a payout date, we may publish only global calendar-day aggregates such as the median and 25th/75th percentiles. Invalid, negative, or over-365-day intervals are excluded. The benchmark does not publish student, parent, provider, invoice, state, rail, exact date, amount, payout reference, or free-text data.
Customer stories and publication consent
An authenticated customer may separately submit a display name, optional business name, provider type, state, quote, and outcome for possible publication on our customer stories page. Submission requires explicit written confirmation that the words are the customer’s own, contain no sensitive student or payment data, and may be published. A human reviews the story before publication. The customer can withdraw it from the submission page, which removes it from public display.
Your choices
Email us to access, correct, export, or delete your data. Marketing emails include an unsubscribe link; transactional emails (billing, security) are required for the service.