Skip to content
Back to home

Privacy Policy

Last updated: 21 July 2026.

iEasySR ("we", "us", "our") is a company registered in Australia. This Policy describes how we collect, use, share and protect personal information when you use the iEasySR platform ("Service"). By using the Service you agree to the practices described here.

1. Data controller

iEasySR is the data controller for account-level information (teacher profiles, billing records). For student data that you upload, you (the school owner or teacher) are the data controller and we act as a data processor on your instructions.

2. What we collect

  • Account information: full name, email address, bcrypt-hashed password, profile photo, MFA preference, and sign-in method (email/password or Google OAuth).
  • School and student data you upload: school name and details, student names and photos, parent email addresses, academic scores, and generated report cards.
  • Payment records: payment status, amount, currency, and the Stripe payment reference. Raw card data is handled exclusively by Stripe and is never stored on our servers.
  • Usage data: server logs (IP address, user-agent, timestamps) retained for security and abuse prevention.
  • Session cookies: encrypted JWT tokens required to keep you signed in (7-day lifetime).

3. How we use your information

  • To create and manage your account and authenticate your sessions.
  • To generate and deliver student report cards to the parent email addresses you provide.
  • To process payments via Stripe and maintain your billing history.
  • To send transactional emails (OTP codes, payment receipts, magic-link access for parents).
  • To detect and prevent abuse, fraud, and unauthorised access.
  • We do not sell your data or student data to third parties.
  • We do not use student data for advertising or profiling of any kind.

4. Third-party processors

We share data with the following sub-processors only to the extent necessary to operate the Service. Each is bound by appropriate data-protection terms.

  • Vercel — cloud hosting and serverless functions (United States). Processes all request traffic.
  • Neon — managed PostgreSQL database (United States). Stores account, school, student, and payment records.
  • Vercel Blob — object storage (United States). Stores profile photos and student photos.
  • Resend — transactional email delivery (United States). Receives recipient address and email body for each outbound email.
  • Stripe — payment processing (United States). Handles all card-level data under PCI-DSS compliance.
  • Google — optional OAuth sign-in. If you sign in with Google, your Google profile email and name are shared with us by Google.

5. Storage and security

  • Passwords are stored as bcrypt hashes — plaintext passwords are never stored or logged.
  • All data in transit is encrypted via TLS.
  • Uploaded files are stored in per-account folders in Vercel Blob with access controls.
  • Multi-factor authentication (OTP by email) is available and enabled by default.
  • We apply principle of least privilege for internal data access.

6. Data retention

  • Account data is retained for as long as your account is active.
  • Generated reports are retained until you delete them from the app, at which point they are permanently removed.
  • Payment records are retained for a minimum of 7 years to meet Australian financial record-keeping obligations.
  • Server logs are retained for up to 90 days.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export or delete your personal data. You can:

  • Access and edit your account information from your Profile page.
  • Delete reports directly from the dashboard.
  • Request account deletion — email support@ieasysr.com. All account data and associated student data is permanently deleted within 7 days.
  • Object or restrict processing by contacting us at the address below.

Australian residents may direct complaints to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

8. Children's data

The Service is used by teachers and school administrators. Student data (including minors) is uploaded by authorised school staff. You are responsible for ensuring that you have the appropriate consent or legal basis to process student data under the laws of your jurisdiction — including parental or guardian consent where required. We do not knowingly solicit information directly from minors.

9. Data breach notification

In the event of a data breach likely to cause serious harm, we will notify affected users and, where required, the Office of the Australian Information Commissioner within 72 hours of becoming aware of the breach. We will provide details of the breach and steps taken to mitigate it.

10. International transfers

Our sub-processors operate in the United States. By using the Service, you consent to your data being transferred to and processed in the United States under the data protection terms of each sub-processor.

11. Changes to this policy

We may update this Policy from time to time. Material changes will be communicated via the dashboard or email at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

12. Contact

Privacy questions, data requests, or complaints: support@ieasysr.com.