PRIVACY POLICY

Your data,
protected.

FundEd is built for educational institutions. We take data privacy seriously — your student and payment data belongs to your institution alone.

Last updated: February 2026

Data We Collect

  • Student information: full name, roll number, department, and year of study.
  • Contact details: email addresses used for payment receipts and notifications.
  • Payment data: payment screenshots, amounts, event names, and timestamps.
  • Admin account data: name, email, hashed password, and role designation.
  • Usage data: login timestamps and action logs for security auditing.

How We Use Your Data

  • To facilitate and verify student payments within your institution.
  • To send automated email receipts and payment confirmation notifications.
  • To generate financial reports accessible only to the managing admin.
  • To power the student payment status check portal.
  • To detect fraudulent activity using AI-powered screenshot analysis.

Data Access & Scoping

  • Each admin can only access data they have created — student records, events, and payments are scoped to the creating admin.
  • Superadmins may access aggregate analytics but not individual payment screenshots.
  • Student status pages are protected by unique event-scoped links.
  • No cross-admin data leakage — strict database-level access control is enforced.

Data Security

  • All data is stored in an encrypted PostgreSQL database hosted on a secure cloud infrastructure.
  • Passwords are hashed using bcrypt and are never stored in plaintext.
  • All connections are encrypted in transit via HTTPS/TLS.
  • Payment screenshots are stored as base64-encoded data with no third-party hosting.

Data Retention & Deletion

  • Admins can delete individual student records, events, or payment entries at any time.
  • Deleted data is permanently removed from the database — there is no recycle bin.
  • Admin accounts can be deleted by a superadmin, removing all associated data.
  • We do not retain backups of deleted records beyond our database's automated 7-day snapshot window.

Third Parties

  • FundEd does not sell, rent, or share your data with any third-party advertising networks.
  • Email delivery is handled via a transactional email service (e.g., Nodemailer/SMTP). Email content is not stored by the provider.
  • No external analytics or tracking scripts are used on the dashboard.

Questions about your data?

Contact your institution's FundEd administrator or reach out to us at support@funded.com