Proudly Canadian - Supporting Quality Education in Canada

SECURITY & PRIVACY OVERVIEW



Last updated: 28 August 2026


This page summarises how ClassTrack protects institutional and student information. It is intended for the IT, privacy and procurement teams of the colleges and schools we serve. It is a summary — the binding terms are in our Data Processing Agreement and our Privacy Policy.


Operator


ClassTrack is operated by EDUWEB CONSULTING LTD., a company incorporated in British Columbia with its principal office at 3507-9981 Whalley Blvd, Surrey, BC, Canada V3T 0G6.


1. Data residency and hosting


ClassTrack is hosted in Canada. Our application servers, relational databases, cache, document store and file/object storage all run in the OVHcloud Beauharnois, Quebec (BHS) region.


Institutional records — student profiles, enrolment data, grades, attendance, documents and uploaded files — are stored in Canada and are not replicated outside Canada.


A small number of sub-processors, used only to deliver specific features, process limited data outside Canada. These are listed in section 6 below.


2. Tenant isolation


Each institution is provisioned with its own dedicated database, its own domain, its own background job workers and its own scheduled tasks. One institution's data is not stored in a shared table with another institution's data, and no application query path crosses tenant boundaries.


3. Authentication and access control


Multi-factor authentication (MFA). ClassTrack supports MFA using a time-based one-time password (TOTP) authenticator app — such as Microsoft Authenticator, Google Authenticator or Authy — as well as one-time codes delivered by email, with downloadable single-use recovery codes. MFA can be enforced by the institution independently for each role: students, staff, instructors and agents. Once enforced, a user in that role is required to enrol at next sign-in before reaching any other page.


Single sign-on (SSO). ClassTrack supports Microsoft Entra ID (Azure AD), Google Workspace and SAML 2.0 identity providers. When SSO is used, authentication — including any MFA and conditional access policy — is performed by the institution's own identity provider, and ClassTrack never receives the user's password.


Passwords. Where local accounts are used, passwords are never stored in readable form. They are stored as salted bcrypt hashes.


Authorisation. Access within the platform is governed by role-based permissions administered by the institution's own administrators, so staff see only the records their role permits.


4. Sending email from your own domain


Institutions may have ClassTrack send email from their own mailboxes. This is done through Microsoft or Google OAuth: the institution's administrator grants consent in their own tenant, and ClassTrack receives a limited, revocable token. We request send-only permissions (Mail.Send, User.Read, offline_access, openid, profile, email). ClassTrack cannot read inboxes, delete mail or access other Microsoft 365 or Google Workspace data. No mailbox password is ever requested, transmitted or stored, and the institution can revoke access at any time from its own admin console.


5. Encryption


In transit. All traffic between users and ClassTrack is served over HTTPS/TLS. Connections to third-party APIs are made over TLS.


At rest. Account passwords are stored as bcrypt hashes. Integration secrets and OAuth access and refresh tokens are encrypted in the database. Files are stored in OVHcloud object storage in Canada.


6. Sub-processors


The following third parties may process limited institutional data on our behalf. Each is engaged for a single, defined purpose.


Sub-processor Purpose Location
OVHcloud Application hosting, databases, file and object storage Canada (Beauharnois, QC)
SendGrid (Twilio Inc.) Transactional and notification email delivery United States
Twilio Inc. SMS and voice messaging United States
Stripe, Inc. Payment processing United States
Block, Inc. (Square) Payment processing United States
PayPal Holdings, Inc. Payment processing United States
Microsoft / Google Only where the institution connects its own Microsoft 365 or Google Workspace account. Data remains in the institution's own tenant. Institution's own tenant

Payment processors are used only where an institution enables online payments, and they receive only the data needed to process a transaction. ClassTrack does not store complete payment card numbers.


We will notify institutions before adding a new sub-processor that processes their data.


7. Use of institutional data


Student and staff records belonging to an institution are processed solely to provide the services set out in our agreement with that institution. They are never sold or rented, never used for advertising, marketing, profiling or audience targeting, and never shared with advertising networks or social media platforms.


8. Data retention and deletion


The institution remains the controller of its records and determines how long they are kept, in line with its own regulatory obligations — which, for a licensed institution, may require records to be retained for a defined statutory period. Records are retained for the term of the agreement. On termination, an institution may request an export of its data, and ClassTrack will delete the institution's data within 90 days of the request, except where retention is required by law. Backups are retained on a rolling schedule and expire on that schedule.


9. Breach notification


ClassTrack will notify the affected institution without undue delay after becoming aware of a personal data breach, as set out in clause 5.7 of our Data Processing Agreement. The notification will describe the nature of the breach, the categories and approximate number of individuals concerned, the likely consequences and the measures taken or proposed. ClassTrack will assist the institution in meeting its own notification obligations, including to the Office of the Information and Privacy Commissioner and to affected individuals.


10. Access, correction and privacy requests


Because the institution is the controller of its student and staff records, individuals should direct access, correction and deletion requests to their institution. ClassTrack will assist the institution in responding within the timeframes set by applicable law.


11. Contact


Security or privacy questions, including reports of a suspected vulnerability, may be sent to techsupport@classtrack.com.