For districts: how RallyOrder fits your rules
Merchant of record, money flow, data posture, and access control: the district-level design, stated plainly.
District offices don’t evaluate software the way users do, and they shouldn’t. You’re underwriting risk: money handling, student data, access control, and whether a vendor will still answer the phone in three years. Here’s RallyOrder’s district-level design, stated plainly.
The money: your school is the merchant
Every school on RallyOrder operates as its own merchant of record. Sales settle directly to the school-controlled account the district designates, under the financial procedures you already enforce. RallyOrder never holds, pools, or routes the money through our own accounts.
That single design choice does most of the compliance work: store revenue is school money in school accounts from the moment of sale, visible to your finance office through the banking relationships you already audit. There’s no vendor-held balance to reconcile and no new counterparty risk added to student activity funds.
Card processing runs on Stripe. Card data moves from the reader into Stripe’s PCI-certified infrastructure and never touches RallyOrder’s servers, the register screen, or a student’s hands.
The data: students are never the product
We don’t sell student data. We don’t share it, monetize it, or repurpose it beyond what directly serves the educational experience. That’s a founding principle, it’s written into our agreements, and it isn’t a policy we plan to revisit.
The platform is built for FERPA and COPPA from the ground up, we collect the minimum needed to run a store and teach from its data, and we’ll walk your team through the full picture whenever you’re ready. The store’s reporting is about the store (sales, inventory, margins), not about surveilling individual kids.
The access model: separation of duties, enforced
The same control structure your district requires everywhere money moves, built into the platform rather than promised by a policy binder:
- Advisors configure permissions. A named adult controls who has access to set and view inventory, pricing, reporting, and refunds.
- Students operate. Selling is open to the crew; sensitive actions (refunds are the everyday example) sit behind the permission structure.
- Devices are enrolled, not logged into. Registers pair to a specific store and can be revoked remotely the day one goes missing. There are no shared passwords circulating through a student body.
- Everything is recorded. Every transaction carries a full record your auditors can review whenever they ask, viewable in HomeRoom or exported to CSV. The data is yours, with no paywalls or extra fees.
The blast radius: each school stands alone
Each school’s store, data, and money path are isolated to that school. One school’s operation can’t see, touch, or affect another’s. For a district, that means a pilot at one high school is genuinely contained, and growth to a second school is a second clean setup rather than a shared-risk expansion.
The posture: meet your process where it is
We work inside district procurement, not around it. That means real answers in writing, security and data documentation for your review, the demo call with your finance office included, and agreement language your office can mark up without a fight about boilerplate.
Our standing offer to any district office: send us the vendor questionnaire you wish every vendor had to answer, and we’ll answer it. Start here.