STAGE DRAFT — status: draft-for-riley-review · scheduled Sep 8, 2026 · not on production

Compliance & Safety

Student data and the school store: the FERPA and COPPA questions

The two federal privacy laws that follow student data into any software a school adopts, what they require, and the questions to put in writing to any vendor. Including us.

When a school store moves onto software, a specific question lands on someone’s desk, usually the district’s: student data is about to flow through a vendor’s system. Which laws follow it, and who’s on the hook?

Two federal laws, and “who’s on the hook” has a short answer: the school. That answer is the reason this post exists, because it changes how you should read every vendor agreement put in front of you. Including ours.

FERPA, plainly

The Family Educational Rights and Privacy Act protects the records schools keep about students, and it binds the school, as a condition of federal funding. Vendors don’t get FERPA obligations by default; they get access to student information through an exception the school grants, most commonly the school-official exception, and that exception has conditions the school is responsible for enforcing:

  • The vendor performs a function the school would otherwise use its own staff for.
  • The vendor has a legitimate educational interest in the data it touches.
  • The school maintains direct control over the vendor’s use and maintenance of the records.
  • The vendor uses the data only for the authorized purpose and does not re-disclose it.

Read that list again as a district would: it’s a vendor requirements document. A school can only extend the exception to a vendor whose data practices actually fit inside those four conditions, and the fit has to survive in writing, in the agreement, in terms the district can enforce. FERPA compliance is a posture the school and vendor hold together, and the vendor’s paperwork either makes that posture easy to hold or impossible.

COPPA, plainly

The Children’s Online Privacy Protection Act is the FTC’s rule for online services that collect personal information from children under 13. It was substantially strengthened in 2025, with full compliance required as of April 2026: a broader definition of personal information, separate opt-in consent before children’s data goes to third parties (targeted advertising most of all), limits on how long data can be retained, and a required written security program.

The part that matters for schools: the FTC permits a school to consent on parents’ behalf only when the vendor uses the data solely for educational purposes, and not for any commercial purpose. That’s the whole deal. The legal basis a school relies on holds exactly as long as the vendor’s use of student data stays inside the educational purpose, and evaporates the moment that data serves the vendor’s commerce instead.

For a high school store the under-13 question is narrow. For the middle school programs that run stores, it’s live. Either way, the “solely educational, never commercial” line is the right standard to hold any school software to, because it’s the standard the school’s own permission structure depends on.

What this has to do with a cash register

More than it first appears. A student-run store puts students on both sides of the counter: student operators have accounts, logins, and activity records in whatever system the store runs on, and the store itself is a class activity, which means its records live in an educational context. The moment a system knows which student rang which sale, it’s holding information about students, and the questions above are on the table.

Where general-purpose software fits

Here’s the structural fact worth understanding, stated without villains: commerce platforms are built for merchants, and their data practices are written for that market. A typical commerce privacy policy describes analytics, marketing uses, product improvement, affiliate and partner sharing, and advertising measurement, because those are normal, legitimate practices in the merchant economy. That’s the business those tools are built for, and they’re good at it.

None of that makes a commerce platform a bad actor. It makes it a commercial actor, with terms drafted for a customer who is a business, at a moment when your signature is standing in for students. The school-official exception’s four conditions, and COPPA’s educational-purpose-only line, were not design inputs for software built to serve coffee shops, and the compliance analysis doesn’t complete itself just because a vendor is large and reputable. The obligations stay with the school either way.

So run the test that settles it in five minutes: open the privacy policy of any system your store’s student data would touch, and search for the words “student,” “FERPA,” and “COPPA.” If they appear, read what’s promised and bring it to your counsel. If they don’t appear, that’s your answer about who the document was written for, and the full weight of the compliance analysis is yours to construct alone.

The questions to put in writing

To any vendor, ours included:

  1. What do you collect about student users, exactly? The full list, not the summary.
  2. Will you sign a data privacy agreement that satisfies the school-official exception: our direct control, your use limited to the authorized educational purpose, no re-disclosure?
  3. Will you commit contractually to never selling, sharing, or monetizing student data? Yes or no reads fast.
  4. Where does student data flow? Analytics providers, advertising systems, model training, “partners”: names and purposes.
  5. What are your retention and deletion terms? When we leave, what happens to the records, and how fast?
  6. Do you meet our state’s student data privacy law? Most states now have one, and several require specific contract terms.

Ask in writing, and weigh the character of the answers along with the content: specific beats smooth, and a vendor comfortable with question 3 answers it in one sentence.

Our answers, on the record

RallyOrder was built for FERPA and COPPA from the ground up. We collect the minimum needed to run a store and teach from its data. We don’t sell student data, we don’t share it, and we don’t monetize it beyond what directly serves the educational experience; that’s a founding principle, it’s written into our agreements, and it isn’t a policy we plan to revisit. And we’ll walk your counsel through all of it, question by question, whenever they’re ready: start here.

Your students run a real business. The data it generates should answer to the same standard everything else in your building answers to: it exists to teach, and for no other reason.

Compliance & Safety ← All posts

Keep reading