Privacy Policy
Last updated:
Pathfinch LLC (“Pathfinch,” “we,” “us”) is a California limited liability company. This policy explains what personal information we collect, why we collect it, how we protect it, and how long we keep it.
1. Who we are and what this policy covers
This policy covers three situations in which you might share information with us:
- This website, pathfinch.com.
- TripBridge™, our field-trip chat product at tripbridge.chat, in summary.
- Consulting and client work we do for other companies.
TripBridge is not yet generally available. When it launches, the product’s own privacy policy at tripbridge.chat/privacy will be the authoritative document for it, and the summary in section 3 is provided for convenience. If the two ever differ, the product policy controls.
2. This website (pathfinch.com)
This website is a set of static pages. It has no accounts, no sign-in, no forms, and no comments. It does not set cookies, and it does not use analytics, advertising, or tracking of any kind. Fonts and images are served from our own domain, so viewing a page does not send a request to any third party.
Server logs. This website is served by a hosting provider that records standard technical details of each request: the network (IP) address it came from, the browser and device type, the page requested, the page that linked to it, and the time. We use these logs only to operate and secure the site and to diagnose problems. They are kept under the hosting provider’s standard retention period and are not combined with any other information about you.
Email you send us. If you email us, we keep your message and our reply for as long as we need them to handle your request and any follow-up. Our mailboxes are hosted by Zoho Mail, which processes that email on our behalf.
Do Not Track. Because this website does not track visitors, it treats every browser the same whether or not a “Do Not Track” signal is sent.
Links to other sites. This site may link to other sites. Each has its own privacy policy, and this policy does not cover them.
3. TripBridge (summary)
TripBridge lets a teacher run a temporary, moderated chat room for a school field trip without sharing a personal phone number. TripBridge is pre-launch and not yet generally available; the product’s own policy, published at tripbridge.chat/privacy when it launches, will cover it in full and may change before then. In summary, as the product is designed today:
Roles
The school, acting through the teacher who creates a trip, is the data controller. Pathfinch LLC, which operates TripBridge, is the data processor: we handle information on the school’s behalf, under its direction, solely to provide the service. Under the U.S. Children’s Online Privacy Protection Act (COPPA) we rely on the school-consent exception, under which a school may authorize the collection of students’ information for a school-directed educational purpose. When a teacher registers, they affirm that they are authorized by their school and that the school has obtained, or will obtain, any required parental consent.
Telling your school
When a teacher creates their first trip we email the school administrator they identify. The email says which teacher set up the room, what we collect from students, how long we keep it, and how to reach us. It gives that administrator one link to acknowledge the notice and one to tell us they were not aware of the room. If they tell us they were not aware of it, we lock that teacher’s trips and stop them creating new ones until it is sorted out. We keep a record that the notice was sent and what the answer was, including the date of the answer and basic request details such as browser and network address, so the school, not only the teacher, is genuinely on notice. Some states also require a signed agreement with the school district before a service like ours may collect student information at all; where that applies, we do not let a trip start until the agreement is in place.
What is collected from students
- A username the student chooses when joining a trip. Students do not create accounts and are not asked for a real name. A session identity is kept for each student so that staff can moderate the room and remove someone if needed.
- The messages the student sends in the trip room or in direct messages to staff. Message content is encrypted while stored.
- A random device identifier stored by the browser on the device. It is used, on a best-effort basis, to help keep the room safe and to send notifications, and it is not a security control. It is not tied to the hardware, is not used to track anyone across other sites or for advertising, and goes away when the browser’s site data is cleared.
TripBridge does not collect a student’s email address, phone number, real name, or date of birth, and it runs no advertising or analytics trackers. A student’s network (IP) address is not kept in their record or alongside their messages and never reaches a school; as on any web service the servers see it in order to answer a request and use it briefly to limit abuse, and it is not used to identify anyone.
What is collected from teachers and chaperones
How the teacher signs in: either an email address and a securely hashed password (the password itself is never stored), or a Google or Microsoft account, in which case TripBridge receives the name, email address, and a stable account identifier from that provider and never receives the password. Signing in that way also tells that provider the teacher uses the product. Also a display name and optional honorific, and a timezone. Also the school, district, or organization the teacher identifies when they register: its name, its state, and whether it is a public school district, a private or parochial school, or a group that is not a school. Where a teacher picks their school from the public federal school directory, its directory id is kept as well; that search runs against a copy of the directory on our own servers, so typing a school name sends nothing to anyone else. When they create their first trip we keep the administrator email address they give us for that organization, and the age range they declare for each trip. Finally, a record of the teacher’s acceptance of the product’s terms: the version accepted, the date and time, and basic request details such as browser and network address.
What is collected from school administrators
A school administrator has no account and is not a user, but the safeguards above are addressed to them, so a small amount of information is held: the administrator email address a teacher gives for their school, or the address a signed district agreement names; their answer to the notice above, its date, and basic request details such as browser and network address; and, when a school asks us to delete a trip or release a trip’s oversight record, the name and email address of the person who asked, what they asked for, and what we did. These records are the evidence that a school was told and that we acted on what it said. None of them contains anything a student wrote.
Location pins
Staff can share a location pin in a trip room, such as a meeting point, that they choose on a map or from their own current position. To center its map, the app checks the staff device’s location when the sharing dialog is opened and when the “use my location” button is used; it never checks location in the background. Students do not share their location. Pin labels are encrypted while stored. Map imagery comes from an independent map service, which receives the ordinary technical details of any web request (such as the device’s network address) and the map area being shown, but never a user’s identity, the trip, or any message content. When a staff member searches for a place, the typed text and the approximate map area are sent to a place-search (geocoding) service; that request travels through TripBridge’s own server, so the search service never receives who was searching, and recent results are cached briefly on that server.
Payments
Billing applies only to teacher and staff accounts on a paid plan. No student information is ever involved in billing. Payments are processed by Stripe, which handles card details directly under its own privacy policy; we never see or store card numbers. We keep the billing contact for the account, the plan and subscription status, and a payment reference from Stripe.
How information is used and shared
Information is used to run the trip room, to keep it safe (automatic filtering of inappropriate language, limits on how quickly messages can be sent, and staff tools to rename, remove, or ban a participant), to maintain the school’s compliance record, and to send notifications a member has opted into. Chat content is visible within a trip to that trip’s members according to the room’s rules: when a teacher enables the group chat, a student’s messages there are visible to the whole trip, and a direct message is always between one student and staff. Students can never send a direct message to another student. The school itself is the other reader: a school may ask us to release a trip’s oversight record to an administrator it names, as described below. Personal information is never sold and never used for advertising. TripBridge runs on servers and a database we operate ourselves, so no hosting company holds trip information; beyond the school, it is shared only with the independent map and place-search services described above (for location pins only), our email provider, our payment processor for staff subscriptions, the notification services a browser or device maker operates, when required by law, or as part of a sale or reorganization of the business, subject to the product policy. Our own personnel can reach account and school information in order to run the service and act on a school’s written instructions; that access is limited to what those tasks require, every administrative action is logged, and the internal administration screens are built so that no student username, message, or device identifier can be reached through them.
Security
Message content and location-pin labels are encrypted while stored, with a separate encryption key for each trip. Information is encrypted in transit using HTTPS. This is not end-to-end encryption: TripBridge’s servers can read message content because they must, in order to filter inappropriate content and to produce the school’s oversight record.
Retention and deletion
Retention is mandatory, automated, and bounded. There is no option to keep a trip’s data indefinitely. After a trip ends it becomes read-only, is held briefly in a recoverable state, and is then permanently deleted. The total time from the end of a trip to permanent deletion is capped at 90 days; a teacher can shorten it but never extend it. When a trip is permanently deleted, its encryption key is destroyed as well. Only one thing can pause that schedule: a legal requirement to preserve data, such as a preservation order. It is rare, it is not something we choose, and deletion completes once the requirement ends. A few compliance records outlive the trip, and are meant to: that a school was notified and what it answered, that a teacher affirmed their authorization at each trip, that a school asked for a deletion or a release and what we did, and any signed agreement with a district. None of them contains a student’s username or anything a student wrote.
The school’s oversight record
Before a trip’s data is deleted, a full oversight record of the trip can be produced. It is the school’s copy: the moderation and activity history and the complete chat transcript, including private direct messages between students and staff and messages that were deleted (each clearly marked). The record is decrypted into plain, readable text and delivered through a secure, expiring link. There are exactly two ways to obtain it, and both belong to the school. The teacher who owns the trip may download it, if the trip allows the export. And the school may ask us in writing to release the same record to an administrator it names, whether or not the teacher is still available and whether or not they agree, so a teacher cannot switch off the school’s access to it.
Push notifications
A member may opt in to notifications for announcements, direct messages, or pins. By default a notification is generic and does not include message content. Notifications are delivered through the browser or device maker’s standard notification service and can be turned off at any time in the device’s settings.
Requests about a student
Because the school is the data controller, a parent or school official can direct a request about a specific student’s data to the teacher who ran the trip, or to us at support@tripbridge.chat. A school does not have to go through the teacher. On a school’s written request we will delete a named trip’s data, stopping the room the day we receive the request and confirming once the deletion is done, and we will release that trip’s oversight record to an administrator the school names. A school may also ask us to stop its use of the service altogether. The one thing that can delay a deletion is a legal requirement to preserve the data; where that happens we tell the school and delete it once the requirement ends.
4. Consulting and client work
When a company asks about, or engages us for, consulting or software work, we collect the business contact details needed to run the engagement: names, work email addresses and phone numbers, company names, and billing details for invoicing. We use them to scope, deliver, and invoice the work, and we keep them for the length of the engagement and for as long afterwards as tax and accounting rules require.
Project materials a client provides (code, documents, credentials, data, and any access we are granted to their systems or cloud accounts) are handled under the client’s contract or non-disclosure agreement, used only for that engagement, and returned, revoked, or deleted as that agreement says. Consulting engagements do not involve TripBridge student data.
The business tools we use to run the company (email, document storage, invoicing and accounting) process this information on our behalf. We will name them on request.
5. Children’s privacy
This website is not directed to children under 13, and we do not knowingly collect personal information from children through it. If you believe a child has sent us personal information through this site, contact us and we will delete it. Students use TripBridge only under the school-authorized model described in section 3 and in the product policy published at launch. Because education records may be involved, schools should treat trip data consistently with their obligations under FERPA and applicable state student-privacy laws.
6. How we share information
We share personal information only with: the providers that host this website and our email, each of which processes it on our behalf (TripBridge itself runs on hardware we operate, so no hosting company holds trip information); the independent map and place-search services described in section 3, for TripBridge location pins only; our payment processor, for TripBridge staff subscriptions only; the business tools described in section 4; law enforcement or other parties when the law requires it; and, if the business is ever sold or reorganized, the other party to that transaction, subject to this policy. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. Your rights and choices
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email contact@pathfinch.com and we will respond within the time the law allows. We will not treat you differently for exercising these rights. California residents have these rights under state law, and we extend them to everyone. For information about a student in TripBridge, the school is the data controller, so we may route the request through the teacher who ran the trip.
8. Changes to this policy
We may update this policy as the company and our legal obligations change. The current version is always at pathfinch.com/privacy, and the “last updated” date above shows when it last changed. Changes to the TripBridge product policy are governed by that policy, and teachers may be asked to accept an updated version.
9. Contact
Pathfinch LLC, a California limited liability company, is responsible for the information practices described here. Questions about this policy, and any request about your information, can be sent to contact@pathfinch.com. Questions about TripBridge, including trip data requests, go to support@tripbridge.chat. You can also use our contact page.