01Who we are and whose data this covers
BastaKaapi ("we", "us") provides the BastaKaapi: School Management platform from Lahore, Punjab, Pakistan. Schools ("the School") subscribe and create accounts for their administrators, teachers, parents and students.
For school records, the School decides what is collected and why, and we process that data on its behalf and under its instructions. For enquiries you send us directly (for example through the onboarding form, WhatsApp or email), we are responsible for that data ourselves.
02Data we collect
- Account data: name, username, role, school, email and phone number, and a one-way hash of your password (we never store or see the password itself).
- Student records entered by the School: admission number, class and section, date of birth, guardian contacts, attendance, marks, assignments, timetables, leave requests, library and transport records.
- Fee records: invoices, challans, balances and payment references. We do not collect or store card numbers.
- Communication: announcements, messages between parents and teachers, WhatsApp notification logs, and support tickets with any screenshots you attach.
- Onboarding chats: if you use the live chat on our website before your school has an account, we collect the name, school name and (optional) phone or email you give, the messages you send, and a hashed form of your IP address to prevent abuse.
- Technical and security data: IP address, device and browser type, sign-in times, an audit trail of changes made in the School's account and, if you turn on notifications, a push subscription address for your device.
We do not collect precise location, contacts, call logs, SMS or advertising identifiers.
03How we use data
- To provide the service the School subscribed to: portals, attendance, results, fee tracking, timetables and messaging.
- To keep accounts secure: authentication, limiting failed sign-in attempts, detecting misuse and keeping audit logs.
- To send notifications you or your School asked for (in-app, push, WhatsApp).
- To answer support tickets and onboarding enquiries.
- To meet legal obligations and resolve disputes.
We never sell personal data, never show advertising, and never use student data to build advertising profiles.
04Children and student data
Students, including children under 13, receive accounts only through their School, which is responsible for obtaining any consent that parents or guardians must give. Students cannot sign themselves up.
- The app contains no advertising and no third-party analytics or tracking SDKs.
- Student data is used only for school purposes, and is visible only to authorised staff and the student's linked parents.
- Optional AI tools (study help and report drafting) are used under the School's supervision. Their prompts are not used to build profiles of children.
- Parents can ask the School to review, correct or delete their child's records.
06Device permissions
- Notifications: asked only when you tap "Turn on notifications". You can switch them off at any time in your browser or phone settings.
- Microphone: used only while you use voice input in the AI assistant, and only after your browser asks for permission.
- Photos and files: used only for images you choose to attach, such as support screenshots or profile photos.
The app does not request location, contacts, camera or other permissions.
07How we protect data
- All traffic is encrypted with HTTPS, and browsers are required to use it (HSTS).
- Passwords are stored only as salted bcrypt hashes.
- Sessions use cookies that page scripts cannot read (HttpOnly, Secure, SameSite).
- Each School's data is kept separate, and every request is checked against the user's role and School.
- Repeated failed sign-ins are blocked for a while, and heavy use of sensitive endpoints is slowed down.
- Administrative actions are recorded in an audit log.
No system is perfectly secure. If a breach affects your data, we will notify the School and, where required, the authorities without undue delay.
08Retention and deletion
We keep School data for as long as the School's subscription is active. When a subscription ends, the School has 60 days to export its data, and after that we delete it from live systems. Backups are overwritten within a further 30 days. Security logs are kept for up to 12 months. Onboarding chat conversations are kept permanently as a record of our pre-sales correspondence. You can still ask us to remove your contact details from them.
To delete an account or its data: ask your School's administrator, who can remove it directly, or email support@bastakaapi.com with the subject "Account deletion request", your name, your School and your role. We confirm your identity with the School and complete the request within 30 days. Records the School must keep by law, such as fee receipts, may be retained until that duty ends.
09Your rights
Subject to applicable law, you can ask to access, correct, export or delete your personal data, and to object to or restrict how it is used. For school records, send your request to your School; we will help it respond. For other requests, contact us directly.
11Changes and contact
If we make significant changes to this policy, we will tell Schools in the app before the changes take effect, and we will update the effective date above.
Privacy questions and requests: support@bastakaapi.com · +92 314 3148098 · BastaKaapi, Lahore, Punjab, Pakistan.