What information MAP collects
Districts filling security questionnaires or NDPA Exhibit B schedules often ask what categories of information MAP stores. This article is a plain-language inventory of what the product collects today. The public Privacy Notice includes the same inventory. Neither is a signed Data Privacy Agreement, legal advice, or a certification.
For classroom privacy practices (roles, no ads, invite-only join), see Data privacy: how MAP handles school and student information. To send a district DPA packet, use Contact Us.
Account and profile information
- Names — first name, last name, and optional display name
- Email — login and transactional messages (invites, verification, operational alerts)
- Username — unique login handle
- Password — stored with Django’s password hashing (not plain text)
- Gender — optional at signup (Male or Female). Skipping leaves the field empty; it is not stored as “Other”
- Organization name — optional for Teacher and IT Support accounts
- Account type — Student, Teacher, Parent, or IT Support
- Last login and related session metadata used to keep a single active session per account
- State and time zone — optional US state code (often from last-login IP geolocation) and IANA time zone (often from the browser on sign-in). Either field can be locked to a manual choice in Account Settings so login detection does not overwrite it. Used for operational audience filters (for example IT notification blasts), not for advertising
Course, enrollment, and family links
- Course membership — which students and teachers belong to which courses (invite-based; not a full SIS roster)
- Pending invite emails — temporary addresses for student, parent, and co-teacher invitations until accepted or voided
- Parent–student–course links — when a parent invite is accepted for a specific student in a specific course
Assessment, grades, and student work
- Assessment attempts — when a student starts, submits, or continues work
- Student answers and generated problem copies — in-progress and submitted work used for grading
- Scores and course gradebook data — points, weights, curves, and related grade calculations as configured by the teacher
- Focus-leave lock events — optional integrity pauses when a student leaves the assessment tab (not webcam or remote monitoring)
Technical and operational data
- Session and CSRF cookies — browser cookies needed to stay signed in and submit forms securely
- Application logs — operational logs that may include IP addresses and request metadata, as with typical web hosting
- Transactional email delivery — messages sent through MAP’s configured SMTP provider for invites and alerts
- Paid course purchase records — operational records for 12-month course instances (caps and expiry) kept with course data; sensitive export files stay outside the public media URL space
What MAP does not collect by design
MAP does not ask for or store the following as structured profile fields:
- Date of birth or age
- Race or ethnicity
- IEP / 504 / medical / health alerts
- Home address, phone, or transportation details
- Official district or state student ID numbers (unless a teacher types such an ID into a free-text name field)
Where information lives (high level)
- Production application and database — MAP runs as a dedicated hosted stack; account and course data live in the application database on that host
- Backups — scheduled database and media archives with a retention window so operations can recover from failure
- Private files — certain sensitive uploads (for example disposition export zips) are kept off the public media path
Exact server region and subprocessors for a signed agreement are confirmed when your district sends a DPA / NDPA packet via Contact Us.
FAQ
Is this the same as Exhibit B on an NDPA?
It is the product inventory districts usually map onto Exhibit B. The signed schedule on your district packet is the official list for that agreement.
Does MAP sell this information?
No. MAP does not sell student personal information or use student data for targeted advertising. See the main data privacy article for purpose limitation details.
How do we get a copy or deletion of classroom records?
Teachers start from Contact Us using purpose District data / offboarding. See District data requests and teacher offboarding.