Privacy Policy
1Overview
DataVot is a web-based service for New Jersey schools that turns official state assessment data sets (such as NJSLA files) into dashboards, pivot-table reports, and shareable analyses. DataVot is operated by Salesforce Hub LLC ("we", "us", or "our"), an independent New Jersey company. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at datavot.com and any related pages.
We are committed to protecting your privacy. We collect only the minimum data necessary to provide the service, and we never sell your personal information to third parties.
2Data We Collect
We collect information in the following categories:
| Category | What we collect | Why |
|---|---|---|
| Account data | Name, email address, hashed password | Account creation and authentication |
| School data | School name, admin-assigned roles (teacher / school admin) | Multi-user school accounts |
| Uploaded files | CSV files you upload for analysis | Core product functionality — building pivot tables |
| Reports | Report configurations, field arrangements, and filters you create | Letting you return to your work |
| Preferences | Display settings (dark mode, chart type, aggregation, etc.) | Personalizing your experience |
| Usage data | Cloudflare's standard request logs (IP, user-agent, timestamp) | Security, abuse prevention, uptime monitoring |
We do not collect payment card numbers, social security numbers, health records, or any other sensitive personal data (health, financial, or biometric). We do not use behavioral advertising or tracking pixels.
3How We Use Your Data
We use the data we collect to:
- Operate the service — authenticate your account, process file uploads, compute pivot tables, and display results.
- Create reports — persist reports and preferences so you can resume where you left off.
- Manage school accounts — allow school administrators to invite teachers and manage seat limits.
- Communicate with you — send password-reset emails and important service notifications. We do not send marketing emails.
- Improve the service — review aggregate, anonymized usage patterns to identify errors and plan new features.
- Ensure security — detect and prevent abuse, enforce rate limits, and respond to incidents.
4Storage & Security
DataVot runs on Cloudflare Workers with a Cloudflare D1 database (SQLite). Your data is hosted on Cloudflare's network infrastructure under confidentiality and data protection obligations.
We implement the following technical safeguards:
- All data transmitted between your browser and our servers is encrypted via HTTPS / TLS 1.3.
- Stored data sets and reports are encrypted at rest — the rows are compressed and encrypted with AES-GCM before they are written to the database, and are decrypted only in memory, on the server, when an authorized user opens them.
- Dashboards return aggregated counts only — the totals behind a chart are computed on the server, so raw student rows are never sent to the browser to draw a dashboard.
- Passwords are never stored in plain text — we use a strong hashing algorithm (bcrypt) with per-user salts.
- Authentication uses HTTP-only, Secure, SameSite cookies to prevent cross-site scripting theft of session tokens.
- Uploaded files are processed in-memory and stored only if you explicitly create a report or data set; raw files are not retained after your session ends.
- Role-based access controls mean school admins can only access their own school's data. Teachers can additionally be restricted by a school admin to specific schools within the district; where no restriction is set, a teacher sees their district's data set.
7Data Retention
We retain your data for as long as your account is active. Specifically:
| Data type | Retention period |
|---|---|
| Account profile (name, email, password hash) | Until you request deletion of your account |
| Reports and report configurations | Until you delete them, or until your account is deleted on request |
| User preferences | Until you request deletion of your account |
| Uploaded file data (in unsaved sessions) | Duration of your browser session only — not persisted |
| Server access logs (Cloudflare) | Up to 30 days (Cloudflare's standard log retention) |
| Application diagnostic logs (errors and actions reported by your browser) | Up to 90 days from the date of the entry, then deleted |
| Security and access audit trail (sign-in attempts and the IP address of a failed one, support access, administrative actions) | Up to 3 years from the date of the entry, then deleted |
Account deletion is handled on request rather than through a self-service button. Email info@datavot.com to ask us to close your account, and we will delete or anonymize all personal data associated with it within 30 days of verifying the request, except where we are legally required to retain it for longer.
8Your Rights
If you have a DataVot account — as a teacher, school administrator, or system administrator — you have the following rights over your own personal data:
To exercise any of these rights, contact us at info@datavot.com. We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.
9Children's Privacy
DataVot is designed for use by teachers and school administrators, not by students directly. The service is not directed to children, and we do not knowingly collect personal data directly from children under 13 (consistent with COPPA).
The data that teachers upload (e.g., class performance spreadsheets) may contain student records. Teachers and school administrators are responsible for ensuring they have the appropriate authorization and legal basis to upload and process any student data, and for complying with applicable U.S. laws such as FERPA and COPPA.
If you believe we have inadvertently collected personal data directly from a child under 13, please contact us immediately at info@datavot.com and we will delete it promptly.
10Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the service, technology, or applicable law. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to all registered users at least 14 days before the change takes effect.
Your continued use of DataVot after the effective date constitutes your acceptance of the updated policy. If you do not agree with the changes, you may request deletion of your account before the effective date by emailing info@datavot.com.
11Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy, please contact us:
DataVot — Privacy Contact
📧 Email: info@datavot.com
🌐 Service: datavot.com
We aim to respond to all privacy-related inquiries within 5 business days. For access or deletion requests, we will respond within 30 days.