Raviv

Privacy Policy

Effective September 14, 2026

Who we are

Raviv is school management software built and operated by Torah Tools. Schools license it to run their day-to-day operations — staff attendance, student attendance, maintenance, transport, front-office work and similar.

The school owns its data; we hold it on the school’s behalf. We act only on the school’s instructions. We do not use school data for our own purposes, and we never sell it or use it for advertising.

What we collect

Only what running a school actually requires.

  • Staff. Name, email address, phone number, role and division, work schedule, attendance and check-in records, and — where the school uses Raviv for it — payroll identifier and salary.
  • Students. Name, date of birth, student number, class placement, attendance, and records school staff enter such as behavior notes and progress.
  • Families.Parent or guardian name, email address, phone number and home address, so the school can reach them; the people a family authorises to pick a child up; which van a child rides; and, where a family uses the parent app, the child’s attendance, the notes the school has sent home, planned absences, forms the family signs, notices it acknowledges, conference times it books and changes it requests.
  • Regular drivers. Name, email and phone of a person a school lists as a regular driver, and which van they drive.
  • Messages. Messages staff send one another inside Raviv.
  • Records staff write. Notes, reports and requests entered in the course of the school day — attendance and behaviour notes, maintenance reports, print requests.
  • Roster files, read and discarded. An administrator setting the school up can upload a spreadsheet of students or staff. The file is read to create those records and is not kept— what remains afterwards is the student and staff information described above, not the file itself.
  • Location — only when you tap. Two taps read your device’s location, and nothing else does: a staff member checking in where the school uses location-verified check-in, and a parent or driver pressing “I’m here” in the carpool line. Each reads the position once, at that moment, to confirm you are on or near school grounds. It is never read in the background. The position your device reported at that tap is stored with the record of the tap (the check-in, or the audit entry for the arrival), so the school can answer a later question about it. No track or history of where you go is built from these points.
  • Devices, for notifications. If you turn notifications on, a push token identifying your device is stored so the school can reach it. It is removed when you turn them off, when a device stops responding, or when your account is switched off.
  • Technical records. Sign-in events, and an audit trail of actions taken in the system — including who opened an individual child’s record — with the network address and browser or app version the action came from. This is what lets a school answer “who changed this, and when.”

We do not use advertising or analytics tracking of any kind. Raviv contains no advertising software, no third-party analytics, and no cross-site tracking.

How we use it

To provide the service the school asked for: signing people in, recording attendance, routing requests, notifying the right person, and producing the school’s own reports. We also use it to keep the service secure and working, and to support the school when they ask us for help.

We do not profile students, sell data to anyone, or use school data to train machine-learning models.

Who else touches it

We use a small number of service providers to run Raviv. They process data only to deliver their part of the service and only under contract with us:

  • Clerk — sign-in and account security
  • Neon — database hosting
  • Vercel — application hosting
  • Pusher — live updates between screens
  • Resend — sending email such as absence notices
  • DeepL — translating staff-to-staff text for staff who read another language (never a notification about a child)
  • Apple (APNs) and Google (Firebase Cloud Messaging) — delivering push notifications to iPhones and Android phones. A notification about a child, a family or a parent travels through them as a short generic line (“Open Raviv to see this”), never as the record itself.
  • Google Maps Platform — turning a typed address into a place, and estimating a route time, when a staff member uses those features. The address typed is what is sent.
  • Upstash — a small store used for rate limiting and scheduling, holding request counters and job timings only.

Beyond these, we disclose data only when the school directs us to, or where the law requires it.

Student and children's data

Records about students are provided to us by the school and remain the school’s records. We handle them as a service provider to the school — in US terms, under the school’s direct control and for no other purpose.

Students do not use Raviv and have no accounts. School staff use it; parents and guardians may use the parent app the school issues, which shows them their own children only; a person the school lists as a regular driver may use the driver app, which shows first names only of the children they carry that day. No account is created by a child, and nothing is collected from a child directly. Where a school issues the parent app, the school does so under its agreement with us, which is what United States law (COPPA) calls the school-consent route.

Parents and guardians who want to see, correct or delete a student’s records should contact their school, which controls those records and can direct us to act. Inside the parent app a family can see its children’s attendance and the notes the school has sent, and ask the school to correct its own contact details, address, pickup list and van seats.

How we protect it

  • All traffic is encrypted in transit; data is encrypted at rest by our providers.
  • Each school’s data is scoped to that school on every request, so one school’s records are never reachable from another’s account.
  • People see only what their role allows, and sensitive actions are written to an audit log.
  • Access to production systems is limited to staff who need it for support.

No system is perfectly secure. If a breach affects a school’s data, we follow a written procedure: we contain it, we tell the affected school within 72 hours of confirming it with what we know, what data was involved and what we are doing, and we help the school tell the families it must tell. Schools may ask us for the procedure itself.

How long we keep it

School records — attendance, notes, dismissal records, forms, the audit trail — for as long as the school’s record is on Raviv, because a school’s records are meant to persist across years; the school decides their fate. Working leftovers are cleared on a schedule: in-app notifications after a year; delivered digest lines, device tokens that have been turned off, and processed queue entries after ninety days.

A person who leaves is switched off, not erased: their login stops, their devices receive nothing, and the records they are part of stay readable to the school. When a school stops using Raviv, we export its data to it as one file, switch the school off, and delete the data from our systems once the school has confirmed receipt and any retention period it is bound by has passed.

Requesting deletion of your data

Raviv accounts are created by schools, not by individuals signing themselves up, so accounts are removed through the school rather than from inside the app — this stops one person from erasing records that belong to their school.

To request that your account and personal data be deleted:

  • Staff— ask your school administrator, who can deactivate and remove your account, or email us at the address below and we will act on the school’s confirmation.
  • Parents and guardians — contact your school, which controls student and family records.
  • Directly — email bentzi@torahtools.org from the address on the account. We respond within 30 days.

Deleting an account removes the person’s profile and contact details. Records the school is required to keep — such as an attendance history — remain the school’s, and are deleted when the school’s own retention period ends.

Changes to this policy

If we change how Raviv handles data we will update this page and change the effective date above. Material changes are communicated to the schools that use Raviv directly.

Contact

Torah Tools · bentzi@torahtools.org