Privacy Policy
Last updated: January 1, 2025
Account Information
- Full name, email address, phone number, and profile photo
- Authentication credentials managed through Supabase Auth
- User role (Administrator, Student, or Parent)
Student Academic Information
- Current school, graduation year, and academic records
- Target universities and program preferences
- Application documents, transcripts, and personal statements
- Application timeline and status information
Parent Information (if applicable)
- Contact details and relationship to student
- Communication preferences
Automatically Collected Data
- Activity logs including actions performed and timestamps
- IP address and browser user agent for security purposes
- Device information for push notification delivery
Service Delivery
- Managing university applications and tracking progress
- Storing and organizing application documents securely
- Facilitating communication between students, parents, and administrators
- Scheduling appointments and video consultations
- Assigning and tracking tasks throughout the application process
Communication & Notifications
- Sending real-time updates via in-app notifications
- Delivering push notifications to subscribed devices
- Email communications regarding application status and deadlines
- In-platform messaging between users
Security & Improvement
- Maintaining activity logs for security and audit purposes
- Analyzing usage patterns to improve our services
- Preventing unauthorized access and fraud
Infrastructure Providers
- Supabase: Database hosting, user authentication, file storage, and real-time data synchronization
- SMTP Email Services: Transactional email delivery for notifications and contact form submissions
- Web Push Services: Browser push notification delivery
Data Sharing
- University admissions offices (only application materials you authorize us to submit)
- Your assigned administrator and authorized support staff
- Parents linked to your account (for student users)
- Legal authorities when required by applicable law
- Documents are stored securely in Supabase Storage with access controls based on your user role
- File names are sanitized to remove special characters before storage for security
- Administrators can request specific documents from students through the platform
- Document templates may be provided for standardized submissions (transcripts, recommendations, etc.)
- You can view, download, and manage your uploaded files through your dashboard
- Real-time updates are delivered via Supabase Realtime for instant synchronization across devices
- Push notifications require explicit opt-in and store your device endpoint, browser information, and encryption keys
- You can manage or revoke push notification subscriptions at any time
- In-app notifications track read/unread status to ensure you don't miss important updates
- Email notifications can be configured through your account preferences
- Authentication is handled through Supabase Auth with secure session management
- Role-based access control ensures users only access authorized data
- All data transmission is encrypted using HTTPS/TLS
- Database access is protected by Row Level Security (RLS) policies
- Activity logging enables security monitoring and audit trails
- Push notification keys are encrypted and stored separately from user data
- Account data is retained for the duration of your active relationship with Ariona Study Abroad
- Application records may be retained for up to 7 years after completion for reference and compliance
- Activity logs are partitioned monthly and may be archived after 12 months
- Messages and communications are retained for the duration of your account
- Upon account deletion request, personal data will be removed within 30 days, except where retention is required by law
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your data (subject to legal retention requirements)
- Portability: Receive your data in a machine-readable format
- Withdraw Consent: Opt out of optional data processing (e.g., push notifications)
- Restriction: Limit how we process your data in certain circumstances
To exercise these rights, contact your administrator or reach out to us directly.
Our services may be used by students under 18 years of age. For minor users, we require parental or guardian consent and provide parent accounts to allow guardians to monitor their child's application progress. Parents can access student information, communications, and documents through their linked parent account.
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through in-app notifications or email. Continued use of the platform after changes constitutes acceptance of the updated policy.
For questions about this Privacy Policy, data requests, or privacy concerns, please contact us at info@ariona.click