Privacy Policy
Last updated: August 26, 2026This policy covers two Global Book Passport products operated by Global Book Passport LLC: the curriculum website (globalbookpassport.com/homeschool) and the Global Book Passport reading app. It describes what information we collect from each, how it is used, who we share it with, and the protections in place. Where a section applies only to one product, it's labeled.
Information we collect
Curriculum website
- Name and email address — entered at checkout and used to create your curriculum account and provision your reading-app accounts.
- Payment information — card details are entered directly into Stripe's secure checkout and are never seen or stored by us.
- Contact form submissions — if you use our contact form, we collect your name, email address, and message. This information is used only to respond to your inquiry.
The curriculum website does not collect any student data. It is parent- and educator-facing content only.
Reading app
- Account information — username, first name (optional), email address (optional for student accounts; required for administrator accounts), and a hashed password.
- Reading activity — books logged (title, author, country of origin), star ratings, written recommendations, and quest or challenge progress.
- Organizational data — which family, co-op, or school account a user belongs to, and their role (student, librarian, teacher, or administrator).
We do not collect date of birth, home address, government ID numbers, photographs, precise location, or biometric data from any user.
How accounts are created
- Family accounts — a parent or guardian purchases a plan and creates their own account plus one account per child. The parent's purchase and account creation constitutes their direct consent under COPPA for their children's accounts.
- Co-op accounts — a co-op administrator creates accounts and adds members, or shares a sign-up code members use to register, subject to administrator approval before the account becomes active.
- School/District accounts — a school or district administrator creates student accounts directly, or approves student self-registration requests before they become active. The school or district — not Global Book Passport — is responsible for obtaining any parental consent required under COPPA, acting as the parent's agent for the student's educational use of the app, consistent with FTC guidance on COPPA's school-consent provision.
How we use this information
- To process your payment and provide access to the curriculum and app.
- To create and manage accounts and provision reading-app access based on your subscription.
- To send transactional emails — account setup instructions, password resets, and purchase receipts.
- To respond to contact form inquiries.
- To determine when a subscription has expired and update access accordingly.
We do not use any information — including student data — for targeted or behavioral advertising. We do not sell or rent personal information to third parties under any circumstances.
Who we share information with
We do not sell your personal information. We share it only with the services required to operate the product:
- Stripe — processes payments and stores your payment method and purchase history. Stripe is PCI-DSS compliant. See stripe.com/privacy.
- Netlify — hosts the curriculum website, manages curriculum account authentication, and receives contact form submissions. See netlify.com/privacy.
- DigitalOcean — hosts the reading app's server and database, where app account and reading data is stored. See digitalocean.com/legal/privacy-policy.
- Google Firebase Hosting — serves the reading app's static files only; does not process or store student data.
- Resend — delivers transactional emails (account setup, password reset). See resend.com/legal/privacy-policy.
- Google Sign-In (school accounts only, optional) — used for identity verification only. We do not request or receive access to any other Google account data.
Information is transmitted to these services via encrypted HTTPS connections. No information is disclosed for advertising purposes.
Security practices
- All pages are served over HTTPS.
- Payment data is handled entirely by Stripe and never passes through our servers.
- Passwords are cryptographically hashed and never stored in plain text.
- Access is restricted by role and organization — one school, family, or co-op cannot access another's data.
- Login and password-reset attempts are rate-limited.
Data retention and deletion
- Family and Co-op accounts — the purchasing parent or administrator can delete their account and any accounts they manage at any time by contacting us. Deletion permanently removes the account, reading history, and progress.
- School/District accounts — the school's administrator controls creation, management, and deletion of student accounts. Global Book Passport does not have the technical ability to view, modify, or delete individual student accounts for self-governed schools — enforced at the software level. Upon termination of a school's use of the app, student data is deleted or returned per the applicable Data Privacy Agreement.
- Stripe retains purchase records per its own policies. Netlify retains curriculum account data for as long as the account exists.
Children's privacy (COPPA)
Global Book Passport is designed for K–9 students and takes children's privacy seriously. We collect only the limited information described above. We never condition participation on disclosing more information than is necessary. We never use children's data for behavioral advertising or disclose it for marketing. Parents provide direct consent for family accounts; schools provide consent on parents' behalf for school accounts, consistent with FTC guidance. To review, correct, or request deletion of a child's account, contact us using the information below.
Schools and FERPA
Applies to School/District accounts only. Global Book Passport acts as a "school official" with a legitimate educational interest in student data under FERPA's school-official exception (34 CFR § 99.31(a)(1)), under the direct control of the school. Full commitments are set out in our Data Privacy Agreement for institutional customers.
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision. School and district customers will be notified of material changes by email.
Contact
Questions about this policy, or requests to access, correct, or delete your information, can be sent to globalbookpassport@gmail.com or through our contact page.