Security & student data privacy
How IdentMint protects student and staff data.
A summary for district technology directors, privacy officers, and procurement teams. A full security packet and our signed data privacy agreement are available on request.
Last updated October 9, 2026
What data we handle
IdentMint collects only what it takes to make and manage an ID badge.
| Data | Who | Where it comes from |
|---|---|---|
| Name, school, grade or role | Students, staff | District directory or SIS export |
| Student or employee ID | Students, staff | District directory or SIS export |
| Photo | Students, staff | Microsoft 365, Google Workspace, webcam, picture-day import, upload |
| Name, host, time in and out | Visitors | Front-desk check-in |
| Name and email | District administrators | Single sign-on |
We do not collect Social Security numbers, health information, grades, discipline records, or biometric data.
Legal framework
FERPA
Student photos and identifiers are education records. IdentMint acts as a school official with a legitimate educational interest under 34 CFR 99.31(a)(1). That means the district keeps direct control of the data, we use it only for badging, and we do not disclose it to anyone else.
COPPA
For students under 13, the district provides consent on parents' behalf for this educational use only. IdentMint has no student-facing accounts and no commercial use of student data.
HIPAA
Records covered by FERPA are excluded from HIPAA, and IdentMint does not collect health information. IdentMint is not a HIPAA-covered service.
Biometrics
Auto-cropping runs in the browser to center a face in the frame. IdentMint never stores face geometry, face templates, or any other biometric identifier.
Data privacy agreements
We sign the Student Data Privacy Consortium (SDPC) standard agreement where your state uses it, or your district's own agreement.
Directory integrations
IdentMint connects to your directory with the narrowest permissions that do the job. A district administrator grants access once and can revoke it at any time from the Microsoft or Google admin console.
| Directory | Default permission | Optional write-back |
|---|---|---|
| Microsoft 365 / Entra ID | ProfilePhoto.Read.All (read photos) | ProfilePhoto.ReadWrite.All |
| Google Workspace | admin.directory.user.readonly | admin.directory.user |
Writing photos back to Teams, Outlook, and Gmail is off until a district administrator turns it on.
Hosting
- All data is stored on servers in the United States.
- Cloudflare provides the network edge and blocks malicious traffic. Photo and record pages are never cached at the edge.
- Subprocessors are limited to hosting and network providers. We publish the list and notify districts before adding one.
Security controls
- TLS 1.2 or newer for every connection, with HSTS.
- Photos stored outside the web root and served only to signed-in users with permission.
- Photos and sign-in secrets encrypted at rest with per-purpose keys. District data runs on dedicated, encrypted hosting before any real records are loaded, and backups are encrypted.
- Sign-in through Microsoft or Google, or a local account with multi-factor authentication.
- Role-based access: district admin, building admin, badge operator, and front desk.
- Every query is scoped to your district. One district can never see another's data.
- No third-party analytics, advertising, or tracking scripts in the app.
Audit logging
IdentMint records who viewed, captured, changed, printed, exported, or synced each person's photo and record, with a timestamp. District administrators can review and export the log.
Directory-information opt-outs
If a parent has opted out of directory information, the district can flag that student. IdentMint then blocks the photo from write-back and export while still allowing a badge to be printed for building access.
Retention and deletion
- Districts can delete individual records at any time.
- When a contract ends, all district data, including backups, is purged within 30 days.
- We provide a written certificate of destruction.
Incident response
If we confirm unauthorized access to district data, we notify the district's designated contact within 72 hours, or sooner if your agreement requires it. The notice covers what happened, what data was involved, and what we are doing about it.
Contact
Security and privacy questions: [email protected]
IdentMint is a product of Moore Zeigler Group, LLC, a veteran-owned technology firm in Montgomery, Alabama.