identmint

Security & student data privacy

How IdentMint protects student and staff data.

A summary for district technology directors, privacy officers, and procurement teams. A full security packet and our signed data privacy agreement are available on request.

Last updated October 9, 2026

What data we handle

IdentMint collects only what it takes to make and manage an ID badge.

DataWhoWhere it comes from
Name, school, grade or roleStudents, staffDistrict directory or SIS export
Student or employee IDStudents, staffDistrict directory or SIS export
PhotoStudents, staffMicrosoft 365, Google Workspace, webcam, picture-day import, upload
Name, host, time in and outVisitorsFront-desk check-in
Name and emailDistrict administratorsSingle sign-on

We do not collect Social Security numbers, health information, grades, discipline records, or biometric data.

Legal framework

FERPA

Student photos and identifiers are education records. IdentMint acts as a school official with a legitimate educational interest under 34 CFR 99.31(a)(1). That means the district keeps direct control of the data, we use it only for badging, and we do not disclose it to anyone else.

COPPA

For students under 13, the district provides consent on parents' behalf for this educational use only. IdentMint has no student-facing accounts and no commercial use of student data.

HIPAA

Records covered by FERPA are excluded from HIPAA, and IdentMint does not collect health information. IdentMint is not a HIPAA-covered service.

Biometrics

Auto-cropping runs in the browser to center a face in the frame. IdentMint never stores face geometry, face templates, or any other biometric identifier.

Data privacy agreements

We sign the Student Data Privacy Consortium (SDPC) standard agreement where your state uses it, or your district's own agreement.

Directory integrations

IdentMint connects to your directory with the narrowest permissions that do the job. A district administrator grants access once and can revoke it at any time from the Microsoft or Google admin console.

DirectoryDefault permissionOptional write-back
Microsoft 365 / Entra IDProfilePhoto.Read.All (read photos)ProfilePhoto.ReadWrite.All
Google Workspaceadmin.directory.user.readonlyadmin.directory.user

Writing photos back to Teams, Outlook, and Gmail is off until a district administrator turns it on.

Hosting

  • All data is stored on servers in the United States.
  • Cloudflare provides the network edge and blocks malicious traffic. Photo and record pages are never cached at the edge.
  • Subprocessors are limited to hosting and network providers. We publish the list and notify districts before adding one.

Security controls

  • TLS 1.2 or newer for every connection, with HSTS.
  • Photos stored outside the web root and served only to signed-in users with permission.
  • Photos and sign-in secrets encrypted at rest with per-purpose keys. District data runs on dedicated, encrypted hosting before any real records are loaded, and backups are encrypted.
  • Sign-in through Microsoft or Google, or a local account with multi-factor authentication.
  • Role-based access: district admin, building admin, badge operator, and front desk.
  • Every query is scoped to your district. One district can never see another's data.
  • No third-party analytics, advertising, or tracking scripts in the app.

Audit logging

IdentMint records who viewed, captured, changed, printed, exported, or synced each person's photo and record, with a timestamp. District administrators can review and export the log.

Directory-information opt-outs

If a parent has opted out of directory information, the district can flag that student. IdentMint then blocks the photo from write-back and export while still allowing a badge to be printed for building access.

Retention and deletion

  • Districts can delete individual records at any time.
  • When a contract ends, all district data, including backups, is purged within 30 days.
  • We provide a written certificate of destruction.

Incident response

If we confirm unauthorized access to district data, we notify the district's designated contact within 72 hours, or sooner if your agreement requires it. The notice covers what happened, what data was involved, and what we are doing about it.

Contact

Security and privacy questions: [email protected]
IdentMint is a product of Moore Zeigler Group, LLC, a veteran-owned technology firm in Montgomery, Alabama.