How RallyOrder protects schools
Money and student data are the two most regulated things that move through a school, and most campuses still handle both on tools not built to meet the unique requirements. RallyOrder is the compliant way to take payments in school: the student store, the concession stand, game night. Below we detail the four pillars of our promise to you.
Schools are the merchant of record, daily payouts to your bank, no chargeback risk.
Read the pillar ↓ II. Data We never monetize or sell student data.Minimal collection, anonymous buyers, and our Student Data Promise.
Read the pillar ↓ III. Compliance The agreements your district already trusts.The NDPA commitment, FERPA compliant, state laws, published data retention schedule.
Read the pillar ↓ IV. Accountability Every promise has an auditable control.Audit trails, NIST-mapped security, two subprocessors, incident clocks.
Read the pillar ↓Your money is always in accounts you control.
Every school on RallyOrder is the merchant of record on its own Stripe account, under its own EIN. Sales settle to the bank account your district designates, with daily payouts. Cash goes from your drawer to your existing deposit process without touching us at all. In many states, including Washington, Texas, and Idaho, store revenue is public money with deposit rules, and this architecture is built for them.
Your school's. The IRS form names the school as the merchant, under the school's EIN. No advisor's Social Security number is ever attached to your store's revenue.
When a store runs on a consumer payment account opened in a teacher's name, the IRS sees the teacher as the business: the store's gross sales get reported under their personal SSN, before refunds and fees, and some processors aggregate every account sharing that SSN. Your school's EIN on the form keeps store revenue where it belongs, on the school's books and on nobody's personal taxes.
We absorb it. When a dispute happens, RallyOrder carries the cost, not your school. No chargeback fees.
Disputes at an in-person school store are rare, but a school budget should never eat a surprise clawback. Absorbing the occasional dispute ourselves beats pricing dispute risk into every school's rate, so your deposits stay predictable and your rate stays low.
In your school's own accounts: your Stripe account, paying out daily to your bank, exactly as before.
Money held by a vendor lives inside that vendor's business risk: their reserves, their disputes, their solvency. Because your funds settle to accounts in your school's name every single day, nothing about our company's health can ever strand your money.
Nothing in our model requires it, because we never receive, hold, or remit your money. Stripe, a regulated payments company, processes every transaction, and settlement runs directly into your school's own account. Segregation is structural, not procedural.
A vendor that receives and remits school funds is operating as a payments intermediary, with licensing and custody questions your procurement office has to resolve. Some platforms hold proceeds in settlement accounts pooled with other customers' money. Direct settlement removes the question entirely: there is no vendor-held account to regulate, audit, or unwind.
We are the software provider, never the bank. Daily deposits ensure you have control of your money and don't rely on a paper check sent once a month in the mail that opens up audit, compliance, and merchant of record risk for your school.
We never monetize or sell student data.
The data we collect is what a store needs to run in a compliant manner: who is working the register, what was sold, cash v. card payments, and inventory details. Customer purchase data is not collected or retained at all. And since we never collect student information for marketing, the federal notice-and-opt-out machinery (PPRA) that other vendors may subject you to will never happen with RallyOrder.
Run your store, reconcile registers, power your reporting. The full commitment list is our Student Data Promise below, and every line of it also binds us in the agreements we sign with your district.
Terms of service decide what actually happens to data, and consumer POS terms routinely reserve rights to build cross-merchant profiles, share buyer data with advertisers, or use records for any lawful purpose. Read every vendor's terms the way you'd read our privacy policy, because the contract is the promise.
Nothing. A sale is recorded; the person never is. Card payments keep only the last 4 digits, for the receipt.
A student buying a snack shouldn't create a data trail. Registers that attach names, emails, or accounts to lunchtime purchases turn a cafeteria line into a marketing list. Ours can't, because the field doesn't exist.
Never. No advertisers, no data brokers, no buyers of any kind. And if RallyOrder is ever acquired, these commitments travel with the data and bind the successor in writing.
Acquisition is where data promises historically die: the company changes hands and the policy quietly changes with it. Ours is written to survive that, and the full detail is public in our privacy policy.
What we do with student data, and what we will never do.
Student data matters enough that our promise is published, in writing, for everyone to hold us to. Every commitment below also binds us in the agreements we sign with your district.
We collect what a school store needs to run: who's on the register, what sold, what's in stock. We use it to run your store, teach your students, and hand your finance office reports that reconcile.
No advertisers, no data brokers, no buyers of any kind. There's no price. And if RallyOrder is ever acquired, these commitments travel with the data and bind the successor in writing.
No targeted ads in our software or anywhere else, built from anything we learn at your register.
Running the store and powering your reporting. It never feeds a profile for any purpose outside your school’s program.
We use aggregated, de-identified data across schools to show what sells well regionally and nationally, build year-end reports, and power curriculum examples. We build every benchmark with minimum group sizes so no student, buyer, or single store can be picked out of it, and none of it is ever sold.
Our registers never ask who's buying: no names, no emails, no phone numbers, no accounts. Card payments run through Stripe like any card purchase, and we keep only the last 4 digits for the receipt, never a buyer's identity.
Ask us to delete your students' data and it's done within 60 days, confirmed in writing. Your export comes first if you want it. One exception, because it protects you: the sales ledger your finance office reconciles against survives with every student identifier stripped out. It's your books, not student data.
Your district gets at least 30 days written notice before any material change takes effect, and changes never weaken these commitments.
RallyOrder is a vendor member of the Student Data Privacy Consortium, and the National Data Privacy Agreement, the standard used by state alliances across 40 states, is our standard district agreement.
The agreements your district already trusts.
We set out to build a platform that meets the strictest federal and state compliance laws in this space. The standards we meet are outlined below. If your state has a unique requirement, let us know.
Card data flows from the reader directly to Stripe, a certified PCI Level 1 service provider. Full card numbers never touch RallyOrder systems; we keep only the last 4 digits, for receipts. Your school validates with a pre-filled questionnaire from the Stripe dashboard, and we walk you through it.
FERPA binds schools, and a vendor participates lawfully only under the school’s direct control as a "school official." That control is exactly what our data privacy agreement gives your district: named purposes, no re-disclosure, and terms we cannot change out from under you.
COPPA protects children under 13, and RallyOrder is built for high school programs. We hold ourselves to its standards anyway: minimal collection, a written retention schedule, and deletion on request.
State student-privacy laws bind vendors directly: no targeted advertising, no profiling, no sale of student data, real security, deletion on request. We build to the strictest of them, including Washington’s SUPER Act, the Texas Student Privacy Act, Idaho Code 33-133, and California’s SOPIPA.
Our Data Retention Schedule
Districts can request deletion at any time; we complete it within 60 days and confirm in writing, with your export delivered first if you want it.
We set out to meet the strictest state standards in all categories. By taking this approach and building for the hardest use cases we ensure that every school, in every state, benefits from being on RallyOrder.
Every promise on this page has an auditable control.
Our platform is built to pass an audit. User permissions are controlled by advisors, transactions reconcile to the penny, the register manages cash in and out, and nothing is editable after the fact.
Drawer sessions get opening, mid, and closing counts with variance tracking. Refunds require a PIN and record who approved them. Every count and approval survives in the activity log.
Cash-handling findings are among the most common in school audits. Counts tied to named operators turn end-of-semester reconciliation from an argument into a report your business office can pull in a minute.
Two: Stripe for payments and AWS for hosting, database, and identity. That's the list.
Every additional company that touches school data multiplies your review surface. Two named partners keep the chain short and checkable: card data lives with Stripe, every password lives in AWS Cognito, and neither ever sits in RallyOrder's own systems.
Refunds require a PIN and record who approved them. Card refunds return to the buyer's original card through Stripe, and every refund posts against the sale it reverses, in your reporting and in the activity log.
Refunds are where money walks out of a store unnoticed, and an unattributed refund path is how shrinkage hides inside clean-looking totals. Named approval on every refund, tied to the sale it reverses, turns refund review into a one-minute report instead of an investigation.
Without unreasonable delay, directly from us, with what happened, what data was involved, and what we're doing about it.
A vendor that can't name its notification commitment before an incident won't improvise one well during it. The binding version, with its clock, lives in the data privacy agreement we sign with your district, and your district gets a named incident contact at signing.
Our written information security program follows the NIST Cybersecurity Framework, every school's data is isolated at the database layer, and register PINs lock out after 5 failed attempts. Districts can request the full program any time.
Two companies touch your data. That's the list.
Stripe is one of the largest payment processors in the world, moving over $1 trillion a year for millions of businesses, and it powers many of the payment platforms districts already use. On RallyOrder, card data is encrypted in the reader and goes straight to Stripe, a certified PCI Level 1 service provider. It never touches our systems.
Amazon Web Services is the world's largest cloud provider, the infrastructure behind millions of organizations, from startups to banks to federal agencies. RallyOrder runs entirely on AWS: every school's data is isolated at the database layer, and every password lives in AWS Cognito, never in our systems.
Every document your procurement process asks for.
Let us know what you need
Reach out to us if you have any questions or need a specific document as part of this process. We are here to work with you on getting RallyOrder launched at your school.