EduOnTrack Education Technology Solutions
Services deviceontrack.com classontrack.com Contact

EduOnTrack LLC

Service Providers and External Services

Last updated: August 21, 2026

EduOnTrack LLC uses the providers below to operate EduOnTrack, DeviceOnTrack, and ClassOnTrack. Each provider receives only the information reasonably needed for its listed function. This page does not list ordinary open-source libraries, development tools, or internal tools that do not receive production customer information. It also does not publish account credentials, project identifiers, or private system endpoints.

Subprocessors

The following providers process information on EduOnTrack's behalf under service terms or agreements used to operate the products. The applicable School Data Privacy Addendum authorizes these providers for the functions described below.

Cloudflare

Products: EduOnTrack, DeviceOnTrack, and ClassOnTrack.

Cloudflare provides website and application delivery, server execution, database services used by DeviceOnTrack, private DeviceOnTrack basemap storage and delivery, traffic security, rate limiting, scheduled processing, and operational request handling. Depending on the product and request, Cloudflare may process technical request information, account or organization identifiers, managed-device records, classroom session records, billing workflow records, and other information needed to run the requested application function.

Supabase

Product: ClassOnTrack.

Supabase provides teacher authentication, the ClassOnTrack application database, realtime classroom updates, and private storage for requested lesson snapshots. It processes teacher account and organization information, lesson and session records, participant display names and activity, scoped extension-session records, and snapshots requested during a session.

Google Services and Firebase

Products: DeviceOnTrack and ClassOnTrack.

DeviceOnTrack uses Firebase Authentication and Google sign-in for approved administrator access, Firebase Cloud Messaging for configured device-sync notifications, and Firebase Analytics for basic dashboard usage and technical measurement when supported by the administrator's browser. This may involve administrator identity, authentication identifiers, device-messaging identifiers, page views, browser or device properties, and automatically generated usage events. ClassOnTrack uses Google Identity Services when a teacher chooses optional Google sign-in. EduOnTrack products do not receive users' Google passwords.

Stripe

Products: DeviceOnTrack and ClassOnTrack.

Stripe provides customer, subscription, quote, invoice, payment, and tax-related billing functions. Stripe processes billing contacts, billing addresses, payment methods, transaction information, tax status, and the customer or subscription identifiers needed for billing. EduOnTrack products do not store complete payment-card numbers entered into Stripe.

Brevo

Products: DeviceOnTrack and ClassOnTrack.

Brevo delivers transactional email, including requested quotes, invoice notices, account communications, alerts, and renewal reminders. It processes the recipient's email address and name when available, delivery information, and the content needed for the applicable message.

Sentry

Product: DeviceOnTrack, when enabled.

Sentry receives application error and limited performance information used to diagnose failures and maintain reliability. DeviceOnTrack disables Sentry's default collection of personally identifying information in the web application. Error details may still contain technical context associated with the failed operation, so access is limited to troubleshooting and security purposes.

Upstash

Product: ClassOnTrack, only when the fallback is configured.

Upstash may provide distributed request rate limiting when the primary platform rate limiter is unavailable or not configured. It receives a scoped rate-limit key and counters needed to determine whether a request limit has been reached. It does not receive lesson content or snapshots through this function.

Map Data and Licensing Sources

DeviceOnTrack's privately hosted basemap is built from the map-data sources below. They supply licensed map content and attribution requirements; they do not receive routine production tile requests, device coordinates, or customer records when an administrator views the DeviceOnTrack map. They are therefore identified as map-data and licensing sources rather than Subprocessors.

OpenStreetMap and Protomaps

Product: DeviceOnTrack.

OpenStreetMap contributors provide the underlying geographic data, and Protomaps provides the basemap distribution and rendering format used to prepare DeviceOnTrack's privately hosted map. DeviceOnTrack downloads the map data in advance and serves it through its own Cloudflare-hosted map domain. Device locations, serial numbers, asset tags, account emails, device IDs, and organization names are not added to the basemap and are not sent to OpenStreetMap or Protomaps for routine production map display. Required attribution remains visible in DeviceOnTrack map views.

Changes and School Requests

Providers and product configurations may change as services are improved. We will update this page when a production provider begins or stops receiving information in a way that materially changes these descriptions. Schools and districts may contact us for the current list, product-specific privacy information, or available data-processing terms before deployment.

Contact

Questions about providers or product data practices may be sent to privacy@eduontrack.com.

© 2026 EduOnTrack LLC
Privacy Policy School DPA Security Service Providers Terms of Service Contact