Effective August 16, 2026
The short version
PhoneLock uses school account, campus-presence, device-health, and compliance information to provide school-managed phone controls. It does not sell personal information, show advertising, track students for advertising, or collect the private content of messages, photos, passwords, notifications, screens, browsing, or personal files.
This policy explains how the PhoneLock student app, related services, and administration portal (“PhoneLock”) handle personal information.
PhoneLock is a school-managed service. The school or educational organization that enrolls a user (“School”) manages enrollment, policies, authorized staff access, and use of school records. The PhoneLock service operator (“Operator”) processes information to operate, secure, maintain, and support the service. The School is responsible for its own notices, authority, and consent requirements.
School account information: name, school email, school identifier, grade or homeroom, role, campus assignment, and account status.
Device information: a device or installation identifier, device code, platform, app and operating-system information, time zone, enrollment status, and service-security information. A pseudonymous identifier may remain after reinstall on supported devices so the same device can be recognized. It is not used for advertising.
Campus-presence information: the app uses precise location, including in the background, to determine whether the device is inside or outside a School campus. PhoneLock receives the campus-presence result, related time, and location-permission health. PhoneLock does not maintain a continuous location or route history.
Policy and compliance information: assigned policy, restriction or exemption state, permission status, background-operation status, connectivity and protection status, last contact, compliance incidents, restoration, review, and dismissal history.
Administrative and support information: administrator identity and role, policy and account actions, audit records, exports, support communications, and limited security or diagnostic logs.
Passwords are transmitted through the authentication provider and are not stored by PhoneLock in readable form. The app and portal use local device or browser storage for sign-in, setup, policy, and reliability information.
PhoneLock may request location, app-control, background-operation, accessibility, notification, or network-protection permissions where required by the device platform. These permissions are used only to apply School policy, keep essential functions available, and report whether required controls remain operational.
PhoneLock does not use these permissions to collect or transmit message content, notification content, typed text, passwords, photos, videos, contacts, call contents, microphone or camera recordings, screen content, browser-page content, documents, or personal files. It does not create or sell browsing or app-usage histories. The service may receive whether a required permission or protection is enabled and when that state changes.
Authenticate users and enroll authorized devices.
Deliver and apply School policies at the appropriate campus and time.
Verify required permissions and device-health signals.
Create and maintain compliance records for authorized School review.
Provide exemptions, reports, support, security, auditing, troubleshooting, and service reliability.
Meet contractual and legal obligations and prevent misuse.
PhoneLock may automatically apply a policy and create an incident using School policy, campus presence, time, exemption, and device-health information. PhoneLock does not make final disciplinary or educational decisions; authorized School staff should review the relevant circumstances.
Information may be disclosed as reasonably necessary to:
Authorized School personnel responsible for enrollment, policy, support, safety, or compliance.
Cloud, authentication, platform, infrastructure, security, and support providers that help operate PhoneLock.
Professional advisers or a successor organization subject to confidentiality and applicable law.
Authorities or other parties when required by valid legal process or necessary to protect rights or safety.
Providers must protect information and use it only to deliver their services. PhoneLock does not sell or rent personal information and does not disclose it to advertising networks or data brokers. Providers may process information in Canada, the United States, or other countries where they operate, subject to the laws of those jurisdictions.
Information is retained only as reasonably necessary to operate and secure PhoneLock, maintain School records, investigate incidents, resolve disputes, and meet contractual or legal requirements. Retention may vary by record type and School policy. At the end of the applicable period, information is deleted or de-identified through normal system and backup processes.
Removing the app or disabling a permission limits future collection through that permission but does not erase existing School records. Restoring a permission does not erase the historical incident. Removing a student account retires enrolled devices, but compliance and audit records may remain for the School’s lawful retention period.
Device permissions can be reviewed in iOS or Android Settings. Withdrawing a required permission may prevent PhoneLock from operating or verifying policy and may be reported as a compliance incident. Access, correction, deletion, consent, or complaint requests may be submitted through the School’s privacy officer or designated administrator. Requests may require identity verification and remain subject to lawful exceptions.
PhoneLock is provided through participating Schools and may be used by students who are minors. It is not offered to children for advertising or commercial profiling. The School is responsible for determining whether it has the authority or consent needed to enroll a student. Parents or guardians with questions should contact the School.
PhoneLock uses administrative, technical, and organizational safeguards appropriate to the information it handles, including access controls and encrypted network transport. No system can be guaranteed completely secure. Suspected unauthorized access should be reported promptly to the School.
This policy may be updated when PhoneLock’s practices or legal requirements change. The effective date will be updated and material changes will be communicated through the app, the School, or another appropriate channel where required.
For privacy questions, access, correction, deletion, consent, or complaint requests, email schoolapp@khalsaschool.ca. The School will coordinate service-provider questions with the Operator where necessary.