StackERP Solutions Private Limited
School ERP Software · Web Dashboard · Cloud ERP Platform
Admin · Teacher · Student · Parent · Accountant · Admission Modules
Website: https://www.stackerpsolutions.com
Email: admin@stackerpsolutions.com
Phone: +91 85408 01482
CIN: U62013RJ2026PTC115794
Registered Office: E-409, IV Floor, Avni Homes, Khasra No. 356, Vatika, Sanganer, Jaipur, Rajasthan, India
Effective Date: 13 July 2026 · Last Updated: 13 July 2026
This Privacy Policy ("Policy") is published and maintained by StackERP Solutions Private Limited, a company incorporated under the Companies Act, 2013, bearing Corporate Identification Number (CIN) U62013RJ2026PTC115794, having its registered office at E-409, IV Floor, Avni Homes, Khasra No. 356, Vatika, Sanganer, Jaipur, Rajasthan, India.
StackERP operates a cloud-based School Enterprise Resource Planning (ERP) platform, accessible via the website https://www.stackerpsolutions.com, associated web dashboards, and dedicated mobile applications for Administrators, Teachers, and Students/Parents (collectively, the "Platform" or "Services"). The Services enable schools, trusts, and educational institutions ("Institution", "School", or "Client") to digitize and manage academics, attendance, communication, fee and finance management, admissions, transport, hostel operations, examinations, homework, AI-assisted academic tools, and related administrative functions.
This Policy explains, in plain and professional language, what personal information StackERP collects, how and why it is collected, how it is used, stored, secured, shared, and retained, and the rights available to individuals whose personal data is processed through the Platform. This Policy is framed with due regard to the Information Technology Act, 2000 and rules made thereunder (including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011), and the Digital Personal Data Protection Act, 2023 ("DPDP Act"), together with such rules as may be notified thereunder from time to time.
By accessing or using the Platform — whether as a School, Administrator, Teacher, Accountant, Student, or Parent/Guardian — you acknowledge that you have read and understood this Policy. Where the Platform is used by or on behalf of a School, the School's own institutional privacy notices and its agreement with StackERP (including any Data Processing Agreement, "DPA") shall operate alongside this Policy, and in the event of any conflict solely as between StackERP and the School regarding the processing of Student, Parent, or Teacher data, the terms of the applicable DPA shall prevail.
This Policy does not apply to any third-party website, application, or service that may be linked to or integrated with the Platform, except to the extent expressly stated in Section 10 (Third-Party Service Providers and Data Sharing) below.
For the purposes of this Policy, unless the context otherwise requires:
This Policy applies to all personal data processed by StackERP in connection with the Platform, whether collected directly through the website or mobile applications, entered into the ERP by a School or its Administrators/Teachers, or generated automatically through use of the Platform (such as device and log data). This Policy applies uniformly across StackERP's Basic, Standard, Professional, and Enterprise subscription plans, save that certain modules described in this Policy (for example, biometric, GPS, RFID integrations, WhatsApp/SMS communication modules, or a dedicated Parent App) are available only on specific plans or as optional add-ons, and the corresponding processing activities described herein will only be relevant to an Institution to the extent it has activated such modules.
StackERP collects personal data from multiple categories of individuals, in connection with the operation of the Platform. The categories set out below are illustrative of the fields typically configured within the Platform's modules; the precise fields collected for a given Institution depend on the modules and plan activated by that Institution.
Name, gender, date of birth, contact number, email address, residential address, photograph, government-issued identification numbers (such as Aadhaar, where voluntarily provided by a School for admission or verification records), and login credentials (username and encrypted password) associated with a User's account on the Platform.
School or trust name, registered address, affiliation/board details, official contact persons, institutional email domains, billing and subscription information, GSTIN and other statutory registration details of the Institution, bank account or payment details used for invoicing, and configuration data such as academic sessions, class/section structures, and fee heads created by the Institution within the Admin Panel.
Full name, date of birth, gender, class/section, roll number, admission number, photograph, parent/guardian names and contact details, residential address, blood group and medical information (where voluntarily entered for hostel or emergency purposes), attendance records, academic performance, examination results, homework and assignment submissions, disciplinary and leave records, library borrowing history, transport route and pickup details, hostel room allocation and mess/complaint records, fee payment history, and any documents uploaded to the Student Panel.
Name, relationship to the Student, contact number, email address, residential address, occupation (where requested by a School for admission records), parent login credentials for the Student/Parent App, communication preferences, and fee payment and transaction records associated with the Parent's account.
Name, contact details, photograph, employee/staff ID, subject and class assignments, qualifications, attendance and leave records, timetable and schedule data, salary and remuneration details (Professional and Enterprise Plans), digital ID card data, and materials, assignments, question banks, or exam content uploaded by the Teacher.
Name, designation, contact details, login credentials, and activity logs associated with administrative actions performed on the Platform, which are retained for audit and security purposes.
IP address, browser type and version, device type, operating system, unique device identifiers, mobile network information, and general location information (such as city-level location inferred from IP address), collected automatically when the Platform is accessed.
StackERP and its service providers use cookies, local storage, and similar tracking technologies on the website and web dashboards to enable core functionality, remember preferences, and understand usage patterns. Further detail is provided in Section 17 (Cookies Policy) below.
Aggregated and, where necessary, individual-level usage data — such as pages/screens visited, features used, session duration, click patterns, and crash/error reports — collected through analytics tools (including Google Analytics and Firebase Analytics, where enabled) to help StackERP understand and improve the Platform.
Server and application log files recording access timestamps, IP addresses, requests made to the Platform, error codes, and referring/exit pages, retained for security monitoring, troubleshooting, and audit purposes.
StackERP collects and processes personal data for the following purposes:
StackERP does not use Student, Parent, or Teacher personal data processed on behalf of a School for StackERP's own independent marketing purposes, and does not sell such personal data to third parties.
Where the DPDP Act applies, StackERP and the relevant Institution rely on the following legal bases for processing personal data through the Platform:
Where processing is based on consent under the Digital Personal Data Protection Act, 2023, Data Principals may withdraw their consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out before such withdrawal. Certain services may become unavailable where consent is withdrawn.
As between StackERP and an Institution, the Institution is responsible for obtaining and maintaining valid consent from Students, Parents, and Teachers (or, in the case of children, verifiable consent from parents/guardians) prior to entering their personal data into the Platform, and for providing appropriate notice regarding such processing, as further detailed in the applicable DPA between StackERP and the Institution.
StackERP recognises that a significant proportion of personal data processed through the Platform relates to children, being Students enrolled with an Institution. StackERP takes the following approach to children's privacy, consistent with the heightened obligations applicable to processing of children's personal data under the DPDP Act:
StackERP expressly acknowledges that all data entered into the Platform by or on behalf of an Institution remains the property of that Institution. StackERP does not claim ownership over any Institutional data processed through the Platform. StackERP's role in respect of such data is that of a service provider and Data Processor, processing the data strictly on the documented instructions of the Institution and for the purpose of providing the Services.
Upon termination or expiry of an Institution's subscription, StackERP shall, subject to the terms of the applicable agreement, make Institutional data available for export by the Institution for a reasonable transition period, after which such data shall be deleted or anonymised in accordance with Section 13 (Data Deletion) below, save where retention is required by applicable law.
StackERP performs periodic backups to support disaster recovery and business continuity. Backup retention periods may vary depending on the customer's subscription plan and technical architecture. StackERP implements administrative, technical, and organisational security measures designed to protect personal data processed through the Platform against unauthorised access, alteration, disclosure, or destruction.
Personal data transmitted between User devices and StackERP's servers is protected using industry-standard transport encryption protocols (such as TLS/HTTPS). Passwords are stored using one-way cryptographic hashing and are not stored or transmitted in plain text. Sensitive fields are handled in conjunction with PCI-DSS compliant payment gateway partners rather than stored directly on StackERP's servers wherever technically feasible.
The Platform and associated databases are hosted on reputable third-party cloud infrastructure providers. StackERP configures logical access controls, network firewalls, and role-based access restrictions to limit access to Institutional data to authorised personnel on a need-to-know basis. Enterprise Plan clients may be offered dedicated server/hosting arrangements as described in their commercial agreement.
Access to production systems and databases is restricted to authorised StackERP personnel involved in the operation, maintenance, and support of the Platform. Administrative actions performed on the Platform are logged for audit purposes. StackERP conducts periodic reviews of its access control and security practices as part of its ordinary course of business.
No method of electronic transmission or storage is completely secure, and while StackERP takes reasonable and appropriate measures to protect personal data in line with the requirements of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, StackERP cannot guarantee absolute security of information transmitted to or stored on the Platform.
StackERP engages certain third-party service providers to operate specific features of the Platform. These providers process personal data solely to the extent necessary to perform the relevant function, under contractual confidentiality and data-protection obligations consistent with this Policy.
StackERP does not permit any of the above service providers to use personal data processed through the Platform for their own independent marketing purposes, and requires such providers to implement appropriate security safeguards consistent with this Policy.
Save as set out in Section 11 above, StackERP does not sell, rent, or trade personal data processed through the Platform. StackERP may disclose personal data in the following limited circumstances:
StackERP retains personal data processed through the Platform for as long as reasonably necessary to provide the Services to the relevant Institution and for such further period as may be required to comply with applicable legal, tax, accounting, or regulatory retention obligations.
An Institution may request deletion of specific Student, Parent, or Teacher records through the Admin Panel or by written request to StackERP, subject to any retention obligations under applicable law. Upon termination or non-renewal of an Institution's subscription, StackERP will delete or irreversibly anonymise the Institution's data from its production systems within a reasonable period, save for data that StackERP is required to retain under applicable law or that persists in encrypted backup systems until the ordinary backup-cycle overwrite/deletion occurs.
Subject to applicable law, including the DPDP Act, individuals have the following rights in relation to their personal data processed through the Platform:
Requests to exercise these rights in respect of Student, Parent, or Teacher data should ordinarily be directed to the relevant Institution in the first instance. Requests relating to data for which StackERP is itself the Data Fiduciary may be directed to StackERP using the contact details in Section 22.
Each Institution using the Platform is responsible for: (a) obtaining and maintaining valid notice and consent from Students, Parents, and Teachers prior to entering their data into the Platform; (b) ensuring the accuracy of data entered into the Platform; (c) configuring role-based access appropriately; (d) promptly notifying StackERP of any unauthorised access to its Administrator accounts; and (e) complying with its own obligations as an educational institution under applicable Indian law.
The Platform's primary hosting infrastructure is intended to be located within India; however, certain third-party service providers (such as Google/Firebase services) may process or store data on servers located outside India. Where personal data is transferred outside India, StackERP takes reasonable steps to ensure that such transfers occur through service providers that maintain appropriate contractual and technical safeguards. Institutions that require data to be hosted exclusively within India may request such an arrangement, subject to availability under the applicable subscription plan.
The StackERP website and web-based dashboards use cookies and similar technologies for the following purposes:
Users may control or disable non-essential cookies through their browser settings; however, disabling strictly necessary cookies may prevent proper functioning of the Platform. StackERP does not use cookies to serve third-party behavioural advertising on the Platform.
Certain features of the Platform (currently made available primarily under the Enterprise Plan) involve automated analysis of academic data to generate insights, summaries, or recommendations for the Institution. In connection with such AI-assisted features:
In the event StackERP becomes aware of a breach of personal data processed through the Platform that is likely to affect Users, StackERP will: (a) take prompt steps to investigate, contain, and remediate the incident; (b) notify the affected Institution(s) without undue delay, in accordance with the DPDP Act and its rules; and (c) provide the affected Institution with such information as is reasonably necessary to enable the Institution to meet its own notification obligations.
StackERP may update or revise this Policy from time to time to reflect changes in the Platform's features, legal or regulatory requirements, or StackERP's data-processing practices. The "Last Updated" date at the foot of this Policy indicates when it was last revised. Continued use of the Platform following any update to this Policy constitutes acceptance of the revised Policy.
In accordance with the Information Technology Act, 2000 and the DPDP Act, StackERP has designated the following contact point for queries, complaints, and grievances relating to this Policy:
Grievance Officer / Data Protection Contact
StackERP Solutions Private Limited
E-409, IV Floor, Avni Homes, Khasra No. 356, Vatika, Sanganer, Jaipur, Rajasthan, India
Email: admin@stackerpsolutions.com
Phone: +91 85408 01482
StackERP will endeavour to acknowledge grievances promptly and to resolve them within the timelines prescribed under applicable Indian law.
This Policy shall be governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the rules and regulations made thereunder. Subject to the dispute resolution provisions of the applicable agreement between StackERP and an Institution, the courts at Jaipur, Rajasthan shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy. Any dispute shall first be attempted to be resolved through good-faith negotiations before initiating legal proceedings.
This Privacy Policy has been prepared to reflect StackERP Solutions Private Limited's data-processing practices as described to the drafter as of the date above. It is recommended that this Policy be reviewed periodically — and prior to publication — by StackERP's internal stakeholders and, where appropriate, by independent Indian legal counsel.
© 2026 StackERP Solutions Private Limited. All Rights Reserved.