Privacy Policy and Data Use – FERPA and COPPA
FERPA Privacy and Data Protection Statement**
*In compliance with the Family Educational Rights and Privacy Act (FERPA)*
At Spoiled Rotten Photography, we are committed to safeguarding student data and complying with the Family Educational Rights and Privacy Act (FERPA). Below are the principles we follow to ensure transparency, security, and respect for students and their families.
Transparency
To create the PSPA file required by the yearbook company, schools must provide us with limited student data:
* Student first and last name
* Grade
* Teacher
* Student ID number
When parents access their child’s private photo gallery (using student name and ID number), we collect:
* Guardian’s name
* Email address
* (Optional) Phone number
If a parent places a ship-to-home order, we also collect a mailing address for delivery.
We never sell, share, or use student or guardian information for marketing purposes.
The only exception is the PSPA file securely shared with the yearbook company
Control
Spoiled Rotten Photography acts as a school official under FERPA. Schools retain control of all personally identifiable information (PII) from education records.
Parents and guardians voluntarily choose to provide their information to:
* View their child’s portraits
* Place an order
Parents or eligible students may contact our customer service to:
* Review what data we’ve collected
* Request corrections to inaccurate information
* Request that their personal data be permanently deleted
Since the school provides only basic student information, and parents choose what data to share, the need for corrections is minimal.
Choice
Our products are designed to collect only the data necessary to function. We clearly identify:
* Required data for basic operation
* Optional data collection
Parents are never required to submit personal information unless they wish to access or purchase portraits.
Security
We take strong measures to protect all data, including:
* Encrypted access and secure authentication
* Access restrictions and internal audit controls
* Secure server environments with limited access
Education
Our team completes annual training on data privacy, FERPA compliance, and security best practices to ensure your information is always handled responsibly.
COPPA Compliance Statement
Children’s Online Privacy Protection Act
At Spoiled Rotten Photography, we take children’s privacy seriously. In accordance with the Children’s Online Privacy Protection Act (COPPA), we are committed to protecting the personal information of children under 13 and ensuring parents stay in control of their child’s data.
Transparency
We clearly disclose what limited information we collect, how we use it, and with whom it may be shared.
From schools, we receive only the data needed to create photo galleries and yearbook files:
- Student first and last name
- Grade
- Teacher
- Student ID number
From parents or guardians, when accessing a gallery or placing an order, we may collect:
- Name
- Email address
- (Optional) Phone number
- Mailing address (if ordering shipped products)
We do not collect any additional information from children through our website or services.
We never sell, share, or use student or parent information for advertising or marketing. The only exception is the secure PSPA file sent to the yearbook company for school use.
Minimization of Data Collection
We only collect the information strictly necessary to:
- Deliver portrait galleries
- Fulfill photo orders
- Create yearbook files
No other data is collected, and we do not allow any third-party advertising or tracking
Parental Control of Children’s Data
Parents remain fully in control of their child’s data. At any time, parents can contact us at SRPhelp.com to:
- Review what personal data we have collected
- Request corrections to inaccurate information
- Request deletion of their child’s data from our system
- Request that we stop collecting any data from their child in the future
Security
We take the protection of your information seriously. Our data is stored securely using:
- Encrypted systems
- Access restrictions
- Internal audits and best practices
Employee Training
All Spoiled Rotten Photography employees complete annual training on privacy, child protection, and data security best practices. This helps us maintain a high standard of responsibility in working with children’s data.
If you have any questions or concerns about our COPPA compliance or data practices, we’re happy to help. Please contact us for more information or to request a review of your child’s data.
Questions or Requests?
If you have questions about your data or would like to request a correction or deletion, please contact us at SRPhelp.com and we’ll be happy to help.