Google Play Policy Compliant

Privacy Policy

Publisher: OsamByte

Effective Date: July 23, 2026

App Version: 2.0+

Welcome to CampusNave ("we," "our," or "us"), a cloud-based School ERP platform developed and operated by OsamByte (Islamabad, Pakistan). CampusNave provides digital administrative, academic, fee management, payroll, and communication tools for educational institutions, principals, teachers, staff, students, and parents.

This Privacy Policy explains how CampusNave collects, uses, stores, discloses, and protects user data across our mobile applications, web portals, and server APIs. This document is designed to satisfy the strict transparency requirements of the Google Play User Data Policy, Google Play Developer Program Policies, and international educational data privacy standards.

1. Data Controller & Data Processor Roles

Under this system architecture:

  • The Educational Institution (School): Acts as the primary Data Controller. The school determines which students, teachers, parents, and administrators are enrolled, creates accounts, and manages institutional academic and financial records.
  • OsamByte / CampusNave: Acts as the Data Processor. We store and process data strictly under the instructions of the contracting educational institution to deliver school management software services.

2. Information We Collect

We collect only the information necessary to provide core school management functionality. All collected fields correspond directly to data schemas implemented in our applications:

A. Personal & Identification Data

  • Student Records: Full Name, Father's Name, Roll Number, Class, Section, Academic Session, Admission Date, Gender, Age, Date of Birth, Profile Photo (Avatar).
  • National Identifiers (Pakistan): Student CNIC / B-Form Number and Father / Guardian CNIC Number (for official school registration and transcript verification).
  • Teacher & Staff Records: Full Name, Father / Husband Name, Contact Number, Emergency Contact, Residential Address, CNIC, Education, Work Experience, Previous School, Joining Date, Profile Photo, Salary & Bank Payroll details.
  • Administrator Records: Name, Guardian Relation / Name, CNIC, Address, Education, Salary, Profile Photo, System Access Role.
  • Parent / Guardian Records: Contact Phone Numbers, Emergency Contacts, Residential Address, Linked Student Profiles.

B. Academic & Attendance Data

  • Daily student class attendance, teacher attendance punch logs, exam marks, assignment submissions, quiz results, report cards, class timetables, and digital diary entries.

C. Financial Records

  • Fee structures (tuition fee, admission fee, lab fee, paper money, custom fee heads), generated fee vouchers, payment statuses, arrears, fee concessions, and staff salary disbursement history.
  • Note: Raw payment card numbers or bank passwords are never collected or stored on CampusNave servers. Fee payments are recorded manually by school accountants or via authorized third-party payment channels.

D. Device, Technical & Telemetry Data

  • Push Notification Tokens: Expo Push Tokens (`token`), Device OS (`android` / `ios`), Device Name, and App Version stored via our `DeviceToken` model to deliver operational notifications.
  • Technical Telemetry: Anonymized IP address hashes (`ipHash`), User-Agent string, User Login Credentials (salted bcrypt password hashes), and active session tokens (JWT access & refresh tokens).

3. Android Permissions & Explicit Usage Disclosures

The CampusNave Android application requests specific system permissions to deliver core functionality. Every requested permission is strictly mapped to an active feature:

LOCATIONFine & Coarse Location (`ACCESS_FINE_LOCATION`, `ACCESS_COARSE_LOCATION`)

Purpose: Precise location is accessed exclusively for Teacher Self Check-In / Check-Out Geofencing. When a teacher initiates an attendance punch, the app captures current GPS coordinates (`latitude`, `longitude`, `accuracyMeters`) to verify whether the teacher is physically within the school's authorized branch perimeter (`radiusMeters`).

Transparency Guarantee: Location coordinates are recorded ONLY at the exact moment of an attendance punch. CampusNave does NOT run background location tracking or continuously track users outside of attendance events.

CAMERACamera Permission (`CAMERA`)

Purpose: Camera access is used to allow users to capture profile photos (avatars for students, teachers, and admins), take photos of documents for upload, and scan QR codes on Student / Staff ID Cards. Photos are captured only when initiated by the user.

STORAGEStorage & Media Permissions (`READ_EXTERNAL_STORAGE`, `WRITE_EXTERNAL_STORAGE`)

Purpose: Storage access is required to allow users to select profile pictures from device media and download generated PDF files, including monthly fee vouchers, report cards, date sheets, class timetables, and student ID cards.

NOTIFICATIONSPost Notifications (`POST_NOTIFICATIONS`)

Purpose: Notification permission allows CampusNave to deliver urgent school announcements, attendance status alerts, fee due reminders, assignment updates, and examination results directly to your device.

NETWORKInternet & Network Access (`INTERNET`, `ACCESS_NETWORK_STATE`)

Purpose: Required to establish encrypted HTTPS/WSS connections with CampusNave servers to retrieve schedules, transmit attendance, update grades, and receive live notifications.

4. How We Use Your Information

Information collected through CampusNave is used solely for legitimate educational administration purposes, including:

  • Managing daily school operations (student enrollment, attendance marking, class timetables).
  • Compiling academic marks, generating report cards, transcripts, and handling session promotions.
  • Processing school fee vouchers, fee tracking, arrears management, and payroll processing.
  • Verifying teacher attendance proximity via circular geofence rules.
  • Delivering instant push notifications and system operational alerts to parents and staff.
  • Ensuring platform security, audit logging, and protection against unauthorized account access.

Commercial Disclosure: We DO NOT sell, rent, monetize, or trade any personal information, student records, or school data to third-party advertisers or data brokers under any circumstances.

5. Data Protection, Security & Encryption

CampusNave employs rigorous technical and organizational safeguards to ensure your data remains secure:

  • Encryption in Transit: All data transmitted between mobile devices, web portals, and backend servers is encrypted using industry-standard Transport Layer Security (TLS 1.2 / TLS 1.3 / SSL HTTPS).
  • Credential Security: User passwords are never stored in plain text. All passwords are salted and hashed using `bcrypt` before storage.
  • Authentication Tokens: Access is authorized using short-lived JSON Web Tokens (JWT) and cryptographically secure refresh tokens.
  • Role-Based Access Control (RBAC): Strict permission scoping ensures users access only the data permitted by their assigned role (SUPER_ADMIN, ADMIN, TEACHER, STUDENT).
  • Infrastructure Security: Database clusters and servers are protected by automated firewalls, rate limiting, and regular automated database backups.

6. Third-Party SDKs & International Cloud Processing

To maintain system reliability, CampusNave integrates a limited number of trusted infrastructure service providers. Each provider operates under strict confidentiality standards:

Provider / ServicePurposeData Processed
Expo Push Service (`expo-server-sdk`)Push Notification DeliveryPush Tokens, Device OS, App Version, Notification Title/Body
MongoDB Atlas Cloud DatabasePrimary Encrypted Data StorageEncrypted Student, Staff, Academic, and Fee Records
Render & Netlify Cloud HostingServer Hosting & Web Application ExecutionHTTPS API Requests, Application Telemetry, Transient Logs
Leaflet / OpenStreetMapGeofence Boundary Map DisplayBranch Location Coordinates (for admin setup map visualization)
Resend Email APITransactional Email AlertsUser Email Address, Email Message Body

* Note: Server and database infrastructure is hosted in secure tier-3/4 international cloud data centers with 24/7 physical and network security.

7. Data Retention & Account Deletion Policy

A. Data Retention

We retain educational, attendance, and financial records for as long as the contracting school maintains an active subscription with CampusNave, or as required by applicable educational auditing regulations in Pakistan. When a student completes studies or a teacher leaves, school administrators mark the record as inactive (`isActive: false` soft-delete), preserving historical audit trails (such as past transcripts and issued fee receipts).

B. Account & Data Deletion Requests

In full compliance with Google Play Console Account Deletion requirements, users (students, parents, teachers, staff) have the right to request deletion of their personal account and associated data:

  • Via School Administration: Contact your school's administrative office directly. Authorized school administrators can deactivate student/teacher profiles or submit a data purge request to OsamByte.
  • Direct Web / Email Deletion Request: If you cannot reach your school administration, you may submit a formal Data Deletion Request directly to the OsamByte Privacy Officer by emailing campusnave@gmail.com with the subject line "Account Deletion Request - CampusNave" or submitting a request at https://campusnave.com/privacy.

Upon receiving a verified request, OsamByte coordinates with the educational institution to delete or permanently anonymize personal data within 30 days, except where retention is required by statutory auditing laws.

8. Children's & Student Data Privacy

Because CampusNave is a school management system, our services process data relating to minor students. This processing occurs under strict institutional authorization:

  • Students do not independently register for accounts online. Accounts are created and provisioned exclusively by authorized school administrators.
  • The educational institution represents that it has obtained appropriate parental or guardian consent to register student records in the school management system.
  • Parents and legal guardians retain the right to inspect their child's academic records, request corrections, or address privacy inquiries through their school office or by contacting us.

9. User Rights & Policy Updates

Depending on your location, you hold rights regarding your personal data, including the right to request access, rectification, restriction of processing, or data export.

We may update this Privacy Policy periodically to reflect changes in our app features or regulatory requirements. Material updates will be published on this page with a revised "Effective Date" and notified within the app where appropriate.

10. Contact Information & Developer Details

If you have any questions, concerns, or data privacy requests regarding this Privacy Policy or CampusNave, please contact our Privacy & Developer Compliance team:

Application: CampusNave School ERP

Developer / Publisher: OsamByte

Privacy Contact Email: campusnave@gmail.com

Contact Phone: +92 311 5929854

Headquarters Address: Islamabad, Pakistan

Official Website: https://campusnave.com

← Back to Home© 2026 OsamByte. All Rights Reserved.