← ClassOvation

Privacy Policy

Last updated: September 2026

Who we are

ClassOvation is operated by EMSERO LLC, a North Carolina limited liability company. ClassOvation is class-management software used by studios, gyms, swim schools, and academies (“studios”) to run registration, scheduling, billing, and communication. When a studio uses ClassOvation, the studio is the controller of the family and student information it enters; EMSERO LLC processes that information solely on the studio's behalf as its service provider.

Information we process

  • Account information — name, email, and password (stored only as a bcrypt hash) for the people who log in.
  • Family & student records — entered by studios: guardian contact details and student information including names, dates of birth, and any notes a studio records (which may include medical or allergy notes).
  • Payment information — card payments are processed by Stripe. Card numbers are handled by Stripe and are never stored on our servers; we retain only a token and the payment record.
  • Usage & security data — request logs, IP address, and timestamps used to operate the service, secure accounts, and record e-signatures.

How it is used

To provide the service the studio has engaged us for: enrolling students, billing families, sending studio communications and account emails (verification, receipts, reminders), and keeping the platform secure. We do not sell personal information and do not use student information for advertising.

Children's information

Student records are provided by studios and their enrolled families, not collected from children directly. What a studio may store about a student includes name, date of birth, address, photos, and any notes the studio records, which can include allergy or medical notes entered for safety during classes. This information is visible only to the studio's own authorized staff (never another studio's) and, where the platform shows it back to them, the student's own guardians. A studio is responsible for obtaining the consents its families and local laws require. Any studio can export its own family and student data at any time through the platform's self-serve export; a parent or studio may also request access to, correction of, or deletion of a student's information through the studio, or by contacting us below, and we honor deletion requests subject to the financial-record retention described next.

How studios' data is kept separate

All studios share the same application and database — there is no per-studio database — but every tenant table carries a studio (organization) identifier, and the database itself enforces that a query can only read or write rows for the studio it is authorized for. This database-enforced tenant isolation runs underneath the application's own authorization checks, as a second, independent backstop: one studio cannot see another's families, students, or billing records.

Service providers

We share information only with providers that help us run the service: Stripe (payment processing), Resend (email delivery), Fly.io (application hosting), Amazon Web Services (encrypted backup storage), Sentry (error monitoring, so we can find and fix problems), Expo (delivery of mobile push notifications to devices that opt in), and Anthropic (the AI model behind the staff assistant, message drafting, and import column matching; it processes the records needed to answer a staff request and does not train on them). Studios may also enable SMS delivery through a provider they configure. We will update this list, and note a material change here, before adding a new provider that processes personal information.

Your choices

Every broadcast email includes an unsubscribe link. Billing and account emails are required for the service and are not part of that opt-out. To access, correct, or delete information, contact your studio or us.

Security & retention

Data is encrypted in transit, backups are encrypted at rest, and passwords are hashed. We retain information for as long as a studio maintains its account and as required for legal and financial records, then delete or anonymize it — see our data retention policy for the specific schedule. Business, financial, and student/family records of a studio are kept for their audit and legal lifetime and removed only through a deliberate, operator-run studio offboarding, never an automated sweep; operational data with no ongoing purpose (spent tokens, aged telemetry) is purged automatically on a schedule.

If something goes wrong

If we confirm a data breach affecting a studio's information, we will notify the affected studio without undue delay and in any case within 72 hours of confirming the breach, describing what we know at the time: the nature of the incident, the categories and approximate volume of data involved, and the steps taken or planned. A studio is responsible for notifying its own families and, where applicable, its state regulator; we will support that notification with the facts we have.

Contact

Questions or requests: support@classovation.com.

See also our Terms of Service and our Data Processing Addendum.