Privacy Policy
Last updated 2 September 2026
Orange Fee ("Orange Fee", "we", "us") provides fee-collection software to schools and educational institutions ("institutions"). This policy explains what information we handle, how we use it, and how it's protected — for the institutions that use Orange Fee directly, and for the guardians who receive messages through it on behalf of their child's institution.
Who controls this data
Each institution is the data controller for its own students', guardians', and staff's information — they decide what to enter into Orange Fee and are responsible for having a lawful basis to do so. Orange Fee acts as a data processor, storing and transmitting that information on the institution's behalf and only as instructed by them.
What we collect
On behalf of an institution, Orange Fee stores:
- Student records: name, admission number, class, and fee/payment history.
- Guardian records: name and WhatsApp number, used solely to send fee-related messages.
- Payment records: amounts, dates, methods, and who at the institution recorded or confirmed each one.
- Staff accounts: name and login email, used to sign in to the institution's own dashboard.
We do not collect this information directly from students, who are minors — it is entered and managed by the institution itself.
How WhatsApp messages are used
Orange Fee sends fee reminders, payment QR codes, and payment receipts to guardians via the WhatsApp Business Platform, operated by Meta. Every message is sent from Orange Fee's own WhatsApp Business number, on the institution's behalf, and states which institution it's from.
This number does not hold two-way conversations. Any reply a guardian sends receives a single automatic message explaining that the number cannot respond, and directing them to contact their institution directly — no reply content is read, analyzed, or acted on automatically.
How data is stored and protected
Data is stored on infrastructure provided by Supabase (PostgreSQL, hosted in India where available) and Railway. Every institution's records are isolated from every other institution's at the database level — enforced by database-level access rules, not only by the application interface. Within an institution, a staff account only sees the branch(es) it has been explicitly granted access to.
Who we share data with
We do not sell personal data, and we do not share it with third parties for their own marketing purposes. Data is shared only where necessary to provide the service — with Meta, to deliver WhatsApp messages, and with our hosting providers, to store the data securely. If a payment gateway is added to Orange Fee in the future, this policy will be updated before that happens.
Cookies and sessions
Orange Fee uses a single session cookie to keep a staff member signed in. It is not used for advertising or cross-site tracking.
How long data is kept
Data is retained for as long as an institution's account is active. Financial records (invoices, payments, receipts) may be retained longer where an institution has a legitimate need to keep its own accounting history. An institution — or a guardian, regarding their own contact details — can request deletion at any time; see our Data Deletion page for how.
Changes to this policy
If this policy changes in a meaningful way, the "last updated" date above will change with it.
Contact
Questions about this policy, or a request regarding your data, can be sent to aaronjthomas2002@gmail.com.