InstaRaise

COPPA COMPLIANCE POLICY AND NOTICE OF INFORMATION PRACTICES

November 13, 2023

1. Is InstaRaise subject to COPPA?

The Children’s Online Privacy Protection Act (COPPA) governs the collection of personal information by online services directed at children under the age of 13, and general audience online services when they have actual knowledge that a user is a child under the age of 13. Since a portion of the target audience of the InstaRaise service is composed of children under the age of 13, InstaRaise is subject to COPPA. An online service that is subject to COPPA must obtain parental consent prior to collecting personal information from children.

2. How does InstaRaise obtain parental consent?

A longstanding Federal Trade Commission (FTC) staff guidance recognizes an exception to the requirement of obtaining parental consent for online operators providing services to schools (Ed Tech Operators), which is known as the School Exception. The School Exception allows schools to provide consent to the collection of personal data from children in place of the requirement for parental consent. 

Note that the school exception is set out only in FTC guidance and not, expressly, in the statute or COPPA Rule(1.). Under the School Exception, the school’s decision to use the online service obviates the need for the operator to get individual parental consent for school use. The School Exception is described in the FTC FAQ, Section N(2.). Therefore, InstaRaise satisfies the requirement to obtain parental consent when the school, through our contract with the school, provides this consent. Accordingly, InstaRaise will not collect personal information from a child under the age of 13 unless that child’s teacher, school, or school district, acting as the parent’s agent, has agreed to obtain the required parental consent.

3. Scope of the School Exception

Note that the School Exception to obtaining individual parental consent is narrowly interpreted. It applies only to the collection of personal information that is “reasonably necessary for the child to participate in that [educational] activity.”(3.) See the attached InstaRaise Notice of Information Practices describing the information that InstaRaise collects. If an Ed Tech Operator intends to collect personal information that goes beyond that direct purpose, it must still obtain verifiable parental consent before doing so and it may not condition use of the service for the educational activity on obtaining that consent.

4. Personal Data Covered by COPPA

Personal information of children that is covered by COPPA means: means individually identifiable information about an individual collected online, including: (1) A first and last name; (2) A home or other physical address including street name and name of a city or town; (3) Online contact information as defined in this section; (4) A screen or user name where it functions in the same manner as online contact information, as defined in this section; (5) A telephone number; (6) A Social Security number; (7) A persistent identifier that can be used to recognize a user over time and across different Web sites or online services. Such persistent identifier includes, but is not limited to, a customer number held in a cookie, an Internet Protocol (IP) address, a processor or device 

serial number, or unique device identifier; (8) A photograph, video, or audio file where such file contains a child’s image or voice; (9) Geolocation information sufficient to identify street name and name of a city or town; or (10) Information concerning the child or the parents of that child that the operator collects online from the child and combines with an identifier described in this definition.(4.)

5. Other requirements for qualifying for the School Exception

In addition to obtaining parental consent by means of receiving consent from the school, InstaRaise is also required to satisfy the following requirements to qualify for under the School Exception: 

InstaRaise must provide the same Notice of Information Practices to the school that it otherwise would be required to provide directly to a parent,

InstaRaise may only collect data that is directly related to performing a school function, and

InstaRaise may use information collected from child users only to provide the service requested by the school and not for advertising, marketing or any other commercial purpose.

6. Data Retention

COPPA strictly prohibits operators from retaining children’s personal information for longer than is “reasonably necessary to fulfill the purpose for which it is collected.”(5.) Our data retention policy is set forth in our Notice of Information Practices. If the school would like InstaRaise to retain the information for a longer period or subject to other conditions, then this request will need to be stated in our contract with the school, or in a supplemental written document issued by the school.  

7. Data Security Requirements

COPPA requires that operators “establish and maintain reasonable procedures to protect the confidentiality, security, and integrity”(6.) of personal information. If a school requires InstaRaise to agree to specific data privacy agreements these will be set forth in your InstaRaise contract or in a supplemental document issued by the school.

8. InstaRaise Notice of Information Practices

InstaRaise’s Notice of Information Practices is attached as Exhibit A and describes how InstaRaise complies the requirements listed above. 


  1.  See 6 C.F.R. Part 312
  2.  https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions
  3.  (see May 19, 2022 FTC Policy Statement p. 3) https://www.ftc.gov/system/files/ftc_gov/pdf/Policy%20Statement%20of%20the%20Federal%20Trade%20Commission%20on%20Education%20Technology.pdf
  4.  See 16 C.F.R. Part 312.2
  5.  See 16 C.F.R. Part 312.10
  6.  See 16 C.F.R. Part 312.3

Exhibit A

InstaRaise

NOTICE OF INFORMATION PRACTICES

DIRECT NOTICE TO EDUCATIONAL INSTITUTIONS ACTING AS AGENTS FOR PARENTS WITH CHILDREN UNDER THE AGE OF 13 WITH RESPECT TO CHILDREN’S USE OF THE INSTARAISE SERVICE

As a best practice, InstaRaise recommends that educational institutions make this notice available to parents so that they may review the personal information collected.

1. What is the service for which data will be collected?

The service for which data is collected is a fundraising service that facilitates raising funds to support activities of the school.

2. What personal information will be collected?

InstaRaise only collects the minimal amount of personal data necessary for children to use our services. Specifically InstaRaise collects, first name, last name, photograph (optional),  email address, and phone number. We may ask for certain information that is not personally identifiable like, school name, school address, school city/district, or school grade, in connection with a child’s use of the services and to help us improve our services. We store a child’s user name and password on our system when the child registers for the services. We may also store the IP address from which the child accesses the services in connection with the child’s use of the services.

We use cookies, and other similar technology, to collect information when children use our service such as the amount of time children spend on activities available through the services, and the actions performed by children such as logging in and out, and the pages children visit. Note that InstaRaise staff are able to access and view the time children spend on activities. This information may also be used for analytical and security purposes by InstaRaise.

3. How will the information be used?

The  information that InstaRaise collects from children is only used to provide the specific service requested by the school and is not used for advertising, marketing or any other commercial purpose.

We use children’s personal data to provide the services in which a child is participating. This may include communicating with the child multiple times through email or other forms of communication. We may use the non-personally identifiable data we collect to improve the services.

InstaRaise retains personal data in a form which permits identification of a child for as long as necessary to provide the services in which the child is participating, or for other business purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements. We may be required by law to keep some types of information for certain periods of time (e.g., statute of limitations).

4. How and with whom is information shared?

We do not sell or rent children’s personal data.

Some services allow children to make information, including personal data, available for other children participating in the same services and InstaRaise staff to view online. In certain limited circumstances, the services may include features that allow children to publicly post their information, including personal data. 

We may disclose aggregated data that does not identify any individual or device. In addition, we may disclose children’s personal data: (i) to third parties we use to provide or support our services; (ii) if we are required to do so by law or legal process, such as to comply with any court order or subpoena or to respond to any government or regulatory request; (iii) if we believe disclosure is necessary or appropriate to protect the rights, property, or safety our company, our customers or others, including to protect the safety of a child, protect the safety and security of the services; or enable us to take precautions against liability; or (iv) to law enforcement agencies or for an investigation related to public safety.

In addition, if InstaRaise is involved in a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of the InstaRaise assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding or event, we may transfer the personal data we have collected or maintain to the buyer or other successor.

All of our service providers are bound by agreement not to use or share the information without our express instructions.

5.What is our data retention policy?

Data collected is maintained during the current fundraising campaign, and for future campaigns. If there is no campaign occurring within 36 months, then InstaRaise will thereafter delete the data, unless otherwise required for complying with our legal obligations, resolving disputes, and enforcing our agreements. 

6. What are our data security practices?

InstaRaise uses industry standard methods to protect the confidentiality, security, and integrity of its user’s data, including personal information collected from children, against unauthorized use or access, disclosure, alteration, unlawful or accidental destruction, or loss. We ensure that all such protected data is encrypted in transit, and is only retained or deleted in accordance with our Privacy Policy or any overriding agreements with organizations.

7. What are our data remediation procedures?

If there is a data breach, we will promptly notify the school, perform actions necessary to block the breach and prevent such a breach from recurring, and provide any other notices and perform any actions as may be required by law.

8. How do schools and parents get access to the information?

At any time and upon providing proper identification, the school and parents may access and review a child’s personal data maintained by us, request that we update or delete such personal data, and/or refuse to allow us from further collecting or using the child’s personal data.

You can review, change, or delete the child’s personal data by sending us an email at [email protected] or calling us at 516-620-0855. To protect your and your child’s privacy and security, we may require you to take certain steps or provide additional information to verify your identity before we provide any personal data or make corrections.