
Legal
Agreement for High Schools.
Policies that apply when SpringPath works with high schools and their students are organized below by jurisdiction.
Applicable Policies
California
CCPA Policy
This notice describes the rights of Californians under the California Consumer Privacy Act of 2018 (“CCPA”). The CCPA requires businesses like us, that receive information from more than fifty thousand California consumers, to provide certain information to them. We fully describe our practices to all our users and guests in our Privacy Policy, but use this separate notice to ensure that we meet the CCPA’s requirements. This notice contains the following four parts:
- We Do Not Sell Your Personal Information
- Your CCPA Rights
- The CCPA Categories of Personal Information We Collect and the Sources
- The CCPA Categories of Personal Information We Share for a “Business Purpose”
1. We Do Not Sell Your Personal Information
The CCPA requires us to disclose whether we sell your personal information. We do not sell your personal information.
2. Your Rights Under the CCPA
2.1 Requests for Information
Like all of our users, you (or your authorized agent) can request a copy of your personal information. Under the CCPA, you can also request that we disclose how we have collected, used, and shared your personal information over the past 12 months, including the categories of personal information we collected and our purposes for doing so; the categories of sources for that information; the categories of third parties with whom we shared it for a business purpose and our purposes for doing so. Companies that sell personal information (we do not) must make additional disclosures.
If you are not a SpringPath user, you can submit your request via email to support@springpath.net.
2.2 Your Right to Opt Out of Sales
We do not sell personal information, so we don’t have an opt out.
2.3 Your Right to Notification
Under the CCPA, a company like SpringPath cannot collect new categories of personal information or use them for materially different purposes without first notifying you.
2.4 Nondiscrimination for exercising your CCPA Rights
The CCPA prohibits businesses from discriminating against you for exercising your rights under the law. Such discrimination may include denying services, charging different prices or rates for services, providing a different level or quality of services, or suggesting that you will receive a different level or quality of goods or services as a result of exercising your rights.
2.5 Your Right to Delete Personal Information
Like all of our users, you can request that we delete your personal information by closing your SpringPath account. You also can request that we delete specific information. We honor such requests, unless an exception applies, such as when the information is necessary to complete the transaction or contract for which it was collected or when it is being used to detect, prevent, or investigate security incidents, comply with laws, identify and repair bugs or ensure another consumer’s ability to exercise their free speech rights or other rights provided by law.
3. The CCPA Categories of Personal Information We Collect and the Sources
Our Privacy Policy describes the information we collect and its sources. This notice organizes that information around the personal information categories set forth in the CCPA.
| CCPA Personal Information Category | Sources of this Information |
|---|---|
| Identifiers (e.g., real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers) | Information you provide directly or through your interactions with our Services (as defined in our Privacy Policy) or partners (as described in Sections 1.2 and 2.4 of our Privacy Policy). Vendors that provide information to help us serve users relevant ads and understand the ads’ effectiveness. Information from other SpringPath users or customers. |
| Characteristics of protected classifications under California or Federal law (e.g., your gender or age) (“Characteristics of Protected Classifications”) | Information you provide to us directly and inferences we make based on that information. Information from our customers. |
| Commercial information (e.g., information regarding products or services purchased, obtained, or considered) | Information you provide to us directly, such as to buy a Premium service. Your interactions with our Services. Information from our partners and customers. |
| Internet or Other Electronic Network Activity Information (e.g., browsing history, search history, and information regarding your interactions with our Services) | Your interactions with our Services. Your visits to third party sites that offer our autofill, follow or “Apply with SpringPath” functionality, as needed for fraud prevention and security purposes. If you are a user, your interactions with the services of partners and customers that use the SpringPath platform. |
| Geolocation Data | Information you provide to us directly or through your interactions with our Services, as explained in Section 1.5 of the Privacy Policy |
| Professional or Employment-Related Information | Information you provide to us directly. Information from our customers, partners, or from other users (e.g., if a connection endorses you) |
| Inferences | Information you provide to us directly or through your interactions with our Services. Information from our customers and partners. |
| Personal information described in Cal. Civ. Code §1798.80(e) (such as name, address, telephone number, education, employment history, credit card or debit card number) | Information you provide directly or through your interactions with our Services. Information from our customers or partners. |
| Audio, electronic, visual or similar information | Information you provide directly or through your interactions with our Services, customers or partners |
We use this personal information for the purposes outlined in Section 2 of our Privacy Policy.
4. The CCPA Categories of Personal Information We Share for a “Business Purpose”
While we do not sell your personal information, we may share it to support our own operational purposes in providing Services to you, as described in our Privacy Policy. These operational purposes, known as “business purposes” under the CCPA, are described below. In addition, we may share personal information at your direction, such as when you choose to communicate with other users through our Services.
4.1 Auditing Interactions
We may share the types of personal information listed in Section 3 with partners, service providers and related companies, in order to audit interactions and transactions, such as to count or verify the positioning and quality of ad impressions.
4.2 Security Purposes
In order to secure our Services, including to detect, prevent and investigate security incidents or violations of our Professional Community Policies or applicable laws, we may share the types of personal information listed in Section 3 with our partners, service providers, law enforcement and related companies.
4.3 Service Improvements
In order to improve our Services (such as to identify bugs, repair errors or ensure that services function as intended) or conduct internal research and analysis to improve our technology, we may share the types of personal information listed in Section 3 with our partners, service providers and related companies.
4.4 Service Providers and Other Notified Purposes
We may share the types of personal information listed in Section 3 with Service Providers, as defined by the CCPA, in order to have them perform services specified by a written contract or with others for a notified purpose permitted by the CCPA (e.g., to respond to law enforcement requests).
Connecticut
STUDENT DATA PRIVACY POLICY, FOR CONNECTICUT HIGH SCHOOLS
Effective September 1, 2025 -
Thank you for choosing SpringPath, (which includes our online platform for “Guest” users and “Sign-In” users, collectively, “SpringPath”).
This Student Data Privacy Policy further explains SpringPath’s online information practices and the information collected. There may be other notices about our information practices and choices. Please review these disclosures and any other privacy disclosures to understand how they apply to you. Our standard Privacy Policy is designed to provide transparency into our privacy practices and principles.
INTRODUCTION
SpringPath is a podcast content delivery network and online college and career search platform for students.
Our registered or “sign-in” users (“Users”) share their student preferences for post-secondary locations, academics, athletics and more, while receiving relevant content, learning and developing skills, and find college and career opportunities. Our platform is viewable to Users and non-users (“Guests”). Guests use our online platform as a basic search engine to find college and career content, no contact information or preferences are saved for “Guests”.
These Policies are designed to provide transparency to our privacy practices and principles specifically applicable to student information. Please also review our Privacy Policy and User Agreement.
All student-generated content (collectively, “student data”) provided or accessed pursuant to this policy are not the property of SpringPath. “Student Data” is the property of the student or legal guardian.
The High School and student (or student legal guardian) shall have access to and the ability to delete student data in the possession of the SpringPath except in instances where such data is (A) otherwise prohibited from deletion or required to be retained under state or federal law, or (B) stored as a copy as part of a disaster recovery storage system and that is (i) inaccessible to the public, and (ii) unable to be used in the normal course of business by SpringPath.
The High School may request the deletion of any such student information or student-generated content if such copy has been used by the operator to repopulate accessible data following a disaster recovery.
The High School may request the deletion of student data. Such a request by the High School shall be made by electronic mail to sales@springpath.net SpringPath reserves the right to notify the student or legal guardian “User”, offering the option to continue maintaining an account with SpringPath beyond any agreement with the High School, in accordance with the terms of SpringPath’s User Agreement and Privacy Policy. SpringPath will delete the requested student data within (10) business days of receiving such a request.
A student, parent or legal guardian of a student may review personally identifiable information contained in student data and correct any erroneous information, if any, in such student data.
SpringPath shall take actions designed to ensure the security and confidentiality of student data.
SpringPath will notify the High School, in accordance with Conn. Gen. Stat. § 10-234dd, when there has been an unauthorized release, disclosure or acquisition of student data. Such notification will include the following steps:
Upon the discovery by SpringPath of a breach of security that results in the unauthorized release, disclosure, or acquisition of student data, or the suspicion that such a breach may have occurred, SpringPath shall provide initial notice to the High School and student or guardian as soon as possible, but not more than forty-eight (48) hours after such discovery (“Initial Notice”). The Initial Notice shall be delivered to the High School by electronic mail and shall include the following information, to the extent known at the time of notification:
- Date and time of the breach;
- Names of student(s) whose student data was released, disclosed or acquired;
- The nature and extent of the breach;
- SpringPath’s proposed plan to investigate and remediate the breach.
A. Upon discovery by SpringPath of a breach, SpringPath shall conduct an investigation and restore the integrity of its data systems and, without unreasonable delay, but not later than thirty (30) days after discovery of the breach, shall provide the High School with a more detailed notice of the breach, including but not limited to the date and time of the breach; name(s) of the student(s) whose student data was released, disclosed or acquired; nature and extent of the breach; and measures taken to ensure that such a breach does not occur in the future.
B. SpringPath agrees to cooperate with the Board with respect to investigation of the breach.
Student data shall not be retained or available, except a student, parent or legal guardian of a student may choose independently to establish or maintain an electronic account with SpringPath beyond any agreement with the High School.
SpringPath ensures its own compliance with the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. § 1232g, as amended from time to time.