PRIVACY POLICY - TARTAN APP
Effective Date: August 14, 2026
1. INTRODUCTION
This privacy policy governs the collection and use of information by Tartan App Inc. ("Tartan"), including, without limitation, information collected through Tartan website located at https://tartan.app (the "Website"), the related web-based application located at https://my.tartan.app ("Application"), and any other products or services to which this Privacy Policy applies (collectively, the "Service"). This Privacy Policy explains Tartan's practices for collecting, using, sharing, and otherwise processing personal information in connection with the Service. Tartan primarily offers its Service to academic institutions, such as school districts, school boards, and independent schools, their students and employees. When Tartan provides the Service to an academic institution, Tartan is a processor of information and "School Official" (as such term is defined under applicable student data privacy laws) acting on behalf of, and under the direction and control of, such academic institution. In such cases, the academic institution is the controller of information and retains all rights in the Student Data. When processing Student Data on behalf of an academic institution, Tartan will process such Student Data only for providing the Service as requested by the academic institution and in compliance with all applicable laws and regulations including, but not limited to, the Family Educational Rights and Privacy Act ("FERPA"), the Children's Online Privacy Protection Act ("COPPA"), and U.S. state student data privacy laws. If the terms of this Privacy Policy conflict with the terms of any Student Data Privacy Agreement between Tartan and an academic institution, the terms of the Student Data Privacy Agreement will control.
By clicking "I agree" or similar confirmation, by creating an account on the Service or by using the Service you are agreeing to be bound by the Privacy Policy. If you are using the Service on behalf of an organization, you represent that you have the authority to bind the organization to this Privacy Policy and are agreeing to this Privacy Policy for that organization. Where you are using the Service on behalf of an organization, "you" and "your" refers to the organization.
2. DESCRIPTION OF THE SERVICE
Tartan offers cybersecurity awareness training, phishing simulation, email threat analysis, and security-posture assessment (Google Workspace Audit) services for schools. The Service is provided at the direction of the school and is intended to be used for security education, training, and awareness efforts within the school.
3. COLLECTION OF PERSONAL DATA
As part of the Service, personal data about students and educators will be collected and processed by Tartan as provided by or on behalf of the educational institution. Students are not required to set up their own accounts or otherwise independently provide personal data to Tartan. All Student Data is provided to Tartan by the educational institution or by administrators acting on behalf of the educational institution in order to grant access to and use of the Service.
The Service is provided for use by students at the direction of the educational institution. The Service is not designed to be a social network or to enable social interaction between users of the Service. Students and other users will not be able to independently create content or upload content. The educational institution directs all use of the Service.
The educational institution will obtain any consent required by applicable law prior to the collection, use and disclosure of Personal Data, including the consent of a parent or guardian, as necessary. Parents and/or guardians can withdraw such consent through the educational institution at any time. If consent is withdrawn, Tartan will assist the educational institution with deleting the applicable Student Data within a reasonable period of time and in accordance with contractual and legal requirements.
4. PERSONAL DATA WE COLLECT
Tartan only collects and processes personal data that is necessary for the purposes of providing and supporting the Service. When the Service is provided to an educational institution, personal data, including Student Data, is submitted to Tartan by or on behalf of the educational institution or its authorized administrators. In such cases, Tartan acts as a processor with respect to the information and the educational institution is the controller and is responsible for ensuring that it has obtained any required consents under applicable law.
Student and Staff Data
When accessing the Service through an educational institution, Tartan collects and processes Student and Staff Data, which may include:
- Name and school-assigned email address
- Role (student/staff), department, and other organizational details
- Training module completion and scoring data
- Interaction and usage data within the Service
Threat Manager and Phish Report Button (Google Workspace & Gmail Add-On)
When a school enables the Threat Manager and Phish Report Button (Google Workspace & Gmail Add-On), Tartan requests access to Google user data, and processes reported email content and related technical data for phishing analysis, threat detection, administrator review, and remediation.
Depending on the report and the analysis required, this may include the email subject line, message body, sender and recipient email addresses, message identifiers, headers, links, attachment metadata, and, where necessary, attachment content, as well as related authentication results such as SPF, DKIM, and DMARC.
Tartan may also generate derived security information such as threat classifications, spoofing indicators, reputation results, QR code analysis, risk scores, and summaries. Tartan processes reporter and recipient identity data and limited organizational details only as needed to support administrator review and remediation within the school environment. Reported email content and related message data are retained for 7 days.
We do not use Google Data for advertising, marketing, or any other purposes not directly related to providing our Gmail Add-on.
Google Workspace Audit
Google Workspace Audit. When a school enables Google Workspace Audit and an administrator connects their Google Workspace using a super administrator account, Tartan requests read-only access to Google Workspace configuration and administrative data in order to assess the school's security posture against industry benchmarks. This data is limited to configuration and administrative metadata and includes: directory information (users, groups, organizational units, domains, and administrator role assignments), mobile device inventory and status, group settings, Cloud Identity policy and service settings (including Drive external-sharing configuration), administrator audit and activity logs (including administrator actions and user login events, such as failed sign-in attempts, over a rolling seven-day window), departing-user data-transfer records, per-user Gmail settings (such as automatic forwarding, POP/IMAP access, send-as and outbound-gateway configuration, mailbox delegation, and S/MIME), and public email-authentication DNS records (SPF, DKIM, DMARC, and MTA-STS).
If a school enables the optional "enhanced collection" mode, Tartan uses its existing Google domain-wide delegation to additionally read third-party OAuth application grants, per-user security metadata such as two-step verification enrollment status, Alert Center alerts, ChromeOS device inventory, Classroom course and roster membership, and the per-user Gmail settings described above. In this mode Tartan acts on behalf of an authorized administrator for administrator-level data and on behalf of the individual user for per-mailbox settings. Tartan only reads in this mode and never modifies any setting; some of these scopes are not offered by Google in a read-only form, so the access granted is technically capable of changes that Tartan never makes.
Google Workspace Audit does not access the content of emails, files, documents, calendars, or chats; it reads only configuration settings and administrative metadata. Tartan uses this data solely to generate audit findings (pass, warning, manual, or error results) and remediation guidance shown to administrators within the Service. Stored evidence is limited to identifiers such as user email addresses, group addresses, and device identifiers, and never includes message or file content.
Tartan requests the minimum scopes needed and only ever reads — it does not modify your Google Workspace settings. The standard connection uses read-only scopes. The optional enhanced-collection mode uses additional scopes, some of which Google does not offer in a read-only form (so the access granted is technically capable of making changes); Tartan uses them solely to read and never to write. Administrators can disconnect Google Workspace at any time, which revokes Tartan's access and deletes the stored authorization tokens.
Google API Services User Data Policy / Limited Use
Google API Services User Data Policy (Limited Use). Tartan App's use and transfer of any information received from Google APIs to other apps will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, with respect to raw or derived user data obtained through Google Workspace APIs: (I) we use it only to provide and improve the user-facing features through which it was accessed (directory synchronization, DMI integration, the Threat Manager / Tartan App Shield Phish Report Gmail add-on, and Google Workspace Audit); (II) we do not transfer it except as necessary to provide or improve those features, to comply with applicable law, or in connection with a merger, acquisition, or sale of assets with user consent; (III) we do not use it for serving advertisements; (IV) we do not allow humans to read it unless we have the user's affirmative consent for specific messages, it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or the data is aggregated and anonymized; and (V) data obtained through Google Workspace APIs is not used to develop, improve, or train generalized or non-personalized artificial intelligence and/or machine learning models.
Microsoft 365 Directory Synchronization
Microsoft 365 Directory Synchronization. When a school connects Microsoft 365, an administrator grants Tartan delegated, read-only access to the school's Microsoft Entra ID directory through the Microsoft Graph API in order to synchronize training and simulation recipients. This data is limited to: user profile information (name, school email address, user principal name, job title, department, office location, organization name, and account status), group names and memberships, administrative units and their members, the school's verified domains, and basic organization information. Directory synchronization does not access the content of emails, files, calendars, or chats.
Microsoft Direct Message Injection (DMI) and Threat Response
Microsoft Direct Message Injection (DMI) and Threat Response. If a school additionally enables Microsoft DMI, a Global Administrator grants Tartan application-level Microsoft Graph permissions (Mail.Send and Mail.ReadWrite) for the school's tenant. Tartan uses this access solely to: (i) deliver school-authorized phishing-simulation messages directly to staff mailboxes; and (ii) when a school administrator directs a threat-response action, locate a specific reported or identified message in affected mailboxes and move it to the junk folder, restore it, or delete it. Tartan reads mailbox data only to the minimum extent needed to locate the specific messages an administrator has asked it to act on, and never for any other purpose. The permissions granted are technically capable of broader mailbox access than Tartan uses; Tartan's use is limited to the functions described here. Schools can revoke this access at any time from their Microsoft admin center, and Tartan re-requires administrator consent whenever the Microsoft connection is re-established.
Outlook Add-in
Outlook Add-in. Where a school deploys the Tartan App Shield report button for Outlook, staff can report suspicious emails for analysis. When an email is reported, the add-in transmits the reported message and associated metadata to Tartan for threat analysis, in the same manner described for the Gmail add-on above. Reported message content is retained for seven days.
Children's Privacy
Children's Privacy. Tartan's Service is used by school students only at the direction of their school. Tartan does not permit children to create accounts, does not knowingly collect personal information directly from children, and collects Student Data only as a service provider to the school under FERPA's School Official framework and, where COPPA applies, in reliance on the school's authorization to consent on a parent's behalf for educational purposes. Tartan uses Student Data solely to provide the Service to the school, never for advertising or profiling, and retains it only as described in Section 8. Parents and guardians who wish to review, correct, or delete their child's information should contact their school district, which controls the data; Tartan responds to all such district requests within the timelines in its agreements.
Other Personal Data
- Account Information: Administrator name, full name (first and last), job title, phone number, physical address, email address, account login, and password.
- Usage Information: Technical information about browsers, operating systems, IP addresses, timestamps of when and how often our pages are accessed, page visit history, links clicked, emails reported to Tartan, including associated metadata (such as timestamps and sender/recipient information), training modules completed, buttons clicked in training modules, and amount of time spent on training modules.
- Payment Information: When you provide payment information to access paid features of the Service, that information is collected and processed by third-party payment providers (such as Stripe). Tartan does not have access to complete payment card numbers. In rare cases where we do not use a payment processor, we may ask you to provide us with billing or financial information directly. This would not include sensitive financial data, such as your complete credit card number, but would include information such as bank account numbers and payment terms.
- Other Information: Any information you provide when submitting support requests, surveys, communications, and through helpdesk interactions.
TARTAN DOES NOT COLLECT UNNECESSARY PERSONAL INFORMATION FROM STUDENTS AND DOES NOT EXPECT STUDENTS TO INDEPENDENTLY SUBMIT THEIR PERSONAL DATA.
5. THIRD-PARTY SERVICES
Tartan engages certain third-party service providers ("Subprocessors") to support the delivery, operation, and maintenance of the Service. These Subprocessors may process personal data, including Student and Staff Data, solely on behalf of and under the instructions of Tartan and the applicable educational institution, or as necessary to support authorised use of the Service in accordance with applicable agreements. Tartan ensures that all Subprocessors are subject to written agreements requiring them to protect personal data in a manner consistent with this Privacy Policy and applicable laws. Subprocessors are only permitted to process personal data to the extent necessary to provide their services and are not permitted to use such data for their own independent purposes.
The following Subprocessors are used in connection with the Service:
| Subprocessor Name | Country | Purpose / Service Provided | Personal Data Processed |
|---|---|---|---|
| Amazon Web Services (AWS) | USA | Cloud infrastructure and hosting | Data stored or processed via the application |
| Stripe, Inc. | USA | Payment processing | Limited payment and billing information (processed via Stripe; Tartan does not access full payment card details) |
| Mailgun Technologies, Inc. | USA | Transactional email delivery | Email addresses and message metadata (e.g., timestamps, delivery data) |
| ActiveCampaign, LLC (Postmark) | USA | Email notifications and messaging | Email addresses and message metadata (e.g., timestamps, delivery data) |
| Google LLC (Google Cloud / Google Workspace APIs) | USA | Google Workspace integration for directory synchronization, DMI integration, Google Workspace Audit, and school-enabled Gmail add-on features. | Limited Google Workspace user, directory, and administrative data needed to support directory sync, DMI integration, and when enabled by a school, reported email content and related metadata may also be processed for phishing analysis, administrator review, and remediation. |
| Microsoft Corporation | USA | Microsoft 365 integration for directory synchronization, DMI integration, threat response, and school-enabled Outlook add-in features | Limited Microsoft 365 user, directory, and administrative data; simulation and threat-response message operations within the school's own tenant |
| Bugsnag (SmartBear Software) | USA | Application performance monitoring and error tracking | Device data, error logs, and system identifiers (no Student Data content) |
| Anthropic PBC (Claude AI) | USA | AI-assisted phishing simulation content generation and, when enabled by a school, AI-assisted threat analysis, classification, and summary generation for email security features. | For phishing simulation content generation, pseudonymized scenario parameters, prompts, and related contextual inputs. When the Threat Manager and the Phish Report Button AI functionality is enabled by a school, reported email content and related metadata may also be processed for threat analysis, classification, and summaries, including subject lines, message bodies, sender and recipient email addresses, message identifiers, headers, links, attachment metadata, authentication results (such as SPF, DKIM, and DMARC), and related technical or contextual information. This may include non-pseudonymized personal data contained in reported messages. Student and Staff data, and any data obtained through Google Workspace APIs (including reported email content), is not used to develop, improve, or train generalized or non-personalized AI/ML models. |
| Cloudflare, Inc. | USA | Website and application delivery, DNS, and security services. | IP addresses, browser and device data, request metadata, and limited traffic and security log information associated with use of the Website and Service. |
Other Third-Party Services
Certain third-party services (including Google Analytics, Meta Pixel, LinkedIn Insight Tag, Reddit Pixel, Google Ads Tag, Microsoft Clarity, HubSpot, and SmartLead.ai) are used in connection with Tartan's public-facing website, analytics, or marketing activities. These tools are not integrated into, and are not used to process Student Data within, the core Service provided to educational institutions.
| Service Provider Name | Country | Purpose / Service Provided | Personal Data Processed |
|---|---|---|---|
| HubSpot, Inc. | USA | CRM, support, and communication tools | Names, email addresses, and support interaction history (primarily administrative users) |
| Chargebee | USA | Subscription billing system | Business data of school only; no Student Data processed |
| Google Analytics | USA | Website analytics and performance monitoring | No personal data or Student Data is intentionally transmitted; limited to aggregated or non-identifiable usage data |
| Microsoft Clarity | USA | Website session analytics and heatmapping | No personal data or Student Data is intentionally transmitted; limited to aggregated or non-identifiable interaction data |
| Meta Pixel / LinkedIn Insight Tag / Reddit Pixel / Google Ads Tag | USA | Marketing and advertising analytics | No personal data or Student Data is intentionally transmitted; limited to cookie-based or aggregated data |
| SmartLead.ai | USA | Outbound communication and sales automation | Business contact data of school administrators only; no Student Data processed |
Where such tools are used, Tartan applies appropriate contractual, technical, and organisational safeguards. Tartan seeks to limit any Personal Data processed to what is necessary for legitimate service-related purposes and applies data minimisation measures. Where feasible and appropriate, aggregated, pseudonymized, or non-identifiable data will be used.
Tartan implements appropriate contractual and organizational measures, including Data Processing Agreements or similar safeguards, with its Subprocessors and monitors their compliance with applicable privacy and security standards.
The Service may contain links to third-party websites or services that are not operated or controlled by Tartan. This Privacy Policy does not apply to such third-party services, and Tartan is not responsible for their data practices. Users are encouraged to review the privacy policies of any third-party services they access.
6. COOKIES AND OTHER TRACKING TECHNOLOGIES
Tartan collects information through the use of cookies and similar tracking technologies (including session cookies and web beacons). Tartan may use cookies and tracking technologies to facilitate and improve the Service, for Service administration and maintenance, to understand how the Service is used, and to monitor the Service's performance. Cookies and tracking technologies can help us gather information such as your IP address, device type, browser type, and usage activity. The Tartan Service only uses those tracking technologies that are necessary to facilitate normal operations. These include tracking technologies necessary to administer user sessions and for system maintenance and to improve Tartan services. Tartan may also use tracking and analytics technologies on Tartan's public website and for Tartan marketing purposes. These tracking and analytics technologies are subject to their own privacy policies and may collect information about your online activity over time. Cookies and similar technologies can often be managed through your web browser. Please note that if you choose to disable certain cookies you may experience reduced functionality from certain parts of the Service.
7. ACCESSING, CORRECTING AND MANAGING YOUR PERSONAL DATA
Tartan allows individuals to access and correct or update their personal data in accordance with applicable law.
When you access the Service through an educational institution, if you wish to access your Student Data (or request correction or deletion of your Student Data), you should direct your request to the applicable educational institution. Tartan will assist the educational institution with your request in accordance with applicable law.
As for administrators and other individuals who are not students, you can contact Tartan using the information below to request access to or correction or deletion of your personal data in accordance with applicable law.
Tartan may not delete your personal data where required to comply with legal obligations, to enforce existing contracts, to investigate potential wrongdoing, or to protect the rights, safety and security of Tartan and its users.
8. DATA STORAGE AND RETENTION
Tartan may store and process personal data in jurisdictions where it or its service providers operate, subject to applicable legal and contractual requirements. Tartan implements appropriate safeguards to ensure that personal data is protected in accordance with applicable data protection laws.
Where the Service is provided to an educational institution, Student Data is stored and retained in accordance with the instructions of the educational institution and applicable contractual obligations. Tartan retains Student Data only for as long as necessary to provide the Service and will delete or return such data upon request from the educational institution or upon termination of the relevant services, in accordance with applicable agreements and legal requirements.
For administrators and other non-student users, personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including to provide the Service, comply with legal obligations, and resolve disputes. Individuals may request deletion of their personal data by contacting Tartan using the contact details provided below, subject to applicable legal limitations.
9. CHANGE OF OWNERSHIP OR BUSINESS TRANSITION
In the event of, or in preparation for, a change of ownership, control, or business transition of Tartan (including a merger, acquisition, reorganization, or sale of assets), personal data may be disclosed to or transferred to a successor entity, subject to appropriate confidentiality and data protection safeguards.
Where personal data includes Student Data provided by an educational institution, such data will remain subject to the same restrictions and protections set out in this Privacy Policy and any applicable agreements with the educational institution. Any successor entity will be required to continue to process such data in accordance with those obligations.
Tartan will take reasonable steps to ensure that any such transfer is carried out in a manner that protects the confidentiality and security of personal data.
10. SECURITY
Tartan implements appropriate technical, administrative, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction. These safeguards include, but are not limited to, encryption of data in transit and at rest, role-based access controls, secure authentication mechanisms, and monitoring of systems for potential vulnerabilities and threats.
Access to personal data is limited to authorized personnel who require such access to perform their duties and who are subject to confidentiality obligations.
Tartan regularly reviews and updates its security practices to maintain the integrity, confidentiality, and availability of personal data, taking into account the nature of the data processed and applicable legal and contractual requirements.
11. COMMUNICATION PREFERENCES
In order to provide and administer the Service and for service-related announcements or to respond to your inquiries, Tartan may communicate with you through email, telephone, or other electronic communication methods.
You can change your communication preferences, or opt out of receiving certain non-service communications, by clicking on the unsubscribe link provided in such communications or by contacting Tartan. Communications that are required for the operation of the Service (including service updates, security alerts, and account notices) cannot be opted out of unless you cease use of the Service.
12. UPDATES
Tartan may revise this Privacy Policy as necessary to keep it up to date with changes in our practices or services, or to comply with applicable laws. When we do, we will post the updated Privacy Policy on our Website. If required by applicable law or under an agreement we have with you, we will notify you of material changes to this Privacy Policy by contacting the educational institution to which you belong. Your continued use of the Service after the effective date of a posted revision indicates your agreement to be bound by the revised Privacy Policy.
13. CONTACT US
If you have requests, questions or comments about the Privacy Policy or our data collection in general, please contact our Data Privacy Officer or our Privacy Team at [email protected] or at
Tartan App Inc.150 King Street West
Suite 200
Toronto, ON
M5H 1J9