Privacy Policy

This policy explains the personal data OnLime processes to provide learning, attendance, reporting, parent-access, and connected-service features.

Last updated 3 September 2026

Who this policy covers

This policy covers students, parents and guardians, teachers, teaching assistants, administrators, and visitors who use OnLime.

OnLime is currently operated personally by its owner as a sole operator based in Egypt. OnLime is not currently an incorporated or registered company. In this policy, “OnLime,” “we,” “us,” and “our” mean the OnLime service and that sole operator. Users may access OnLime from Egypt and other countries. Contact support@learnonlime.com for privacy questions or requests.

Data we process

Depending on your role, OnLime processes account and profile details, course and enrollment information, submitted learning work, grades and feedback, attendance, schedules, parent relationships, support correspondence, and security and audit events.

We process only the information needed to provide the service, protect accounts, meet educational recordkeeping needs, and support authorized users. We do not sell personal data.

Zoom data

When a teacher authorizes the Account-managed Zoom app as their own Zoom account's owner or administrator, OnLime receives the teacher's Zoom user and account identifiers, display name, email address, granted scopes, meeting and registrant identifiers, encrypted participant join links, meeting lifecycle times, participant join and leave intervals, and the attendance evidence derived from those intervals.

The authorizing teacher is also the supported meeting host. Students do not authorize the Zoom app. OnLime uses this data only to connect the teacher's account, provision classes, provide authorized student join access, reconcile participation, propose attendance, troubleshoot the integration, and protect the service. OnLime does not request Zoom recordings, chat messages, contacts, calendar data, or Zoom Phone data.

Children and student data

OnLime is used in an educational setting and may process data about students under 16. Zoom treats information about children under 16 as Sensitive User Data for Marketplace review. For a student under 16, the Teacher, school, or educational organization that enrolls the student or enables Zoom functionality through OnLime is responsible for having the required authority and for obtaining parental or guardian consent and any other permission required by applicable law before enrollment or use. A student under 16 must not join a course or use OnLime or its Zoom functionality without that authorization. OnLime relies on the enrolling Teacher, school, or educational organization's confirmation of authority. Student Zoom participation data is limited to class access and attendance and is available only to authorized education roles.

How data is protected

Network traffic uses HTTPS. Zoom OAuth tokens and student-specific Zoom join links are encrypted with authenticated AES-256-GCM envelopes before database storage. Provider identity references used for matching are keyed hashes. Access is role- and ownership-restricted, webhook requests are signature-verified, and security-sensitive logs pass through a central redaction boundary.

Retention and deletion

  • Expired OAuth state is deleted; consumed state is retained no longer than 24 hours.
  • A pseudonymous deauthorization replay marker is retained for no more than 30 days.
  • Encrypted Zoom join links are deleted on cancellation or within seven days after class end.
  • Operational provider events are normally retained for about 15 months.
  • Participant intervals are normally retained until 24 months after the course ends.
  • Final attendance and necessary audit history follow OnLime's educational record policy.

Zoom deauthorization immediately deletes tokens, provider profile data, raw provider identifiers, join links, participant intervals, provider events, and normalized Zoom evidence and provider-proposal audit details. OnLime retains only the minimized final OnLime academic attendance result where required for legitimate educational records. The retained result contains the final status and limited academic decision provenance; provider identifiers, provider source and channel, exact Zoom-derived join time, participation intervals, join URLs, participation notes, and raw or normalized Zoom event data are removed. The minimized result is retained only for as long as required for legitimate educational recordkeeping.

Service providers and disclosures

OnLime currently uses Vercel for the web application, Render for the API, Supabase for PostgreSQL and authentication, Cloudflare for network and object-storage services, Bunny.net for video delivery, Resend for transactional email, and Zoom for connected meetings and attendance. Each provider receives only the information needed for its operational purpose. Provider regions, contractual terms, and this list are reviewed as the service changes. We may also disclose information when required by law, to protect users or the service, or as part of an authorized organizational change.

Your choices and requests

You may request access, correction, or deletion by emailing support@learnonlime.com. Include the OnLime account email and your relationship to the learner, but never send a password, QR credential, OAuth token, or Zoom join link. We verify authority before fulfilling a request and will explain when records must be retained for security, legal, or legitimate educational purposes. Requests may be made from Egypt or another country in which a user accesses OnLime and will be handled by the OnLime sole operator based in Egypt, subject to applicable law.