1. Who We Are
FEYRA is an online school fee collection service for schools in Nigeria. Schools use FEYRA to set up their fees and student records, give parents a payment page for school fees, send receipts, track payments and receive payouts to their bank account.
In this policy, “FEYRA”, “we”, “us” and “our” refer to the FEYRA service.
You can contact us about this policy or your information at ifeosamenkem@gmail.com.
2. Who This Policy Covers
This policy covers information about:
- Schools and school administrators: schools that register for FEYRA, and the people who sign in to manage a school’s account.
- Parents, guardians and other payers: people who pay school fees through a school’s FEYRA payment page.
- Students: students whose records a school adds to FEYRA. Students do not create accounts or use FEYRA themselves.
- Website visitors: anyone who visits the FEYRA website or contacts us.
Schools provide and manage the student and guardian information in their FEYRA account. FEYRA processes that information to provide its payment and school-management services to the school.
3. Information We Collect
Information schools provide when registering and managing their account
- School name (also used as the sign-in name), email address, address and phone number.
- Payout bank details: bank name, bank code and account number. When a school adds or changes its bank account, we check it with Paystack and store the account name that verification returns.
- An administrator password. We store it only in a one-way hashed form (see Data Security).
- Optional branding: a school logo, and a short footer message shown on receipts.
- Fee, session, term and class set-up information.
Student and guardian information provided by schools
- Student full name, admission number, class, academic session and status (for example active, graduated or left).
- The school’s records of students moving between classes and sessions.
- Optional guardian details: guardian name, phone number and email address.
Information from parents and other payers
- Email address: required, so that we can process the payment and send a receipt.
- Name: optional.
- Student details: to pay for a student, the payer enters the student’s full name and complete admission number, which we use to find the matching student at that school.
Payment and transaction information
- Payment reference numbers (ours and Paystack’s), amount, fee details, service fee, status and payment time.
- The payment method reported by Paystack, and, if a payment fails, Paystack’s short description of why.
- Copies of the student’s name, admission number and class, and the fee, session and term, stored with the transaction so the record stays accurate over time.
- The payer’s email address and name, if given.
We do not receive or store card details. See Payments and Paystack.
Payout information
- Payout amounts, references, status, and the transfer details Paystack returns to us.
- Records of any manual action taken to resolve a payout.
Messages you send us
- When you use our contact form, we receive your name, email address, subject and message. These are sent to us by email.
- If you choose to contact us by WhatsApp or email directly, we receive whatever you send through that channel.
Technical and security information
- Session records: when you visit the website, we keep a session record that includes your IP address, your browser’s user-agent (the information your browser sends that identifies its type and version) and the session’s recent activity. This happens on public pages as well as signed-in pages.
- Rate limiting: to limit repeated attempts (for example failed sign-ins), we use IP addresses and, for sign-in and password-reset attempts, the school name or email entered. These are stored only as one-way hashes, in short-lived counters.
- Remember Me: if a school administrator chooses “Remember me”, we store a hashed security token for that browser (see Cookies).
- Audit trail: when school information is changed through an administrator account, we keep a record of what changed. It identifies the action by role and a hashed session identifier, not by individual name. Passwords, bank account numbers and security tokens are removed from these records.
- Operational records: our systems keep logs and records of background tasks, such as sending receipts, to keep the service running and investigate problems. These can include payment references, internal record numbers and, in some security events, IP addresses. Records of background tasks that fail can include the information those tasks were handling, such as a payer’s email address.
4. How We Use Information
We use information to:
- Provide school accounts: registering schools, signing administrators in, and running the school dashboard, settings and public payment page.
- Manage student records: so a school can maintain its records and parents can pay for the right student.
- Process school-fee payments: starting a payment with Paystack, confirming the result directly with Paystack, and recording the transaction.
- Provide receipts: emailing a receipt to the payer, and making the receipt available online and as a PDF.
- Pay schools: transferring the amounts due to a school’s verified bank account through Paystack, and keeping track of each transfer.
- Keep records: giving schools a record of their payments, including a downloadable export, and keeping our own financial and transaction records.
- Keep the service secure: signing people in and keeping them signed in, protecting forms, limiting repeated attempts, keeping each school’s information separate, and recording changes to school information.
- Send service emails: receipts, account links when a school registers, password reset links, a notice to the school when its payout bank account changes, and operational alerts to FEYRA’s operator.
- Provide support: reading and replying to messages sent through the contact form.
We do not sell personal information.
FEYRA currently does not use personal information for advertising, profiling, newsletters or marketing emails.
5. Payments and Paystack
FEYRA uses Paystack to process school-fee payments.
When a payer chooses to pay, we send Paystack:
- the payer’s email address;
- the amount;
- our payment reference;
- details that identify the payment: our transaction number, the quantity, the school’s ID, name and web address, the student’s admission number, and the term.
The payer is then taken to Paystack’s hosted payment page to complete the payment. Card and bank payment details are entered on Paystack’s payment page. FEYRA does not receive or store card details.
After the payment, we confirm its status, amount and currency directly with Paystack before recording it as paid. Paystack also sends us notifications about payment and payout status.
We also use Paystack to:
- verify bank accounts: we send the account number and bank code, and Paystack returns the account holder’s name;
- pay schools: we send the school’s bank details and each transfer’s amount and reference, so Paystack can set up the payout and make the transfer.
Paystack handles the information it receives under its own terms and privacy policy.
Receipts
A receipt can be viewed through:
- a secure link we generate (for example, in the receipt email or the download button);
- the browser session that completed the payment;
- the school’s own administrator account.
Receipt links currently do not expire automatically. Anyone who has a receipt link can open that receipt, so please treat a receipt link as you would the receipt itself.
6. How We Share Information
We share information only as described in this policy:
- With the school. When you pay a school through FEYRA, that school can see the payment in its dashboard, including the student details, the payer’s name (if given) and email address. The school can also download these records.
- With Paystack, for payments, payment verification, bank account verification and payouts (see section 5).
- With our email service provider, which delivers the emails FEYRA sends: receipts, password resets, school notifications, contact-form messages and operational emails. The provider receives the contents and recipients of those emails.
- With Render, which hosts FEYRA’s application, database, background processing and logs.
FEYRA serves its own fonts and compiled styling files from its own website, so loading our pages does not connect your browser to a separate font or styling provider.
If you choose to use the WhatsApp link on our contact page, WhatsApp handles that conversation under its own terms and privacy policy.
FEYRA does not use analytics services, advertising networks or tracking pixels.
7. Cookies and Similar Technologies
FEYRA uses only the following cookies, all needed for the service to work and stay secure:
- Session cookie
- Keeps your visit working across pages, including keeping administrators signed in. Set on all pages, including public ones. Expires after 120 minutes of inactivity.
- XSRF-TOKEN
- A security token that protects forms against cross-site request forgery (another site submitting forms in your name). Lasts as long as the session.
- school_remember
- Set only when a school administrator ticks “Remember me” at sign-in, so they stay signed in on that browser. Lasts up to 30 days from sign-in, after which they must sign in again. It is replaced each time it is used, and cancelled on sign-out or when the password changes.
FEYRA does not use analytics, advertising or preference cookies, and does not store information in your browser’s local storage.
8. Data Security
We use technical measures designed to protect the information we hold, including:
- Passwords: administrator passwords are stored only in a one-way hashed form. When a new password is chosen, it is checked against passwords known from public data breaches using the Have I Been Pwned service: only the first five characters of a one-way hash of the password are sent, never the password itself.
- Password resets: only a hashed copy of each reset token is stored, and reset links expire after 60 minutes.
- Remember Me: only a hashed version of the secret is stored; the token is replaced each time it is used; and it is cancelled when the administrator signs out or the password changes.
- Secure connections: the live service only works over encrypted connections (HTTPS).
- Cookies: encrypted, and sent only over HTTPS on the live service. The session and Remember Me cookies cannot be read by scripts on the page.
- Card details: FEYRA does not store them.
- Access controls: each school’s administrators can access only their own school’s information, and receipts are available only through the methods described in section 5.
- Rate limits: sign-in, password reset, payment, bank lookup, student lookup, registration and contact requests are limited to reduce abuse.
- Audit trail: changes to school information are recorded, with passwords, bank account numbers and security tokens removed from those records.
No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security.
9. Data Retention
We retain information for as long as reasonably necessary to provide the service, maintain financial and transaction records, meet applicable legal or operational requirements, resolve disputes, and enforce our agreements.
Some technical items expire on their own, but these are not how long we keep information in general:
- sessions expire after 120 minutes of inactivity;
- password reset links expire after 60 minutes;
- Remember Me sign-ins expire after at most 30 days.
10. Data Deletion and Your Requests
School administrators can update their school’s profile and student records from the FEYRA dashboard.
FEYRA does not currently offer self-service deletion of school accounts, student records or transactions.
To ask about the personal information we hold about you, or to request that it be corrected or deleted, email ifeosamenkem@gmail.com. Please tell us who you are and which school or payment your request relates to. We may need to verify your identity before acting on a request.
Requests may be subject to applicable legal, financial record-keeping, security, dispute or operational requirements. For example, we may need to keep records of completed payments and payouts.
If your request concerns student or guardian information that a school provided, we may refer you to that school or involve it, because the school manages that information.
11. Student and Children’s Information
Student information in FEYRA may relate to children. Schools provide and manage this information, and each school is responsible for having the appropriate authority and permissions to provide student and guardian information to FEYRA.
Students do not create FEYRA accounts. FEYRA uses student information only to provide its services to the school: maintaining the school’s records, helping payers find the right student, and recording payments and receipts.
On a school’s public payment page, a student is found only when the payer enters that student’s full name and complete admission number, as the school recorded them. The page then shows only the student’s name, class and a partly hidden admission number.
12. International and Third-Party Services
FEYRA relies on the third-party services described in section 6. Some of them may process information in countries other than the one where you live, including countries outside Nigeria. This includes our hosting provider, Render, and our email service provider.
Each third-party service handles information under its own terms and privacy policy.
13. Changes to This Privacy Policy
We may update this Privacy Policy as FEYRA changes. When we do, we will post the updated version on this page and change the “Last updated” date.
14. Contact Us
For questions about this Privacy Policy or requests about your information, contact FEYRA at ifeosamenkem@gmail.com.