Skip to content
SizzleGo

Security

Schools trust us with family contacts, student records, and money. Here is what we do to protect them, in plain words, with nothing we cannot back up. Updated September 30, 2026.

Encryption

  • Every page and every request travels over HTTPS. Browsers are told to use HTTPS only, every time.
  • Student health notes (allergies, medications, conditions, and nurse notes) are encrypted with AES-256-GCM before they are saved, with a key kept outside the database.
  • The private links we send families, for tickets, signups, conference bookings, school forms, and messages, are stored as one way hashes. A copy of the database is not enough to open anyone's link.
  • Card numbers never touch our servers. Payments go through Stripe, and we keep only what we need to show a receipt or issue a refund.

Who can see what

  • Organizers sign in through Clerk. Parents, buyers, and volunteers never make an account, so there is no parent password to steal.
  • Every record belongs to one organization. Pages and actions check that a record belongs to your organization and that your role allows the action before anything is shown or changed.
  • Schools give each staff member a role: owner, admin, principal, office staff, nurse, teacher, PTA volunteer, or viewer, or a custom mix. Each role is set per tool, from view only to full admin.
  • A teacher sees their own classes. Health notes stay with the office and the nurse, and reach a teacher only when the office chooses to share them.

The audit trail

SizzleGo records who did what and when for the actions a school or an auditor asks about: every data export, money movement such as refunds, changes to student records, emergency alerts, and changes to who is on the team and in what role. Opening a student safety record, a fee, a form, or a directory is recorded too. Owners and admins can read the trail in Settings and download it as a spreadsheet.

Student records and FERPA

When a school uses SizzleGo, the school controls its student records and we act as a school official with a legitimate educational interest under FERPA. We use student records only to run the service for that school. We never sell them, never use them for advertising, and never build profiles from them. On the School and District plans we sign a data privacy agreement with you: request one here. The privacy page lists exactly which student details each product keeps.

On the site itself

  • A content security policy limits which outside services a page may load from, and our pages cannot be framed by other sites, except the calendar and hub embeds that exist to sit on your own website.
  • Public forms are rate limited and screened for bots, and every form is checked again on the server.
  • Errors are reported to our monitoring service. A screen replay is kept only around an error, with every word, form field, and image masked, so we can fix a problem without reading what a family typed.

Who else touches the data

We use a short list of vendors to host, send, and take payments. Each one, and what it handles, is on the privacy page.

Report a problem

If you think you have found a security problem, or you believe data was seen by someone who should not have it, email hello@sizzlego.com with "Security" in the subject. A person reads it and replies, and we tell affected schools as our agreements with them require. Please give us a chance to fix a problem before you share it publicly.