Last Updated: September 17, 2026
Effective Date: September 17, 2026
Privacy Policy
At SmartAttend, privacy is part of how we design our product. SmartAttend is operated by Dev with Mercedes (“Dev with Mercedes,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, protect, and otherwise process personal information when you use SmartAttend. SmartAttend is designed primarily for educational institutions and their authorized users, including students, attendance officers, administrators, and other staff.
1. Information We Collect
The information collected through SmartAttend depends on how an institution configures and uses the platform.
Account information. We may collect information such as:
- Full name
- Email address
- Username, student ID, or staff ID
- Password credentials stored only as a one-way hash (we do not store passwords in plain text)
- Institution, department, programme, level, semester, and role
- Phone number, where provided
- Account status (for example active or deactivated)
- For school or platform administrators who enable two-factor authentication: an encrypted authenticator secret and hashed backup codes
Academic and institutional information
Depending on the institution’s use of SmartAttend, we may process:
- Course and class information, including course codes
- Timetables and scheduled class times
- Lecturer assignments and student–class relationships
- Attendance records and attendance session information
- Classroom or campus location settings configured by the institution (for example authorized coordinates and geofence radius)
Attendance information
When you record attendance, the platform may process information such as:
- Attendance status (for example present, late, excused, or pending verification)
- Date and time of the mark
- Course, class, and attendance session
- Verification method (for example hall GPS, staff-verified, or online join)
- Where device binding is enabled: hashed device identifiers derived from the phone so an account can be limited to one device
- Where location verification is enabled for a physical check-in: the latitude and longitude submitted with that check-in, which may be stored on the attendance record. Reported GPS accuracy may be used to decide whether a check-in qualifies; it is not always retained as its own field on the student attendance record
- For online classes: join and participation status and related timestamps where that feature is used
- Notes or reasons entered by authorized staff when they mark or adjust attendance
Device and technical information
We may process certain technical information required to operate and secure SmartAttend, such as:
- IP address recorded in security and audit logs
- Authentication and security events (for example login, device bind or mismatch, and attendance accept or reject outcomes)
- On the mobile app, device attributes used only to create a hashed device fingerprint for binding (for example operating system and model information)
- Kiosk identifiers and last-seen times where a classroom kiosk is configured
Information stored on your device
The website may store signed session cookies and, in browser storage, preferences such as cookie-consent status and the last selected institution.
The mobile app may store a login token, refresh token, user profile summary, and a device identifier on the device. Where offline attendance is supported, queued check-ins may be stored temporarily on the device — including session identifiers and location readings — until they sync when connectivity returns.
Local class reminders on the mobile app are scheduled on the device. We do not operate a server-side push-token registry for marketing messages.
2. Location Information
SmartAttend may use location information when an institution enables location-based attendance verification.
Location information is used to help determine whether an attendance submission was made within an authorized attendance area. When that feature is used, the location reading associated with a check-in may be stored as described above.
We do not use location functionality to continuously track students or staff merely because they have a SmartAttend account. Location access is associated with supported attendance functionality and depends on device permissions and the institution’s configuration.
You can control location permissions through your device settings. Disabling location permissions may prevent location-based attendance from working.
SmartAttend does not guarantee that GPS or location services will always be precise or available.
3. How We Use Information
We use information to:
- Create and manage accounts
- Authenticate users and protect accounts
- Provide attendance services
- Verify attendance submissions, including location and device checks where enabled
- Maintain institutional records and generate attendance reports
- Provide administrative dashboards
- Maintain and secure SmartAttend
- Detect fraud, proxy attendance, and unauthorized activity
- Troubleshoot technical problems
- Communicate important service information (for example password reset or account email where applicable)
- Process institutional subscriptions and billing where a paid plan is used
- Improve the Service
- Meet legal and regulatory obligations
Use limits
We do not sell personal information.
We do not use student attendance, GPS, or device-binding data for advertising, credit scoring, or unrelated commercial profiling merely because it is available to us.
4. Legal Basis for Processing
Where applicable, personal information is processed on one or more lawful bases, which may include:
- Performance of a service requested by an institution or user
- Compliance with legal obligations
- Legitimate interests, where permitted (including protecting the integrity of attendance records)
- Consent, where consent is required
- Other lawful grounds recognized under applicable data protection law
Institutional purposes
For institutional users, the educational institution may determine the purposes and policies governing certain student and staff information.
5. Institutional Responsibility
An educational institution using SmartAttend may determine:
- Which users are added
- What information is collected for its workspace
- Which attendance methods are enabled
- Whether location verification or device binding is used
- How attendance records are reviewed
- How long institutional records should be retained under its policies
Controller and processor roles
Where the institution determines the purpose and means of processing, it may have responsibilities as the relevant data controller or equivalent entity under applicable law.
SmartAttend acts according to the applicable arrangement between the institution and Dev with Mercedes.
6. Sharing of Information
We do not sell personal information.
Information may be accessible to authorized people within an institution according to their SmartAttend permissions. For example:
- Students may access information associated with their own account
- Lecturers may access attendance information for classes assigned to them
- Institutional administrators may access broader institutional information according to their permissions
Service providers and legal disclosure
We may also disclose information to service providers that help us operate SmartAttend, such as hosting, database, email delivery, payment processing, or other technology providers. Such providers should receive only the information reasonably necessary for the services they provide. They act on our instructions to run the Service and are not permitted to use school records for their own marketing.
Those providers may process information outside Ghana. Where personal information is transferred internationally, we seek to use appropriate safeguards and contractual or legal mechanisms where required by applicable law.
We may also disclose information when required by law, legal process, or to protect the rights, safety, security, or integrity of SmartAttend and its users.
7. Security
We use reasonable technical and organizational safeguards intended to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
Security measures may include:
- Authentication controls and signed session tokens
- Role-based access controls
- Password hashing
- Encryption where appropriate (including for administrator authenticator secrets)
- Secure communications
- Access restrictions
- Logging and monitoring of security-relevant events
- Security updates
Security limits
No internet-based system can be guaranteed to be completely secure.
Users are also responsible for protecting their credentials and devices.
8. Data Retention
We retain information for as long as reasonably necessary to provide SmartAttend, maintain institutional records, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
Because attendance records may form part of an institution’s academic records, the applicable institution may determine retention requirements for institutional data. Retention periods may therefore vary between institutions and types of information.
Deactivating a user or school account may restrict access while historical attendance and related records remain available to the institution according to its settings and our operational needs.
You can also delete your own SmartAttend account from the mobile app (Profile → Delete account) or the web dashboard (Account). Personal identifiers are removed and sign-in is disabled. Schools may retain anonymized attendance history where needed for academic records.
When information is no longer required, it may be deleted, anonymized, or otherwise securely disposed of, subject to applicable legal and institutional requirements.
9. Children’s Privacy
SmartAttend is primarily intended for use by educational institutions and their authorized students and staff.
Where students are under the applicable age of consent, the relevant institution and/or responsible authority is responsible for ensuring that appropriate permissions and legal requirements are satisfied.
We do not knowingly design SmartAttend as a consumer service for collecting unnecessary information from children.
10. Your Rights
Depending on applicable law and your relationship with the institution, you may have rights relating to your personal information, including rights to:
- Request access to information held about you
- Request correction of inaccurate information
- Request deletion where legally applicable
- Delete your own account in the SmartAttend app or web dashboard where self-serve deletion is available
- Object to certain processing
- Request restriction of processing in certain circumstances
- Withdraw consent where processing is based on consent
- Raise a complaint with an appropriate data protection authority
How to exercise rights
If your information is controlled by your educational institution, some requests may need to be directed to the institution first (for example correcting a name, resetting a bound device, or reviewing an attendance mark).
You may also contact us at support@smartattend.co.
11. Ghana Data Protection
SmartAttend is operated by Dev with Mercedes and may process information relating to individuals in Ghana.
Where applicable, processing is intended to comply with relevant requirements of Ghana’s data protection framework, including the Data Protection Act, 2012 (Act 843).
Nothing in this Privacy Policy limits rights provided by applicable data protection law. You may also contact the Data Protection Commission of Ghana about your rights under that Act.
12. International Processing
Some technology providers used to operate SmartAttend may process information in countries outside Ghana.
Where personal information is transferred internationally, we seek to use appropriate safeguards and contractual or legal mechanisms where required by applicable law.
13. Cookies and Similar Technologies
SmartAttend may use cookies and similar technologies necessary to keep users authenticated, maintain sessions, remember appropriate preferences, protect accounts, and maintain platform security.
We do not currently use third-party advertising cookies. Analytics cookies or similar technologies will only be used if such services are actually enabled on the relevant environment.
For more information, see our Cookie Policy.
14. Third-Party Links
SmartAttend may contain links to external websites or services.
We are not responsible for the privacy practices of websites that we do not operate.
We encourage users to review the privacy policies of external services before providing information to them.
15. Changes to This Privacy Policy
We may update this Privacy Policy when SmartAttend changes or when legal or regulatory requirements change.
The “Last Updated” date at the beginning of this document indicates when the policy was most recently revised.
Where legally required, we will provide additional notice of significant changes.
16. Contact Us
If you have questions about this Privacy Policy or how SmartAttend processes information, contact:
SmartAttend
Operated by Dev with Mercedes
Website: https://www.smartattend.co
Email: support@smartattend.co
If your request concerns information managed by your educational institution, we may direct you to the appropriate institutional administrator.
SmartAttend
Operated by Dev with Mercedes
Website: https://www.smartattend.co
Email: support@smartattend.co
© 2026 Dev with Mercedes. All rights reserved.