Moneyling™ LLC – Moneyling™ LMS Privacy Policy

Document version: LMS-PP-2026.08.06
Effective Date: August 6, 2026
Last Updated: August 6, 2026

Moneyling™ LLC (“Moneyling™,” “we,” “us,” or “our”) provides the Moneyling™ Learning Management System (“Moneyling™ LMS”), educational content, simulations, assessments, dashboards, school integrations, and a Google Classroom (Add-on) (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, retain, protect, and delete information through the Services.

Google Limited Use affirmation. The use of information received from Google APIs / Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API User Data and Developer Policy.

This Policy supplements any school or institutional data processing addendum (“DPA”). If a signed DPA provides greater protection for institutional or student data, the DPA controls for that data. Related products such as Dreamlife-Sim™ have separate notices; see the Trust Center.

Nothing in this Policy states that Moneyling™ has completed a SOC 2 examination or received a SOC 2 Type II report unless Moneyling™ expressly confirms that status in writing. Current readiness status is described on the Trust Center.

1. Scope and Roles

This Policy applies to Moneyling™ LMS users, educators, administrators, parents and guardians, and visitors to LMS-related pages on moneyling.org and lms.moneyling.org.

When a school, district, or other educational institution (an “Institution”) provides access, the Institution generally controls the educational records and instructs Moneyling™ how to process them. Moneyling™ acts as the Institution’s service provider or processor to the extent required by applicable law. Moneyling™ may act independently for limited operational matters such as account security, legal compliance, billing, and maintaining its business records.

2. Information We Collect

We collect only information reasonably necessary for the enabled Services.

3. How We Use Information

Moneyling™ uses information only for legitimate purposes consistent with this Policy, the applicable agreement, and user-facing disclosures:

4. Google Classroom and Google Workspace API Data

Moneyling™ requests only the narrowest Google OAuth permissions reasonably necessary for implemented, visible, user-facing features. We do not request Google permissions solely for possible future functionality.

Access: We access Google user data only after authorization through Google’s OAuth consent flow, for the scopes granted by the user or domain administrator.

Use: Google Workspace API data is used only to provide or improve the user-facing features for which access was granted (for example, Classroom Add-on attachment setup, teacher/student views, roster or assignment context, and progress or grade status where enabled), except for security, legal compliance, or other uses expressly permitted by Google’s policies.

Storage: Authorized Google-derived records needed to operate the educational feature (such as identifiers linking a Classroom assignment to a Moneyling™ lesson, or progress associated with an Authorized User) are stored on Moneyling™’s secured systems. OAuth access and refresh tokens are stored encrypted at rest and retained only while the integration remains authorized.

Sharing / transfer: We do not sell Google user data; use it for advertising, retargeting, lending, or creditworthiness decisions; transfer it to data brokers or information resellers; or transfer it to third parties for purposes other than providing or improving the Services (except security, legal compliance, or a business transaction with required consent as permitted by Google’s policies). Vetted subprocessors that host or secure the platform may process data under contractual confidentiality and security obligations.

AI / ML: Moneyling™ does not use information received from Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models. Any use for a user’s personalized model must be an appropriate, visible feature and will occur only with the explicit consent and other safeguards required by Google and applicable law.

Human access: Moneyling™ personnel and contractors do not read Google user data unless the user has given documented consent for access to specific data for support, the access is necessary for security or legal compliance, or the data is aggregated and anonymized for lawful internal operations. Permitted human access is restricted to authorized personnel and logged where appropriate.

Users or administrators may revoke Google authorization through Google account or Workspace administrator controls. Revocation stops future API access and may disable integrated features.

5. Children Under 13: Authorized Access Without Child PII

A child under 13 may use the Services only through (a) an educator-authorized or school-managed program, including an approved Google Classroom deployment, or (b) an access method established or expressly approved by the child’s parent or legal guardian, in each case as permitted by law.

The under-13 experience is designed not to request, collect, or retain personally identifiable information about the child (“Child PII”). Moneyling™ does not intentionally store the child’s name, personal or school email address, telephone number, home address, precise location, government identifier, photograph, profile image, voice recording, financial information, or another direct identifier in the child’s LMS profile.

Under-13 participation must use a non-identifying alias, randomized identifier, or privacy-preserving reference approved by the Institution or parent. Educators, parents, and students must not include Child PII in usernames, assignments, free-text responses, uploaded files, filenames, or support requests.

For under-13 sessions, Moneyling™ configures systems to avoid retaining advertising identifiers, Google profile information for the child, or other persistent identifiers that can be used to recognize or contact the child. Any transient technical data strictly necessary to route a connection or protect security (which may include short-lived network metadata) will not be added to a child profile, used to identify or contact the child, or retained longer than ninety (90) days in security logs, except where a longer period is required for an active investigation or by law.

If Moneyling™ learns that it inadvertently received Child PII outside a separately disclosed and legally authorized process, it will restrict further use and delete the information within thirty (30) days, except to preserve necessary security evidence or comply with law. We may notify the Institution or parent and suspend the affected feature until a privacy-preserving configuration is restored.

6. Schools, FERPA, and COPPA

Where FERPA applies and the Institution uses the school-official exception, Moneyling™ performs an institutional service for which the Institution would otherwise use employees; operates under the Institution’s direct control regarding education records as established by the agreement and DPA; uses personally identifiable information from education records only for the purpose for which it was disclosed; and does not redisclose it except as authorized by law and contract.

Where COPPA applies, an Institution may authorize under-13 participation only when legally permitted to do so for the use and benefit of the school and for no other commercial purpose. Moneyling™ provides the Institution notice of its collection, use, and disclosure practices through this Policy, the LMS Terms of Service, and applicable onboarding materials. If school authorization is insufficient for a particular feature, that feature may not be enabled until valid parental consent is obtained.

Institutions are responsible for providing notices, obtaining legally required permissions, configuring privacy-preserving accounts, limiting access to personnel with a legitimate educational interest, and ensuring that rosters and integrations do not transmit Child PII contrary to Section 5.

7. Information Sharing

Moneyling™ does not sell personal information or Student Data. We disclose information only as described below:

8. Cookies and Analytics

Moneyling™ may use strictly necessary cookies or similar technologies for authentication, session continuity, preferences, load balancing, and security. Nonessential analytics or marketing technologies will not be used in an under-13 experience. Moneyling™ does not use Student Data or Google user data for targeted advertising.

Browser settings may block certain cookies; doing so may disable required functionality. Site-level cookie preferences on moneyling.org are also described in the cookie consent experience on that site.

9. Data Retention and Deletion

Moneyling™ retains information only for the time needed for the purposes described in this Policy, the Institution’s documented instructions, the applicable DPA, security needs, and legal obligations.

Moneyling™ may retain aggregated or de-identified information that cannot reasonably identify a person and will not attempt to re-identify it.

10. Access, Correction, Export, Deletion, and Revocation

Adult users may request access, correction, export, or deletion by contacting privacy@moneyling.org. When an Institution controls the account, students and parents should normally submit requests to the Institution; Moneyling™ will assist the Institution as required by the DPA and law. We may verify identity and authority before acting.

Google access may be revoked through applicable Google account or administrator controls. Revocation stops future API access and may disable integrated features. It does not by itself delete records the Institution lawfully directs Moneyling™ to retain. A separate deletion request may be required.

Moneyling™ will respond within the period required by applicable law and will explain any lawful limitation. Parents and Institutions may request review or deletion of inadvertently received Child PII through the privacy contact.

11. Security and SOC 2 Type II Readiness

Moneyling™ maintains a written information-security program appropriate to the Services and information processed. The program is intended to support the Trust Services Criteria categories relevant to ongoing SOC 2 Type II readiness: security, availability, processing integrity, confidentiality, and privacy.

Safeguards are designed to include:

SOC 2 is an independent examination of controls over a period of time, not a privacy “certification.” Nothing in this Policy represents that Moneyling™ has completed a SOC 2 examination or received a SOC 2 Type II report unless Moneyling™ expressly confirms that status in writing. No security program eliminates all risk. See the Trust Center for current program status.

12. Security Incidents

Moneyling™ maintains procedures to identify, contain, investigate, and remediate confirmed unauthorized access to protected information. We will notify an affected Institution or individual without unreasonable delay and within the period required by the applicable DPA and law, and provide reasonably available information to support required notices.

Users and Institutions should promptly report suspected compromise to security@moneyling.org and maintain current security contacts. Where Google user data is involved in a known or suspected unauthorized access to systems where that data is stored, Moneyling™ will also follow applicable Google notification expectations for Workspace API developers.

13. International and State-Specific Rights

The Services are operated from the United States. If information is transferred across borders, Moneyling™ will use safeguards required by applicable law. Depending on location and relationship, users may have additional rights to know, access, correct, delete, restrict, object, or appeal. Contact privacy@moneyling.org to exercise applicable rights. Moneyling™ does not discriminate against a person for exercising a privacy right.

14. Third-Party Services

The Services may link to or interoperate with third-party services (including Google). Their independent practices are governed by their policies. Moneyling™ remains responsible for its subprocessors to the extent required by law and contract, but is not responsible for a third party selected and independently controlled by the user or Institution.

15. Changes to This Policy

Moneyling™ may update this Policy to reflect legal, security, or product changes. We will update the date and document version above. For material changes, we will provide reasonable advance notice through the Services, email, or Institution communication and obtain renewed consent when required. Google data will not be used for a materially new purpose until required notice and consent have been provided.

16. Contact Us

Moneyling™ LLC

150 Southfield Ave, 1248
Stamford, CT 06902
Phone: 1-844-777-6773

Document version: LMS-PP-2026.08.06 — cite this code in Google OAuth verification, Workspace Marketplace listings, and institutional packets when referencing this Privacy Policy revision. Host this URL on your verified domain in the OAuth consent screen and Marketplace support links.