Moneyling™ LLC – Moneyling™ LMS Privacy Policy
Document version: LMS-PP-2026.08.06
Effective Date: August 6, 2026
Last Updated: August 6, 2026
Moneyling™ LLC (“Moneyling™,” “we,” “us,” or “our”) provides the Moneyling™ Learning Management System (“Moneyling™ LMS”), educational content, simulations, assessments, dashboards, school integrations, and a Google Classroom (Add-on) (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, retain, protect, and delete information through the Services.
Google Limited Use affirmation. The use of information received from Google APIs / Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API User Data and Developer Policy.
This Policy supplements any school or institutional data processing addendum (“DPA”). If a signed DPA provides greater protection for institutional or student data, the DPA controls for that data. Related products such as Dreamlife-Sim™ have separate notices; see the Trust Center.
Nothing in this Policy states that Moneyling™ has completed a SOC 2 examination or received a SOC 2 Type II report unless Moneyling™ expressly confirms that status in writing. Current readiness status is described on the Trust Center.
1. Scope and Roles
This Policy applies to Moneyling™ LMS users, educators, administrators, parents and guardians, and visitors to LMS-related pages on moneyling.org and lms.moneyling.org.
When a school, district, or other educational institution (an “Institution”) provides access, the Institution generally controls the educational records and instructs Moneyling™ how to process them. Moneyling™ acts as the Institution’s service provider or processor to the extent required by applicable law. Moneyling™ may act independently for limited operational matters such as account security, legal compliance, billing, and maintaining its business records.
2. Information We Collect
We collect only information reasonably necessary for the enabled Services.
- Institution and administrator information: institution name, business contact information, authorized administrators, subscription details, and technical configuration.
- Adult educator, administrator, or parent information: name, professional or personal email address, role, authentication information, communications, and support requests.
- Learning information for users age 13 or older: enrollment, assigned content, progress, quiz or assessment results, submissions, feedback, and engagement information.
- Google Workspace / Classroom information: only data covered by the OAuth permissions displayed during authorization and required for enabled Google Classroom Add-on and related Workspace features. Depending on which features an Institution enables, this may include Google account identity used for single sign-on (for example, name and email for adult educators/administrators), course and roster identifiers, assignment and attachment metadata, submission and grade or status information, and related Classroom Add-on context. Exact scopes appear on the Google consent screen and in our Google Cloud / Marketplace configuration and must match production functionality.
- Technical and security information: browser and device type, timestamps, diagnostic events, security logs, and IP address where necessary to operate and secure the Services. Under-13 restrictions are described in Section 5.
- Transaction information: subscription and billing records. Payment-card information is processed by the payment provider; Moneyling™ does not store full payment-card numbers except limited transaction references needed for support and accounting.
3. How We Use Information
Moneyling™ uses information only for legitimate purposes consistent with this Policy, the applicable agreement, and user-facing disclosures:
- Provide, personalize, and administer the enabled educational Services.
- Authenticate users (including Google SSO where enabled), connect approved systems, synchronize authorized records, and maintain account permissions.
- Display assignments, learning resources, progress, feedback, grades, and reports to authorized users.
- Provide customer support and respond to verified requests.
- Maintain security, prevent fraud and abuse, investigate incidents, debug errors, and protect users.
- Operate, analyze, and improve the Services using aggregated or de-identified information when reasonably practicable.
- Process payments, manage subscriptions, and maintain required business records.
- Comply with law, enforce agreements, and establish or defend legal claims.
4. Google Classroom and Google Workspace API Data
Moneyling™ requests only the narrowest Google OAuth permissions reasonably necessary for implemented, visible, user-facing features. We do not request Google permissions solely for possible future functionality.
Access: We access Google user data only after authorization through Google’s OAuth consent flow, for the scopes granted by the user or domain administrator.
Use: Google Workspace API data is used only to provide or improve the user-facing features for which access was granted (for example, Classroom Add-on attachment setup, teacher/student views, roster or assignment context, and progress or grade status where enabled), except for security, legal compliance, or other uses expressly permitted by Google’s policies.
Storage: Authorized Google-derived records needed to operate the educational feature (such as identifiers linking a Classroom assignment to a Moneyling™ lesson, or progress associated with an Authorized User) are stored on Moneyling™’s secured systems. OAuth access and refresh tokens are stored encrypted at rest and retained only while the integration remains authorized.
Sharing / transfer: We do not sell Google user data; use it for advertising, retargeting, lending, or creditworthiness decisions; transfer it to data brokers or information resellers; or transfer it to third parties for purposes other than providing or improving the Services (except security, legal compliance, or a business transaction with required consent as permitted by Google’s policies). Vetted subprocessors that host or secure the platform may process data under contractual confidentiality and security obligations.
AI / ML: Moneyling™ does not use information received from Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models. Any use for a user’s personalized model must be an appropriate, visible feature and will occur only with the explicit consent and other safeguards required by Google and applicable law.
Human access: Moneyling™ personnel and contractors do not read Google user data unless the user has given documented consent for access to specific data for support, the access is necessary for security or legal compliance, or the data is aggregated and anonymized for lawful internal operations. Permitted human access is restricted to authorized personnel and logged where appropriate.
Users or administrators may revoke Google authorization through Google account or Workspace administrator controls. Revocation stops future API access and may disable integrated features.
5. Children Under 13: Authorized Access Without Child PII
A child under 13 may use the Services only through (a) an educator-authorized or school-managed program, including an approved Google Classroom deployment, or (b) an access method established or expressly approved by the child’s parent or legal guardian, in each case as permitted by law.
The under-13 experience is designed not to request, collect, or retain personally identifiable information about the child (“Child PII”). Moneyling™ does not intentionally store the child’s name, personal or school email address, telephone number, home address, precise location, government identifier, photograph, profile image, voice recording, financial information, or another direct identifier in the child’s LMS profile.
Under-13 participation must use a non-identifying alias, randomized identifier, or privacy-preserving reference approved by the Institution or parent. Educators, parents, and students must not include Child PII in usernames, assignments, free-text responses, uploaded files, filenames, or support requests.
For under-13 sessions, Moneyling™ configures systems to avoid retaining advertising identifiers, Google profile information for the child, or other persistent identifiers that can be used to recognize or contact the child. Any transient technical data strictly necessary to route a connection or protect security (which may include short-lived network metadata) will not be added to a child profile, used to identify or contact the child, or retained longer than ninety (90) days in security logs, except where a longer period is required for an active investigation or by law.
If Moneyling™ learns that it inadvertently received Child PII outside a separately disclosed and legally authorized process, it will restrict further use and delete the information within thirty (30) days, except to preserve necessary security evidence or comply with law. We may notify the Institution or parent and suspend the affected feature until a privacy-preserving configuration is restored.
6. Schools, FERPA, and COPPA
Where FERPA applies and the Institution uses the school-official exception, Moneyling™ performs an institutional service for which the Institution would otherwise use employees; operates under the Institution’s direct control regarding education records as established by the agreement and DPA; uses personally identifiable information from education records only for the purpose for which it was disclosed; and does not redisclose it except as authorized by law and contract.
Where COPPA applies, an Institution may authorize under-13 participation only when legally permitted to do so for the use and benefit of the school and for no other commercial purpose. Moneyling™ provides the Institution notice of its collection, use, and disclosure practices through this Policy, the LMS Terms of Service, and applicable onboarding materials. If school authorization is insufficient for a particular feature, that feature may not be enabled until valid parental consent is obtained.
Institutions are responsible for providing notices, obtaining legally required permissions, configuring privacy-preserving accounts, limiting access to personnel with a legitimate educational interest, and ensuring that rosters and integrations do not transmit Child PII contrary to Section 5.
7. Information Sharing
Moneyling™ does not sell personal information or Student Data. We disclose information only as described below:
- Institutions and authorized users: educators and administrators may access information needed for legitimate educational and administrative purposes, subject to their roles.
- Service providers and subprocessors: vetted providers may process information for hosting, security, authentication, communications, customer support, analytics, or payments under contractual confidentiality and security obligations. A current subprocessor summary may be provided under NDA or via the applicable DPA; contact privacy@moneyling.org or trust@moneyling.org.
- Legal and safety purposes: when reasonably necessary to comply with law, respond to valid process, prevent harm, investigate abuse, or protect rights and security.
- Business transaction: information may transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to applicable law and Google consent requirements for Google data.
- With authorization: when the Institution, adult user, or parent has directed or validly consented to the disclosure.
8. Cookies and Analytics
Moneyling™ may use strictly necessary cookies or similar technologies for authentication, session continuity, preferences, load balancing, and security. Nonessential analytics or marketing technologies will not be used in an under-13 experience. Moneyling™ does not use Student Data or Google user data for targeted advertising.
Browser settings may block certain cookies; doing so may disable required functionality. Site-level cookie preferences on moneyling.org are also described in the cookie consent experience on that site.
9. Data Retention and Deletion
Moneyling™ retains information only for the time needed for the purposes described in this Policy, the Institution’s documented instructions, the applicable DPA, security needs, and legal obligations.
- Active accounts: retained while the subscription or school program remains active and as needed to deliver the Services.
- Google OAuth tokens: retained only while the integration is authorized. After revocation or termination, tokens will be deleted or invalidated within seven (7) days.
- Customer / Student Data after termination or verified deletion request: returned or deleted within sixty (60) days, subject to legal holds, dispute resolution, and backup cycles, unless a DPA or order form states a different period.
- Security logs: typically up to ninety (90) days, longer if needed for an active investigation or legal requirement.
- Billing and business records: retained as required for tax, accounting, and legal obligations (generally up to seven years where required).
- Backups: protected copies may remain until overwritten within a maximum of ninety (90) days and remain isolated from ordinary use.
Moneyling™ may retain aggregated or de-identified information that cannot reasonably identify a person and will not attempt to re-identify it.
10. Access, Correction, Export, Deletion, and Revocation
Adult users may request access, correction, export, or deletion by contacting privacy@moneyling.org. When an Institution controls the account, students and parents should normally submit requests to the Institution; Moneyling™ will assist the Institution as required by the DPA and law. We may verify identity and authority before acting.
Google access may be revoked through applicable Google account or administrator controls. Revocation stops future API access and may disable integrated features. It does not by itself delete records the Institution lawfully directs Moneyling™ to retain. A separate deletion request may be required.
Moneyling™ will respond within the period required by applicable law and will explain any lawful limitation. Parents and Institutions may request review or deletion of inadvertently received Child PII through the privacy contact.
11. Security and SOC 2 Type II Readiness
Moneyling™ maintains a written information-security program appropriate to the Services and information processed. The program is intended to support the Trust Services Criteria categories relevant to ongoing SOC 2 Type II readiness: security, availability, processing integrity, confidentiality, and privacy.
Safeguards are designed to include:
- Risk assessment
- Access controls and least privilege
- Authentication protections
- Encryption in transit (TLS/HTTPS) and at rest where appropriate
- Secure development and change management
- Vulnerability and patch management
- Logging and monitoring
- Incident response
- Backup and continuity practices
- Vendor-risk management
- Personnel security and training
SOC 2 is an independent examination of controls over a period of time, not a privacy “certification.” Nothing in this Policy represents that Moneyling™ has completed a SOC 2 examination or received a SOC 2 Type II report unless Moneyling™ expressly confirms that status in writing. No security program eliminates all risk. See the Trust Center for current program status.
12. Security Incidents
Moneyling™ maintains procedures to identify, contain, investigate, and remediate confirmed unauthorized access to protected information. We will notify an affected Institution or individual without unreasonable delay and within the period required by the applicable DPA and law, and provide reasonably available information to support required notices.
Users and Institutions should promptly report suspected compromise to security@moneyling.org and maintain current security contacts. Where Google user data is involved in a known or suspected unauthorized access to systems where that data is stored, Moneyling™ will also follow applicable Google notification expectations for Workspace API developers.
13. International and State-Specific Rights
The Services are operated from the United States. If information is transferred across borders, Moneyling™ will use safeguards required by applicable law. Depending on location and relationship, users may have additional rights to know, access, correct, delete, restrict, object, or appeal. Contact privacy@moneyling.org to exercise applicable rights. Moneyling™ does not discriminate against a person for exercising a privacy right.
14. Third-Party Services
The Services may link to or interoperate with third-party services (including Google). Their independent practices are governed by their policies. Moneyling™ remains responsible for its subprocessors to the extent required by law and contract, but is not responsible for a third party selected and independently controlled by the user or Institution.
15. Changes to This Policy
Moneyling™ may update this Policy to reflect legal, security, or product changes. We will update the date and document version above. For material changes, we will provide reasonable advance notice through the Services, email, or Institution communication and obtain renewed consent when required. Google data will not be used for a materially new purpose until required notice and consent have been provided.
16. Contact Us
Moneyling™ LLC
150 Southfield Ave, 1248
Stamford, CT 06902
Phone: 1-844-777-6773
- Website: https://www.moneyling.org
- LMS: https://lms.moneyling.org
- Privacy: privacy@moneyling.org
- Security: security@moneyling.org
- Trust / compliance: trust@moneyling.org
- General: info@moneyling.org
- This Policy (canonical): https://www.moneyling.org/trust/lms-privacy
- LMS Terms of Service: https://www.moneyling.org/trust/lms-terms
Document version: LMS-PP-2026.08.06 — cite this code in Google OAuth verification, Workspace Marketplace listings, and institutional packets when referencing this Privacy Policy revision. Host this URL on your verified domain in the OAuth consent screen and Marketplace support links.