Effective date: 18 August 2026
Operated by: CodeInFront (ABN 71 362 605 165) ("we", "us", "CodeInFront")
Contact: support@codeinfront.com.au
Across Australian states and territories, the decision to use third-party software like CodeInFront is made by the school itself — typically the principal, with input from IT or the relevant education department's own digital/technology services team — rather than by a central body certifying vendors in advance. Exactly how that assessment works varies by state and by school; CodeInFront is not certified, approved, or endorsed by any Australian education department.
What we've done instead is design this page, and the companion Security page, to directly answer what that assessment usually asks: what's collected, why, where it's stored, how it's protected, and who to contact. Both pages describe the system exactly as built — nothing here is aspirational or marketing language. If your assessment needs something not covered on either page, email support@codeinfront.com.au and we'll answer directly.
year9-python-4821) — chosen so that it identifies nothing about the actual studentThat's the complete list. We do not collect, and have deliberately not built any way to collect, a student's real name, date of birth, email address, photo, location, academic results, or any record of what they do once logged in.
If a teacher wants to keep their own record of which real student a generated username belongs to, the Platform provides a class roster CSV export so that mapping can be kept in the teacher's own files, entirely outside this system. We never see or store that mapping.
| Information | Why |
|---|---|
| Teacher/admin email | Account verification, password recovery, service emails |
| Teacher/admin username | Login |
| School name / ABN | Billing and invoicing |
| Student username/password | The only way a student can log in to gated course content |
| Class/course assignment | Determines what content a student can access |
| Payment records | Required to know which classes are paid for, and for tax/accounting purposes |
We don't collect information "in case it's useful later." If a field isn't listed above, we don't have it.
We use a single session cookie to keep you logged in. It contains no tracking identifier and is not used for advertising or analytics. It's deleted when you log out or when your browser session ends. We don't use any other cookies — no analytics, no advertising, no third-party trackers.
When you purchase a Class Subscription, we issue a real invoice through Xero, our accounting platform, which you can pay by bank transfer or card. Card payments are processed by Stripe, connected as Xero's payment processor. We do not collect or store any credit card or bank account details ourselves — that information is handled directly by Xero and Stripe, not by us. We retain a record of the transaction (amount, date, invoice reference) for accounting and tax purposes, as required by law.
password_hash()), never in plain or reversible form. Nobody — including us — can look up an existing password. Resetting is the only recovery path.We don't sell, rent, or otherwise disclose personal information to third parties, beyond the sub-processors listed below who help us run the service. We don't share data with data brokers, advertisers, or analytics providers, because we don't use any.
We may disclose information if required to by law (for example, a valid legal process), but this has never happened and isn't something we expect.
| Provider | Purpose | Data location |
|---|---|---|
| DreamITHost | Web and database hosting, and account/service email delivery | Australia |
| Xero | Invoicing and payment records | See Xero's own privacy policy |
| Stripe | Card payment processing (via Xero's integration) | See Stripe's own privacy policy |
You can ask us, at any time, to:
For students: since we hold no identifying information about a student in the first place, there's no separate "student data" to request or delete beyond the account itself — a teacher can remove a student's account at any time from their class roster, which immediately disables that login.
To exercise any of these rights, contact support@codeinfront.com.au.
CodeInFront is designed from the ground up around the fact that students using it are minors, and are never asked to provide any personal information themselves. Student accounts are created and managed entirely by their teacher — a student never registers, never provides an email address, and is never asked for any personal detail. This is a deliberate design choice, not an afterthought. Parents or guardians with questions about how their school uses the Platform should contact their child's teacher or school in the first instance, or us directly at support@codeinfront.com.au.
Whether a particular use of CodeInFront needs separate parental notice beyond a school's standard ICT-use agreement is a determination for each school to make, not something we can decide on a school's behalf. We've designed the Platform to make that determination as simple as possible: since no personal information about a student is ever collected, there is no student data exposure to weigh in the first place.
If we make a material change to what we collect or how we use it, we'll update this page and, where practical, notify active teacher/admin accounts by email.
Questions or requests about this policy: support@codeinfront.com.au