Legal
Security
Last updated August 1, 2026
Who runs TeachPassport
TeachPassport is operated by Buddy Labs LLC. These pages and the register are governed by the laws of the State of Georgia.
Hosting and infrastructure
The application runs on Vercel, hosted in the United States. The database, authentication and private file storage run on Supabase, also hosted in the United States.
Encryption
Data is encrypted in transit with HTTPS and at rest in the database and file storage.
Account access
Multifactor authentication is required for every TeachPassport for Schools administrator account.
Evidence storage
An optional screenshot of an official lookup result is uploaded to private quarantine storage, scanned by a contracted malware-scanning service, and moved to private, access-controlled storage only after a clean result. A file that fails the scan is removed. Downloads use short-lived signed links.
Data retention
If a TeachPassport for Schools organization cancels, the register stays read-only for 30 days, during which the organization can export its data. After 30 days, the organization's data is deleted unless a legal hold applies.
Subprocessors
TeachPassport uses a small number of contracted providers, each limited to the information needed for its function:
- Vercel — application hosting
- Supabase — database, authentication and file storage
- Stripe — payment processing
- Resend — transactional email delivery
- Cloudmersive — malware scanning of uploaded evidence files
Report a problem
Email hello@teachpassport.com or use the support inbox to report a security problem or ask a question. We reply by email within one business day.