Protecting school information

Security at SchoolPay

Last updated: 23 September 2026

SchoolPay handles information that schools rely on for fee administration. Keeping accounts and records safe is a shared responsibility between SchoolPay, participating schools, and their authorized users. This page provides practical guidance without making unverified claims about certifications or guarantees.

The public website accepts demo requests through a server-side endpoint. That endpoint checks submitted fields, limits request size, and passes valid requests to an email-delivery provider for follow-up. Please do not enter passwords, student records, card details, or other sensitive information in the demo form.

  • Use a unique, strong password and never share it with colleagues.
  • Grant school-account access only to people who need it for their role.
  • Check the website address before signing in, and avoid following unexpected login links.
  • Sign out of devices you do not control and report unexpected account activity promptly.

Before uploading student, guardian, or fee information, confirm that your school is authorized to use it. Keep contact details current, review who can see school records, and avoid sharing account screenshots or exports through unsecured channels. Do not treat a fee status shown in software as proof of settlement without checking the school’s own payment records.

If you suspect unauthorized access, an exposed record, a phishing message, or another security issue, notify your school administrator and the SchoolPay team through your established support contact as soon as possible. If you do not yet have a support contact, use the to ask our team to get in touch. Do not include passwords, full student records, or exploit details in the public demo form.

This page is guidance, not a certification, audit report, promise of specific technical safeguards, or guarantee against incidents. Any security commitments specific to your school should be confirmed in its service agreement. We will update this page as the service and available security documentation evolve.