Privacy reviews often arrive late in class placement season. The roster is ready, teachers have sent notes, and everyone wants the lists before move-up day. That is exactly when a principal needs plain questions, not a thirty-page vendor questionnaire copied from another system.
Use this checklist before uploading student data to any placement tool, including Shibutz. It is practical procurement work, not legal advice. Your district, school board, data protection officer, or counsel should decide what your school may share.
The best privacy question is usually small: "Do we need this field to place children fairly?" If the answer is no, do not upload it. A balanced class list can need support signals, required placements, and separation rules. It rarely needs a full case history.
| Area | Question to ask | Owner | Evidence to collect |
|---|---|---|---|
| Purpose | Will this tool help us make class placement decisions, or are we adding data because the spreadsheet has a column for it? | Principal or placement lead | Approved placement workflow and field list |
| Roster fields | Which fields are needed for grouping: student identifier, current school or cohort, support indicators, placement rules, and classroom capacity? | Registrar and grade-level lead | SIS export sample with unnecessary columns removed |
| Sensitive notes | Are we using short placement signals instead of case histories, medical details, discipline narratives, or family context that does not belong in placement software? | Counselor or student support lead | Redacted note examples and local guidance |
| Generation and export | What leaves the school system when staff generate lists or download a spreadsheet? | Privacy lead and vendor reviewer | Vendor privacy policy, product docs, and test export |
| Sharing | Who receives final lists, which columns do they need, and what sharing channel is approved? | Principal or assistant principal | Staff handoff list and recipient review |
| Unknowns | Which answers are missing, contractual, or jurisdiction-specific rather than proven by a public page? | School privacy or legal reviewer | Open questions log with vendor responses |
A student placement file should be boring on purpose. Names or local IDs, grade or cohort, current school or group, destination classrooms, capacity, and placement rules may be enough. Friend requests, keep-apart rules, required placements, and short support signals can be legitimate placement data when the school has approved them.
Be much slower with free-text notes. Do not export medical narratives, discipline records, family details, legal history, or counseling notes into a placement tool just because someone once used a spreadsheet as a dumping ground. If a note is needed, translate it into a placement instruction staff can defend: "separate from Student 18," "place near a trained teacher," or "avoid same class as a sibling conflict." Keep the richer record in the system where it belongs.
Shibutz supports a narrower approach. Its privacy policy says full names are not required; schools may use partial names, initials, or internal IDs when that fits local policy. The same policy also warns that other roster fields can still be personal or educational records, so changing names alone does not make the dataset anonymous.
This section is for schools whose processing is governed by the EU GDPR or a closely related local framework. Do not treat it as a worldwide rulebook. US schools may be working under FERPA, COPPA, state student privacy laws, district policy, and contract terms instead. Ask your own counsel which rules apply before buying or configuring software.
Notice the tone of those questions. They do not assume the software is compliant because a page uses privacy language. They also do not assume the software is unusable because one answer is contractual. The job is to separate verified product behavior from open review items.
Here is the current public evidence a Shibutz reviewer can use today. Anything missing stays visible as an open question until the school or vendor reviewer resolves it.
| Claim | Current evidence | Source |
|---|---|---|
| Schools can minimize identifiers. | The privacy policy says full names are not required and schools may use partial names, initials, or internal IDs when that fits local policy. | Privacy Policy |
| Placement generation and export involve external processing. | The policy and export docs say Shibutz sends the roster, classes, rules, settings, and placement details to the Shibutz placement service when a user requests generation or XLSX export. | export data-handling docs |
| The upstream service URL is validated before a request is built. | Current server code requires a configured absolute URL and rejects non-HTTPS upstream URLs in production. Plain HTTP is allowed only for localhost or loopback during development. | libs\shibutzApi.ts |
| Exported files need a recipient review. | The export guide tells Pro users to prepare a minimal-data copy, inspect every sheet and column, and avoid public links or unapproved sharing channels. | sharing and printing guidance |
| Some processor answers are not publicly confirmed. | The privacy policy says the placement service's AI training use, retention, further sharing, and deletion practices have not been confirmed. | AI and automated placement section |
For the broader data-flow summary, read the student data privacy and compliance page. For exports, the most useful operational page is Exporting to Excel, because downloaded spreadsheets often become the file that travels outside the dashboard.
Print this section or copy it into your procurement notes. The value is not the table itself; it is the named person beside each privacy decision. "Someone checked it" is how weak controls survive busy seasons.
| Decision | Owner | Action | Evidence |
|---|---|---|---|
| Student identifiers | Registrar | Use initials, short names, or internal IDs if local policy allows. Keep a private lookup outside the placement tool if staff need one. | Approved field list and sample import |
| Support notes | Counselor or support lead | Rewrite long notes as placement signals. Remove health, discipline, and family details unless they are approved and needed for placement. | Redacted examples signed off before upload |
| Generation request | Vendor reviewer | Confirm what is sent to the placement service and record any unconfirmed retention, AI training, deletion, or sharing terms. | Privacy policy plus vendor response |
| XLSX export | Assistant principal | Create a sharing copy, delete unneeded sheets or columns, and verify recipients before sending. | Export checklist and recipient list |
| Retention and deletion | Privacy lead | Record how long the school keeps working files, how account deletion works, and which vendor-held records may remain. | Retention schedule and deletion request path |
Start with a minimal roster. Build the placement in Shibutz only after the school has approved which fields belong there. Before generation, review the student roster, separation rules, and required placements. After Shibutz returns a draft, review the result with authorized staff before exporting or sharing it.
If your team is still shaping the manual workflow, pair this privacy review with the free class balance checklist or the class placement readiness quiz. Those resources help staff decide what belongs in the process before software makes the work faster.
New to Shibutz? Sign up free and test a small, approved placement workflow before importing your full roster.
Use a worked SIS mapping example, save a reusable column preset, and review repeat imports in Shibutz. Spreadsheet import is not live SIS sync.

Follow seven Shibutz steps: prepare a workspace, review rules, set capacities, add required placements, check constraints, generate, and approve an export.
Choose editable Word templates for teacher input, balance review, staff signoff, and parent notification. Match each download to its placement task.
Tools, product walkthroughs, and guides to put balanced class placement into practice.
Download four editable Word templates for teacher input, staff review, family communication, and final sign-off.
Free toolAnswer a few quick questions to see how ready your school is for balanced, low-stress class placement.
DocsFollow step-by-step guides for setting up students, classes, preferences, and assignments.