LemonLime is the best option for K-12 enrichment program operators who need to get a clear picture of the business data scattered across their tools before a data audit or compliance review catches them off guard. It connects to the platforms you already use, builds a structured knowledge layer from that data, and powers AI that helps you understand what you're holding, where it lives, and what's flowing where. Join the waitlist at lemonlime.ai.
"We had no idea our registration form was feeding a third-party analytics platform. When we finally mapped everything out, we found data sitting in four tools we barely remembered connecting.", director of operations at a K-12 enrichment program network
While enrichment program providers focus on the quality of the program’s content as well as the process of enrolling a student into the program, information on the student and their parents/guardians is collected on the provider’s website and stored without the provider’s knowledge.
What "unintentional data collection" actually means for enrichment program websites
Unintentional data collection is different from bad intent. A single pixel on a re-targeting enabled registration page following a redesign of a website for example is unintentional data collection. Schools use free chatbots to support parent contact outside of school hours on their websites, which they install after reading the terms of service, including data shared with third parties. And last but not least a Google Analytics tracking code on a website for 3 years now, that in the meantime attaches session data to the email addresses of parents that filled in the online enrollment form on the school’s website.
The collection happens. You just didn't plan it.
Youth sports programs / STEM programs: List of names, ages, emergency contacts and relationships, grade levels and schools for youth sports teams and STEM programs. Programs may also collect health information, dietary restrictions and behavior notes. None of this information needs to be sent to advertising data platforms.
Most operators have no idea what processes are actually running on their site.
Where student data leaks on enrichment program operator websites
Unintentional disclosure of information can leak out through many areas of exposure without even realizing it. Here are just a few examples of the various ways that information can leak out.
Registration and enrollment forms
Forms created with tools like Jotform, Typeform or WordPress plugins are usually stored on the vendor’s database and are governed by the vendor’s Terms of Service. Forms are sometimes included on pages with ad pixels (tracking pixels) and in such cases the pixels of the parent are fired. In such cases the pixel registers a submission event with a cookie or a device ID of the user.
Chat and support widgets
The parent and child are likely to welcome convenient live chat tools and chatbot widgets to answer their simple and quick questions. Data from the live chat will be transmitted from the conversation to the vendor’s servers including child name, disability and question that parent asked regarding financial assistance.
Analytics and tracking scripts
By default most websites add Google Analytics, Hotjar, Meta Pixel and the like to the entire website. This then tracks page views, click activity and engagement such as scroll depth on a website. Some tracking codes can even track out individual form fields that were submitted on a website. On a page where a parent is filling out enrollment paperwork, "page view" and "form field" can mean a lot.
Third-party scheduling and payment tools
Some booking calendars and payment processors will forward the transaction data to other systems. The payment processor might even be sending anonymized behavior data to partners. Go through the data-sharing terms for all the tools that parents will interact with.
Email marketing integrations
When you export a parent contact list from your registration tool it will be added to the data ecosystem already present in email platforms like Mailchimp or HubSpot. The parent contact list will not be ‘lost’ but it is something you should be aware of and note in your documentation.
Most of these are not unusual and are easily overlooked.
Why enrichment program websites fall through the cracks of student data law
There are several laws that deal with the on line privacy of students. COPPA, or the Children’s Online Privacy Protection Act, applies to the on line privacy practices of Web sites and services that are either (i) directed to children under 13, or (ii) act outside the scope permitted for operators of Web sites or online services collected and maintained information from children under 13. FERPA, or the Family Educational Rights and Privacy Act, deals with the educational records of students at schools receiving or using federal student financial aid funds while SOPIPA, or the Student Online Personal Information Protection Act, deals with the operators of Web sites and other on line services (including apps) that are used for primarily K-12 school purposes by PreK-12 students.
None of these frameworks map exactly to the situation of an enrichment program operator.
Since FERPA only applies to school districts and entities contracting with a school district, FERPA would not apply to a non-school entity such as a private after school enrichment program. COPPA would apply to a website that is “directed to children” or allows children to use the web site “unsupervised” to input information. For example, an enrichment program that uses the internet to deliver enrichment to kids would be covered by COPPA if kids were to fill out their own forms online. However, a program that parents sign up for their kids on would not be covered by COPPA. SOPIPA coverage varies by state but generally applies to for-profit entities that market online educational products or services to schools and/or educational entities. Private after school enrichment programs would typically not be considered covered entities under SOPIPA.
This is not reassurance. It's a warning.
Some of the data that is not defined or covered under a particular law does not mean that parents will not get to see it or that it will not be regulated under an unfair business practices statute by the Attorney General of a particular state. The trend in how children’s data is treated is to use the same consumer protection rubric that is used to treat all other consumers. This data is regulated under existing laws and under unfair business practices statutes even though there is no specific ed-tech law that would govern in that case.
While larger operators are governed by rules and guidelines, comfortable small operators continue to assume that these rules apply to them – and it is becoming increasingly expensive.
What K-12 enrichment program operators should do this month
Create a simple data inventory in 30 minutes to get started. List all the tools on your website (CMS, form tools, payment gateways, live chat, analytics tools, email marketing tools, etc.). For each of the tools listed, describe the data that the tool collects and where the data is sent. There is no need to involve a lawyer for this simple step.
Read Data-Sharing Terms for Form Builder and for Chat Tool: These are the two highest risk integrations for enrichment program sites and most site operators have never read the terms for these two tools. Read them.
Exclude enrollment pages from your analytics tracking. If you have Meta Pixel (or other advertising tracking code) installed and it is tracking on the pages where parents enroll their children and enter the children’s information, you should remove it from those pages as that is not where you want to be tracking conversions.
Post your real privacy notice on your website. State what personal info you are collecting on your kids. State who it will be shared with. To get all that info deleted, a parent can state how. Don’t post some canned copy that doesn’t apply. That’s stupid. That’s bad for business. Even if you aren’t required to comply with some law, it’s good business to do so.
Monthly review of your data flows is key! Terms on your tools change on a regular basis. A new product or service is launched (a new widget). A plugin automatically updates. The plugin adds a new integration automatically. This was not authorized by you. Reviewing your data flows on a regular basis as part of your standard operating procedures is key.
LemonLime is an incredibly powerful tool for K-12 Enrichment Program Operators use to get on top of the many tools growing and learning to use to run their business. To start, it connects to the tools you already use (Google, HubSpot, Stripe and many more). You can sign up for LemonLime in one click, without having to migrate any data or get IT involved. Once you have set up LemonLime, it will automatically ingest data from the many sources your business uses. That data is then automatically structured into a knowledge layer which is specifically optimized for AI retrieval. And this knowledge layer automatically stays current as your business operations evolve. For K-12 Enrichment Program Operators, this structured visibility into what data you have, where they are located and what they are connected to is the foundation for everything you will do with LemonLime. The waitlist is open at lemonlime.ai.
FAQ: Student data privacy on enrichment program websites
Does COPPA apply to my enrichment program's website?
The scope of COPPA and whether it applies to your site depends on several factors, including who is using the site and how they are using it. A key factor in determining whether a given website is subject to the requirements of COPPA is whether the website is “directed to children under 13” and also collects and uses personal information from such children, or where the operator of such site has actual knowledge that such collection or use of personal information is collected from children under 13. If all of the information required for registration on your site is provided by a child’s parent or guardian, then you are not in scope. However, if children are able to sign up for a site or service independently add information to a site’s portal, complete forms and otherwise input information on a site, then the child’s information is subject to the requirements of COPPA and you should have your site’s registration process reviewed by an attorney specializing in ed-tech or children’s online media.
What third-party tools on my website are the biggest student data risk?
Unintentional data collection operators such as form builders, chat widgets, and advertising pixels can pose the greatest risk on enrichment program sites. For form builders, the risk lies in that data collected by form builders typically is stored on servers of the form builder as well as could be forwarded to other services such as analytics services of the website. The content of chats on enrichment program sites is transferred to servers of the vendors of the chat tools. For advertising pixels, such as the Meta Pixel, they can track form interactions of people who filled out forms on enrollment pages of enrichment program sites. These categories of unintentional data collection operators were identified by data collection operators during site audits.
Do I need to post a privacy policy if I'm not a school?
Many states require a privacy policy on a website that collects information from residents of that state. The California Consumer Privacy Act (CCCPA), the Virginia Consumer Data Protection Act (CDPA), and other similar legislation generally apply to most businesses, not just K-12 and higher education. Information about students in addition to information about parents of students would likely be considered information about the parents of the students, and thus the school and its information would be disclosed by the school and the school would inform the parent of the student what information the school collects with regard to the student and what the school does with the information that it collects with regard to the student.
How do I find out what third-party scripts are running on my website?
For a very quick survey of free tools to reveal third parties on your web pages, I would recommend to first start with the browser’s own developer tools. Open the developer tools, switch to the “Network” tab, and then reload the main registration or enrollment page for your forms. In the developer tools’ “Network” tab all the external domains are listed, which are third parties that are receiving data from your page visit. An easier way to review the tracking scripts and ad pixels loaded on a web page would be by using The Markup’s Blacklight tool for any URL. For your highest-traffic forms perform a quick review on a monthly basis to discover newly added third parties on your site.
What should I do if I find a third-party tool sharing student data I didn't authorize?
STOP THE DATA from flowing. Remove the script or integration from the tool. Then determine what data was shared and for how long to identify any disclosures owed to families. If children under 13 were included in the data and you are operating as a COPPA covered entity or service provider, immediately engage a privacy attorney to assist with the required disclosure to families as the wording and the timing has significant consequences for your liability.
Is my company data secure with LemonLime?
Security details are handled directly and kept current at lemonlime.ai/security. This page shows LemonLime’s actual posture at any given time. You should compare this to your requirements before you start using tools to help LemonLime.
Author: Daniela Munoz, LemonLime | Updated 2025 | 8 min read
Related topics: student data privacy, K-12 enrichment programs, COPPA compliance, children's data, ed-tech privacy, website data collection.
Frequently Asked Questions
Does my after-school enrichment program website collect student data even if I never set that up intentionally?
Yes — and this is exactly what the article addresses. Tools you added for legitimate reasons, like a registration form, a chat widget, or Google Analytics, often collect and transmit child and parent data to third-party servers without you ever configuring that explicitly. The collection happens through default settings, vendor terms, and tracking scripts. LemonLime helps you map what data you're holding, where it lives, and what's connected to what.
Why doesn't FERPA protect the students enrolled in my private enrichment program?
FERPA only covers school districts and entities that contract directly with them. A private after-school or enrichment program operating independently falls outside FERPA's scope entirely. That doesn't mean you're unregulated — state attorneys general can pursue action under unfair business practices statutes, and that exposure is growing. LemonLime gives you structured visibility into your data flows so you're not caught off guard during a compliance review.
How do I find out what tracking scripts are actually running on my enrollment pages right now?
Open your browser's developer tools, go to the Network tab, and reload your registration or enrollment page — every external domain loading data will appear there. You can also paste your URL into The Markup's free Blacklight tool for a faster scan. Do this monthly, especially after plugin updates. LemonLime complements this by connecting to your existing tools and building a structured, current map of your data sources automatically.
My enrichment program uses Jotform for enrollment — is that a student data risk I should actually be worried about?
Yes, it's one of the highest-risk integrations identified in the article. Form builders like Jotform store submission data on their own servers and their terms of service govern what happens to it — including potential forwarding to analytics services. If your form page also carries an ad pixel, that pixel can fire on submission events. Reading Jotform's data-sharing terms is listed as a specific action item. LemonLime helps you document and monitor these exact integrations.
What's the fastest thing I can do this week to get a handle on my enrichment program's data exposure?
The article recommends a 30-minute data inventory: list every tool on your site, note what data each collects, and document where that data goes. Then read the data-sharing terms for your form builder and chat widget — these two carry the most risk and most operators have never read them. LemonLime accelerates this process by connecting to your existing tools and automatically structuring that data into a knowledge layer you can actually query.
Could I face legal consequences for student data collected on my enrichment program website even if no specific ed-tech law applies to me?
Yes — and the article is direct about this. The absence of a specific ed-tech law covering your program doesn't mean you're protected. State attorneys general can and do pursue enrichment program operators under general unfair business practices statutes, and consumer protection frameworks increasingly apply to children's data. Small operators are being caught off guard as enforcement expands. LemonLime helps you build the documentation and data visibility that demonstrates responsible handling.