Legal · App
Limen Campus Manager Privacy Policy
This is the privacy policy for the app Limen Campus Manager, which truck-driving schools use to keep student records, schedules, timesheets, grades and fee records. It explains what the app collects, why, who else handles it, how long it is kept, and how to have it deleted. It applies to the app on Android, iOS, the web, Windows and macOS.
Last updated and effective: 29 July 2026.
The app and its developer
App name: Limen Campus Manager.
Android package name on Google Play: com.limendigitalstudios.campusmanager.
Apple App Store: Limen Campus Manager, app ID 6777803111.
Developer: Neelesh Sirdana, operating as Limen Digital Studio, Toronto, Ontario, Canada.
Neelesh Sirdana is the developer named on the Google Play listing for Limen Campus Manager and the seller named on the Apple App Store listing for the same app. Limen Digital Studio is the business name that same developer trades under. In this policy, “we” and “us” mean that developer.
Privacy contact: admin@limends.com. Write to that address for any question, access request or deletion request about this app.
Who uses the app
The app is licensed to driving schools. Three kinds of people sign in: school office staff, driving instructors, and shared tablets kept in the yard. Students never get an account and never install the app. Their records are typed in by their school.
Schools own their records. We process them.
Each school decides what to record about its own students and staff and how long to keep it. The school is responsible for that information. We run the software and store the information on the school’s behalf and on its instructions. If you are a student or an instructor and you want to see, correct or delete your record, ask your school first. If the school does not respond, write to us and we will contact them.
What school staff give us
When a school opens an account we collect: the email address and password of the person creating it, the school name, street address, city, province and postal code, the school phone number, the manager’s name and title, the school’s Ontario Career Colleges registration number, and the school logo. The school name and address are printed on the enrolment contracts and transcripts the school has to issue.
Two of those details, the school name and the city typed into the Location box, are also copied into a small separate list of schools. You should treat that list as public: anyone who knows the identifier of our database can read it, with no account and without signing in at all. It holds nothing else — no street address, no phone number, no person’s name, and nothing whatsoever about any student or any instructor. It is there because older versions of the app showed a joining instructor a list of schools to pick from. A school’s entry is removed when that school’s account is deleted, and no one can write to that list from the app.
Passwords are held by Google Firebase Authentication in hashed form. We never see or store a readable password.
Opening a school account needs a one-time licence key we issue. We record which key was used, the email address that used it, and when.
To confirm the email address is real, we email a six-digit code to it. That email address and code are stored while the code is valid (ten minutes) and are deleted when the account is created. If a sign-up is abandoned part-way, that email address and code can stay in our records; email us and we will remove them.
What instructors give us
The office adds each instructor to the roster with their name and their mobile phone number. The number is required, because it is how an instructor gets back in on a new phone: they type their own number, Google sends them a six-digit text, and they land back on the same account.
When any number is typed into that sign-in screen, we keep a short record of it so that nobody can sit there guessing numbers, and a one-way scrambled (hashed) form of the network address the request came from, for the same reason. We do not keep readable network addresses and we do not use either for tracking.
An instructor’s name is frozen onto every class they sign off. Ontario MELT rules require the record to name the licensed instructor who actually gave the instruction, so that cannot be removed later.
If an instructor allows notifications, their phone gives us a push token. That is an address Google’s push service uses to reach that one device, and nothing else. It is stored with the platform name (Android or iOS) and the date. No one can read those tokens from inside the app; only our server uses them to send a notification. Tokens are only ever registered on an instructor’s own phone, never on the web, the desktop app or a shared tablet.
So an instructor is not asked to sign in twice, the app can keep a sign-in credential in the phone’s own secure storage (the iOS Keychain or the Android keystore), along with their name and their school name. Our server keeps only a scrambled copy so it can check it. The credential itself never leaves that phone and is not backed up to iCloud.
If a school uses a shared yard tablet, an instructor can set a four-digit PIN so that sign-offs made on that tablet are made under their own login. The PIN is stored only as a scrambled value with a random salt. Nobody can read it back, including the school and including us. The app records whether a PIN is set, how many wrong tries there have been, and whether it is locked.
What schools record about students
Students do not have accounts. Office staff type these details into the student record: student number and status; title, gender, first, middle and last name; date of birth; whether the student is international; permanent address and mailing address; telephone, mobile and email; driver’s licence number and licence class; emergency contact name and phone; how the student heard about the school; funding source; full-time or part-time; sales representative; and the start, registration and graduation dates.
The same record holds the academic side: the programs the student is enrolled in, course codes, hours, marks, grades, pass or fail status and the transcript, plus which class group the student belongs to.
It also holds the money side: the fee breakdown, the payment plan, and each payment the school received with its date, receipt number, amount, deposit slip number, method, bank name, remarks and the general-ledger breakdown. Three of those fields are free text the school fills in itself, labelled “Check / Credit card No.”, “Card Exp.” and “Cc Name Holder”, and whatever the school types is stored as typed. The app does not take payments, is not connected to any card network and never charges anyone. It is a record of money the school has already collected. Schools should record a cheque number or the last four digits of a card there, not a full card number.
Finally it holds the timesheet hours for the three official MELT forms: the in-class, in-yard and in-cab days, with start and end times, notes, and for in-cab days the hours spent on in-cab behind-the-wheel time, backing, coupling, vehicle inspection and handling emergencies, and whether the trailer was loaded.
Signatures
At the end of a class the student and the instructor sign with a finger, on the instructor’s phone or on the shared yard tablet. The app saves both signatures as small images on that class record and reprints them on the MELT timesheet forms. Ontario requires a signed record that a named licensed instructor taught that class to that student. While a signature is being drawn, the strokes are also held on that one device for up to 72 hours, so a half-finished sign-off is not lost if the app closes.
Schedules and sign-off records
Each class in the schedule holds the instructor, the student, the day, the start and end time, the class type, the class number, notes written by the office, notes the instructor writes at sign-off about how the class went, and the account that signed it. Draft schedules the office has not published yet are kept separately and instructors cannot read them.
The office also has an in-app message list, which contains lines naming an instructor, such as a request to join the school.
Documents the app creates
The app generates PDFs: the one-page transcript, the five-page enrolment contract, the three MELT timesheets with the signatures reproduced on them, and instructor schedule sheets. These contain student information. On a phone or tablet the file is written into the app’s own documents folder and then handed to the device’s share sheet, so the person who generated it chooses where it goes, which can be another app or a cloud drive. On Windows, Mac and the web it is an ordinary download. These files are never uploaded to us. On iPhone and iPad the app’s documents folder is visible in the Files app, so anyone holding the unlocked device can open those PDFs.
Copies kept on the device
The app has to work in a truck yard with no signal, so every device keeps a local copy of what it has already loaded. On an instructor’s phone or a shared tablet that can include the student roster with names, dates of birth, addresses, phone numbers and signatures. Signing out clears that copy. If work is still waiting to upload, such as a class just signed off, the copy is kept until the upload succeeds, because losing a real sign-off is worse than holding the roster a little longer.
On Windows and Mac, if you tick the box to be remembered, the app stores your email address and, only if you ask it to, your password, encrypted by Windows or macOS and locked to your computer account. It is never uploaded. The owner account is never remembered.
Notifications
The app sends four kinds of notification to instructors: your schedule changed, a new schedule was published, a security receipt when a shared tablet signs in as you, and a request to confirm when a yard tablet is asking to sign you in. Android asks for notification permission the first time an instructor opens their calendar, not on first launch. If you decline, the app does not ask again. Notification text never contains a student’s name.
What the app does not collect
There is no analytics, no crash-reporting service, no advertising and no tracking of any kind in the app. The released Android app does not carry the advertising-ID permission, so it cannot read the advertising identifier on your phone, and it contains no advertising or ad-attribution code. The app never asks for your camera, microphone, location, contacts or calendar, and contains no permission to reach them. It does not open your photo library on its own: the one time it reaches an image on your device is when the office taps Upload logo in the school profile and picks a file through the device’s own picker, and that logo is the only file the app ever takes from your device’s storage. The two signatures described above are images the app draws itself from your finger strokes, not files taken from your device. It does not read your text messages: the six-digit sign-in code is typed in by hand. It does not read any hardware identifier from your phone — no IMEI, no MAC address, no advertising ID. The one device-scoped identifier we hold is the push token described above, which Google’s push service issues so we can reach one phone, and the id used for a shared tablet is a random number our own server makes up. We do not sell personal information and we never use it for advertising or profiling.
How the information is used
Only to run the app for the school: sign people in, hold the roster, build and publish schedules, record class sign-offs, produce the ministry and student documents, send the three notifications above, stop abuse of the sign-in screens, and give the school support when it asks for it. Nothing else.
Who else handles the information
We do not sell information and we do not give it to anyone to use for their own purposes. A small number of service providers handle it strictly on our instructions so the app can work:
Google, through Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging and Firebase Phone Authentication. Google holds the accounts and passwords, stores the database, runs our server code, delivers the notifications, and sends the six-digit sign-in text messages. There is no separate text-message company; Google sends those texts.
Apple. On iPhone and iPad, notifications and the check that confirms the request came from the real app pass through Apple’s push service.
Google Play services. On Android, Google’s Play Integrity check confirms the request came from the real app before a sign-in text is sent, and Google Play handles app updates.
Microsoft, through Microsoft 365 and Microsoft Graph, sends exactly two emails, both from admin@limends.com: the six-digit sign-up code, and a password-reset link. Nothing about a student or an instructor is ever emailed.
The Apple App Store and Google Play collect their own install, update and crash statistics when you download or update the app. That happens on the store, outside the app, under Apple’s and Google’s own policies.
The app itself never sends anything to a payment company. A school’s own subscription to Limen Campus Manager is billed on our website through Stripe. Stripe receives the school’s billing details only, and never receives any student, instructor or school record from the app.
We will also disclose information if the law requires it, for example a court order, and we will tell the school unless we are forbidden to.
Where the information is stored
The database is held in Google’s Canadian region, in Toronto, Ontario (northamerica-northeast2). Accounts and passwords are held by Google Firebase Authentication. Some server processing, and the delivery of notifications and sign-in text messages, runs on Google infrastructure in the United States.
Data retention: how long it is kept
School records are never deleted on a timer. A school’s records stay until the school deletes the record, deletes its account, or asks us to remove it. Only the short-lived sign-in and safety items listed further down expire on their own.
By design, an instructor’s classes and the signatures on them stay with the school even after the instructor leaves or deletes their account. They are the school’s Ontario training record, which the school is legally required to keep, not the instructor’s property.
Some sign-in and safety items are deliberately short-lived and do go on a timer: instructor join codes and tablet enrolment codes expire after seven days and work once; a tablet pairing request expires after two minutes; five wrong PIN tries lock that PIN for fifteen minutes; a sign-up email code expires after ten minutes; and unfinished signature strokes on a device expire after 72 hours.
The sign-in protection records described above, the number typed into the phone sign-in screen and the scrambled network address, are kept only to protect that screen and are used for nothing else. Ask us and we will delete the record of a number.
Two things mean a deletion is not instant everywhere. First, Google’s database keeps a seven-day recovery window, so for up to seven days after something is deleted it can still exist in that recovery data before it ages out for good. Second, scheduled Google backups of the database are switched on. A backup is a frozen snapshot of the database as it stood at one moment, so anything deleted afterwards still sits inside snapshots taken before the deletion until Google discards each of those snapshots on its own schedule, which can be longer than the seven-day recovery window. Backups are held by Google, are used only to put the service back after a failure or a mistake, and are not searched, exported or read for any other purpose. Your deletion request is carried out in the live database straight away; only these snapshots lag behind.
Data deletion: how to have information removed
A school can delete its own account from inside the app: Organization profile, then Delete account, then type DELETE to confirm. That erases the school and everything in it, including students, transcripts, payment records, schedules, timesheets, class groups, instructor logins, tablet logins, PINs, push tokens and unused codes. It cannot be undone.
An instructor can delete their own account from inside the instructor app. That removes their login, their yard-tablet PIN, every push token for their devices and every stored sign-in credential. Classes they already signed off stay with the school as its training record, as described above.
A school can remove an instructor from its roster. That deletes that instructor’s login, PIN, push tokens and stored credentials immediately, and burns any unused join code. A school can also remove one shared tablet on its own, without affecting its other tablets.
Students have no account, so a student who wants their record deleted should ask their school; the office deletes the student record from its student list. If the school does not act, write to us and we will contact the school on your behalf.
You can always ask us directly. Email admin@limends.comto see, correct or delete information about you or, if you are the school, about your school. We reply within 30 days. Where the request concerns a school’s own records we act on the school’s instruction, as described above.
Security
Everything moves over encrypted connections (HTTPS and TLS) and Google encrypts it at rest. Who can see what is enforced by rules on the server, not by the app: a school can only reach its own data, an instructor can only reach their own classes and their school’s roster, and a shared yard tablet gets a short session that signs itself out after a few minutes of no use. Passwords are held hashed by Google and never by us. Yard-tablet PINs are stored hashed with a random per-record salt and cannot be read back by anyone. The operations that matter, creating accounts, issuing join codes, setting PINs, and deleting accounts, run on our server rather than in the app, so they cannot be tampered with from a device.
One support account at Limen Digital Studio, admin@limends.com, can read a school’s records, including student records, transcripts, payment records and instructor contact details, so that we can support the school and confirm the service is working. That account cannot edit or add a school’s student, instructor, schedule, grade, timesheet or payment records.
Two things it can do besides reading, so you know the whole picture. It issues and revokes the one-time licence keys that let a school open an account. And it can delete an entire school, which erases that school and everything in it exactly as the school’s own Delete account button does, and cannot be undone; we do that only when the school itself asks us to. No other account at Limen Digital Studio has access to school data.
Children
Limen Campus Manager is a record-keeping tool for Ontario MELT commercial truck-driver training. Nobody signs themselves up for it: there is no public sign-up anywhere, and a new school account can only be created with a licence key we issue directly to a school. Students have no login of any kind, are never invited to make one, and never install the app; a student record exists only because a school’s office staff typed it in while enrolling that person on a commercial truck-driver training program. The app is not directed at children, is not designed for family audiences, and nothing in it is aimed at them. It carries no advertising and does not profile anyone.
To be straight with you: the app itself does not check anybody’s age and does not work anything out from a date of birth. A school records a date of birth because its Ontario enrolment paperwork asks for one. Deciding who a school may lawfully enrol, and getting any consent that decision needs, is the school’s responsibility, as with everything else in its own records. We do not knowingly collect information about children ourselves; if you believe a record about a child has been entered, write to us at admin@limends.com and we will take it up with the school.
Changes to this policy
If this policy changes we update this page and the date near the top. The current version always lives at limendigitalstudio.com/campus-manager/privacy.
Contact
Neelesh Sirdana, operating as Limen Digital Studio. Toronto, Ontario, Canada. Email admin@limends.com. This policy is governed by the laws of Ontario, Canada.
This policy covers the Limen Campus Manager app. Our website has its own separate website privacy policy, and our terms and conditions apply to the site and to purchases made on it.


