Service Providers

Rally Reader — Service Providers

Last updated 10/1/2026

1. How Rally Reader is built

Rally Reader runs on three platforms, not one. Amazon Web Services and Google each maintain separate Canadian and United States environments, and a customer’s information is stored in the environment for their country. Vercel runs our server-side code in Montréal.

Amazon Web Services: The book system — book storage, copy protection, licensing and purchases — and the login system.
Google Firebase / Google Cloud: The rest of the application — application data, reading data, reading content, logs and backups.
Vercel: Our websites, and the server-side code behind our registration forms.

2. The list

Amazon Web Services (AWS)

What it does — two core parts of Rally Reader:

  1. The book system. Stores the digital books, protects them against copying, handles licensing and purchases, and runs a small AI model that prepares book previews.
  2. The login system. Authentication for parents, teachers and students, including school sign-in through Clever and ClassLink.

Personal information involved: Yes, including children’s. Account and identity information, and purchase records.

Where it is processed: Separate Canadian and United States environments. Canadian accounts are in the Canadian environment: ca-central-1 (Montréal) as primary, with ca-west-1 (Calgary) as backup. Both are in Canada.

The book preview model works on book content only. It does not use a child’s personal information, and no personal information is used to train, refine, fine-tune or evaluate it or any other model.

Google Firebase / Google Cloud Platform

What it does: the rest of the platform — application data, reading data, reading content, logs and backups.

Personal information involved: Yes, including children’s.

Where it is processed: Canadian accounts in region northamerica-northeast1 (Montréal); northamerica-northeast2 (Toronto) may also be used. Logs and backups for Canadian accounts are in Canada only. US accounts are processed in the United States.

Vercel

What it does: hosts our websites, including rallyreader.com and the program websites, and runs the server-side code behind our registration forms.

Personal information involved: Yes, including children’s. The program registration forms collect a parent’s name and contact details and, for each child, first name, last name, date of birth, school and grade.

Where it is processed: A dedicated Canadian region, yul1 (Montréal). Vercel is configured so that all server-side code — which is what processes personal information — executes inside that region. A Canadian parent’s form submission is processed in Montréal.

Static assets such as images, stylesheets and scripts are served from Vercel’s global network, as they are for any website. Those files contain no personal information.

Clever and ClassLink

These are the School’s services for rostering and sign-in, not ours. A School decides to use Clever or ClassLink, holds its own agreement with them, and controls what student information flows through them.

We pay Clever and ClassLink an integration fee. That is a commercial arrangement between us and them for the connection itself. It does not make them our service providers for student information. They do not process student data on our instructions or on our behalf; they process it on the School’s behalf and deliver it to us.

In practice: data is pushed to us from those systems. We do not send student information to them, and we are not accountable for how they handle a School’s information. A School with questions about Clever or ClassLink should raise them with Clever or ClassLink.

Apple and Google application stores

What they do: distribute the application and process purchases of Book Credits.

Personal information involved: payment information, held by the store. Rally Reader does not receive or store payment card or bank account details.

Google Analytics

What it does: tells us how our websites and application are used and how they perform.

Personal information involved: none. It is configured so that it does not receive information that identifies an individual, and it does not retain IP addresses.

Where it is processed: Google’s global infrastructure. Because it receives no personal information, this does not affect our data residency position.

Sentry

What it does: catches application errors and sends us a report so we can fix them.

Personal information involved: none. It is configured so that it does not receive information that identifies an individual. User identifiers are not sent, error reports do not carry personal information, and IP addresses are not retained.

Where it is processed: outside Canada. Because it receives no personal information, this does not affect our data residency position.

3. What we require of every provider

Each service provider is engaged to operate or support the Service, and is required to:

  • meet our security standards;
  • use personal information only to provide or support the Service;
  • not use personal information to train, refine, fine-tune, evaluate or otherwise develop any artificial intelligence or machine learning model;
  • comply with applicable privacy law.

What we can and cannot promise. We do not authorize any provider to use personal information to train a model, and we do not send personal information to anyone for that purpose. We cannot guarantee the future conduct of another company. Where we learn that a provider has used personal information in a way we did not authorize, we will address it, including by ending the arrangement.

We remain responsible to our customers for the acts and omissions of our service providers in providing the Service.