Privacy Policy
Last updated September 15, 2026
This is a short, plain-language summary of how LittleSteps OS handles data — it is a starting point for your centre's own privacy notice to families, not a substitute for legal review against Canadian privacy law (PIPEDA and any applicable provincial equivalent) for your specific situation.
What we collect
Centre staff and admin accounts (via Clerk), and the records your centre enters to run its program: children's names, dates of birth, guardian contact info, daily care logs, incident and medication records, attendance, photos you choose to upload, and billing records. We do not collect this information directly from children.
How it's used
Solely to operate the software your centre uses: showing ratios and rosters, generating invoices, and giving invited guardians read-only access to their own child's records through the parent portal. We do not sell data, and we do not use centre or child data to train models.
Where it's stored
In a Postgres database with row-level security enforcing that one centre can never see another's data, hosted on infrastructure in North America. Photos and receipts are stored via presigned uploads to S3-compatible object storage.
Who it's shared with
Only the service providers required to run the app (hosting, authentication, email, and payment processing), each bound by their own data processing terms, and only ever what's needed for that service to function. A guardian only ever sees their own linked child's records.
Your rights
A centre director can export or delete their centre's data on request. A guardian can ask their centre to correct or remove their family's records at any time.
Contact
Questions about this policy or a data request — see the Contact page.