MyLittleWorld
HomeFeaturesFor FamiliesOperationsResourcesPricing
/
Log inGet started

Privacy Policy

Last updated August 20, 2026

MyLittleWorld Inc.¹ ("MyLittleWorld," "we," "us," or "our") provides a business-to-business software-as-a-service platform for licensed childcare centers and daycares ("Organizations") to manage attendance, daily reporting, billing, staff scheduling, and family communication (the "Service"). This Privacy Policy explains what personal information we collect through the Service, how we use and share it, how long we keep it, and the rights available to the people whose information passes through our systems.

Please read this Privacy Policy carefully. If you are a parent or guardian with questions about your child's specific records, please see Section 1 and Section 10 below regarding the distinction between MyLittleWorld and your child's Organization.

1. Who This Policy Covers, and the Controller/Processor Relationship

MyLittleWorld is used by two categories of individuals:

  • Organization users — owners, directors, administrators, and staff of a licensed childcare center or daycare that has contracted with MyLittleWorld (each, an "Organization"). Organization users access a full administrative application to manage children's records, attendance, staffing, billing, and communications.
  • Family portal users — parents and legal guardians ("Parents/Guardians") of children enrolled at an Organization. Family portal users access a scoped "family portal" that shows only information relating to their own child or children.

Children do not create accounts, log in, or submit information directly through the Service. All information relating to a child is entered into the Service by an Organization's staff or by the child's Parent/Guardian, acting on behalf of the Organization or the child, as applicable.

Controller and processor roles. For information about children, families, and the day-to-day operation of a childcare center (collectively, "Customer Data"), the Organization is the data controller (referred to as the "responsible party" under Quebec's Law 25 and "organization" under PIPEDA), and MyLittleWorld acts as a data processor (or "service provider") on the Organization's behalf, under the terms of our agreement with that Organization. This means:

  • The Organization determines what information is collected about children and families, how long it is generally kept (subject to the platform-wide limits in Section 7), and who at the Organization may access it.
  • MyLittleWorld processes Customer Data only as instructed by the Organization, as necessary to provide, maintain, secure, and support the Service, and as otherwise required by law.
  • Requests from a Parent/Guardian to access, correct, or delete their child's information should generally be directed to the child's Organization first, since the Organization controls that data and can act on the request directly within the Service. MyLittleWorld will nonetheless assist with, and can be contacted directly regarding, any such request — see Section 10.

For a narrower set of information that MyLittleWorld collects and controls in its own right — such as account credentials, billing contact details for the Organization's subscription, and technical/usage data about how the Service is accessed — MyLittleWorld acts as the data controller. This Privacy Policy addresses both roles and identifies which applies in each section where the distinction matters.

2. Information We Collect

We collect the following categories of personal information through the Service. Not every category applies to every Organization: several features (in particular, health information) are optional and must be affirmatively enabled by the Organization before staff can enter that information.

2.1 Child Profile Information

Entered by Organization staff (and in some cases Parents/Guardians during enrollment), this includes: the child's first and last name, date of birth, classroom or group assignment, attendance records (check-in and check-out times), pickup authorization details (the names and relationship of individuals authorized to pick up the child), and emergency contact names and phone numbers.

2.2 Health Information (Optional, Organization-Enabled)

Where an Organization enables this functionality, staff or Parents/Guardians may enter: allergies, medications and administration schedules, dietary restrictions, medical notes, and emergency care instructions (e.g., epinephrine auto-injector instructions, seizure protocols). This is sensitive personal information, and we apply heightened access controls to it as described in Section 8.

2.3 Daily Reports

Staff use the Service to record day-to-day activity for each child, including nap times, meals, diaper/potty logs, mood indicators, activities and observations, and learning milestones. Daily reports may include photos uploaded by staff to illustrate a specific activity or moment.

2.4 Photos and Media

The Service allows staff to upload classroom photos, activity and event photos, child profile photos, and — where relevant to documenting a health or safety event — incident report photos. Photos are associated with the child(ren) depicted and are visible to that child's Parent/Guardian and to authorized Organization staff.

2.5 Parent/Guardian Information

We collect the Parent or Guardian's name, email address, phone number, and mailing address; billing and payment history associated with their account (see Section 2.8 regarding card data specifically); and messages exchanged with Organization staff through the Service's messaging features.

2.6 Staff Information

For individuals employed or engaged by an Organization, the Service may be used to record work schedules, attendance and clock-in/clock-out records, employment records used for payroll purposes, and role/permission assignments within the Service.

2.7 Account and Authentication Data

To create and secure a user account (for both Organization staff and Parents/Guardians), we collect an email address and a password. Passwords are never stored in plain text: they are hashed using industry-standard hashing algorithms via Supabase Auth, our authentication provider. We also record whether multi-factor authentication ("MFA") has been enabled on an account.

2.8 Payment Data

Subscription payments (by Organizations) and, where applicable, family billing payments are processed by Stripe, Inc., our payment processor. MyLittleWorld does not receive, transmit through its own servers, or store full payment card numbers. We retain limited billing metadata (such as invoice amounts, payment status, and the last four digits of a card, as provided to us by Stripe) for accounting and customer support purposes.

2.9 Technical and Usage Information

As with most software services, we automatically collect limited technical information necessary to operate and secure the Service, such as IP address, browser and device type, log timestamps, and general usage data (e.g., which features are accessed). We do not use this information for advertising and do not share it with data brokers or ad networks (see Section 5).

3. How We Use Information

We use the personal information described in Section 2 for the following purposes, each grounded in providing and operating the Service on behalf of Organizations:

  • Operating the Service, including enabling staff to record attendance, daily reports, and health information; enabling Parents/Guardians to view their child's records and communicate with staff; and enabling Organizations to manage staff scheduling and billing.
  • Enrollment and account administration, including creating and authenticating user accounts, verifying that a person requesting family-portal access is an authorized Parent/Guardian, and managing permissions and roles.
  • Communications, including facilitating messages between staff and Parents/Guardians, sending Service-related notifications (e.g., a new daily report has been posted, an invoice is due), and responding to support requests.
  • Billing and payments, including processing Organization subscription fees and, where applicable, family tuition or fee payments through Stripe, and maintaining billing records for accounting and tax purposes.
  • Payroll support, where an Organization uses the Service's staff scheduling and clock-in/clock-out features to generate records used in its own payroll processes.
  • Safety and incident documentation, including maintaining pickup authorization records, emergency contact information, and incident reports to support the Organization's health and safety obligations.
  • Security and integrity of the Service, including detecting and preventing unauthorized access, enforcing tenant isolation between Organizations, and maintaining audit logs.
  • Product support and improvement, including diagnosing technical issues and understanding aggregate, de-identified feature usage to improve the Service. We do not use Customer Data (child, family, or health information) to train general-purpose machine learning models, and we do not use it for advertising or marketing to third parties.
  • Legal compliance, including responding to lawful requests from regulators or courts, and retaining records as required by applicable law (see Section 7).

4. Legal Basis for Processing

4.1 Quebec and Canada (Law 25 and PIPEDA)

MyLittleWorld is established in Quebec, Canada, and processes personal information in accordance with Quebec's *Act respecting the protection of personal information in the private sector* (as amended by the *Act to modernize legislative provisions as regards the protection of personal information*, commonly known as "Law 25"), and, for personal information processed in the course of commercial activity across Canada, the federal *Personal Information Protection and Electronic Documents Act* ("PIPEDA").

Consistent with these frameworks:

  • Personal information about children and families is collected and used with the knowledge and, where required, the consent of the Organization (as controller) and, for family-portal information, the Parent/Guardian who creates the account. Consent may be express (e.g., agreeing to Organization enrollment terms that describe use of the Service) or, for certain uses necessary to provide the Service the individual has requested, implied by the individual's use of the Service.
  • We collect only the personal information reasonably necessary for the purposes described in Section 3, and we do not use personal information for a purpose incompatible with those for which it was collected without obtaining fresh consent, except as permitted or required by law.
  • Organizations, as controllers, are responsible for ensuring they have the appropriate consents and legal authority from Parents/Guardians and staff to submit information to the Service, including any consent required to enable optional health-information features.
  • We conduct privacy impact assessments for projects involving significant changes to the collection, use, or communication of personal information, as required under Law 25, and maintain a privacy governance framework, including internal policies and designated privacy contacts, as required under Law 25.
  • Individuals in Canada have the rights described in Section 10, including rights of access, correction, and, in certain circumstances, de-indexing or cessation of dissemination.

4.2 GDPR-Ready Provisions for Users in the European Economic Area

MyLittleWorld's Organization customers, and the individuals whose information they process, are presently based in Canada. However, because we may serve Organizations located in, or with users located in, the European Economic Area ("EEA") in the future, we describe below the framework we intend to apply to such users, extending rights consistent with the EU General Data Protection Regulation ("GDPR"). This section describes rights we extend to EEA users as a matter of policy; it is not a representation that MyLittleWorld has undergone, or is required to undergo, formal GDPR compliance certification, and should not be relied upon as a legal compliance determination.

Lawful basis for processing. Where the GDPR applies, we process personal information on the following legal bases:

  • Performance of a contract (Article 6(1)(b)) — to provide the Service to the Organization and to Parents/Guardians who use the family portal, including processing child, family, and staff information as instructed by the Organization.
  • Legitimate interests (Article 6(1)(f)) — to secure the Service, prevent fraud, and improve our product, balanced against the interests and fundamental rights of the individuals concerned.
  • Consent (Article 6(1)(a), and Article 9(2)(a) for special category data such as health information) — where an Organization or Parent/Guardian affirmatively enables and provides health information, or otherwise where consent is the appropriate basis under applicable law.
  • Compliance with a legal obligation (Article 6(1)(c)) — including retaining certain financial records as required by law.

Data subject rights. Subject to applicable exceptions, individuals in the EEA have the right to: (i) access their personal information; (ii) rectify inaccurate personal information; (iii) request erasure of their personal information; (iv) obtain a portable copy of personal information they have provided, in a structured, commonly used, machine-readable format; (v) object to processing based on legitimate interests; (vi) restrict processing in certain circumstances; and (vii) lodge a complaint with a supervisory authority in their country of residence. Requests relating to a specific child's or family's records should generally be directed first to the relevant Organization (as controller); see Section 10.

EU representative. MyLittleWorld has not yet appointed an EU representative under Article 27 of the GDPR. If required, contact details for MyLittleWorld's EU representative will be added here.

5. Who We Share Information With

We do not sell personal information, and we never have. We do not share personal information with advertisers, data brokers, or analytics networks for advertising purposes. We share personal information only in the following circumstances:

Subprocessors that support the Service. We use a small number of third-party service providers ("subprocessors") to operate the Service — Vercel (application hosting), Supabase (database, authentication, and file storage), Stripe (payment processing), and Resend (transactional email delivery). Each subprocessor is contractually bound to use personal information only to provide services to MyLittleWorld, to protect it with appropriate security measures, and not to use it for its own independent purposes. Full details, including the categories of data each subprocessor handles and where it's located, are published in our Subprocessor List.

Within an Organization. Information is shared, by design, among authorized staff of the same Organization who require it to perform their roles (e.g., a classroom teacher sees children in their classroom; an administrator may see billing records), and with the Parent/Guardian of the specific child to whom the information relates. Role-based access controls limit what each type of user can see, as described in Section 8.

Legal and safety disclosures. We may disclose personal information where required to comply with a valid legal process (such as a court order or government demand), to comply with mandatory reporting obligations that apply to childcare settings, to protect the rights, property, or safety of MyLittleWorld, an Organization, a child, or the public, or in connection with the enforcement of our terms of service.

Business transfers. If MyLittleWorld is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to standard confidentiality protections and, where required by law, notice to affected individuals or Organizations.

We do not have, and do not intend to establish, any advertising, data-broker, or analytics-resale relationships involving Customer Data.

6. International Data Transfers

MyLittleWorld is based in Quebec, Canada, and Customer Data is primarily hosted with Supabase in a Canadian data region where available. However, because we rely on subprocessors described in Section 5 — including Vercel, Stripe, and Resend — some personal information may be processed on servers located in the United States or accessed as part of a global content-delivery or edge-computing network.

When personal information is transferred outside of Canada (including to the United States), we take steps intended to ensure it receives an appropriate level of protection, including: (i) entering into contractual data protection commitments with our subprocessors that require them to safeguard personal information consistently with applicable privacy laws; (ii) encrypting personal information in transit (via TLS) and at rest; and (iii) limiting the categories of information each subprocessor receives to what is necessary for the service it provides. Before transferring personal information outside Quebec, we conduct an assessment intended to ensure the information will receive protection equivalent to that required under Quebec's Law 25, consistent with that law's requirements for transfers of personal information outside the province.

7. Data Retention

We retain personal information according to the following principles:

  • Active child and family records. Child profile information, health information, daily reports, photos, and related family records are retained for as long as the Organization's MyLittleWorld account remains active, or until the Organization deletes specific records, whichever occurs first. Because the Organization controls this data, it may establish and apply its own retention practices for individual records (for example, archiving a child's profile at the end of an enrollment period), consistent with its own legal obligations as a licensed childcare provider.
  • Backups. Deleted data may persist in encrypted backups for a limited period after deletion, to protect against accidental loss and to support disaster recovery. We currently target a backup retention period of 30 days after deletion.
  • Closed Organization accounts. When an Organization's account with MyLittleWorld is closed or terminated, we will permanently delete the associated Customer Data within 90 days, except where a longer retention period is required by law — for example, certain financial, billing, or tax-related records that we or the Organization may be legally obligated to retain for longer.
  • Account and authentication data. Login credentials and MFA status are retained for as long as the associated account is active, and are deleted or de-activated upon account closure, subject to the backup retention period above.
  • Billing records. Billing metadata retained by MyLittleWorld (as opposed to full payment data held by Stripe) is kept for as long as necessary to support accounting, audit, and tax obligations, which may exceed the retention periods above for the limited purpose of financial record-keeping.

Full detail on how each data category is retained is available in our standalone Data Retention Policy.

8. Security Measures

We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction, including:

  • Encryption in transit. All communication with the Service is encrypted using HTTPS/TLS.
  • Encryption at rest. Our database is encrypted at rest.
  • Tenant isolation enforced at the database layer. Each Organization's data is isolated from every other Organization's data using PostgreSQL Row-Level Security ("RLS") policies enforced directly by the database — not solely by application-layer logic. This means that even if a defect existed in the application code, the database itself is configured to reject cross-Organization data access.
  • Password security. Passwords are hashed using bcrypt via Supabase Auth; we never store passwords in plain text and do not have access to a user's plaintext password.
  • Multi-factor authentication. Staff accounts may optionally enable MFA for an additional layer of account security.
  • Role-based access control. Access within the Service is governed by role-based permissions, so that, for example, a Parent/Guardian can see only their own child's records, and a staff member sees only the children, classrooms, or functions relevant to their role.
  • Least-privilege access to production systems. Access to production data by MyLittleWorld personnel is limited to those who require it to operate and support the Service, and is scoped and monitored accordingly.

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We continually evaluate and update our security practices as the Service and the threat landscape evolve. Full detail is available on our Security page.

9. Children's Privacy

MyLittleWorld is a business tool designed for use by adults — specifically, verified childcare staff and Parents/Guardians acting on behalf of an Organization or a child. The Service is not directed at children, and children do not create accounts, log in, or submit information about themselves through the Service. Every piece of information relating to a child that exists in the Service — including profile details, health information, daily reports, and photos — is entered by an adult: either a staff member of the child's Organization, acting within the scope of the Organization's engagement with a childcare provider and its licensing obligations, or the child's Parent/Guardian.

Because information about children is collected exclusively from, and entered by, verified adults rather than collected directly from children themselves, MyLittleWorld's data practices are designed with the expectation that the direct-collection-from-children provisions found in laws such as the U.S. Children's Online Privacy Protection Act ("COPPA") are not implicated in the same way they would be for a service that collects information directly from child users. This description is intended to explain how the Service is designed and operated; it is not a legal conclusion that any particular law does or does not apply to MyLittleWorld, and Organizations and MyLittleWorld each remain responsible for complying with applicable childcare, education, and privacy laws in their own jurisdictions.

Parents and Guardians who no longer wish for their child's information to be maintained in the Service should contact their child's Organization directly, as the Organization controls that data; MyLittleWorld will assist with such requests as described in Section 10.

10. Your Rights and Choices

Rights available to you. Subject to applicable law and the exceptions described below, you may have the right to: request access to personal information we (or, where applicable, the relevant Organization) hold about you or your child; request correction of inaccurate or incomplete information; request deletion of your information; and, where applicable, request that we cease disseminating certain information or de-index it, consistent with Quebec's Law 25.

Who to contact first — controller vs. processor. Because MyLittleWorld generally acts as a data processor for records relating to a specific child, family, or staff member (with the child's Organization acting as the controller of that data), requests concerning a specific child's records — including access, correction, or deletion requests — should generally be directed first to the child's daycare or childcare center, since the Organization controls that information and can typically act on the request directly within the Service.

MyLittleWorld will still help. If you are unsure which Organization to contact, if your Organization is unresponsive, or if your request relates to information MyLittleWorld controls directly (such as your own account credentials, or billing contact details for an Organization subscription), you may contact us directly at privacy@mylittleworld.ca, and we will assist you or direct your request appropriately, including facilitating communication with the relevant Organization where needed.

Verification. To protect personal information from unauthorized access, correction, or deletion, we may need to verify your identity, and the identity of your relationship to a child (e.g., as a Parent/Guardian), before completing a request.

Response time. We will acknowledge and respond to requests within the timeframes required by applicable law (including Law 25 and PIPEDA), generally within 30 days, subject to permitted extensions with notice to you.

No retaliation. We will not deny you access to the Service or otherwise penalize you for exercising your privacy rights, subject to the practical reality that some Service functionality may not be available if certain information is deleted (for example, an Organization cannot maintain attendance records for a child whose profile has been deleted).

11. Cookies

The Service uses cookies and similar technologies necessary to operate the application (such as maintaining a logged-in session) and, where applicable, limited technologies to understand aggregate product usage. We do not use cookies for third-party advertising. For a full description of the cookies and similar technologies we use, their purposes, and your choices, please see our separate Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. If we make material changes, we will notify Organizations (and, where appropriate, Parents/Guardians) through the Service or by email, and will update the "Last Updated" date above. We encourage you to review this Privacy Policy periodically. Continued use of the Service after a change becomes effective constitutes acceptance of the updated policy, to the extent permitted by applicable law.

13. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or MyLittleWorld's privacy practices, please contact:

MyLittleWorld Inc. Montreal, Quebec, Canada Email: privacy@mylittleworld.ca

If you are a Parent/Guardian with a question about a specific child's records, please first contact your child's Organization (daycare/childcare center), as explained in Section 10. MyLittleWorld remains available to assist at the email address above.

¹ "Inc." is used here as a placeholder pending confirmation of MyLittleWorld's actual registered legal entity name and corporate form.

MyLittleWorld
© 2026 MyLittleWorld. Made for childcare teams.
HomeFeaturesFor FamiliesOperationsResourcesPricingAboutSecurityTrust CenterFAQPrivacyTermsContact