TotsPal Privacy Policy

Effective Date: February 18, 2026 | Last Updated: February 18, 2026

Welcome to TotsPal. This Privacy Policy describes how TotsPal Solutions Inc. (“TotsPal,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects Personal Information when you use the TotsPal mobile application for iOS and Android and the TotsPal web application at totspal.com (collectively, the “Service”).

This policy is designed to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), applicable Canadian provincial privacy legislation, the U.S. Children's Online Privacy Protection Act (COPPA), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), other applicable U.S. state privacy laws, and Google Play Store and Apple App Store policies.

By creating an account or using the Service you acknowledge that you have read and understood this Privacy Policy.

1. Definitions

  • “Personal Information” means any information about an identifiable individual, as defined under PIPEDA and applicable law.
  • “Child Data” means information about a child enrolled or waitlisted through the Service (name, date of birth, gender, special needs, allergies, medical information).
  • “User” means any individual who creates an account on the Service, including Parents, Childcare Providers, and Job Seekers.

2. Information We Collect

2.1 Information You Provide Directly

CategoryData ElementsWho Provides It
Account & IdentityEmail address, display name, password (hashed), profile photo, user type selectionAll Users
Location & AddressCountry, province/state, city, street address, geographic coordinatesAll Users
Parent ProfilePhone number, address, language preferences, service type preference, search radiusParents
Child InformationChild's first and last name, date of birth, gender, age group, special needs, allergies, medical informationParents
Guardian & Emergency ContactsSecond parent/guardian name, email, phone, address, relationship; emergency contact name and phone; authorized pick-up/drop-off personsParents / Providers
Provider ProfileBusiness name, provider type, licensing status, programs, age groups, capacity, fees, hours, activities, certifications, education, screen-time policy, food menu, languages, gallery images, website, privacy preferencesChildcare Providers
Job Seeker ProfileSeeker type, experience, education, certifications, criminal record check status, availability, hourly rate, languages, referencesJob Seekers
Employment & TimesheetsEmployee name, email, phone, role, hire date, emergency contact; clock-in/out times, work hours, break hoursProviders / Employees
Job Postings & ApplicationsJob title, description, requirements, qualifications, responsibilities, schedule, compensation, cover letterParents / Providers / Job Seekers
Waitlist RequestsChild data, parent information, enrollment start date preference, notesParents
Attendance RecordsEnrollment details, daily attendance status, drop-off/pick-up times, absence records and reasonsParents / Providers
MessagesText content of in-app messages, conversation metadata, read receiptsAll Users
Spotlight PostsText content, optional image, display nameAll Users

2.2 Information Collected Automatically

  • Device Location: With your explicit permission, we access your device's precise location (GPS) to enable provider search, map display, and the “On The Way” estimated-arrival feature.
  • Device Information: Device type, operating system version, app version, and unique device identifiers for push-notification delivery.
  • Usage Analytics: Screen views, feature interactions, session duration, and crash reports, collected through Firebase Analytics.
  • Push-Notification Token: A Firebase Cloud Messaging (FCM) device token used solely for delivering in-app notifications.

2.3 Information from Third Parties

  • Google Sign-In: If you choose to sign in with Google, we receive your Google account email address, display name, and profile photo URL. We do not access your Google contacts, calendar, or other Google data.

2.4 Camera and Photo Library

Camera & Photos Permission: We request access to your device camera and photo library to allow you to take and upload profile photos, capture facility/gallery images (Providers), and upload images for Spotlight posts. Camera and photo library access is optional.

3. How We Use Your Information

We use Personal Information for the following purposes:

  1. Account Creation & Authentication: To create, secure, and manage your account.
  2. Service Delivery: To connect Parents with Childcare Providers and Job Seekers; to facilitate waitlist management, enrollment, attendance tracking, and employee management.
  3. Location-Based Search: To display nearby Providers on a map and calculate proximity for search results.
  4. “On The Way” Feature: To share real-time estimated arrival time between Parents and Providers. Location data is cleared when the session ends.
  5. Messaging: To facilitate direct, private communication between Users.
  6. Notifications: To send push and in-app notifications about messages, attendance events, waitlist updates, job applications, authorization requests, and system alerts.
  7. Attendance & Reporting: To generate attendance reports for Providers and Parents.
  8. Employee Management: To manage employee invitations, timesheets, and employment records.
  9. Safety & Security: To detect and prevent fraud, abuse, and unauthorized access.
  10. Service Improvement: To analyze aggregate, de-identified usage data to improve app performance and features.
  11. Legal Compliance: To comply with applicable laws, regulations, and legal processes.

4. Legal Basis for Processing (PIPEDA & Applicable Law)

  • Consent: You provide express consent when you create an account, submit profile information, grant device permissions, and use features that share data with other Users.
  • Contractual Necessity: Processing is necessary to deliver the Service you requested.
  • Legitimate Interest: We may process data for fraud prevention, security, and service improvement.
  • Legal Obligation: We retain certain records as required by Canadian childcare regulations and tax law.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your Personal Information to third parties for marketing or advertising purposes.

5.1 With Other Users

  • Provider profiles are visible to Parents and Job Seekers (subject to provider privacy controls).
  • Job Seeker profiles are visible to Parents and Providers posting jobs.
  • Parent and child information is shared only with Providers who have an active enrollment or waitlist entry.
  • Messages are visible only to conversation participants.
  • Spotlight posts are visible to other Users in the community feed.

5.2 Third-Party Service Providers

ServicePurpose
Firebase AuthenticationUser sign-in and account management
Cloud FirestoreDatabase storage
Firebase Cloud StorageImage and file storage
Firebase Cloud MessagingPush notifications
Firebase AnalyticsDe-identified usage analytics
Google Sign-InOptional social login
Google Maps / GeocodingAddress geocoding and map display
MapboxMap display (mobile apps)
Google Play Services (Location)Device location for search & ETA
Google reCAPTCHA EnterpriseBot protection on sign-in, sign-up, and password reset (web only)

5.2.1 Bot Protection (Google reCAPTCHA Enterprise)

Our web application uses Google reCAPTCHA Enterprise to protect authentication flows (sign-up, sign-in, and password reset) from automated abuse such as fake account creation and credential-stuffing attacks. When you visit pages that include reCAPTCHA, Google may collect hardware and software information — including device and application data, browser type, language, and the results of integrity checks — and send it to Google for fraud analysis. reCAPTCHA does not collect the contents of any forms you submit. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.

5.3 Legal & Safety Disclosures

We may disclose Personal Information if required by law or to protect the rights, property, or safety of TotsPal, our Users, or the public.

6. Data Storage and Security

  • All data is stored on Google Cloud / Firebase infrastructure in the United States and Canada.
  • All data in transit is encrypted using TLS/SSL.
  • Data at rest is encrypted using Google-managed encryption keys.
  • Passwords are hashed by Firebase Authentication; we never store plaintext passwords.
  • Firestore Security Rules restrict data access to authorized Users.
  • Uploaded images are compressed, limited to 10 MB, and stored with path-based security rules.

7. Your Rights and Choices

7.1 Rights Under PIPEDA (Canada)

  • Access: Request a copy of the Personal Information we hold about you.
  • Correction: Request correction of inaccurate or incomplete Personal Information.
  • Withdrawal of Consent: Withdraw consent at any time (subject to legal restrictions).
  • Complaint: File a complaint with the Office of the Privacy Commissioner of Canada.

7.2 Rights Under U.S. State Privacy Laws (CCPA/CPRA)

  • Know: Request disclosure of categories and specific pieces of Personal Information collected.
  • Delete: Request deletion of your Personal Information, subject to legal exceptions.
  • Opt-Out of Sale: We do not sell Personal Information.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Data Portability: Request your data in a portable, machine-readable format.

7.3 How to Exercise Your Rights

  • In-App Data Export: Export your data from Settings > Account > Delete Account > Export Data (JSON format).
  • Account Deletion: Initiate from Settings > Account > Delete Account. Includes a 30-day grace period.
  • Device Permissions: Revoke camera, location, and notification permissions through device Settings.
  • Email Requests: Contact support@totspal.com. Response within 30 days (PIPEDA) or 45 days (CCPA/CPRA).

7.4 Provider Privacy Controls

  • Address Visibility: Choose full, partial, or hidden address display.
  • Phone Display: Choose whether your phone number is visible publicly.
  • Email Display: Choose whether your email is visible publicly.

8. Data Retention

Data CategoryRetention PeriodReason
Active account dataDuration of account + 30-day deletion grace periodService delivery
Attendance & enrollment recordsUp to 6 years (anonymized)Regulatory compliance
Employment & timesheet recordsUp to 6 years (archived)Employment standards
Messages (after deletion)Anonymized for other participantConversation continuity
Photos & gallery imagesDeleted with accountNo retention
Firebase Analytics dataPer Google's policy (14 months)Service improvement

9. Children's Privacy

Important: TotsPal is a tool for adults (parents, childcare providers, and job seekers). The Service is not directed to children under 13. Children do not create accounts or interact with the Service directly.
  • Child Data is collected only as provided by a parent or legal guardian for childcare enrollment and attendance.
  • Child Data is shared only with the specific Provider(s) with whom the child is enrolled or waitlisted.
  • We do not use Child Data for advertising, analytics profiling, or any purpose other than facilitating childcare services.
  • Parents may access, correct, or delete their children's information at any time.
  • If we learn that information has been collected from a child under 13 without parental consent, we will delete it promptly.

10. Location Data

  • Permission Required: Precise location is requested only for provider search, map features, or “On The Way” ETA. You can deny or revoke this at any time.
  • How It's Used: Coordinates calculate distance to Providers and estimate travel time.
  • “On The Way”: Location updates every 10 seconds during an active session and is automatically cleared when the session ends.
  • No Background Tracking: We do not track your location in the background.

11. Push Notifications

  • We use Firebase Cloud Messaging to deliver notifications about messages, attendance events, waitlist updates, job applications, authorization requests, and system announcements.
  • You can disable push notifications at any time through device or app settings.
  • FCM device tokens are used solely for notification delivery, not for advertising or tracking.

12. Cookies and Tracking (Web Application)

  • Essential Cookies: Firebase Authentication session cookies required for login.
  • Firebase Analytics: De-identified usage data. You can opt out via browser “Do Not Track” settings.

We do not use advertising cookies, third-party tracking pixels, or retargeting technologies.

13. International Data Transfers

TotsPal Solutions Inc. is operated from Saskatoon, Saskatchewan, Canada. Our infrastructure is hosted on Google Cloud / Firebase servers in the United States and Canada. By using the Service, you consent to the transfer and processing of your data in these jurisdictions.

14. Do Not Track Signals

TotsPal does not currently respond to “Do Not Track” browser signals as there is no industry standard for compliance. However, we do not engage in cross-site tracking or targeted advertising.

15. Account Deletion and Data Portability

  1. Data Export: Export all your data in JSON format from the app's Settings screen before deletion.
  2. Initiate Deletion: Go to Settings > Account > Delete Account. Re-authentication is required.
  3. Grace Period: A 30-day grace period begins. Log in during this time to cancel deletion.
  4. Permanent Deletion: After 30 days, all personal data is permanently deleted. Storage files are removed. Messages are anonymized. Attendance and employment records are anonymized and archived for regulatory compliance (up to 6 years).
  5. Data Transfer: Providers can request transfer of records to a successor provider before deletion, subject to parent consent.

16. Security Incident Response

In the event of a data breach that poses a real risk of significant harm to Users:

  • We will notify affected Users as soon as feasible.
  • We will report the breach to the Office of the Privacy Commissioner of Canada as required by PIPEDA when there is a real risk of significant harm.
  • We will notify applicable U.S. state authorities as required by applicable state breach notification laws.
  • We will take immediate steps to contain and remediate the breach.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will update the “Last Updated” date, notify you via in-app notification or email for significant changes, and your continued use constitutes acceptance of the updated policy.

18. Contact Us

TotsPal Solutions Inc.

Email: support@totspal.com

Address: Saskatoon, Saskatchewan, Canada

Office of the Privacy Commissioner of Canada:

Website: www.priv.gc.ca


© 2026 TotsPal Solutions Inc. All rights reserved.