Tinypaths.com Privacy Policy
Last Updated: October 28, 2025
1. Introduction and Scope
Welcome to Tinypaths.com ("we," "us," "our"). We provide an online software platform and related services (the "Service") to facilitate preschool and early learning operations for our clients, which are childcare centers, preschools, and other early learning providers ("Clients").
This Privacy Policy explains how we collect, use, and protect personal information when we act as a Data Processor on behalf of our Clients. It also describes our data practices when we act as a Data Controller for our own business purposes (e.g., for marketing and managing our own Client accounts).
This policy is designed to comply with federal laws like the Children's Online Privacy Protection Act (COPPA) and comprehensive state privacy laws, including Washington's My Health, My Data Act (MHMDA) and the California Consumer Privacy Act (CCPA).
2. Our Role as a Data Processor
When our Clients use our Service, they upload and manage personal information about the children in their care, as well as their parents, guardians, and staff. In this context:
- Our Client (the childcare provider) is the Data Controller. They determine the purposes and means of collecting and processing personal data. They are responsible for obtaining all necessary consents, including Verifiable Parental Consent under COPPA.
- Tinypaths.com is the Data Processor. We process personal data only on behalf of and as instructed by our Clients to provide and maintain the Service. Our Clients retain full ownership and control of the data they upload.
- If you are a parent or guardian with questions about your child's data, please contact your childcare provider directly.
3. Our Commitment to Children's Privacy (COPPA)
We are fully compliant with the Children's Online Privacy Protection Act (COPPA). Our Service is designed to enable our Clients to meet their COPPA obligations.
Verifiable Parental Consent: We do not collect personal information from children under 13. Our Clients are responsible for obtaining verifiable parental consent before any personal information about a child is entered into our Service. The child's school may act as an agent for the parent to provide consent for the use of our Service in an educational context.
Parental Rights: We provide our Clients with the tools necessary to honor parental rights. Parents who wish to review their child's personal information, request its deletion, or prevent further collection must direct their requests to their childcare provider (the Data Controller). We will assist our Clients in responding to these requests promptly.
4. Information We Process on Behalf of Our Clients
As a Data Processor, we process the information that our Clients and their authorized users (including parents and guardians) knowingly provide and upload to the Service. This may include:
- Child's Personal Information: First and last name, date of birth, and home address.
- Parent/Guardian Information: First and last name, email address, phone number, and physical address.
- Child's Health and Wellness Data ("Consumer Health Data"): This is a category of sensitive data that our Clients may collect to comply with licensing requirements and ensure child safety. It can include immunization records, allergies, medication authorizations, individual care plans, and incident reports.
- Photographs, Videos, and Audio Files: Our Clients may upload media containing a child's image or voice after obtaining explicit consent from the parent or guardian.
- Emergency and Authorization Information: Contact details for emergency contacts and individuals authorized for pickup.
5. How We Use Information as a Data Processor
We use the data entrusted to us by our Clients for the sole purpose of providing and maintaining the Service as directed by them. This includes:
- Operating and securing our platform.
- Enabling communication between our Clients and the families they serve.
- Facilitating administrative tasks like attendance tracking and billing.
- Providing customer support and troubleshooting issues.
- Ensuring our Clients can comply with legal and licensing obligations.
We will not use Client data for our own commercial benefit, such as advertising to children or parents. We may use de-identified and/or aggregated information for analytics, research, and to improve our Service.
6. How We Share and Disclose Information
We are committed to maintaining the confidentiality of our Clients' data. We do not sell or rent personal information.
We will not share or disclose the personal information processed on behalf of a Client except in the following limited circumstances:
- At the Client's Direction: We will share data as instructed by the Client through the functionality of the Service.
- With Service Providers (Subprocessors): We engage trusted third-party vendors for services like cloud hosting (e.g., Amazon Web Services) and payment processing. These subprocessors are contractually bound to protect the data and are prohibited from using it for any other purpose.
- For Legal Reasons: We may disclose information if required by law, such as in response to a court order or a lawful request by public authorities.
- During a Business Transfer: In the event of a merger, acquisition, or sale of assets, we will provide our Clients with notice before their data is transferred and becomes subject to a different privacy policy.
7. Data Security and Retention
We implement and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, security, and integrity of all personal information. These measures include data encryption in transit and at rest, role-based access controls, and regular security audits.
We retain personal data for as long as our Client's account is active or as instructed by the Client. Upon termination of a Client's contract, we will securely delete or anonymize their data in accordance with our data retention policy and the terms of our agreement with them.
8. Your Privacy Rights and How to Exercise Them
As we act as a Data Processor, individuals (parents, guardians, and staff) must contact their childcare provider (the Data Controller) to exercise their privacy rights. These rights may include:
- Access and Review Information.
- Correct Inaccurate Information.
- Delete Information.
- Withdraw Consent.
Upon request from our Client, we will provide reasonable assistance to help them respond to these data subject requests.
9. Information We Collect and Process as a Data Controller
When a representative of a childcare provider contacts us, registers for an account, or visits our marketing website (Tinypaths.com), we act as a Data Controller. In this capacity, we may collect:
- Business Contact Information: Name, job title, email, phone number, and childcare center details.
- Billing Information: Payment details for subscription services.
- Technical and Usage Data: IP address, browser type, and information about how you interact with our marketing website, collected via cookies and similar technologies.
We use this information for our legitimate business interests, such as marketing our Service, managing Client accounts, processing payments, and improving our website.
10. State-Specific Privacy Notices
A. For Washington Residents:
The My Health, My Data Act (MHMDA) provides specific rights regarding "Consumer Health Data." Our Clients are the "regulated entities" responsible for obtaining the necessary consents to collect and share this data through our platform.
B. For California Residents:
The California Consumer Privacy Act (CCPA) provides specific rights. For children under 16, our Clients are responsible for obtaining the required opt-in consent before any personal information is sold or shared. We do not sell or share the data our Clients entrust to us.
C. For Colorado and Virginia Residents:
The Colorado Privacy Act (CPA) and Virginia Consumer Data Protection Act (VCDPA) classify personal data from a known child as "sensitive data," which requires consent to process. Our Clients are responsible for obtaining this consent in accordance with COPPA.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify our Clients of any material changes by posting the new policy on this page, updating the "Last Updated" date, and providing a more prominent notice (such as by email).
12. Contact Us
If you are a parent, guardian, or staff member with questions about your data, please contact your childcare provider.
If you are a Client or have questions about our practices as a SaaS provider, please contact us through our contact page.