Effective: October 4, 2026 · Last updated: September 4, 2026

Privacy Policy

This Privacy Policy explains how RoundUp Early Childhood ("RoundUp," "we," "us," "our") collects, uses, shares, and protects information when child-care centers, their families, and their staff use our software, our website at roundupece.com, or our mobile applications (collectively, the "Service").

RoundUp is operated by RoundUp LLC, an Oregon limited liability company. We are committed to protecting child, family, and staff information with the care that early childhood education demands.

Contents

  1. Scope & roles
  2. Information we collect
  3. How we use information
  4. Legal bases for processing
  5. Child data & COPPA
  6. Sharing & service providers
  7. Cookies, tracking & analytics
  8. Information security
  9. Retention & deletion
  10. Your privacy rights
  11. Oregon, California & other state-specific notices
  12. International users
  13. Changes to this policy
  14. Contact us

1. Scope & roles

This Policy applies to information processed in connection with the Service. Two distinct relationships are covered:

2. Information we collect

2.1 Center accounts (directors, owners, staff)

2.2 Family accounts (parents, guardians, authorized contacts)

2.3 Child records

2.4 Operational data

2.5 Records imported from a center’s previous software

When a center moves to RoundUp from another child-care system — Procare, Brightwheel, Lillio, or any product that exports a spreadsheet — a center administrator can import the roster they exported from it. That import can carry a child’s name and date of birth, classroom, allergies, and guardian contact details: the same information the center already held in that system. Importing sends no email to families and creates no family accounts; inviting families stays a separate, deliberate step. Children already on the center’s roster are matched rather than duplicated, and an import never overwrites information a center has already entered here.

Centers that operate inside a school district can also link the district’s roster through Clever or ClassLink, which brings children’s records in from the district automatically. Section 6.1 describes exactly what that link receives.

2.6 Website & marketing

3. How we use information

We use the information described above only for the following purposes:

What we do not do. We do not sell, rent, or trade personal information. We do not use child data, family data, or staff data for advertising, profiling, or any third-party marketing. We do not use any data we hold to train artificial-intelligence models. We do not share information with data brokers.

Where applicable law requires us to identify a legal basis for processing personal information, we rely on the following:

5. Child data & COPPA

We treat child records with extra care.

6. Sharing & service providers

We share personal information only with vendors who help us operate the Service. Each vendor may use the data only as we instruct, except where the table notes that your center holds its own direct relationship with that vendor. Where a written data-processing agreement is not yet in place with a vendor, that is noted in the table below rather than implied away.

VendorPurposeData shared
Amazon Web Services (us-west-2)Cloud hosting and storageAll Service data, encrypted
StripePayment processingTokenized payment methods and transaction metadata
Microsoft 365Business email and document storageCustomer-support correspondence we send and receive
Checkr, Inc.Staff background checks required by child-care licensingStaff name, work email, and work state, sent to start the check. The staff member enters sensitive details — such as Social Security number and date of birth — directly into Checkr’s own hosted flow, and that information never reaches our servers. Checkr returns the status of the check and a link to its report; we do not receive the report’s contents. Staff data only — no child or family information is ever sent to Checkr. Your center connects its own Checkr account and contracts with Checkr directly, so Checkr acts under your center’s agreement with it, and anything you provide to Checkr is also covered by Checkr’s own privacy policy
AWS Bedrock (us-west-2)The Service’s AI features — lesson plans, development summaries, newsletters, search and translationThe text of each request, which can include a child’s age, allergies, developmental milestones and behavior-incident notes. Children’s names are replaced with placeholders before the request is sent, and the request is refused outright if that replacement cannot be verified. Your child’s information is never used to train any AI model
SentryError monitoringApplication crash reports — personal identifiers are removed before transmission
New RelicMobile app performance monitoringInteraction traces, network timings, device and app version. Collected only under the same opt-in as above
PlausiblePrivacy-first analytics on our website (not the app)Aggregate visit data only, no cookies, no personal identifiers
CalendlyDemo schedulingInformation you enter directly into the demo-booking form
Mailchimp (or equivalent)Newsletter deliveryEmail addresses of newsletter subscribers
Auth0 (an Okta company)Optional staff single sign-on, for a center that connects its own Auth0 tenant — staff sign-in only, never parents or childrenStaff sign-in identity only (work email, name, and account identifier), and only for centers whose director connects their own Auth0 tenant. During sign-in, the center’s Auth0 tenant asserts the staff member’s identity to us; we never create accounts from it, and the person must already hold an invited, active staff account at that center. The tenant and its credentials belong to your center, so your center’s own agreement with Auth0 governs Auth0’s processing. No child or family information is ever sent to Auth0.

6.1 Integrations your center chooses to connect

Everything above is part of running RoundUp. The integrations below are different: each is off until a director at your center connects an account, and each sends data only while it stays connected. In every case the account belongs to your center, not to us — so that provider handles the data under your center’s own agreement with it, alongside this Policy. A director can disconnect any of them at any time, which stops all further sharing. Staff background checks (Checkr) work the same way and are described in the table above.

IntegrationPurposeData shared
Intuit QuickBooks, Xero, SageAccounting and payroll exportFamily name and billing email as a customer record, plus invoice amounts and tuition periods. QuickBooks Staff & Time additionally exchanges staff names, work emails, and worked hours — staff only
Gusto, Square Payroll, Rippling, and other payroll and HR systems connected through Merge’s unified HR serviceStaff payroll, HR records, and timekeepingStaff only — never a child or a family. Staff names, work emails, employment status and time-off, and verified worked hours pushed back as timesheets. No pay amounts are read or written
Mailchimp (including its Mandrill service)Center newsletters and family announcementsParent name and email, and tags such as classroom or enrollment status. Phone numbers are deliberately excluded from this sync
DocuSign, Dropbox SignElectronic signatures on enrollment packets, tuition contracts, and consent formsThe signer’s name and email, and the document itself — which can name a child, because enrollment documents do
Canva, Adobe ExpressDesign tools for center newsletters, flyers, and classroom handoutsThe staff account that connects the tool and the designs staff create in it. A design carries whatever staff put into it, so a photo a staff member adds to a flyer is shared with that tool
Okta, Auth0, JumpCloud, Microsoft Entra ID, Google Workspace, or any other provider supporting OpenID ConnectStaff single sign-on, and optional automatic creation and deactivation of staff accountsStaff identity only — never a parent, never a child. During sign-in the provider sends us a signed token carrying the staff member’s email, name and identifier; where a center turns on provisioning, the provider also sends the staff list it manages. The provider is your center’s own, and we hold no account with it
Slack, Microsoft TeamsPosting operational alerts into a channel your center’s team already watchesThe center’s name, a classroom name, and how many children and staff are in that room — or that an incident was logged and in which room. Never a child’s name, never a staff member’s name, and never what happened. The connection is one-way: we post into the channel and can read nothing from the workspace
Google Calendar, Outlook, Apple CalendarPublishing the center calendar so staff and families can subscribe to itEvent titles, times, and locations from the center calendar — for example “Picture day” or “Closed for Labor Day”. No child, family, or staff information. Anyone subscribing receives the calendar through their own provider, and a center calendar link can be reset at any time to cut off everyone holding an old one
Clever, ClassLinkFor programs run inside a school district: staff sign-in with the district account they already have, and automatic roster syncThis is the one integration that brings children’s records in rather than sending them out. When a center links its district, we receive the roster the district shares — children’s names together with details such as date of birth, grade, and class membership, plus staff names, work emails, and roles — and create or update the matching records here. We send Clever or ClassLink only a sign-in request and our own application credentials, never a child’s information. The district controls its own student records, and the link can be removed by a center director at any time
Verizon ThingSpaceClassroom environment sensors, where a center has installed themSensor device identifiers and their readings. No personal information

We may share information when legally required (subpoena, court order, or mandated reporting). Where law allows, we will notify the affected center before disclosing data so the center can take action.

We may share information in connection with a corporate transaction, such as a merger, acquisition, or sale of substantially all our assets. The acquiring party must commit to protections at least as strong as those in this Policy. We will notify you in advance of any such change of control.

7. Cookies, tracking & analytics

We use the smallest possible set of website mechanisms to operate the site.

We do not use Google Analytics, Meta Pixel, advertising trackers, or any cross-site tracking technology.

8. Information security

No system can be made perfectly secure. We work continuously to keep ours as secure as we can.

9. Retention & deletion

While a center is an active subscriber, we retain the data the center needs to run the Service.

When a center cancels:

Marketing data — including newsletter email addresses — is retained until the subscriber unsubscribes or asks us to delete it.

10. Your privacy rights

Depending on your jurisdiction, you may have rights to:

To exercise any right, contact us using the details in Section 14. We will respond within 30 days, or sooner where the law requires. We will not retaliate against any person who exercises a privacy right.

If you are a parent or legal guardian and you want to review, correct, or delete information we hold about your child, please contact your child's center first. The center is the controller of those records and is best positioned to coordinate the request. We will assist the center in fulfilling it.

11. Oregon, California & other state-specific notices

Oregon residents

The Oregon Consumer Privacy Act (effective July 1, 2024) gives Oregon residents specific rights to access, correct, delete, and obtain a copy of personal data, and to opt out of profiling and the sale of personal data. RoundUp does not sell personal data and does not engage in profiling that produces legal or similarly significant effects. To exercise any other right, contact privacy@roundupece.com.

California residents

The California Consumer Privacy Act (CCPA), as amended by the CPRA, gives California residents rights to know, delete, correct, and opt out of the sale or sharing of personal information. RoundUp does not sell personal information and does not share it for cross-context behavioral advertising. We do not knowingly sell or share personal information of consumers under the age of 16.

California residents may exercise their rights by contacting privacy@roundupece.com. We do not discriminate against consumers for exercising any CCPA right.

Other states

Residents of Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws may exercise rights granted to them under their state's law by contacting us at the email above.

12. International users

RoundUp is provided from the United States. Information you provide is processed and stored in the United States, primarily in the AWS us-west-2 region (Oregon). If you are accessing the Service from outside the United States, please be aware that your information will be transferred to and processed in the United States, where data-protection law may differ from that of your country.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of the Service after the effective date of an updated Policy constitutes acceptance of that update.

14. Contact us

For privacy questions, complaints, or rights requests:

If you do not receive a satisfactory response, you may contact your local data-protection authority.