Skip to main content

Legal

Privacy Policy

Effective July 3, 2026 · Version 2026-07-03

This Privacy Policy explains what information LogTender handles, why we handle it, who we share it with, and the choices available to providers and guardians. We built LogTender for child care recordkeeping, so we hold ourselves to a simple standard: collect only what the attendance workflow needs, never sell personal information, and never use children's records for advertising.

1. Overview

LogTender ("we," "us," or "our") provides an attendance-recording service for single-provider child care programs (the "Service"). This policy covers the information we handle when you visit our website, create a provider account, use the app or kiosk, or contact us.

Two roles matter throughout this policy. Providers are the adults who create LogTender accounts and operate a child care program; they decide what child and guardian information is entered and how their program’s records are used. LogTender stores and processes those records on the provider’s behalf. If you are a guardian, Section 9 explains how this affects you.

2. Information You Provide

Provider account information. When you sign up we collect your email address, a password (stored only as a one-way hash), a provider PIN (also stored hashed), your first and last name, facility name, and optionally a facility address and license number. When you accept our Terms of Service at signup, we record the date, time, and document versions you accepted.

Program records. Providers enter information about the children enrolled in their program and the guardians authorized to drop them off and pick them up. Depending on what the provider enters, this can include child names and enrollment details, notes, guardian names and relationships, guardian phone numbers used for PIN-reset text messages, and guardian PINs (stored hashed).

Attendance records. When a child is checked in, checked out, or marked absent, we store the event time, how the event was entered, the name of the authorized person, and any optional signature image or note. Corrections do not overwrite the original event; they are stored as linked entries so the provider has an auditable history.

Contact messages. If you submit the contact form or email us, we keep your name, email address, and message so we can respond, along with basic technical details (such as IP address and browser information) used to prevent abuse.

3. Information Collected Automatically

When you use the Service we automatically collect limited technical information needed to operate and protect it: IP address, browser and device information, timestamps of requests, and security events such as login attempts, verification-code requests, rate-limit events, and administrative-access audit records.

We do not use third-party advertising trackers or third-party analytics services on the Service.

4. Cookies and Local Storage

We use only first-party cookies and browser storage that the Service needs to function:

  • A session cookie that keeps you signed in, and a companion cookie that protects against cross-site request forgery.
  • Short-lived cookies that carry signup and password-reset verification state while you complete those flows.
  • Browser session storage that preserves your progress if the signup page reloads.
  • On devices used for the attendance kiosk, local browser storage (IndexedDB and caches) that holds the app shell, the day’s roster, queued offline attendance events, and PIN verification metadata. Plaintext PINs are never stored in the browser.

We do not use advertising cookies, and we do not allow third parties to place tracking cookies through the Service.

5. Payment Information

When billing is enabled, subscription checkout, payment methods, invoices, and the customer billing portal are provided by Stripe. Stripe collects and processes your payment details under its own terms and privacy policy; card numbers and security codes go directly to Stripe and never touch LogTender’s servers.

LogTender stores the identifiers needed to manage your subscription — such as Stripe customer, subscription, checkout-session, and billing-event identifiers, plan and status information, and billing period dates — so we can provision access, prevent duplicate subscriptions, reconcile payment state, and assist with support.

6. How We Use Information

We use the information described above to:

  • Provide the Service: authenticate providers, run the check-in/check-out workflow, maintain rosters and program records, synchronize offline attendance, and generate requested exports.
  • Maintain record integrity: keep the immutable attendance history and audit trails that make records trustworthy.
  • Verify identity: send email verification codes at signup and for password resets, and text-message verification codes for guardian PIN resets (via Twilio Verify).
  • Manage subscriptions: provision trials, resolve entitlements, and reconcile billing state with Stripe.
  • Protect the Service: enforce rate limits, detect and prevent abuse and unauthorized access, and audit administrative actions.
  • Communicate with you: respond to support and contact messages and send important service or account notices.
  • Comply with law: meet our legal obligations and enforce our Terms of Service.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use child or attendance records for advertising or marketing of any kind. Internal service statistics reviewed by LogTender’s administrators are aggregated and contain no personally identifiable information.

7. How We Share Information

We share information only in the following circumstances:

  • Service providers. We use vendors to run the Service: Amazon Web Services (application hosting and database), Cloudflare (network routing, TLS, and security), Stripe (payments), Twilio (email and text-message verification codes), and an email delivery provider (contact-form notifications and service email). They may process information only as needed to provide their services to us.
  • Your program. Records you enter are visible to your own account. Guardians interacting with the kiosk see only what the check-in workflow requires.
  • Legal reasons. We may disclose information when required by law, subpoena, or legal process, or when reasonably necessary to protect the safety, rights, or property of users, children, LogTender, or others.
  • Business transfers. If LogTender is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction; this policy would continue to apply to it, and we would provide notice of any material change.

We never sell personal information, and we never share it with third parties for their own marketing.

8. Children’s Privacy

LogTender is designed for adult child care providers and the adult guardians they authorize. Children do not create accounts, and the Service is not directed to children; we do not knowingly collect personal information directly from children.

Information about children in the Service — names, enrollment details, and attendance history — is entered and controlled by their child care provider as part of the provider’s legally required recordkeeping. Providers are responsible for having the authority and any required consents to enter and manage that information. We process it only to provide the Service to the provider, we protect it as described in Section 11, and we never use it for advertising or sell it.

If you believe information about a child has been entered by someone without authority to do so, contact us and we will investigate.

9. If You Are a Guardian

Your child care provider — not LogTender — decides what information about you and your child is entered into the Service, who is authorized for pick-up and drop-off, and how the program’s records are used or shared. If you want to access, correct, or remove information in a provider’s program records, please contact your provider first; in most cases they can handle it directly in the product.

LogTender uses your phone number only to deliver PIN-reset verification codes you request, and your signature only as part of the attendance record. If you contact us directly, we will help where we can, but we may need to refer requests about program records to your provider, since those records belong to their program’s legally required documentation.

10. Data Retention

We retain information for as long as it is needed to provide the Service, preserve the integrity of provider records, meet legal obligations, resolve disputes, and enforce our agreements. In practice:

  • Account and program records are kept while your account is active, including through subscription lapses (a lapsed account becomes read-only, but its records are preserved so the provider’s history stays intact).
  • Attendance history is kept immutably, including corrections, because child care attendance records often carry multi-year retention requirements that vary by jurisdiction.
  • Security, rate-limit, and audit records are kept for as long as needed for the protection and integrity of the Service.
  • Verification codes and pending signup or reset records are short-lived and expire automatically.
  • Contact messages are kept as long as needed to respond and to maintain a record of the inquiry.

When an account is deleted, we delete or de-identify its information within a reasonable period, except where we must retain it for legal, audit, security, or dispute-resolution purposes, or in routine backups that roll off on their own schedule. Because attendance records may be subject to your jurisdiction’s retention requirements, export anything your program must keep before requesting deletion.

11. Security

We use administrative and technical safeguards appropriate to the sensitivity of the information we handle, including one-way hashing for passwords and PINs (plaintext PINs are never stored on our servers or in browsers), encrypted connections (HTTPS/TLS) for data in transit, hardened session cookies, cross-site request forgery protection, rate limiting on sensitive endpoints, immutable audit records, and database-backed administrative permissions with audited access.

No storage or transmission system can be guaranteed completely secure. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.

12. Your Rights and Choices

Providers can view and update most account, child, and guardian details directly in the product, change their email, password, and PIN in account settings, export attendance records at any time, and request account deletion.

Depending on where you live, you may also have legal rights to request access to, correction of, deletion of, or a portable copy of your personal information, and the right not to be discriminated against for exercising those rights. To exercise a right that you cannot complete in the product, email us at the address in Section 15. We will verify your request (typically against your account email), respond within the time required by applicable law, and explain if a legal obligation — such as record-integrity or retention requirements — prevents us from fulfilling part of it.

Guardians should route requests about program records through their provider, as described in Section 9. Service email from LogTender is limited to account, security, and billing notices needed to run the Service; we do not send marketing email lists.

13. Where Information Is Processed

LogTender is operated from the United States, and information is stored and processed on infrastructure located in the United States. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.

14. Changes to This Policy

We may update this policy as the Service or legal requirements change. When we make a material change, we will provide reasonable advance notice — for example by email to your account address or a prominent notice in the Service — and update the effective date and version above. Non-material clarifications may be made by updating the document alone. Continued use of the Service after an update takes effect means the updated policy applies.

15. Contact

Questions, concerns, or requests about this policy or your information can be sent to [email protected]. We usually respond within two business days.