Privacy Policy
1. Summary & scope
This Privacy Policy explains how KinderLink collects and handles personal information when you use our daycare and kindergarten management platform — both the mobile apps (parent and teacher) and the admin web portal at portal.kinderlink.sa.
- We collect what we need to run a daycare-to-parent communication service: names, emails, phone numbers, photos and notes from your daycare day.
- We do not sell your data, run advertising trackers, or use it for purposes unrelated to the service.
- You can delete your parent or teacher account from inside the app at any time. Daycare administrators contact support to wind down their account.
- Children's photos and information are entered by the daycare with parental consent and shown only to that child's authorised parents and assigned teachers.
2. Who we are
Data Controller for the platform itself: KinderLink, Riyadh, Kingdom of Saudi Arabia. Contact: privacy@kinderlink.sa.
Important distinction. When a daycare uses KinderLink to manage its own operations, the daycare is the controller of the records about its children, parents, and staff — KinderLink processes that data on the daycare's behalf. We are the processor for the daycare-specific records, and the controller for your account credentials and platform-wide infrastructure data (server logs, security events, billing of daycares).
3. Information we collect
The data we hold falls into the following categories:
3.1 Account & authentication
- Email address — used to log in (admin web) and to send transactional emails like account changes and invoice notifications.
- Phone number (E.164 format) — used by parents to log in via one-time-password (OTP) and to receive SMS verification codes.
- Password — for admin web sign-in. We never see or store your password in clear text; authentication is delegated to Google Firebase Authentication, which hashes and salts passwords on our behalf.
- Single-use invite codes — for teacher sign-in. The code is generated by the daycare administrator, sent to the teacher out-of-band (e.g. SMS or in person), and consumed once during first-time login.
- Display name and profile photo (optional) — visible to other people in the same daycare.
- Role and tenant assignment — whether you're a parent, teacher, daycare administrator, or KinderLink super-administrator, and which daycare's records you can see.
- Push notification tokens (Apple APNs / Firebase Cloud Messaging) — only if you opt in to push notifications. Tokens are device-specific and rotate frequently.
- Session metadata — Firebase ID-token validity, refresh-token timestamps, last-seen IP, IP-failure counters used to throttle brute-force login attempts.
3.2 Records about children (entered by your daycare)
- Name, date of birth, gender.
- Class assignment and enrolled days of the week.
- Allergies, medical notes, emergency contact details.
- Authorised pickup persons (name, relationship to child, phone).
- Profile photo (uploaded by the daycare with the parent's consent).
- Links to the child's parents and teachers (so the right people see the right diary).
This information is entered by the daycare administrator. Parents can review it through the app and ask the administrator to correct anything that's wrong.
3.3 Day-to-day activity records
- Activity entries posted by teachers — type (meal, nap, learning, outdoor, art, music, note, health, other), description, mood (happy / sad / tired / excited / calm), timestamp, and optional photos.
- Group activities — a single entry that applies to several children at once.
- Attendance — check-in / check-out timestamps, pickup-person record, absence flags.
- Extra-day requests when a parent asks for additional enrolment days outside the regular schedule.
- Calendar events visible to the daycare (closures, field trips, parent-teacher meetings).
- Newsletters and documents shared by the daycare (typically PDFs).
3.4 Messages
- Direct messages exchanged between a parent and their child's teacher(s). We store the message body, sender ID, recipient ID, timestamp, and whether the recipient has read it.
- Messages are visible only to the participants and are not used for any other purpose.
3.5 Media (photos and video clips)
- Photos uploaded by teachers (attached to activities) and by parents (profile photos).
- Optional video clips inside activity entries.
- Photo "favourites" — a parent can mark a photo as a favourite for their own account. Favourites are private to that parent.
- Files are stored on Cloudinary with access controlled by signed URLs. Direct URLs are not predictable.
3.6 Billing data (administrators only)
- Daycare invoices issued by KinderLink: amounts, billing period, currency, status, line items, VAT registration number, and PDF copies.
- For ZATCA Phase 1 compliance (Saudi e-invoicing) each tax invoice carries a TLV-encoded QR code that includes the seller name, VAT number, ISO timestamp, total amount, and VAT amount.
- Parents are not billed by KinderLink — the daycare is. Parent-facing invoices are records the daycare issues to parents through the platform, but payment happens between the parent and the daycare directly.
3.7 Automatic / technical data
- Server logs — request method, path, response status, request time, IP address, user agent. Retained briefly for security, debugging, and abuse prevention.
- Audit logs — sensitive operations (login attempts, admin actions, account deletions) recorded with the actor's UID, action, and metadata for compliance.
- Crash diagnostics — anonymous JavaScript error reports if the app crashes (no personal content, just stack traces and device model / OS version).
- The mobile apps run on Hermes; we do not embed third-party analytics, advertising, or attribution SDKs.
3.8 What we do NOT collect
- Advertising identifiers (IDFA / GAID).
- Precise location, GPS, geofences.
- Browsing history outside KinderLink.
- Health or biometric data beyond what a parent / teacher chooses to type into a note (e.g. "had a stuffy nose today").
- Payment card or bank-account details — KinderLink does not process card payments inside the app.
4. How we use information
- To provide the service — delivering daily diaries, attendance, messages, photos, calendar events, and notifications between the people inside one daycare.
- To authenticate you and keep your account secure (password / OTP / invite-code verification, refresh-token revocation, brute-force lockout).
- To send transactional notifications — push notifications you've opted into, and emails for events like a new license being issued, a tenant invoice being sent, or an email-change confirmation.
- To bill daycares — generate invoices and ZATCA-compliant tax invoices for KinderLink's subscription fees.
- To comply with law — respond to lawful requests from Saudi authorities, retain records required by tax law (ZATCA invoices), or defend legal claims.
- To investigate and prevent abuse — analyse server logs and audit trails when we suspect a security incident.
We do not use personal data to train machine-learning models, build advertising profiles, or share with data brokers.
5. Legal basis for processing
Where applicable law requires a stated legal basis, we rely on:
- Performance of a contract — to deliver the service you (or your daycare on your behalf) signed up for.
- Consent — for optional things like push notifications, profile photos, and the daycare uploading photos of children.
- Legitimate interests — security logging, abuse prevention, defending legal claims.
- Legal obligation — keeping ZATCA tax-invoice records for the period mandated by Saudi tax authorities (typically six years).
6. Sharing & subprocessors
We share data only as needed to operate the service, with the following categories of recipient:
6.1 Within your daycare
- The daycare's administrator can see all records inside their own tenant.
- Teachers see the children in classes they're assigned to and conversations with the parents of those children.
- Parents see only their own children's records and conversations with their children's teachers.
- Daycares are isolated from each other — one daycare cannot see another daycare's records.
6.2 Service providers (subprocessors)
The infrastructure that powers KinderLink is built on a small number of well-known providers. Each is bound by a written data-processing agreement and processes data on KinderLink's instructions only.
| Provider | What it does | Where it runs |
|---|---|---|
| Google Firebase | Authentication, Firestore database, Cloud Storage, Cloud Messaging (push notifications). | Google Cloud (US regions). |
| Cloudinary | Image and video storage and delivery for activity photos, profile photos, and document attachments. | AWS (US / EU regions). |
| Resend | Transactional email delivery (license onboarding, tenant invoices, email-change confirmations). | AWS (US). |
| Railway | Hosting for the KinderLink API server and webhook endpoints. | Railway-managed cloud (US / EU). |
| Cloudflare | DNS, CDN, and web hosting (admin portal + marketing site). | Global edge network. |
| SMS gateway | Sending OTP codes for parent phone-login. | Provider-dependent. |
| Apple App Store / Google Play | App distribution and (Apple) APNs push delivery. | Apple / Google. |
6.3 Legal & safety
We may disclose personal data when required by Saudi law or a valid legal process, when necessary to defend legal claims, or to protect the safety of users (for example, if we receive a credible report that a child is at risk and law enforcement requests relevant records).
6.4 What we never do
- We never sell personal data.
- We never share parent or child data with advertisers.
- We never use children's photos for marketing without explicit, separate consent from each parent.
7. Children's data
Children do not directly use KinderLink. The mobile and web apps are designed for adults — parents, teachers, and daycare administrators.
Information about a child is entered by the daycare administrator (and updated over time by the child's teachers). The daycare must obtain the parent's consent before entering the child's information into KinderLink, and before uploading any photo of the child. KinderLink, as the processor, relies on the daycare's representation that this consent has been obtained.
Each child's record is visible only to:
- Their authorised parents (the parents whose accounts are linked to the child).
- Their assigned teachers within the same daycare.
- The daycare's administrator.
Parents can request:
- A copy of all information their daycare holds about their child (contact your daycare administrator first; if they're unresponsive, email privacy@kinderlink.sa).
- Correction of inaccurate information.
- Removal of a specific photo or activity entry.
- Full deletion of the child's record when the child leaves the daycare.
8. Where your data lives
KinderLink is a Saudi-based company building for the Saudi market, but the cloud infrastructure we depend on is global. By using KinderLink you understand that personal data may be processed in Google Cloud, AWS, and Cloudflare regions outside the Kingdom of Saudi Arabia, including the United States and Europe. We rely on the standard contractual safeguards offered by these providers (data-processing agreements, encryption in transit and at rest, the EU Standard Contractual Clauses where applicable) to protect that data.
If Saudi data-residency requirements change in a way that requires the underlying infrastructure to move, we will migrate to compliant regions and update this policy.
9. Retention
How long we keep data depends on what it is:
| Category | Retention |
|---|---|
| Active account data (profile, name, email) | Kept while the account is active. |
| Activity entries, attendance, messages | Kept by the daycare for as long as the daycare's tenant is active. The daycare decides when to archive or delete operational records. |
| Photos uploaded to activities | Same as the parent activity — deleted when the activity is deleted. |
| Server logs | 30 days, then purged. |
| Audit logs (sensitive admin actions) | 365 days, then purged. |
| ZATCA tax invoices | Six years (Saudi tax-law minimum). |
| Deleted user accounts | Removed from active systems within 30 days of deletion. Backups are rotated within a further 30 days, after which any residual copies are gone. |
10. Your rights under PDPL & GDPR
Under Saudi Arabia's Personal Data Protection Law (PDPL) and equivalent regimes you have the right to:
- Access — ask what personal data we hold about you and get a copy.
- Rectification — correct data that's inaccurate or out of date.
- Erasure — delete your account and your associated data (see next section). Some records (audit logs, ZATCA invoices) are retained for the periods listed above to satisfy legal obligations.
- Restriction — ask us to stop processing your data while a complaint or correction request is under review.
- Portability — receive a machine-readable copy of the data you provided.
- Withdrawal of consent — for any processing based on consent (e.g. push notifications, profile photo). Withdrawal does not affect processing that already happened.
- Objection — object to processing based on legitimate interests; we will weigh your objection against our reasons.
- Complaint — lodge a complaint with the Saudi Data & AI Authority (SDAIA) or another competent supervisory authority.
To exercise any of these rights, email privacy@kinderlink.sa. We will respond within 30 days.
11. Deleting your account
You can permanently delete your KinderLink account from inside the app at any time:
- Parent: open the app → Manage → scroll to the bottom → Delete account.
- Teacher: open the app → Profile → scroll to the bottom → Delete account.
You will be asked to confirm twice. When you confirm, we:
- Unlink you from every child's record (the children themselves remain — they belong to the daycare, not the user).
- Revoke all active sessions on every device you've signed in from.
- Delete your profile document, profile photo, and push-notification tokens.
- Delete your authentication identity, freeing the email address for future re-registration.
- Write an audit-log entry recording that the deletion happened (with role and tenant ID, but no further personal content).
Daycare administrators cannot self-delete from the app because doing so would orphan the daycare's tenant — every parent, teacher, and child under that administrator. To wind down a daycare account, please email support@kinderlink.sa; we'll arrange the offboarding so the tenant's data is exported and deleted cleanly.
Operational records the daycare keeps about its activity (e.g. an attendance log from last March) are owned by the daycare, not by you personally; deleting your account unlinks you from those records but does not retroactively erase the daycare's history.
12. Security
- Encryption in transit. All traffic between the apps and our servers is TLS 1.2+ with HTTPS-only cookies. Mobile apps refuse plaintext connections (
NSAllowsArbitraryLoads = false). - Encryption at rest. Firestore and Cloud Storage encrypt every record with AES-256-GCM by default. Cloudinary encrypts uploaded media at rest.
- Authentication. Passwords are handled by Google Firebase Auth (industry-standard hashing). Phone OTPs are single-use and short-lived. Teacher invite codes are single-use and tenant-scoped.
- Token revocation. Signing out (or deleting your account) invalidates every existing refresh token across every device — within one ID-token lifetime, all of your sessions stop working.
- Brute-force protection. Repeated failed login attempts from the same IP trigger an exponentially increasing lockout.
- Tenant isolation. Every Firestore query is scoped by tenant ID, server-side, on every request.
- Least privilege. Production data access inside KinderLink is restricted to a small set of administrators on need-to-know, and every access is logged.
If we ever discover a breach that affects you, we will notify you (and the relevant Saudi authorities) within 72 hours of becoming aware, in line with PDPL article requirements.
13. Tracking, cookies & analytics
The KinderLink mobile apps do not contain any third-party tracking SDKs. The app's PrivacyInfo.xcprivacy manifest declares NSPrivacyTracking = false; the App Store nutrition label is "Data Not Linked to You" for diagnostics and "Data Linked to You" for the records you actively create (photos, messages, profile). We do not request permission to track via Apple's App Tracking Transparency framework because we don't track.
The admin web portal (portal.kinderlink.sa) uses a single first-party authentication cookie / token issued by Firebase Auth. It does not run analytics, ads, or third-party trackers.
14. Changes to this policy
We may update this Privacy Policy from time to time as the service evolves. When we do, we'll change the "Last updated" date at the top of this page. Material changes — anything that broadens the categories of data we collect, the purposes we use it for, or the parties we share it with — will be communicated through the app and / or by email at least 14 days before they take effect.
15. Contact
Questions about this policy or how your data is handled?
- Email: privacy@kinderlink.sa
- Support: support@kinderlink.sa
- Postal: KinderLink, Riyadh, Kingdom of Saudi Arabia.
If your concern is about your daycare's handling of records (rather than the KinderLink platform itself), please contact the daycare administrator first — they're the controller of those records. We're happy to mediate if that path is unsuccessful.
This policy was last updated on 29 April 2026. Policy version 1.0.