Privacy Policy
Last updated:
Seahorse provides child-care administration software for organizations, centres, educators and families. This policy explains how personal information is handled through the Seahorse website, App UI, parent portal and companion mobile apps. It also covers information provided when requesting access or contacting us.
Your child-care organization manages the records it enters into Seahorse. Start with your centre for questions about your family's records, permissions or communication preferences. Seahorse supports the organization in responding to privacy requests.
1. Who is responsible for your information
The child-care organization using Seahorse determines why it collects child, family and staff records, who may access them, and how long it must keep them. Seahorse processes those records to provide the service on the organization's instructions. The organization's own privacy notice also applies to its child-care operations.
Seahorse is responsible for information it handles for its own account administration, access requests, support and service security. The privacy law that applies depends on the organization, activity and jurisdiction, including Alberta's Personal Information Protection Act and Canada's Personal Information Protection and Electronic Documents Act where applicable.
2. Information we handle
The information available depends on the features your organization uses. It may include:
- Account and contact details: names, roles, organization and centre assignments, email addresses, telephone numbers, addresses, account credentials and access requests.
- Child and family records: dates of birth, guardians and authorized contacts, enrolment, room and group assignments, attendance, allergies and care information, permissions, forms, developmental questionnaires, observations, photos and documents.
- Staff records: educator profiles, qualifications, certificates, room assignments, attendance and recorded work or care activities.
- Billing records: plans, invoices, receipts, balances and billing contacts. Any payment service enabled by your organization has its own handling of payment details.
- Communications: messages, attachments, recipients, delivery information, consent records and communication preferences.
- Technical and activity information: IP addresses, browser and device information, sign-in events, timestamps, security logs and recorded actions needed to operate and troubleshoot the service.
Information comes from you, your organization, authorized family contacts and integrations that your organization configures, such as its enrolment or customer relationship system. Please provide only information relevant to the service and that you are authorized to share.
3. How information is used
We use information to provide accounts and authorized access; manage child-care records, planning, attendance and billing; deliver messages and forms; produce reports; respond to support and privacy requests; and maintain service reliability and security. Organizations may use records to meet their child-care, employment, tax and other legal obligations.
Collection, use and disclosure must have an appropriate purpose and consent or another lawful authority where required. Accepting the Terms of Service does not replace consent required for optional messaging, photos or another use of personal information.
4. Children's information and permissions
Seahorse is intended for authorized adults, rather than for children to create accounts or use directly. Child records are provided by organizations and authorized adults. Organizations are responsible for obtaining parent or guardian authorization where required, respecting custody and access restrictions, and limiting information to what is needed.
Photos, developmental information and health or care details may be sensitive. Access and sharing should follow the child's permissions and the organization's policies. Contact your centre to discuss consent, who may receive updates, or an incorrect record.
6. Optional AI features
Where enabled, AI features can use a prompt and relevant records or conversation context to generate drafts, summaries or suggestions. That content is sent to the AI service configured for the deployment, which may include Amazon Bedrock or, in demo environments, OpenRouter and its model providers.
Your organization should confirm the configured provider, data handling and required permissions before using personal information with an AI feature. Do not submit real child, family or staff information to a demo environment. Authorized staff must review AI output before relying on it or sharing it.
7. Browser storage and device permissions
Seahorse uses cookies, local storage and session storage for functions such as authentication, session management, preferences and draft recovery. Sign-in activity is recorded to help monitor and troubleshoot access. The public legal pages do not require an account or load analytics scripts.
Camera, microphone or photo-library access may be requested when you choose a feature that needs it, such as capturing or uploading an attachment. You can manage permissions in your device or browser settings. Refusing a permission limits the associated feature. Clearing browser storage may sign you out or remove locally saved drafts.
8. Retention and safeguards
Records are retained according to the organization's instructions, service arrangements and applicable legal requirements. Different requirements can apply to attendance, staff, financial, consent and other records. Ending access or withdrawing an optional consent does not automatically erase records that must be retained. Backup copies may remain until the applicable backup cycle expires.
We use access controls, authentication, secure transport in production and activity records to help protect information. Your organization must also manage user permissions and devices, protect credentials and verify recipients. No storage or transmission method provides absolute security. Suspected incidents should be reported promptly; notification obligations are assessed under applicable law.
9. Your choices and requests
You may request access to or correction of your personal information, ask about its use or disclosure, and withdraw consent for optional uses, subject to applicable law. Requests to delete information are assessed against legal retention duties and the organization's authority over its records. We may need to verify your identity or your authority to act for a child before a request can be fulfilled.
For child, family or staff records, contact your centre or organization privacy contact first. Seahorse will assist the organization with requests relating to the service. If a concern remains unresolved, you may contact the privacy regulator with jurisdiction, such as the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.
Text-message participation is optional. Reply STOP to unsubscribe from messages on the sending number, or contact your centre to change your preferences. Reply HELP for assistance. See the messaging terms for details. Withdrawing messaging consent does not remove existing child-care records.
10. Policy changes
We may update this policy as the service or legal requirements change. The date above identifies the current revision. Material changes will be brought to the affected organization's attention and, where appropriate, to affected users. Additional consent will be sought when required for a new use of information.
11. Privacy questions
Contact your centre or organization administrator for record requests and privacy questions. Ask them to direct service-related questions to the Seahorse privacy contact, including requests for information about service providers or processing outside Canada. Use the contact already provided by your organization; do not send sensitive child records through an unsecured message.