Privacy Policy
How Scanvale LLC collects, uses, and protects information in Tendroll™, including information about children entrusted to child care programs.
The short version
- Child care programs control the records they keep in Tendroll. We process them only on the program’s behalf.
- We never sell personal information and never use children’s data for ads or AI training.
- No advertising cookies or trackers in the app.
- Parents can ask their program to review, correct, or delete a child’s records.
- Data is encrypted and isolated per program, and deleted after an account closes.
1. Who we are and scope
This Privacy Policy explains how Scanvale LLC (“we,” “us”), which owns and operates Tendroll™, collects, uses, shares, and protects personal information. It covers our websites, web and mobile applications, and related services (the “Service”).
Two roles. We act in two different capacities:
- As a service provider / processor for child care programs (“Providers”). When a Provider uses Tendroll to record information about children, families, and staff, the Provider controls that information and decides how it is used. We process it only on the Provider’s behalf under our Terms and Data Processing Addendum. If you are a parent or guardian with questions about a child’s records, please contact your Provider first; we will help them respond.
- As a business / controller for information about website visitors, prospective customers, and Provider account administrators (for example, billing contacts).
2. Information we collect
Information Providers and their users enter
- Child information: name, date of birth, classroom or group, attendance and check-in/check-out times, daily health check observations, incident reports, allergies or care notes the Provider chooses to record, and authorized-pickup lists.
- Parent and guardian information: name, email, phone number, relationship to child, and messages exchanged with the Provider.
- Staff information: name, role, contact details, shift and attendance records, and bulletin board posts.
- Organization information: program name, address, license type, and settings.
Account and billing information
Administrator name, email, phone, and billing details. Card numbers are collected and stored by our payment processor, not by us; we receive only limited details such as card type, last four digits, and expiration date.
Information collected automatically
Device and log data (IP address, browser type, operating system, pages viewed, timestamps, and error reports) needed to operate, secure, and troubleshoot the Service. We use strictly necessary cookies and local storage for sign-in and preferences. We do not use third-party advertising cookies or cross-site tracking on the Service, and we do not use any tracking technologies inside the application where child data is displayed.
Information you send us
Support requests, survey responses, and communications with us.
3. How we use information
We use personal information only to:
- provide, maintain, and secure the Service, including authentication, notifications, and messaging;
- provide customer support and respond to requests;
- process subscription payments and send administrative messages (receipts, renewal reminders, security alerts, and policy changes);
- detect, prevent, and respond to fraud, abuse, security incidents, and technical problems;
- improve the Service using de-identified or aggregated data;
- send Provider administrators product updates and marketing about Tendroll, from which they can opt out at any time (we never market to children, and never use child or family data for marketing);
- comply with law, enforce our Terms, and protect the rights, safety, and property of children, users, the public, and us.
4. Our commitments about children's data
- We never sell personal information, and never “share” it for cross-context behavioral advertising.
- We do not use child data for advertising, and do not build profiles of children for any purpose other than providing the Service to their Provider.
- Children do not use the Service directly and cannot create accounts. We do not knowingly collect personal information directly from children under 13.
- We rely on each Provider to give families required notices and obtain required consents, as described in our Terms. Where the Children’s Online Privacy Protection Act applies, a Provider may consent on a parent’s behalf only for the program’s own care and educational purposes.
- Parents may ask their Provider to review, correct, or delete their child’s information. If a parent contacts us directly, we will forward the request to the Provider and assist them.
- We do not use child data to train general-purpose artificial intelligence models.
5. How we share information
We disclose personal information only:
- Within a Provider’s account, as the Provider configures it (for example, staff can see their classroom; a parent can see only their own child’s records and messages).
- With subprocessors who help us run the Service (such as hosting, database, email and SMS delivery, and payment processing), under written contracts that require them to protect the information and use it only to provide services to us. See our DPA for the current list.
- For legal reasons, when we believe in good faith it is necessary to comply with law, a subpoena, or a court order; to report suspected child abuse or exploitation where required; or to protect the safety of any person. Where legally permitted, we will notify the affected Provider before disclosing its data.
- In a business transfer, such as a merger or acquisition, to a successor that agrees to honor this Policy for information collected under it.
- With consent or at the Provider’s direction.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, role-based access controls, row-level data isolation between Providers, least-privilege access for our personnel, and logging of administrative access. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting personal information, we will notify affected Providers without undue delay and as required by law, and will cooperate with Providers who must notify families or regulators.
7. Retention
We keep Provider data for as long as the Provider’s account is active and as the Provider directs. After an account is closed, Providers have 30 days to export their data, after which we delete or de-identify it within a further 60 days, except where law requires longer retention. Deleted data may persist in encrypted backups for a limited period until overwritten on our normal schedule. We keep billing and account records as needed for tax, accounting, and legal purposes.
8. Your rights and choices
Parents and guardians: contact your Provider to access, correct, or delete your child’s records or your own family information. You can also email us and we will route your request.
Provider administrators and website visitors: depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. To make a request, email support@tendroll.com. We will verify your request, respond within the time required by law, and not discriminate against you for exercising your rights. You may use an authorized agent where the law allows.
Marketing emails: use the unsubscribe link in any marketing email. You will still receive essential account messages.
Do Not Track / Global Privacy Control: because we do not sell or share personal information for targeted advertising, there is nothing to opt out of, but we honor Global Privacy Control signals as an opt-out where the law requires.
9. Where information is processed
We and our subprocessors store and process information in the United States. If you access the Service from outside the U.S., you understand that your information will be transferred to and processed in the U.S.
10. Changes to this Policy
We may update this Policy. For material changes, we will notify Provider administrators by email or in the Service at least 30 days before they take effect. We will not make a material change to how we use children’s data that is less protective without providing notice to Providers first, so they can obtain any required consent.
11. Contact us
Questions or requests about privacy: email Scanvale LLC at support@tendroll.com with “Privacy” in the subject line.