Legal & Regulatory

Privacy Policy

Effective Date: January 1, 2026 · Last Updated: September 10, 2026
Plain Language Commitment: Child care centers, teachers, and parents deserve unambiguous information regarding how student records, allergies, and daily communications are safeguarded.

1. Who We Are

Steadyroom (“Steadyroom,” “we,” “us”) provides specialized administrative software for licensed child care centers, managing attendance, staff-to-child ratio compliance, tuition billing, staff credentials, incident logs, and family communications.

Headquartered in Pasco County / WesleyChapel, FL. Contact: [email protected].

2. The Two Roles We Play

For center data, we are a data processor, not the owner. The licensed child care center is the customer and the legal controller of its records. We process data strictly according to the center's contractual instructions.

Parents and staff: Your child care provider is your primary point of contact regarding child and employee records. For our public website visitors and account signups, Steadyroom acts as the data controller.

3. What We Collect

From centers (on the center's behalf):

  • Children: Name, birthdate, classroom, attendance, daily activity logs (meals, naps, diapering), photos, developmental assessments, allergies, medication authorizations, and emergency pickup contacts.
  • Families: Guardian contact info, custody arrangements, split billing accounts, and consent options.
  • Staff: Credentials, licensing clearances, CPR expirations, timesheets, and moment-of-clock-in location.

From website visitors:

  • Inquiry and demo form submissions, account credentials, and diagnostic session metadata.

4. Children's Privacy & COPPA

Children under 13 do not hold accounts and do not access Steadyroom directly. Information is entered exclusively by licensed center operators and verified parents or legal guardians.

We never sell children's personal information. We never use children's data for commercial advertising or behavioral profiling.

5. Background Checks and Security Gating

Background checks are performed by state regulatory authorities. Steadyroom records status, verification dates, and expirations solely to enforce database scheduling gates. We do not receive, store, or expose criminal record dossiers.

6. Location & Biometrics

  • Clock-in Location: A soft geofence checks approximate location only at the moment of clock-in. Staff locations are never monitored continuously.
  • Photos: Photos are displayed only to families with verified media consent. No facial recognition or biometric scans are performed.
  • Kiosk: Check-in uses secure numeric PINs and dynamic QR codes — no fingerprint or facial biometric data is collected.

7. Security & Data Retention

Data is protected using end-to-end TLS 1.3 encryption in transit and AES-256 encryption at rest, fortified with Postgres Row-Level Security (RLS). Center records are retained for the duration of subscription and an export period following cancellation.