Privacy Policy
How BrightBadge collects, uses and protects information
Effective: September 29, 2026
This Privacy Policy explains what information BrightBadge collects, how we use and share it, how long we keep it, and the choices you have.
1. Who we are
BrightBadge is a check-in, attendance and enrollment platform for child care programs. It is operated by RNA Executive Solutions LLC, a New York limited liability company ("BrightBadge," "we," "us"). Mailing address: 1883 West Royal Hunte Drive, Cedar City, UT 84720, USA. Privacy questions: privacy@bright-badge.com.
This policy covers our websites (including bright-badge.com), our mobile apps, the kiosk and QR check-in tools, and our emails and notifications (together, the "Service").
2. Two roles: when we decide, and when your child care program decides
BrightBadge is used by child care programs (daycares, preschools, after-school programs and similar), which we call "Programs". Programs use it to manage the families, children, staff and authorized pick-up persons they serve.
- When your Program decides (we act as its service provider or processor). Information about children and families that a Program collects through BrightBadge belongs to the Program. This includes child profiles, health and allergy details, guardians and pick-up persons, sign-in and sign-out records, enrollment packets and signed forms. The Program decides what to collect, who can see it and how long it must be kept. We process it only on the Program's behalf and under our agreement with the Program. If you are a parent, guardian or pick-up person, your Program's own privacy practices also apply, and some requests about this information must be handled by your Program (see section 9).
- When we decide (we act as controller). We are responsible for the information we collect for our own purposes. This includes account and login details, billing for Program owners, website and app usage and security data, support messages, and the stored signature you choose to save with us.
3. Information we collect
a. Account information (all users). Name, email address, phone number, password (stored only in hashed form), role (Program owner, staff, parent or guardian, or authorized pick-up), language preference, and the Programs you are linked to.
b. Information about children, entered by adults. Children never use BrightBadge and never create accounts. A parent, guardian or Program staff member may enter a child's name, date of birth, photo (if the Program uses photos), classroom, schedule, allergies, medical conditions, medications, dietary needs, doctor and emergency information, custody or pick-up restrictions, and notes the Program needs to provide care.
c. Parents, guardians and emergency contacts. Names, relationship to the child, contact details, address, and emergency and secondary contacts.
d. Authorized pick-up persons. When a parent or Program adds someone who may collect a child, we store that person's name, phone number or email, relationship, any expiration date of the authorization, a pick-up code, and (if they have their own account) their QR code. If you add a pick-up person, please tell them you are sharing their details with the Program through BrightBadge and point them to this policy.
e. Sign-in and sign-out records. The date, time, child, the adult who dropped off or picked up, the staff member or kiosk that recorded it, and the signature applied to the record.
f. Signatures.
- Signature on screen: when you sign in or out on a device, we record the image of your signature with the record.
- Stored signature (optional): you can choose to save a signature in your account. You then authorize each Program where you are listed to apply it to your sign-in and sign-out records whenever your own BrightBadge QR code is scanned. We record your consent with the exact consent wording, its version, the date and time, and how you gave it. You can replace or withdraw your stored signature at any time in your account. After that, you sign on screen instead. Records that were already signed keep their signature, because they are the Program's custody records.
- Enrollment and consent forms: when you complete a Program's enrollment packet or consent form, we store the signed form, your signature, and the date and time of signing.
g. Billing information (Program owners). Plan, billing contact, billing address and invoices. Card details are collected and stored by our payment processor, Stripe. BrightBadge never receives or stores full card numbers.
h. Device, usage and security information. IP address, device type and operating system, app version, browser type, push-notification token, time zone, pages and screens used, error reports, sign-in events, and audit logs showing who viewed or changed records. We use this to run, secure and fix the Service.
i. Messages. Emails and support messages you send us, and the in-app notifications and messages sent through the Service.
4. How we use information
- To provide the Service: check-in and check-out, pick-up verification, attendance, enrollment packets and forms, notifications and account management.
- To keep children safe and records accurate, including checking that a pick-up is authorized and keeping a reliable record of who dropped off or collected a child.
- To secure the Service: authentication, rate limiting, fraud and abuse prevention, audit logs, and investigating incidents.
- To bill Program subscriptions and send receipts and account notices.
- To provide support and to diagnose and fix errors.
- To improve the Service using aggregated or de-identified information.
- To comply with law, respond to lawful requests, and enforce our Terms.
We do not sell personal information. We do not share it for cross-context behavioral or targeted advertising. We do not use children's information for advertising, marketing profiles, or to train artificial-intelligence models.
5. Who we share information with
- Your Program. Program staff can see the information needed for their role at their location. Parents and guardians can see their own family's information.
- Service providers (subprocessors). They process information only to provide their service to us, under contract (listed below).
- Legal and safety. When the law requires it, to respond to valid legal process, or to protect the safety of a child or any person.
- Business transfers. If BrightBadge is merged, acquired or sold, information may transfer to the new owner under the protections of this policy. We will give notice before it becomes subject to a different policy.
Our service providers:
- Supabase (hosted on Amazon Web Services, USA): database, login and file storage. Information involved: all Service data.
- Vercel (USA): website and app hosting, and cookieless, aggregated web analytics. Information involved: request data, IP address, pages viewed.
- Resend (USA): sending email. Information involved: name, email address, email content.
- Sentry (USA): error monitoring; on the web, session replay only after you accept cookies, with all text and form entries masked. Information involved: device and error data, masked session replay.
- Stripe (USA): payment processing and the billing portal. Information involved: billing contact and payment details.
- Expo, Apple Push Notification service, Google Firebase Cloud Messaging: delivering push notifications. Information involved: device push token, notification content.
- Upstash (USA): rate limiting to protect against abuse. Information involved: IP address, request counts.
- Cloudflare (USA): routing email sent to our @bright-badge.com addresses. Information involved: sender address, message content.
- Google Fonts: web fonts (we host fonts ourselves where possible; where we don't, Google receives your IP address when fonts load). Information involved: IP address, browser type.
Stripe, Apple and Google also process some information under their own privacy policies, for example for fraud prevention and device services. We will update this list before we add a new subprocessor that handles child or family information.
6. Where information is stored
Information is stored and processed in the United States.
7. How long we keep information
- Account and contact details: while your account is open. If you ask us to delete your account, it is closed and these details are removed within 30 days (see section 9).
- Stored signature: until you replace or withdraw it, or your account is deleted. Records that were already signed keep their signature.
- Sign-in and sign-out records, with the signatures on them: for the retention period the Program sets, counted from the date of each record, and then deleted. The default is 6 years; the minimum is 5 years.
- Signed enrollment and consent forms, with their signatures: for the Program's retention period after the latest of the signing, the last change to the enrollment, and the child's last sign-in or sign-out, and then deleted.
- Enrollment applications that were declined, withdrawn or expired: contact details are removed about 90 days after the application closes. A minimal record that the application existed is kept.
- A Program's data after the Program closes a site: the site can be restored for 30 days, and after that it can no longer be restored. Its sign-in and sign-out records and signed forms are kept on the schedule above and then deleted; the Program can email privacy@bright-badge.com for copies. Other information from a closed site is deleted when the Program asks us at privacy@bright-badge.com.
- Billing and tax records: as long as tax and accounting law requires (generally up to 7 years).
- Security, server and error logs: as long as our hosting and monitoring providers keep them, generally no longer than 90 days.
- Backups: deleted information may remain in encrypted backups, kept on our hosting provider's backup schedule (up to 30 days), until they are overwritten.
Each Program sets its own retention period (default 6 years, minimum 5 years). A Program can turn on a legal hold, which pauses all deletion of its records until it is turned off. We email the Program at least 30 days before any of its records are deleted, so it can download copies, lengthen the period or turn on a legal hold, and we send a receipt after the deletion.
8. How we protect information
Information is encrypted in transit (TLS). It is stored on SOC 2-audited hosting infrastructure that encrypts data at rest. Access to child and family information is limited by role and by Program location. Access and changes are logged. Security measures include rate limiting, least-privilege administrative access, and regular review of our providers.
We maintain a written information-security program with administrative, technical and physical safeguards, as required by New York's SHIELD Act (N.Y. Gen. Bus. Law § 899-bb).
If there is a data breach. If we discover a breach of security that affects your personal information, we will notify you and the affected Program. We will also notify regulators where the law requires, within the time the law requires, and in any event without unreasonable delay. Where a Program is the controller, we notify the Program promptly so it can meet its own obligations to families.
No system is perfectly secure, and we can't guarantee that information will never be accessed without authorization.
9. Your choices and rights
Depending on where you live, you may have the right to:
- access your information and receive a copy,
- correct it,
- delete it,
- receive it in a portable format,
- withdraw consent, including to your stored signature, and
- appeal our decision on your request.
We do not discriminate against anyone for using these rights.
How to make a request. Email privacy@bright-badge.com from the address on your account, or use Delete my account in the app or on your dashboard. We may need to verify your identity before acting. We respond within 45 days, or sooner if the law requires. If we deny a request, you can appeal by replying to our response with "Appeal" in the subject line.
Requests about child and family records. Your Program controls children's records, sign-in and sign-out logs, and enrollment and consent forms. For example, the Program decides whether a child's record can be changed or deleted, and how long its records are kept (see section 7). We will send your request to the Program, or ask you to contact it directly, and we help the Program respond. You can always ask us for a copy of your own records.
What deleting your account does. When you delete your account, we close it and remove your login and contact details, and your stored signature. Records that your child care program must keep (sign-in and sign-out logs, signed enrollment and consent forms, and attendance) are kept on the schedule in section 7 and then deleted. Those records belong to your Program and are not deleted when an individual account is closed. To get copies, email privacy@bright-badge.com. Program owner accounts hold a Program's sites and subscription, so they are closed through support rather than in the app.
Notifications. You can turn off push notifications in your device settings. Some account and safety notices can't be turned off while you have an account.
10. Children's privacy
BrightBadge is intended for adults: Program staff, parents and guardians, and authorized pick-up persons. It is not directed to children, and children do not create accounts or use the Service. We do not knowingly collect personal information directly from children under 13. For that reason the Children's Online Privacy Protection Act (COPPA), which governs information collected online from children, does not apply to how BrightBadge is used.
Information about children is provided by their parents, guardians or Program. It is used only to provide child care services through the Service, and is protected as described in this policy. If we learn that a child has given us personal information directly, we will delete it. Parents and guardians can review or correct their child's information in the app, or through their Program.
11. Health information
Allergy, medical, medication and similar health details are entered so the Program can care for the child safely. Only authorized Program staff at the child's location, and the child's own parents or guardians, can see them. BrightBadge is not a health care provider and is not a "covered entity" under HIPAA.
12. Cookies and similar technologies
- Essential: cookies and local storage that keep you signed in, remember your language, secure your session and record your cookie choice. The Service can't work without them.
- Analytics: Vercel Web Analytics measures page visits in aggregate, without cookies, and without following you across other websites.
- Error diagnostics (optional): with your consent through our cookie banner, Sentry may record a masked replay of some web sessions, and of sessions where an error happens, to help us find and fix problems. All text and form entries are hidden, and images are blocked. You can change your choice at any time from the cookie banner or your browser settings.
We don't use advertising cookies or cross-site tracking. Because we don't sell personal information or share it for advertising, there is nothing further to opt out of, and a Global Privacy Control signal from your browser is already honored.
13. Other websites
The Service may link to websites we don't control. Their privacy policies apply to them.
14. Changes to this policy
We may update this policy. If we make a material change, we will notify you in the Service or by email before it takes effect, and update the effective date above.
15. Contact
RNA Executive Solutions LLC (BrightBadge)
1883 West Royal Hunte Drive, Cedar City, UT 84720, USA
Privacy: privacy@bright-badge.com · Legal: legal@bright-badge.com · Billing: billing@bright-badge.com
Protecting families, one check-in at a time.
© 2026 BrightBadge, a service of RNA Executive Solutions LLC. Secure attendance tracking for childcare.