1. Who We Are
Service name: Little Steps
Operator: Ahmed Saad
Contact email: ahmed.saad.kader@gmail.com
2. Who This Service Is For
Little Steps is designed for use by childcare centers, schools, administrators, teachers, staff members, and other authorized adults. The Service is not intended for direct use by children. However, the Service may process information about children when that information is entered and managed by authorized adult users for childcare administration purposes.
3. Information We Collect
Depending on how the Service is configured, which features are enabled, and how the Service is used, we may collect the following categories of information:
A. Account and authentication information
- Name, user ID, workspace membership, and role or permission data
- Email address and phone number
- Login credentials such as password data submitted during sign-in
- Authentication-related information such as session tokens
- If you choose Google sign-in, your Google account email address, display name, given name, family name, and a Google ID token used to authenticate you with our backend
- Authentication identifiers related to Google sign-in or phone-based sign-in
- Little Steps currently uses Google sign-in only for basic identity and authentication. It does not request Google Drive, Gmail, Calendar, Contacts, or other Google service data through this flow
B. Childcare and family management information
- Family records such as display name, language preference, and notes
- Guardian information such as full name, phone number, email address, and preferred contact method
- Child records such as first name, last name, preferred name, date of birth, enrollment dates, classroom assignment, status, and internal codes
- Sensitive childcare-related notes entered by authorized users, such as medical notes and allergy notes
C. Daily operations information
- Attendance records including check-in, check-out, status, classroom, and dates
- Daily report information including report date, summary text, meals, activities, and mood
- Teacher and staff records including contact details, role, and classroom assignments
- Messages, reminders, announcements, or other communications sent through the Service
D. Files, photos, and uploaded content
- Photos, documents, attachments, and other files uploaded to the Service
- Metadata about uploaded files such as file name, type, size, and timestamps
E. Payment and billing information
- Billing records, invoices, invoice line items, due dates, and payment status
- Payment transaction records including payment method (cash, bank transfer, or wallet), amount, receipt number, and custom reference notes
- Payment proof files uploaded by authorized users (e.g. bank transfer receipts)
- Payments are recorded manually by authorized staff; no third-party payment processor is integrated at this time
F. Device and permissions data
- Camera and photo library access data if you choose to use photo upload features — these are user-initiated and not collected in the background
- Device metadata including device model, operating system version, app version, and build number, used to identify your device for API communication and push notification delivery
G. Notifications data
- Firebase Cloud Messaging (FCM) device tokens used to deliver push notifications to your device
- Device tokens are stored on our servers alongside your platform (Android or iOS) and app surface (staff or parent), and are retained while your account is active
- Records of notification delivery status, delivery attempts, and read timestamps
H. Activity and audit information
- A full audit trail of actions performed within the Service, including which user performed an action, what was changed, and when — this applies to records such as children, families, attendance, classrooms, billing, and communications
- This audit log is retained to support operational integrity, dispute resolution, and accountability within your organization
I. Technical and usage information
- IP address and network request metadata
- Error logs, security logs, and operational diagnostics
- Local app data needed to keep users signed in securely, stored in encrypted secure storage on your device
- Real-time connection state maintained via WebSocket for live updates to notifications and communications
4. How We Collect Information
We collect information:
- Directly from you or your organization when you create accounts, sign in, or enter records into the Service
- Directly from Google when you intentionally choose Google sign-in
- Automatically when the Service communicates with our servers for authentication, security, and core functionality
- From workspace administrators when they create or manage user accounts, classrooms, families, or child records
5. How We Use Information
We use information to:
- Provide the Service and its core features
- Authenticate users with password or Google sign-in and maintain secure sessions
- Verify Google identity tokens with our backend and prefill available onboarding details when a user chooses Google sign-in
- Manage childcare operations such as attendance, classrooms, families, child records, and daily reports
- Enforce user roles, permissions, and workspace access controls
- Support communications, notifications, reminders, and family or staff engagement features
- Deliver push notifications to your device via Firebase Cloud Messaging
- Process billing records and related financial operations
- Support file uploads and document management via cloud file storage
- Maintain a comprehensive audit trail of actions for organizational accountability
- Maintain, secure, troubleshoot, and improve the Service
- Comply with legal obligations and respond to lawful requests
We do not use child or family information for advertising. We do not use third-party analytics or crash reporting services.
6. Local Storage on Your Device
The Little Steps app stores authentication session information locally on the device using secure storage so that users can remain signed in between sessions. The app may also use local preferences, cached state, or temporary files needed for normal operation.
7. How We Share Information
We do not sell personal information.
We may share information only in the following circumstances:
- With your childcare center, school, workspace, or organization and its authorized users
- With service providers that help us host, secure, maintain, or support the Service
- With authentication providers such as Google when you intentionally choose a third-party sign-in method
- With analytics, communications, notification, storage, authentication, or payment providers that process information for the purposes described in this policy
- If required by law, regulation, legal process, or a valid governmental request
- In connection with a merger, acquisition, or sale of all or part of our business, subject to appropriate safeguards
We require service providers to handle personal information only as needed to provide services to us and in a manner consistent with applicable law.
8. Third-Party Services
Little Steps relies on the following third-party providers for infrastructure and support functions:
- Google Sign-In (Google) — used when you choose Google sign-in. Google processes the sign-in flow under its own privacy policy and service terms. Little Steps receives the account data and Google ID token needed for authentication and onboarding. This flow does not request Google Drive, Gmail, Calendar, Contacts, or other Google service data.
- Firebase Cloud Messaging (Google) — used to deliver push notifications to your device. Your FCM device token is transmitted to Google's servers to route notifications. Firebase Analytics and crash reporting are disabled and not used.
- Amazon Web Services (AWS S3) — used for cloud file storage. Uploaded files, photos, and documents are stored in AWS S3. File metadata (name, type, size, timestamps) is stored in our database.
- Cloud hosting and database providers — our backend servers and database run on third-party cloud infrastructure. All data stored in the Service resides on these servers.
We do not integrate third-party analytics platforms, advertising networks, or crash reporting services. We do not authorize any third-party provider to use your personal information for their own marketing purposes.
9. Children's Information
Little Steps is not directed to children as end users. Any information about children is intended to be provided and managed by authorized adult users, such as childcare staff or guardians, for legitimate childcare administration purposes.
If you believe child information has been submitted to the Service unlawfully or without proper authorization, contact us at ahmed.saad.kader@gmail.com.
10. Data Retention
We retain information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain business and security records. Retention periods may vary depending on the type of data and applicable legal requirements.
11. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including access controls, authenticated sessions, role-based permissions, and secure storage of session data on user devices. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.
12. Deletion Requests
You may request deletion of your account information or other personal data by contacting us at ahmed.saad.kader@gmail.com, subject to any legal or operational obligations that require retention of certain information.
If your information is controlled by a childcare center or workspace administrator, we may direct your request to that organization for handling.
13. International Transfers
Your information may be processed in countries other than the one in which you live, depending on where we or our service providers operate. Where required, we will take appropriate steps to protect personal information transferred across borders.
14. Your Rights and Choices
Depending on your location and applicable law, you or your organization may have rights to request access to, correction of, deletion of, or restriction of certain personal information. To make a privacy request, contact us at ahmed.saad.kader@gmail.com.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and take other steps as required by law.
16. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact:
Ahmed Saad
ahmed.saad.kader@gmail.com