Back to home

Privacy Policy

Effective May 21, 2026

Today's Kidz Simple Sign In Tax ("Simple Sign In Tax", "we", "us") is operated by Today's Kidz Childcare Center. We help licensed US childcare providers organize their tax documents, track CACFP (Child and Adult Care Food Program) reimbursements, and produce TurboTax-ready reports. This Privacy Policy explains what we collect, why we collect it, and what rights you have over your data.

1. Who this policy applies to

This policy applies to anyone who creates an account, uploads documents, or pays for a subscription on todayskidztax.com. If you are visiting the public landing page only and have not registered, the only data we may collect about you is standard server access logs (IP address, browser type, request time) for security and abuse prevention.

2. What we collect

  • Account information: your name, email address, center name, US state, entity type (LLC / sole proprietor / etc.), and whether you participate in CACFP.
  • Tax documents: the bank statements, receipts, payroll records, CACFP reports, vehicle logs, and equipment receipts you upload. These contain personally identifiable financial information by their nature.
  • Generated tax data: the line-item transactions extracted from your uploads, your CACFP allocation percentages, your Schedule C summaries, your equipment depreciation schedules.
  • Payment information: we use Square as our payment processor. Card numbers are entered directly into Square's hosted checkout and are never stored on our servers. We retain only Square's payment confirmation IDs, the amount paid, and which tax year was activated.
  • Usage data: pages uploaded, number of transactions processed, login timestamps, IP addresses, and coarse geolocation derived from IP (state / country level only). This is used for trial-abuse prevention, security alerts, and aggregate metrics.
  • Email communication: we use Resend to send transactional emails (verification codes, password resets, renewal reminders, accountant exports). We retain a log of when each email was sent and to what address.

3. Why we collect it

  • To provide the core service: categorizing your tax documents and producing reports.
  • To enforce paid subscriptions and prevent abuse of the free trial (one trial per email per filing year).
  • To send you the notifications you've signed up for: renewal reminders, year-end checklist nudges, password reset codes.
  • To detect suspicious account behavior (e.g., a single account being accessed from many countries within hours).
  • To comply with US tax law record-retention guidance (we retain your tax-year data for 7 years from filing — the IRS audit window).

4. Who we share with (third parties)

We use a small number of third-party services to run the app. Each is a contractual data-processor — they handle data on our behalf and do not own it. They are:

  • Square — payment processing. Receives only billing email, transaction amount, and Square's internal IDs.
  • Resend — transactional email delivery. Receives your email address and the message body.
  • Cloudflare R2 — encrypted object storage for your uploaded source files (bank statements, receipts). Files are not indexed or read by Cloudflare; they sit in a bucket only our application server can access.
  • Google Gemini (via Emergent) — used to extract text from uploaded PDFs and images so we can categorize transactions. Per Google's Gemini API terms, your file contents are NOT used to train any model. CSV and Excel files do NOT pass through Gemini at all.
  • Sentry — application error monitoring. Captures error stack traces; we have configured Sentry to NOT capture user-input fields, request bodies, or auth tokens.
  • MongoDB Atlas / Emergent-hosted DB — encrypted-at-rest database for your account information, transactions, and metadata.
  • ipinfo.io — IP-to-coarse-geolocation lookup (state/country only) for trial-abuse prevention and security alerts.

We do not sell your data, share it with advertisers, or use it for any marketing purpose beyond emailing you the notifications you've subscribed to.

5. Your rights (CCPA / general data rights)

You have the following rights at any time:

  • Access: request a copy of all data we have on you. Use the "Export my data" button in Settings — we'll send you a ZIP archive of your account data, transactions, and uploaded files within 30 days.
  • Correction: edit your account details, transactions, and uploads at any time directly in the app.
  • Deletion: request account deletion. Use the "Delete my account" button in Settings. We honor a 7-day grace period during which you can restore. After 7 days your account and all associated tax data are permanently deleted.
  • Opt out of marketing: we do not run marketing campaigns; however, you can disable renewal reminders in Settings.
  • Non-discrimination: we will not deny service, charge a different price, or provide a different level of service if you exercise any of these rights.

If you are a California resident, the rights above are guaranteed under the California Consumer Privacy Act (CCPA). For all other US states, equivalent rights apply where state law requires.

6. Children's privacy

This service is for childcare-business operators (adults). It is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

7. Security

All traffic is encrypted in transit (HTTPS / TLS 1.2+). Passwords are stored hashed using bcrypt with per-user salt — we never store or see your plaintext password. Your uploaded source files are stored encrypted at rest in Cloudflare R2. Our database is encrypted at rest. We enforce HTTP security headers (HSTS, CSP, X-Frame-Options) on every response.

No system is 100% secure. If we ever experience a data breach that affects you, we will notify you by email within 72 hours of confirming the breach, in accordance with applicable state-law breach-notification requirements.

8. Data retention

While your account is active, we retain your data as long as you keep using it. When you delete your account, we permanently delete your transactions, uploads, CACFP records, and account profile within 7 days of confirmation. We may retain certain records longer ONLY if required by law (e.g., payment-related records for 7 years per IRS guidance).

9. Cookies

We use only first-party cookies necessary for authentication (your login session). We do not use third-party advertising cookies, analytics cookies, or cross-site tracking.

10. Changes to this policy

If we make material changes to this policy, we will email all active users at least 30 days before the changes take effect. The latest version always lives at this URL.

11. Contact us

For privacy questions, data requests, or to report a concern, email admin@todayskidzsimplesignin.com.

This Privacy Policy is provided as a reasonable starting point for a US-based SaaS handling tax records. It is not legal advice. We recommend you have it reviewed by an attorney before relying on it for compliance with specific state or federal frameworks.