Milestone

Legal

Privacy Policy

How 1001664551 Ontario Inc. handles personal information in connection with Milestone, its public website, childcare-management application, support services, and related communications.

Last updated: August 6, 2026

1. About this policy

This Privacy Policy explains how 1001664551 Ontario Inc. handles personal information in connection with Milestone, its public website, childcare-management application, support services, and related communications.

In this policy:

  • “Milestone,” the “Platform,” or the “Service” means the childcare-management software and related services operated by 1001664551 Ontario Inc.. Milestone is the current product name and may change in the future.
  • “Centre” means a childcare centre or childcare organization that subscribes to, evaluates, or uses the Service.
  • “Centre Users” means owners, administrators, employees, contractors, consultants, and other individuals authorized by a Centre to access its workspace.
  • “Centre Data” means information a Centre or its authorized users enter, upload, import, generate, or manage through the Service.
  • “Personal information” means information about an identifiable individual, as defined by applicable privacy law.

This public policy describes our general information practices. A Centre's use of the Service may also be governed by a beta agreement, subscription agreement, data-processing schedule, order form, or other written contract. Where a binding agreement provides additional or more specific requirements, that agreement governs the relationship between the Centre and 1001664551 Ontario Inc..

2. Our role and the Centre's role

Childcare centres use the Platform to manage their own operations. Each Centre determines which Centre Data it enters, why it uses that information, which authorized users may access it, and how long its operational records must be retained.

For Centre Data, the Centre is generally responsible for:

  • collecting information lawfully;
  • providing required privacy notices;
  • obtaining any consent or other legal authority required to collect, use, disclose, upload, or otherwise process the information;
  • ensuring that the information is relevant and reasonably necessary;
  • maintaining accurate and current records;
  • deciding who receives access;
  • managing custody, guardianship, consent, access, and correction questions;
  • meeting childcare, employment, tax, accounting, licensing, and other record-retention obligations; and
  • giving us lawful and authorized instructions.

We operate the Platform and process Centre Data to provide, secure, maintain, support, and improve the Service. We do not independently decide family-law, guardianship, custody, authorized-pickup, or childcare-record disputes. We act on appropriately authorized instructions from the relevant Centre unless applicable law requires otherwise.

3. Information we handle

3.1 Centre-controlled operational information

Depending on the features a Centre chooses to use, Centre Data may include:

  • children's names, preferred names, birth dates, photographs, addresses, enrollment status, attendance schedules, room assignments, program information, waitlist records, graduation or withdrawal information, and related notes;
  • family, parent, guardian, emergency-contact, authorized-pickup, and relationship information;
  • allergy, dietary, medical, medication, immunization, health, developmental, inclusion, accommodation, safety, consent, custody, and emergency information;
  • forms, submissions, uploaded records, supporting documents, and communications;
  • staff names, contact details, roles, employment information, room assignments, funding information, payroll-support records, and imported payroll amounts;
  • billing accounts, invoices, payments recorded as having been processed elsewhere, subsidies, funding information, account statements, receipts, transactions, expenses, categorizations, and financial reports;
  • room, program, capacity, scheduling, waitlist, enrollment, attendance, and operational-planning information;
  • Centre branding, settings, workflows, notes, reports, imports, and exports; and
  • support requests and feedback relating to the Centre's workspace.

The Service records payments processed through other methods or providers. Milestone does not currently process payment-card transactions directly.

3.2 Account and user information

We may collect or generate:

  • names;
  • business email addresses;
  • account and Centre memberships;
  • roles and permissions;
  • invitation records;
  • authentication and multi-factor authentication information;
  • account status;
  • security and recovery records;
  • trusted-device and session information;
  • user preferences; and
  • records of important account and administrative actions.

Passwords are not stored in readable form. They are processed using secure password-hashing mechanisms.

3.3 Technical and security information

We and our service providers may process technical information needed to operate and protect the Platform, including:

  • IP addresses;
  • browser, device, and operating-system information;
  • request dates and times;
  • authentication events;
  • security events;
  • error and diagnostic information;
  • application and infrastructure logs;
  • page and feature interactions needed for security, support, or product operation;
  • request identifiers;
  • audit records; and
  • cookie or session identifiers.

We seek to limit diagnostic information to what is reasonably necessary and to avoid including sensitive Centre Data where it is not needed.

3.4 Website, contact, and support information

When someone contacts us, requests information, reports a security concern, participates in a beta, or communicates with support, we may collect:

  • their name;
  • contact details;
  • organization and role;
  • message content;
  • attachments they choose to provide;
  • troubleshooting information;
  • correspondence history; and
  • feedback about the Service.

Do not send unnecessary child, health, payroll, financial, or other sensitive records through ordinary email or public contact forms.

4. Children's information

Milestone is a business service provided to childcare organizations and their authorized personnel. Children do not currently create their own Milestone accounts. Parents also do not currently create product accounts during the initial external beta.

Child information is entered and managed by the relevant Centre for childcare administration and related operational purposes. Parents, guardians, and other individuals seeking access to, correction of, or information about a Centre-controlled record should ordinarily contact that Centre directly.

We assist Centres with appropriate requests when required by contract or applicable law, but the Centre remains responsible for verifying identity, authority, custody or guardianship status, applicable exceptions, and legal retention obligations.

5. Information that must not be uploaded

Unless we expressly approve a purpose-built feature in writing, users must not upload or store:

  • Social Insurance Numbers;
  • complete credit- or debit-card numbers;
  • card verification values or security codes;
  • online-banking usernames, passwords, security answers, or authentication codes;
  • account passwords or unencrypted credential lists;
  • unnecessary government-issued identification numbers or copies;
  • malware, malicious code, or files intended to interfere with the Service;
  • unlawful, fraudulent, infringing, or deceptive content;
  • information the Centre or user lacks authority to collect or process; or
  • highly sensitive information that is unnecessary for the intended childcare-management function.

This restriction does not prohibit legitimate childcare records such as necessary medical, allergy, immunization, custody, consent, emergency, safety, or accommodation information where the Centre has lawful authority and an appropriate operational purpose.

Bank statements, payroll files, receipts, and transaction records may incidentally display account references. Centres should minimize or redact unnecessary account and financial identifiers before uploading files where reasonably practical.

6. How we use information

We may use personal information to:

  • provide and administer Centre workspaces;
  • authenticate users and manage accounts, invitations, memberships, roles, permissions, and MFA;
  • process authorized data imports and exports;
  • support waitlist, enrollment, child-record, family, room, program, attendance, staffing, form, billing, payroll-support, expense, reporting, and related features;
  • generate records, calculations, previews, reports, and exports requested by authorized users;
  • respond to support requests and provide onboarding or migration assistance;
  • investigate errors, service failures, and suspected misuse;
  • monitor, maintain, secure, test, and improve the Platform;
  • prevent unauthorized access, fraud, abuse, and cross-Centre data exposure;
  • create and maintain backups and recovery capabilities;
  • record security-sensitive, privacy-sensitive, and administrative actions;
  • communicate about the Service, maintenance, security, agreements, and policy changes;
  • manage subscriptions, contracts, invoices, and the business relationship;
  • investigate and respond to privacy requests, complaints, and incidents;
  • comply with legal obligations and lawful requests; and
  • establish, exercise, or defend legal rights.

Automated categorizations, forecasts, calculations, reports, imports, and suggestions may assist Centre operations but may require human review. Centres remain responsible for reviewing outputs before using them for financial, payroll, funding, compliance, safety, enrollment, or other significant decisions.

7. What we do not do

Unless we clearly disclose a different practice and obtain any authorization required by law or contract:

  • we do not sell Centre Data or personal information contained in Centre workspaces;
  • we do not use Centre-controlled child, family, employee, health, payroll, or financial information for behavioural advertising;
  • we do not permit third parties to use Centre Data for their own unrelated marketing purposes;
  • we do not use Centre-controlled content to train commercial artificial-intelligence models; and
  • we do not make custody, guardianship, childcare, medical, accounting, payroll, tax, legal, or regulatory decisions for Centres.

We may use aggregated or de-identified information that cannot reasonably identify an individual or Centre to understand service performance, improve features, plan capacity, and maintain security. We do not attempt to re-identify properly de-identified information.

8. When information may be disclosed

We may disclose or make information available:

  • to authorized Centre Users according to their Centre memberships, roles, and permissions;
  • to service providers that help us host, store, secure, monitor, back up, maintain, email, support, or otherwise provide the Service;
  • at the lawful direction of the Centre that controls the relevant Centre Data;
  • where reasonably necessary to investigate or respond to a suspected security, privacy, fraud, abuse, or service incident;
  • during a corporate transaction, financing, reorganization, merger, acquisition, sale, or insolvency process, subject to appropriate confidentiality and privacy protections;
  • to professional advisers, insurers, auditors, accountants, and legal counsel where reasonably necessary;
  • where required by applicable law, court order, warrant, subpoena, regulatory requirement, or other lawful process; or
  • where otherwise permitted or required by law.

Service providers are permitted to process information only for authorized service purposes and are expected to protect it using appropriate safeguards.

9. Hosting, service providers, and processing outside Canada

The Platform currently uses third-party infrastructure providers.

The application is hosted through Heroku in the United States. The production PostgreSQL database is hosted through Neon using an AWS US East 2 region in Ohio, United States.

As a result, personal information may be stored or processed outside Canada. While information is in another jurisdiction, it may be subject to that jurisdiction's laws and may be accessible to courts, law-enforcement agencies, national-security authorities, or regulators through lawful processes.

We remain responsible for personal information transferred to service providers for processing within the scope required by applicable law. We use contractual, technical, administrative, and organizational measures intended to require service providers to process information only for authorized purposes and to provide appropriate protection.

We may use or introduce providers for:

  • application hosting;
  • database storage;
  • transactional email;
  • backups and disaster recovery;
  • file handling;
  • security or error monitoring;
  • customer support;
  • communications; and
  • related operational infrastructure.

Specific providers may change as the Service develops. We will maintain or provide information about material subprocessors through this policy, a subprocessor list, contractual documentation, or other appropriate notice. A material change to cross-border processing or subprocessor practices will be handled in accordance with the notice section below.

10. User accounts and access controls

Every individual must use their own named account. Users must not:

  • share accounts;
  • disclose passwords;
  • allow another person to act under their identity;
  • bypass authentication or MFA requirements; or
  • retain access after authorization ends.

Centres are responsible for:

  • inviting only authorized individuals;
  • assigning appropriate roles and permissions;
  • reviewing user access;
  • promptly removing or restricting access when a person leaves or changes responsibilities; and
  • notifying us of suspected account compromise.

Privileged beta accounts may be required to use multi-factor authentication. We may suspend an account or Centre workspace where reasonably necessary to address a security, privacy, unlawful-use, or material operational risk.

11. Support access

Authorized support personnel may access information where reasonably necessary to:

  • respond to a support request;
  • complete an authorized import or migration;
  • diagnose or correct a technical problem;
  • investigate a privacy or security concern;
  • maintain service integrity; or
  • restore the Service.

Ordinary support access to identifiable Centre Data should occur with Centre authorization. In an urgent situation, we may access information without advance authorization where reasonably necessary to investigate suspected unauthorized access, contain a security incident, prevent material harm, correct cross-Centre exposure, or restore the Service.

Support access is limited to authorized personnel, should be proportionate to the issue, and may be logged or otherwise recorded for security and accountability.

12. Security safeguards

We use reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of the information processed through the Platform.

Depending on the feature and deployment, safeguards may include:

  • HTTPS encryption in transit;
  • secure password hashing;
  • authenticated access;
  • Centre-scoped data controls;
  • role-based permissions;
  • multi-factor authentication for privileged accounts;
  • session and login protections;
  • CSRF protection;
  • secure-cookie settings;
  • security headers;
  • upload validation;
  • protected administrative actions;
  • audit records for sensitive actions;
  • private source-code repositories;
  • automated testing;
  • tenant-isolation testing;
  • restricted support access;
  • logging and incident investigation;
  • backups and recovery measures once configured and verified; and
  • controlled development, deployment, and change-management practices.

Security risks and technologies evolve. We review safeguards and make reasonable updates over time. No method of transmission, storage, or online service can guarantee absolute security.

13. Privacy and security incidents

We investigate suspected unauthorized access, loss, disclosure, alteration, destruction, or misuse of personal information.

Where we confirm an incident affecting a Centre's information, we will:

  • take reasonable steps to contain and investigate it;
  • assess the nature and scope of the incident;
  • preserve appropriate evidence;
  • take reasonable mitigation and remediation steps;
  • notify the affected Centre without unreasonable delay;
  • provide material updates as additional reliable information becomes available; and
  • cooperate with the Centre regarding notifications or other steps required by applicable law.

The relevant Centre remains responsible for decisions and notifications relating to individuals whose Centre Data it controls, except where applicable law assigns a responsibility directly to us.

Security concerns may be reported using the contact information below or the security-reporting information in our security.txt file.

14. Accuracy

Centres and authorized users are responsible for maintaining accurate, complete, and current Centre Data.

The Platform may provide tools to review, update, correct, archive, delete, import, or export information. Centres should verify the accuracy of:

  • imported records;
  • child and family information;
  • room assignments;
  • attendance;
  • billing balances;
  • invoices;
  • payroll-support information;
  • expense categorizations;
  • funding calculations;
  • forecasts; and
  • reports.

We may assist with technical corrections but cannot independently confirm the factual accuracy of Centre-supplied information.

15. Retention

We retain information only for as long as reasonably necessary for the purposes described in this policy, the applicable agreement, legitimate business and security needs, and legal or regulatory obligations.

15.1 Centre Data

Centre Data may remain available while the Centre uses the Service and until it is archived, deleted, anonymized, or removed in accordance with authorized Centre actions, the applicable agreement, legal requirements, and product functionality.

Centres are responsible for identifying and meeting their own childcare, licensing, employment, payroll, tax, accounting, litigation, and other retention obligations.

15.2 Imported source files

Source files provided for data migration or import are ordinarily deleted within 30 days after successful import validation unless:

  • a longer period is reasonably required to complete or correct the import;
  • the Centre requests longer retention;
  • a dispute, security matter, or legal obligation requires retention; or
  • the applicable agreement states otherwise.

15.3 Logs, audit records, and support information

Application logs, performance logs, security logs, audit evidence, privacy records, support correspondence, and incident records may be retained for periods appropriate to their purpose, sensitivity, legal relevance, and security value.

Where an underlying personal record is permanently deleted, we may retain minimized or de-identified evidence showing that an authorized action occurred, when it occurred, the relevant Centre, the acting user, and a non-identifying reference or reason.

15.4 Business records

We may retain contracts, corporate records, invoices, payment records, support correspondence, legal records, insurance records, and security evidence where reasonably necessary to manage the business, comply with law, resolve disputes, or establish and defend legal rights.

15.5 Backups

Information may remain in encrypted or access-restricted backups until the applicable backup expires or is securely overwritten through the normal backup cycle.

Backup copies are not ordinarily restored except for disaster recovery, security response, service restoration, legal requirements, or similar operational needs. If a backup is restored, information that should no longer be active will be handled in accordance with applicable deletion and retention procedures.

16. End of service, exports, and deletion

Unless a written agreement provides otherwise, after a Centre's service ends:

  • the Centre will normally have a 30-day transition period;
  • during that period, an authorized Centre representative may request an available export without an additional export fee;
  • export formats will depend on the type of record and the formats then supported by the Platform;
  • supported exports may include CSV, XLSX, XLS where supported, PDF, DOCX, or a structured archive;
  • we do not guarantee that every item can be reproduced in the exact visual layout shown in the Platform; and
  • after the transition period, active Centre Data will be deleted or anonymized, subject to legal retention, security evidence, unresolved disputes, and backup expiration.

We may retain minimized, de-identified, contractual, billing, support, security, or legally required records after active Centre Data is removed.

Where applicable, we will provide the Centre with written confirmation after the active deletion or anonymization process is completed.

Immediate suspension or termination for a serious security, privacy, unlawful-use, or operational risk may restrict access during the normal transition period. We will still address appropriate export and deletion obligations in accordance with the applicable agreement and law.

17. Access, correction, and deletion requests

17.1 Centre-controlled records

Parents, guardians, children, employees, former employees, and other individuals should ordinarily contact the relevant childcare Centre concerning Centre-controlled information.

The Centre is responsible for:

  • verifying the requester's identity and authority;
  • evaluating custody, guardianship, consent, or access restrictions;
  • determining whether an exception applies;
  • correcting inaccurate records;
  • determining whether deletion is legally permitted; and
  • meeting applicable response requirements.

We will provide reasonable technical assistance to the Centre where required by contract or law.

17.2 Information controlled directly by us

Individuals may contact us to request access to, correction of, or information about personal information we control directly, such as account, support, business-contact, or security information.

We may need to verify identity before responding. Access may be restricted where permitted or required by law, including where disclosure would reveal another person's information, compromise security, reveal protected confidential information, or conflict with a legal obligation.

18. Cookies and similar technologies

The Service uses cookies and similar technologies that are reasonably necessary to:

  • authenticate users;
  • maintain secure sessions;
  • prevent cross-site request forgery;
  • remember authorized preferences;
  • manage trusted devices;
  • protect accounts; and
  • operate the website and application.

We do not currently use Centre-controlled personal information for behavioural advertising.

If we introduce non-essential analytics or tracking technologies that require additional notice or consent, we will update our practices and provide appropriate choices where required.

19. Communications

We may send:

  • invitations;
  • password-reset messages;
  • MFA and security codes;
  • account and service notices;
  • support communications;
  • maintenance notices;
  • privacy or security notices;
  • contractual notices; and
  • messages reasonably related to the Centre's use of the Service.

Security, legal, transactional, and service-administration communications are not promotional messages and may continue while an account or contractual relationship remains active.

20. Changes to this policy

We may update this policy as the Platform, our providers, and legal requirements change.

Ordinary software updates, bug fixes, user-interface changes, and feature improvements do not by themselves require a privacy-policy notice unless they materially change how personal information is handled.

We may:

  • post minor wording, formatting, contact, or administrative corrections without individual notice;
  • provide at least 10 days' notice for routine changes that affect information practices;
  • provide at least 30 days' notice for material changes to the collection, use, disclosure, cross-border processing, retention, or protection of personal information; and
  • make an immediate change where reasonably necessary to address a security risk, legal obligation, emergency, or threat to individuals or the Service.

Material changes will not be applied retroactively except where permitted or required by law. Where appropriate, Centres may terminate the Service before a material change takes effect, subject to their agreement.

Notice may be provided by email, in-app message, website notice, or a combination of these methods.

21. Accountability and complaints

1001664551 Ontario Inc. is accountable for the personal information under its control and designates an appropriate privacy contact to oversee privacy questions and practices.

Questions, concerns, or complaints may be submitted using the privacy contact information below.

We will:

  • review the concern;
  • request information reasonably needed to investigate;
  • coordinate with the relevant Centre where the issue concerns Centre-controlled data;
  • document the response where appropriate; and
  • communicate the outcome or next steps.

Individuals may also have the right to contact the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Ontario, or another applicable regulator. The appropriate regulator depends on the organization, information, activity, and law involved.

22. Contact us

Privacy questions and requests

Email the Milestone privacy contact at hello@milestoneapp.ca.

Security concerns

Use the security-reporting information in Milestone's security.txt file or email hello@milestoneapp.ca.

When contacting us, do not include unnecessary child, medical, payroll, financial, password, or other highly sensitive information in ordinary email.