Privacy Policy
1. About this policy
This Privacy Policy explains how Nickel Apps ("we," "us," "our") handles personal information in connection with the Buzzer application and service (the "Service"). It should be read together with our Terms of Service. We handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Newfoundland and Labrador privacy requirements.
2. Our role: controller vs. processor
Most personal information in Buzzer — including children's information, participant records, and staff details — is entered and controlled by the organization that uses the Service (the "Organization"). The Organization is the controller of that information, and we act as a processor on its behalf, handling it only to provide and support the Service.
If you are a parent or guardian with questions about a child's information — or you want to access, correct, or delete it — please contact the program or organization your child attends. They control that information; we will support them in responding.
We act as a controller only for limited information we collect directly, such as the account details of the person who registers an Organization, billing-related records for paid plans, and communications you send us.
3. Information in the Service
Depending on how an Organization configures and uses Buzzer, the Service may store:
- Account information — names, emails, and login credentials of Organization staff and administrators. Authentication is handled by Firebase Authentication with email verification; we do not store account passwords ourselves.
- Participant information — children's names, attendance, emergency contacts, custom fields, and records the Organization enters, which may include allergy, health, medication, and incident details.
- Parent / guardian contact information — such as email addresses, used to send the notifications an Organization configures.
- Logs and content — daily, incident, and medication logs, schedules, praise, transport and supply entries, and custom form submissions, timestamped and attributed to a named staff member.
- Billing information (paid plans only) — handled by Stripe; we receive limited records such as subscription status and the last digits and type of card, not full card numbers.
- Technical information — limited data needed to operate and secure the Service, such as device or browser information and basic usage and security logs.
4. Sensitive and children's information
Buzzer is used by programs serving children, so it may hold sensitive information including health, allergy, and medication details. The Organization is responsible for obtaining the consents required, including parental or guardian consent. We handle this information with care, restrict access to it, apply the security measures below, and use it only to provide the Service.
5. How information is used
Information processed through the Service is used to: provide, operate, maintain, and support the Service; send notifications (such as parent emails and staff schedules) the Organization configures; process payments and manage subscriptions for paid plans (through Stripe); secure the Service and maintain audit trails; and comply with legal obligations.
We may also create aggregated, de-identified information that does not identify any individual, child, family, or Organization, and use it to improve the Service. We do not attempt to re-identify it, and we do not use identifiable children's information to develop or train product features. We never sell personal information, and we do not use it for third-party advertising.
6. Where data is stored
The Service is hosted on Google Firebase / Google Cloud infrastructure, and Organization Data is stored in Canada. Keeping data in Canada is a deliberate choice that supports compliance with PIPEDA and provincial privacy requirements. Some supporting services (such as email delivery and, for paid plans, payment processing) may process limited data outside Canada; where that happens, we use reputable providers bound by appropriate safeguards, as listed next.
7. Service providers (sub-processors)
We use a small number of trusted providers, which process information only as needed to perform services for us:
- Google (Firebase / Google Cloud) — hosting, database, authentication, and backups. Organization Data is stored in Canada.
- Resend — delivery of transactional and notification emails (such as parent notifications and staff schedules); processes the recipient email address and message content needed to send the email.
- Stripe (paid plans only) — payment processing and subscription billing; handles payment-card data directly.
We plan to add SMS-based two-factor authentication for Admin and Owner accounts after the pilot. If we do, an SMS provider (expected to be delivered through Firebase) will process the relevant phone numbers for that purpose, and we will update this policy. If we add or change sub-processors, we will update this list and, where the change is material, notify Organizations.
8. Security
We take reasonable technical and organizational measures to protect personal information, including Firebase Authentication with enforced email verification, encryption in transit, role-based access so staff see only their assigned sites and groups, audit trails attributing actions to named users, and continuous automated backups. No system is perfectly secure, but we work to safeguard the information in our care and limit access to it.
Breach response. If we become aware of a breach of security safeguards involving personal information, we will provide written notification to affected Organizations within 24 to 48 hours of confirming the breach, and we will support the relevant breach-reporting obligations under PIPEDA. As controllers, Organizations are responsible for any notifications they must make to affected individuals, parents, or guardians.
9. Data retention and deletion
We retain Organization Data while the account is active and as needed to provide the Service. When an Organization closes its account or requests deletion, we will delete the Organization Data within 30 days, except for information we must keep by law (such as limited billing records) or that remains briefly in routine encrypted backups before being overwritten. Organizations can export their data in CSV or PDF before deletion.
10. Access, correction, and other rights
Individuals have rights under Canadian privacy law, including to access and correct their personal information and to withdraw consent. Because Organizations control most information in Buzzer, parents, guardians, staff, and others should direct access, correction, and deletion requests to the Organization that holds their information; we will assist the Organization in responding. For information we control directly (such as account-holder or billing details), you may contact us at nick@buzzerteam.com.
11. Children
Buzzer is a tool for organizations, not a service that children sign up for or use directly. Children's information is entered by Organization staff under the Organization's responsibility and with the consents the Organization is required to obtain. We do not knowingly collect information directly from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify Organizations by email or through the Service. The "Last updated" date at the top shows when it was last revised.
13. Contact
If you have a privacy concern we have not resolved, you may also contact the Office of the Privacy Commissioner of Canada.