Skip to content
My Little Peas
PlatformPricing Log in Start free→

Privacy Policy#

DRAFT — pending review by licensed counsel; not yet legal advice. This Privacy Policy is a good-faith draft prepared for review by qualified legal counsel before publication. It is informational only and is not legal advice. Items marked “to be confirmed” are placeholders that must be confirmed before this policy goes live.

Effective date: Draft — not yet in effect Last updated: 2026-07-14 (draft)

Privacy at a glance#

This is a plain-language summary. The full policy below governs.

In plain terms: We help childcare programs run their day and keep families informed — we are not in the advertising business. We do not sell your personal information, and we do not use children’s information for advertising or any other secondary commercial purpose. Your data is encrypted in transit and at rest and stored in the United States. Access is role-based. You can ask to see, correct, or delete your information. Your childcare program controls most of your child’s records, so for some requests we may work together with your program.

On this page#

  1. Notice and Status of This Policy
  2. Who We Are and How to Contact Us
  3. Personal Information We Collect
  4. How We Use Personal Information
  5. Children’s Personal Information (COPPA)
  6. How We Disclose Personal Information
  7. Payments
  8. Data Security
  9. Data Retention and Deletion
  10. Your Privacy Rights
  11. US State Privacy Disclosures
  12. FERPA and Student-Data Notice
  13. Cookies and Tracking
  14. Marketing Communications
  15. Data Location and International Users
  16. Accessibility
  17. Changes to This Policy
  18. Contact Us

1. Notice and Status of This Policy#

This Privacy Policy explains how My Little Peas (“My Little Peas,” “MLP,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with our childcare management platform and our marketing website at www.my-little-peas.com (collectively, the “Services”).

The Services are intended for use by adults — childcare providers (owners, directors, administrators, and staff) and the parents and guardians of enrolled children. The Services are not directed to children under 13, and we do not knowingly permit children under 13 to create accounts or submit personal information through our marketing website. Information about how we handle the personal information of children enrolled in a childcare program (which is provided to us by the program and by guardians) is described in Section 5, Children’s Personal Information (COPPA).

My Little Peas is a software provider only; it is not a licensed childcare provider, daycare, preschool, or early-childhood program. Information on this page is informational only and is not legal advice.

2. Who We Are and How to Contact Us#

My Little Peas is a US-based software platform that helps childcare programs manage daily activities, family communication, billing, enrollment, and staff and classroom operations.

Legal entity: Purple Finch LLC, a Texas limited liability company doing business as “My Little Peas” (business mailing address to be published before launch).

For privacy questions, requests, or to exercise your rights:

  • Privacy contact email: privacy@my-little-peas.com
  • Security contact email: security@my-little-peas.com
  • Accessibility contact email: accessibility@my-little-peas.com
  • Mailing address: to be confirmed before launch

Our roles. When a childcare program uses MLP to manage information about its enrolled children and families, the program generally directs how that information is used, and MLP acts as a service provider / processor on the program’s behalf. When MLP collects information directly through our marketing website or to administer our own business relationship with a subscribing program, MLP acts as a business / controller. The applicable role can affect your rights and the party you should contact first; where a request concerns data controlled by a childcare program, we may direct or refer the request to that program.

3. Personal Information We Collect#

We collect the following categories of personal information, depending on how you interact with the Services.

From childcare providers, owners, and staff (account and employment context): name, work contact details, job title or role, login credentials, role-based permissions, and log and usage data related to actions taken in the platform.

From parents and guardians: name, contact details (email, phone), relationship to the child, login credentials, communications with us, and content they submit through the Service (such as reactions to activity updates).

About enrolled children (provided by the program and by guardians): name, date of birth, room or classroom assignment, enrollment status, guardian information, and daily-care records such as meals, naps, diapering, medications administered, incidents, attendance and check-in/out, notes, and photos uploaded by staff.

Billing and transaction information (from the subscribing program’s account owner or administrator): subscription tier, billing frequency, invoices, and payment status. Card and bank details are handled by our payment processor; we do not store full payment card numbers. Creating an account and using the free tier does not require payment information.

Technical and usage information: IP address, device and browser type, log data, and limited analytics about how the Services are used. See Section 13, Cookies and Tracking.

We collect information directly from you, from the childcare program that enrolls you or your child, automatically through your use of the Services, and from service providers such as our payment processor.

Data minimization. We aim to collect only the personal information reasonably necessary to provide the Services, and we do not condition participation on the collection of more information than is reasonably necessary for the activity.

4. How We Use Personal Information#

We use personal information to:

  • Provide, operate, maintain, and secure the Services, including daily activity tracking, family communication and activity feeds, enrollment management, billing, and staff and room management;
  • Authenticate users, enforce role-based access, and verify email addresses;
  • Process subscriptions, invoices, and payments through our payment processor;
  • Communicate with you about your account, transactions, support requests, and service-related notices;
  • Send marketing communications where permitted, which you can opt out of at any time (see Section 14, Marketing Communications);
  • Maintain records, including daily-care and business records, consistent with our retention practices and a subscribing program’s instructions;
  • Detect, prevent, and respond to security incidents, fraud, and misuse; and
  • Comply with legal obligations and enforce our agreements.

Marketing limitation. We do not use personal information that we process on behalf of a childcare program — including information about children, guardians, and staff provided through a program’s account — for MLP’s own marketing. Marketing communications are limited to business contacts of subscribing or prospective programs and others who provide their information to us directly.

We do not sell personal information, and we do not use the personal information of children for targeted advertising or any secondary commercial purpose.

5. Children’s Personal Information (COPPA)#

Protecting children’s information is central to how MLP is built. The Children’s Online Privacy Protection Act (COPPA) and its implementing rule (16 C.F.R. Part 312) govern the online collection of personal information from children under 13.

MLP’s Services are used by childcare programs and by guardians (adults) to manage information about enrolled children. We do not direct our marketing website to children, and we do not knowingly collect personal information directly from children under 13 through that site.

What we process about children. Through the childcare program and guardians, we process information about enrolled children as described in Section 3, including daily-care records and photos.

Parental rights. Parents and guardians may, subject to verification and the childcare program’s involvement, review the personal information we hold about their child, request that it be corrected or deleted, and refuse to permit further collection or use of their child’s information. Because the enrolling childcare program typically controls this information, we may coordinate these requests with the program. To make a request, contact us at privacy@my-little-peas.com or contact your childcare program.

Consent. MLP processes children’s personal information as a service provider to the enrolling childcare program, on the program’s instructions. The childcare program is responsible for providing any legally required notices to parents and guardians and for obtaining any verifiable parental consent required under COPPA for the collection and use of children’s information through the Services; MLP relies on the consents the program obtains and does not use children’s information for any purpose beyond providing the Services. This allocation is documented in our Data Processing Addendum with childcare programs. (Allocation drafted on the service-provider model; counsel to confirm.)

Data minimization, retention, and security for children’s data. We collect only what is reasonably necessary, apply security safeguards, and require service providers that handle children’s data to protect it by written contract. We maintain retention practices for children’s data rather than retaining it indefinitely; see Section 9, Data Retention and Deletion.

6. How We Disclose Personal Information#

We disclose personal information only as described here:

  • To the childcare program: information about children, guardians, and staff is accessible to the enrolling childcare program and its authorized users, subject to role-based access controls.
  • To guardians and authorized users: as needed to provide activity feeds, communications, and account access.
  • To service providers and sub-processors (vendors that process data for us): vendors that help us operate the Services, such as cloud hosting, our payment processor, and email/communication tools. These vendors are bound by contract to use the data only to provide services to us, to protect it, and not to sell it or use it for their own purposes.
  • For legal and safety reasons: to comply with applicable law, legal process, or enforceable governmental request; to enforce our agreements; or to protect the rights, safety, and security of users, the public, or MLP.
  • In a business transfer: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and continued protection of personal information. Any successor will be required to honor this Privacy Policy with respect to previously collected personal information, including children’s personal information, and we will provide notice where required.

We do not sell personal information and do not share it for cross-context behavioral advertising (tracking you across sites for ads).

Subscribing and prospective programs may request our Data Processing Agreement and current sub-processor list by contacting privacy@my-little-peas.com.

7. Payments#

Subscription billing, invoices, and payment processing are handled through Stripe, our third-party payment processor. Today, payments are made by the subscribing childcare program (typically its owner or administrator) — parents and guardians do not pay through the Service. When you make a payment, your payment card or bank information is collected and processed by Stripe under its own terms and privacy policy. MLP does not store full payment card numbers. We receive limited transaction information such as billing status, invoice details, and the outcome of a payment. We rely on Stripe as the PCI-DSS payment processor and do not claim PCI certification beyond our actual scope. Please review Stripe’s privacy policy for details on its handling of your payment information.

8. Data Security#

We maintain administrative, technical, and physical safeguards designed to protect personal information. These include:

  • Encryption of data in transit and at rest;
  • Role-based access controls that limit who can view or act on information;
  • Email verification for accounts; and
  • US-based data residency in secure data centers located in the United States.

We describe only safeguards that are actually implemented. We do not currently hold, and this policy does not claim, SOC 2, HIPAA, ISO 27001, or PCI-DSS certification or any third-party security audit. Any such framework referenced elsewhere as a goal is aspirational / roadmap only and is not a current certification.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify affected parties and regulators as required by applicable breach-notification laws.

9. Data Retention and Deletion#

We retain personal information for as long as needed to provide the Services, to maintain required daily-care and business records, to comply with legal obligations, to resolve disputes, and to enforce our agreements.

How we determine retention. For as long as a childcare program’s account is active, we retain its records subject to any retention window included in its subscription tier (described at the point of purchase). Beyond that, we determine retention periods using: (a) the duration of our relationship with the subscribing program and its instructions; (b) record-keeping periods required of childcare providers or of us by applicable law (for example, childcare-licensing record rules and tax and accounting requirements for billing records); (c) whether the information is needed to resolve disputes or enforce our agreements; and (d) the time reasonably needed to purge data from backups. Children’s personal information is not retained indefinitely and is not used for any secondary purpose while retained. (Criteria-based retention drafted for counsel validation against the amended COPPA rule and state deletion rights.)

Deletion posture. MLP’s posture is explicit-deletion-only: records are not automatically deleted, and a subscribing program’s records are retained to support recordkeeping and audit needs over an extended period. When a childcare program or an authorized individual requests deletion, or upon termination, we delete or return personal information in accordance with our agreement with the program and applicable law, subject to limited copies retained for legal or backup purposes.

10. Your Privacy Rights#

Depending on where you live and applicable law, you may have rights to: access or obtain a copy of your personal information; correct inaccurate information; delete your information; obtain a portable copy; opt out of the sale or sharing of personal information and of targeted advertising and certain profiling; limit the use of sensitive personal information; and appeal a denied request. We do not discriminate against you for exercising these rights.

How to exercise your rights. Submit a request to privacy@my-little-peas.com. We will verify your request and respond within the time required by applicable law (generally within 45 days, with an extension where permitted). Where your request concerns information controlled by a childcare program, we may refer the request to that program.

Children’s data. Parents and guardians have additional rights to review, delete, and refuse further collection of a child’s personal information, as described in Section 5, Children’s Personal Information (COPPA).

Universal opt-out. Where required, we honor recognized universal opt-out mechanisms, including Global Privacy Control (GPC) signals, as an opt-out of sale/share and targeted advertising.

Authorized agents. You may use an authorized agent to submit a request where permitted by law, subject to verification.

11. US State Privacy Disclosures#

The Services are offered across the United States. Rather than limiting privacy rights by state, we extend the core rights described in Section 10 — access, correction, deletion, portability, opt-out of sale/sharing/targeted advertising, non-discrimination, and appeal of a denied request — to all US residents, regardless of whether their state has enacted a comprehensive privacy law. The disclosures below address state-specific requirements for residents of states with comprehensive privacy laws in effect as of 2026 — including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — and states adopting similar laws on a rolling basis. (State list drafted as of mid-2026; counsel to confirm applicability thresholds and effective dates.)

California#

Under the CCPA (as amended by the CPRA), California residents have rights to know/access, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, plus a right to non-discrimination and to appeal. We will provide a Notice at Collection. Because we do not sell or share personal information as defined by the CCPA, we do not currently provide a “Do Not Sell or Share My Personal Information” link; if our practices ever change, we will add one. We use sensitive personal information only as necessary to provide and secure the Services — purposes for which the right to limit does not apply under the CCPA; if that changes, we will provide a functioning “Limit the Use of My Sensitive Personal Information” choice. We do not knowingly sell or share the personal information of consumers under 16 without the required opt-in (or, for those under 13, verifiable parental consent).

Virginia-pattern states (Virginia, Colorado, Connecticut, Delaware, Indiana, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and similar)#

Residents have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, the sale of personal information, and certain profiling, along with an appeal process. We obtain opt-in consent for the processing of sensitive data, including the personal data of known children (processed in accordance with COPPA), and we honor recognized universal opt-out mechanisms, including Global Privacy Control, where required (including in Colorado, Connecticut, Texas, and other states that mandate them). Oregon residents may additionally request a list of the specific third parties to which personal data has been disclosed.

Texas. The Texas Data Privacy and Security Act applies broadly and without a revenue threshold. We do not sell personal data, including sensitive or biometric data, so no “we may sell your sensitive/biometric personal data” notice is required; if that ever changed, we would provide the required notice and choices first.

Utah, Iowa, and Florida#

Residents of Utah and Iowa have rights to access, delete, obtain a portable copy, and opt out of targeted advertising and the sale of personal data; for sensitive data, these states require notice and an opportunity to opt out rather than opt-in consent, but our practice is to apply the stricter opt-in standard nationwide. Florida’s Digital Bill of Rights applies primarily to very large platforms; to the extent it applies to us, we honor the same rights described above.

Maryland#

Maryland’s Online Data Privacy Act imposes strict data-minimization duties and prohibits the sale of sensitive data and of minors’ personal data. Our practices align: we collect only what is reasonably necessary to provide the Services (Section 3), and we do not sell personal information of any kind (Section 6).

Sensitive data and children#

We treat children’s personal information as sensitive and apply opt-in or heightened protections as required by each applicable state law. We do not sell or process children’s personal information for targeted advertising in any state.

12. FERPA and Student-Data Notice#

Most private childcare programs are not subject to the Family Educational Rights and Privacy Act (FERPA). However, if a customer is a FERPA-covered educational agency or institution, or a publicly funded pre-K or Head Start program, additional student-data-privacy obligations (including state laws such as New York Education Law 2-d and California’s SOPIPA) may apply. For those customers, MLP will, where applicable, act as a “school official” under appropriate contractual terms, limit use of student data to providing the Services, and not use student data for secondary commercial purposes, targeted advertising, or sale.

13. Cookies and Tracking#

This section serves as our Cookie Notice. Today, our marketing website is a static site that sets no advertising or analytics cookies and no third-party trackers; the application at app.my-little-peas.com uses only essential cookies (login session and security). If we later adopt analytics or other non-essential technologies, we will update this notice before doing so.

Where we use non-essential or targeting technologies, we provide a consent mechanism with granular controls and honor recognized opt-out signals, including Global Privacy Control. We apply privacy-protective defaults and do not deploy advertising or behavioral cookies before obtaining consent where consent is required. We do not place non-essential tracking on surfaces intended to reach minors without appropriate consent.

If we introduce additional cookies or trackers, we will describe their purposes, durations, and the third parties involved here, and provide preference controls, before they are deployed.

14. Marketing Communications#

If you opt in or otherwise lawfully receive marketing emails from us, every commercial email will identify MLP as the sender, include a valid physical postal address, and provide a clear way to unsubscribe. We honor opt-out requests promptly and as required by the CAN-SPAM Act. Unsubscribing from marketing email does not stop transactional or service-related messages about your account. We do not send marketing text messages without the express written consent required by applicable law.

15. Data Location and International Users#

The Services are intended for use in the United States, and we store and process personal information in secure data centers located in the United States. We represent US-only data residency only to the extent it is accurate across all sub-processors. If you access the Services from outside the United States, you understand that your information will be processed in the United States.

16. Accessibility#

We aim to conform to WCAG 2.1 Level AA. If you have trouble accessing any part of this policy or need it in an alternative format, contact accessibility@my-little-peas.com and we will help. A separate Accessibility Statement is forthcoming; until it is published, this section describes our approach. Any privacy-request form and cookie-consent banner referenced in this policy are built to be keyboard-operable, programmatically labeled, focus-visible, and free of color-only error messaging.

17. Changes to This Policy#

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate or required, provide additional notice (for example, by email or an in-product notice). We encourage you to review this policy periodically. Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy to the extent permitted by law.

Children’s data carve-out. For material changes to how we collect, use, or disclose children’s personal information, we will obtain any newly required parental consent and provide advance notice (by email or in-product notice) before applying the change to previously collected information, rather than relying on continued use as consent.

18. Contact Us#

If you have questions about this Privacy Policy or our data practices, or to exercise your privacy rights, contact us at:

Purple Finch LLC (d/b/a My Little Peas) — a Texas limited liability company

  • Privacy: privacy@my-little-peas.com
  • Security: security@my-little-peas.com
  • Accessibility: accessibility@my-little-peas.com
  • Mailing address: to be confirmed before launch

This policy is informational and is not legal advice. It is a draft pending review by licensed counsel.

Questions about this document? Contact us. This page is a working draft and is not yet in effect.

My Little Peas
PlatformPricingAboutContactTerms of ServicePrivacy PolicyCookie Notice Log in

My Little Peas is a software platform, not a licensed childcare provider. It does not satisfy childcare licensing, staff-to-child ratio, background-check, or mandatory-reporting requirements, which remain the provider’s responsibility. Information on this site is provided for general purposes and is not legal advice.

© 2026 Purple Finch LLC (d/b/a My Little Peas). All rights reserved.