Privacy policy
Who you are contracting with
CareKindle is the product. CareKindle Technologies Inc. is the company behind it. Where this policy says “CareKindle”, “we” or “us”, it means CareKindle Technologies Inc., the legal entity your agency contracts with, and the one accountable for the practices described on this page.
CareKindle is scheduling, care-record, billing and compliance software for home-care agencies. This page explains, in plain language, what personal information passes through CareKindle, the role we play with respect to it, and where to go when you want something seen, corrected or deleted.
Two laws shape how we work: Ontario’s Personal Health Information Protection Act (PHIPA) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA). Our practices are designed to align with both, and because they are laws, not certifications, we say “aligned”, never “certified”.
The role we play
When a home-care agency keeps client records in CareKindle, the agency is the health information custodian (PHIPA’s term in Ontario) or the responsible organization under the comparable laws of other provinces. CareKindle acts as the agency’s service provider: we process personal health information only on the agency’s instructions and only to provide the service the agency signed up for.
We do not sell personal information, and we do not use client health records for advertising. The records an agency keeps in CareKindle belong to that agency and its clients, not to us.
For the information we collect directly (the account details of agency staff who sign up, subscription billing records, and the messages you send us), CareKindle is responsible in its own right.
What we process on an agency’s behalf
- Client records: profiles, intake details, care plans, assessments, visit notes and documents.
- Visit-verification records: GPS check-in and check-out times and locations for scheduled visits.
- Caregiver employment records: credentials and expiry dates, availability and blocked time, and timesheets built from verified visits.
- Client billing records: invoices with their tax lines, recorded payments, and insurer claims.
- Family-portal activity: which authorized family members viewed the records shared with them.
- Messages between office staff and caregivers.
We process these records to run the features the agency uses, nothing else.
What we collect for ourselves
- Account information: name, email address, role and sign-in records for agency staff and caregivers who hold CareKindle accounts.
- Subscription and billing details for the agency’s CareKindle subscription, processed by Stripe. CareKindle never charges an agency’s clients or their families.
- Support correspondence: whatever you send to hello@carekindle.com.
- Cookies: one to keep you signed in, and one that remembers your language preference (English or French). We do not use advertising or cross-site tracking cookies.
- Analytics, on by default with a real opt-out: our public website uses Google Analytics, which helps us understand which pages are useful. It runs only on this public website, never inside the CareKindle application, and we strip email addresses and other identifiers from page URLs before anything is sent. A notice on your first visit offers an Opt out button; choose it and nothing further loads, and the site works identically. The sign-in page at app.carekindle.com is different: it loads one Google Tag Manager container and only after you accept. Decline or ignore the notice there and nothing loads at all. That choice is separate from this one, because the ck-consent cookie is kept per site. Your choice is remembered for 180 days in the ck-consent cookie, and you can change it anytime by deleting that cookie.
- A session-replay tool, Lucky Orange, is set up in our tag manager but is not running: our website blocks it from loading, so no recording of your visit is made and nothing is sent to that company. We are telling you now rather than the day it starts. If we switch it on, it would record how visitors move around the public website only, under the same opt-out, and we will say so here and in the sub-processor register before it collects anything.
- Campaign context: when you arrive from a link that carries campaign tags (like utm_source), we keep those tags, the referring site’s domain, and the first page you landed on in a first-party cookie for 90 days, so that if you later contact us or sign up we know which channel brought you. It contains no name, no email, and no browsing history.
How we protect it
The safeguards below are in place today and described in full on our security page:
- Every agency’s data is isolated at the database layer, so one agency can never reach another’s.
- Sensitive actions are written to an append-only, immutable audit log.
- Chart views are logged, showing who looked at which record, and when.
- Passwords are hashed and salted, and never stored in plain text.
- Personal health information is redacted from our application logs.
- Role-based access control: six operator roles, with separate caregiver and family realms.
- All traffic is encrypted in transit (TLS).
We also publish what we have not yet earned or verified. Our certification roadmap lives on the same page.
Who else touches the data (sub-processors)
A small number of third parties help us run CareKindle. We publish the full register (who they are, what they do, and where they process data) on our security page, and we keep it current. Where a region is not yet confirmed for our live deployment, the register says “Confirming region” rather than guessing.
Today the register includes Amazon Web Services, which hosts the application, the database and encrypted document storage in Canada; Amazon SES (the transactional email that carries invitations and schedule notices, also in Canada); Stripe (agency subscription billing only); Mapbox (maps and geocoding for scheduling and visit verification); and Google (Tag Manager and Analytics), the public-website measurement described above. Lucky Orange, QuickBooks Online and Google reCAPTCHA Enterprise (automated-access protection for the sign-in forms) are listed as coming soon, and none of them receives anything today. Today’s accounting hand-off is a CSV export, which means your accounting data goes where you take it.
What stays in Canada, and what leaves it
The application, the database and encrypted document storage all run in Canada, in Amazon Web Services’ Montréal region. The transactional email that carries invitations and schedule notices is sent through Amazon SES, also in Canada. Care records live in Canada.
Three of the services we rely on are in the United States, and each receives something narrow. Stripe handles agency subscription billing and receives the agency’s own billing details, never a client record. Mapbox turns a visit’s street address into map coordinates for scheduling and visit verification, so it receives client street addresses — but no clinical content: no diagnoses, no medications, no visit notes, no care plans. Google’s Tag Manager and Analytics measure the public website and the sign-in page, and receive no client information at all.
We name this plainly because United States law can compel disclosure to that country’s authorities in ways Canadian law does not. That is why the list is short, why each entry says exactly what it receives, and why nothing clinical crosses the border.
QuickBooks Online is optional, and it is off. The software can send billing information to Intuit in the United States when an agency chooses to connect its own QuickBooks company, but that integration is not enabled on our service today: no agency can connect one, and nothing has been sent. When we do enable it, it will carry accounting records only — client billing contacts (name, billing address, email, phone and a payer note), caregiver vendor contacts or, for employees, employee records with their hire date, invoice lines (service, date, quantity, rate and amount; a cancellation fee is sent as the fixed label “Late cancellation”, never the reason for it; an expense or mileage charge is sent as the fixed label “Out-of-pocket expense” or “Mileage”, never the claim’s description; any other line carries its service name unless the agency typed or edited a description — a manual charge, a late fee or an edited line — which is sent as written) and contractor-bill lines — and never clinical records. We will list Intuit in the register as active before any data flows, not after.
Access, correction and deletion requests
If you receive care from an agency that uses CareKindle, your record belongs to your care relationship with that agency. The agency is the custodian, and requests to see, correct or delete your information go to them. That is not us passing the buck: it is how Canadian health-privacy law assigns responsibility, and it puts the decision with the people who know your care.
CareKindle gives agencies the tooling to handle those requests: a compliance centre that records privacy requests, consents, incidents and retention settings, plus a log of every chart view. If your request reaches us directly, we will refer it to your agency and tell you we did.
If you hold a CareKindle account (agency staff or caregiver), write to hello@carekindle.com about your account information and we will handle it ourselves.
Retention
Retention of client records is directed by the agency, which carries the record-keeping obligations of a custodian under provincial law. CareKindle provides retention settings the agency administers from its compliance centre.
We keep our own records (accounts, subscription and billing history, support correspondence) for as long as we need them to run the service and meet our legal and accounting obligations.
Changes to this policy
When this policy changes, the date at the top changes with it. For material changes we will notify agency account owners. Every revision is dated, and nothing gets rewritten quietly.
Questions
Write to us at hello@carekindle.com. Privacy officers and procurement teams will find the detailed safeguards statement, the certification roadmap and the sub-processor register on our security page.