Skip to content

Now onboarding the first beta cohort — every state welcome

Join the list →
ArkCare — the arkArkCare
ProductPricingReadiness checkDownloadLog in
Join the beta
Menu
ProductPricingReadiness checkDownloadLog inJoin the beta →

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains how Red Standard LLC (“Red Standard,” “we,” “us,” or “our”) handles personal information through the ArkCare website, beta program, accounts, desktop application, and related support (together, the “Service”).

ArkCare is built for authorized adult personnel at licensed childcare programs. It is not a child-directed service and does not offer a child account, parent app, or parent portal. Providers may operate one or more locations in any U.S. state and enter records about the children, families, staff, and locations they manage.

1. Our two data roles

Adult website, beta, account, billing, and support information

Red Standard decides why and how this information is processed to run ArkCare. To the extent applicable privacy law uses these terms, Red Standard acts as the controller or business for this information.

Records entered by a provider

We call these operational records “Provider Records.” The licensed provider decides why they are kept, what is entered, who may access them, and how long they must be retained. To the extent applicable law uses these terms, the provider acts as the controller or business and Red Standard acts as its processor or service provider. We process Provider Records to provide, sync, secure, troubleshoot, and support ArkCare; follow the provider’s documented instructions; and meet applicable legal obligations.

2. Information ArkCare handles

The categories below reflect ArkCare’s current website and application schema.

Children’s records

  • identity and enrollment details, including name, date of birth, program, and other provider-entered profile details;
  • attendance, absences, check-in and check-out times, attendance notes, and pickup details;
  • health information, including immunization status, allergies, medical conditions, physical-exam information, dental information when the provider chooses to keep it, and lead-screening dates;
  • medication-administration records and related notes;
  • illness, injury, and other incident records and parent-notification details;
  • emergency-contact names, relationships, and phone numbers; and
  • uploaded physical and dental PDFs associated with supported fields.

Staff records

  • name, role, location or room assignments, and current or historical addresses;
  • training dates, hours, and credential information;
  • CPR and first-aid dates and supporting PDFs; and
  • clearance records, including state child-abuse-registry, fingerprint, sex-offender- registry, and other background-check dates, status information, and uploaded PDFs where a provider uses those fields. New York providers may know these as SCR, fingerprint, and SOR records; other states use their own systems and names.

Parents and guardians

Contact information entered by the provider, including name, phone number, email address, and address where the provider uses the available address fields.

Business, beta, account, and billing information

  • location and program information, including business name, address, operating hours, license information, jurisdiction, rooms, capacity, safety-drill records, and program settings;
  • beta-lead information: email address, optional name, provider type, U.S. state, and the form source that shows where the request was submitted;
  • account information handled through Supabase Auth, including email address, password credentials, user identifier, and authentication tokens. Passwords are handled by Supabase Auth and are not stored as plaintext in ArkCare’s application database; and
  • when paid billing is active, plan, subscription status, Stripe customer and subscription identifiers, billing interval, and transaction status. Stripe receives payment-card details; Red Standard does not store full payment card numbers on its servers.

Website and security information

  • necessary account cookies named ac_access and ac_refresh. They are HttpOnly, Secure, and SameSite=Lax; the access cookie lasts up to one hour and the refresh cookie up to 30 days unless cleared earlier;
  • the web signup flow’s Supabase session in browser localStorage, created by the Supabase client library so signup can continue to checkout;
  • email address, recipient name when available, and receipt, invite, welcome, support, or administrative message content sent through Cloudflare Email or Google Workspace;
  • when Cloudflare KV rate limiting is active, a salted SHA-256 hash ofCF-Connecting-IP and an attempt count for a 15-minute window. The raw IP address is not stored in that KV rate-limit key; and
  • standard Cloudflare edge and security data, which may include IP address, request time, requested URL, browser or device information, routing data, and security events.

Information we do not collect through the current Service

ArkCare does not ask for Social Security numbers, store full payment card numbers on Red Standard servers, collect precise geolocation, use advertising identifiers, run advertising pixels, or run product-analytics trackers.

3. Where the information comes from

We receive information:

  • directly from adult users who join the beta, create accounts, subscribe, or contact us;
  • from providers and their authorized personnel when they enter, upload, or generate records in ArkCare;
  • automatically from the browser, device, Supabase Auth session, Cloudflare edge, and security tools needed to deliver and protect the Service; and
  • from Stripe about subscription and transaction status when paid billing is active.

4. Local and cloud storage

ArkCare is offline-first, not device-only. Provider Records live in a local SQLite database on the provider’s device. When online, they sync through PowerSync to the provider’s tenant-isolated data in Supabase Postgres. Supported uploaded files sync to private Supabase Storage. PowerSync may process the records needed to synchronize authorized devices with Supabase.

Because local and cloud copies both exist, removing a cloud account or ending a subscription does not erase a device. The provider controls its device and must use the app’s wipe function, remove the application data, or securely erase the device when a local copy should no longer remain.

5. How we use information

We use information to:

  • provide accounts, local operation, synchronization, storage, reports, and support;
  • receive beta requests, issue and claim invites, administer access, and send receipts, invites, and welcome messages;
  • authenticate users, maintain sessions, prevent abuse, protect tenant isolation, and respond to security events;
  • process subscriptions, confirm billing status, and provide account-management access;
  • troubleshoot errors and maintain the Service;
  • respond to support, privacy, and legal requests; and
  • comply with law, enforce our Terms, and establish or defend legal claims.

We do not use Provider Records to advertise to children, families, staff, or providers, or to build marketing profiles about them.

6. Service providers and other disclosures

We disclose information only as needed for the Service, on the provider’s instructions, or for the legal and security purposes described here. A vendor receives only the information relevant to the work it performs.

  • Supabase provides authentication, Postgres database hosting, and private file storage. It receives account information, authentication data, cloud-synced Provider Records, subscription records, and uploaded files as applicable.
  • PowerSync (JourneyApps) synchronizes Provider Records between the local SQLite database and Supabase and processes the data and sync metadata needed to do so.
  • Cloudflare provides Pages, Functions, Email, KV, CDN, routing, and security services. It processes website requests, edge/security data, rate-limit hashes, beta and claim requests passing through Functions, and transactional email content as applicable.
  • Stripe, when paid billing is active, processes checkout, payment-card, subscription, invoice, and billing-portal information. We receive billing identifiers and status rather than full payment card numbers.
  • Google Workspace receives messages and attachments sent tohello@arkcare.app and our replies.

We may also disclose information when reasonably necessary to comply with law or valid legal process; protect a person, the Service, or another provider; investigate fraud or a security incident; enforce our agreements; or complete a merger, financing, acquisition, reorganization, or sale subject to applicable privacy obligations.

7. No ads, analytics trackers, data sales, or marketing list

ArkCare does not run ads or product-analytics trackers. We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share personal information of anyone under 16. We do not maintain a marketing mailing list from beta requests or accounts.

We send only transactional or administrative email needed for the relationship, such as a beta receipt, invite, welcome message, security or account notice, billing notice, response to a support request, or notice of a material legal-term change.

8. Cookies, browser storage, and privacy signals

ArkCare uses the necessary cookies and browser storage described in Section 2 to create and protect accounts and continue signup or checkout. We do not use them for advertising or analytics. You can clear browser storage or cookies, but doing so may sign you out or interrupt account and checkout flows.

Because ArkCare does not sell or share data for behavioral advertising or use targeted-ad tracking, browser Do Not Track and Global Privacy Control signals do not change the site’s behavior. There is no sale, sharing, or targeted-ad processing to opt out of.

9. Children’s information, health fields, and staff records

ArkCare is not directed to children. Children do not create ArkCare accounts or submit their own information. There is no parent app. Authorized adult providers enter records about children as part of operating a licensed program. If you believe a child has directly submitted information to ArkCare, contact us so we can review and take appropriate action.

Providers are responsible for the legal authority, notices, and permissions required for children’s, parent or guardian, and staff information. Red Standard processes those records for the provider and acts on the provider’s documented instructions. This role description does not state that any particular child-privacy statute applies or does not apply in every circumstance.

ArkCare includes health fields because childcare recordkeeping can require them. Red Standard does not represent that ArkCare is a HIPAA-compliant service and does not offer a HIPAA business associate agreement. Providers should not use ArkCare where a law or contract requires safeguards or agreements the Service does not offer.

10. Retention, deletion, and portability

We do not apply one national retention period to childcare records. Providers are responsible for the retention rules in every jurisdiction where they operate. We retain adult beta, account, billing, support, and security information only as long as reasonably needed for the purposes described in this Policy, to maintain transaction and security records, resolve disputes, and meet legal obligations. We do not promise a fixed number of days where none exists in the product or our current operations.

ArkCare does not currently provide an account-deletion API, a parent or staff export portal, or a comprehensive portability export. Available reports and inspection documents are operational records, not a complete export of every database field.

In-app deletion generally sets an is_deleted marker so synced legal records are not immediately destroyed. A local database remains on the provider’s device until the provider wipes the app or device data. Ending access does not erase that local copy. For cloud Provider Records, Red Standard acts on the provider’s documented return or deletion instruction using available administrative processes and as required by applicable law; we may retain information where law permits or requires it. We do not promise an automatic cloud-purge deadline.

11. Security and breach notice

ArkCare uses controls that include tenant-scoped row-level access policies in Supabase, private file storage with signed access links, HttpOnly website account cookies, salted rate-limit keys when KV rate limiting is active, and a site without advertising or analytics scripts. Provider devices hold local copies, so providers must secure their devices, operating-system accounts, passwords, and authorized users.

No system is completely secure. We do not claim a certified security program. Medical information and a username or email address paired with password credentials can qualify as “private information” under breach-notification law. If we learn of unauthorized access to covered information, we will investigate and provide notice to affected people, providers, regulators, or others as required by applicable law, including New York General Business Law sections 899-aa and 899-bb when they apply.

12. Privacy choices and requests

Requests about your adult website, beta, account, billing, or support information

Depending on where you live and whether a law applies, you may have rights to request access to, correction of, or deletion of personal information Red Standard controls about you, and to receive a portable copy where required and technically available. You may also have the right not to be discriminated against for making a request.

Send a request to hello@arkcare.app. Describe the request and the email address tied to ArkCare. We may need to verify your identity and authority. If we deny a request, you may reply with “Privacy appeal” and explain why you believe the decision should be reconsidered. We will review the appeal where applicable. Legal exceptions may allow or require us to keep certain information.

Requests about records entered by a provider

A child, parent or guardian, staff member, or other person seeking access, correction, deletion, or a copy of a provider’s operational records should contact the licensed provider that collected and controls those records. ArkCare does not provide a direct parent or staff portal for these requests. We will assist and act on that provider’s documented instructions as required by our agreement and applicable law.

13. Changes to this Policy

We may update this Policy as the Service or law changes. We will post the updated Policy and change the “Last updated” date. For a material change, we will also provide reasonable advance notice by email, through the Service, or both, unless an urgent legal or security reason requires faster action.

14. Contact

Privacy questions and requests may be sent to Red Standard LLC athello@arkcare.app.

ArkCare

Built to carry what you carry.

Product

Join the betaPricingReadiness checkDownloadLog inManage subscription

Legal

Terms of servicePrivacy policy

ArkCare

ArkCare, by Red Standard — so child care providers can spend less time proving the care and more time giving it.

© 2026 Red Standard LLC