Security and privacy

Where your records are, and who can see them

KeepCount holds records about children, staff and providers. This page says plainly where they are kept, which services touch them, how they are protected, and how you get them back. The privacy notice is the formal version.

Where the data is

In Canada. The database, sign-in and file storage run on Supabase in its Canada (Central) region. A few services outside Canada handle limited information so that email can be sent and cards can be charged; they are listed below with exactly what each receives.

ServiceWhat it doesWhat it receives
SupabaseDatabase, sign-in, file storage. Canada (Central) region.Everything in your account.
CloudflareDelivers the website and the app; the Turnstile check on public forms.Your browser’s requests for pages and files. No account data is stored there.
ResendSends the reminder, summary and sign-up emails. United States.The recipient’s address and name, the organization’s name and the titles of outstanding items.
StripeCard payments, invoices and receipts. United States.The organization’s billing name, address, email and HST number, and the card, which KeepCount never sees.
Google WorkspaceThe [email protected] mailbox.Whatever you write to us.
YouTubePlays a training video only where an organization has embedded one, in privacy-enhanced mode.That a video was watched from your device, not who you are.

Information processed outside Canada may be accessible to the courts and authorities of that country under its laws. No information is sold, shared for advertising or used to train anything. There are no analytics trackers on the site or in the app.

How it is protected

Encryption
Everything travels over TLS and is encrypted at rest by the database provider. On top of that, children’s names, pick-up notes and incident narratives are encrypted inside the database with a key the application holds, so a database export on its own does not reveal them.
Who sees a child’s name
Staff see a first name and an initial ("Amara R."); administrators see the full name. Each organization sees only its own records; the database enforces this on every table, not the screen.
Sign-in
Passwords of at least twelve characters that are not obvious ones. A second step (an authenticator app) for administrators, required when the organization turns it on. Sign-in attempts are rate-limited and locked after repeated failures.
Who looked
Every view, print, export or download of a person’s record is logged with who did it and when. GATS support can open an organization only through a support session that the organization’s own activity log records, for eight hours at a time, with a second sign-in step.
Files
Uploaded documents live in private storage and are served through links that expire in ten minutes. The only public bucket holds organizations’ logos.
The browser
A strict content security policy: scripts and fonts come from KeepCount itself, with Cloudflare Turnstile on public forms and YouTube’s player only where a training video is embedded. Nothing else runs on the page.
Payments
Cards are entered on Stripe’s pages, never on KeepCount’s. KeepCount stores the subscription status Stripe reports, nothing about the card itself.

Retention, export and leaving

Three years
O. Reg. 137/15 s. 82 requires most records to be kept for three years. KeepCount keeps them for that long and refuses to delete them earlier, even on request, so a record cannot vanish before an inspection can ask for it.
Export
An administrator can export the organization’s complete records at any time, and a single person’s record on request. The export is a complete file in an open format (JSON); lists can also be downloaded as CSV from their screens, and the binder prints.
When someone leaves
Their access is removed and their contact details dropped; the training and screening record stays for the retention period, because the inspection may still ask about them.
When an organization leaves
You export, then choose a deletion date no earlier than the end of retention. The deletion runs automatically on that date and is recorded. Until then the records stay readable.
If something goes wrong
GATS tells the affected organization of a breach involving its data without undue delay, with what happened, what was affected and what to do; the organization tells its families and staff as the law requires. Access requests are answered within 30 days.

Who is responsible

The licensed organization decides what goes into its account and remains responsible for it. KeepCount Inc., operated by the people behind GATS, processes it only to provide the service, on the organization’s instructions. Questions about the system go to [email protected]. Questions about personal information, including a request to see or correct it, go to the same address or by post to KeepCount Inc., 51 Village Centre Place, Mississauga, Ontario L4Z 1V9; a person answers within 30 days. The privacy notice has the detail.

Found a security problem? Write to [email protected] with "security" in the subject; security.txt says the same.

Ask about a specific record or a specific risk.