Skip to main content

Privacy Policy

Last updated: August 2026

At Kidsflow, we take student and family data privacy as seriously as you take their safety. This policy describes how we collect, use, and protect your information.

1. Information We Collect

We collect information the school provides to us directly, including: names and contact information of parents/guardians, and student names and classes.

We also collect information provided by users themselves (parents, guardians, and authorized pickup persons), including: authorized pickup person data, device location data, app usage data and, when the school requires it, identification documents and photos, as detailed in section 2.

2. Identification Documents and Photos

Some schools require document verification at the moment of pickup. When this requirement is active, we collect the following from the people authorized to pick up the student — legal guardians and authorized pickup persons:

  • the type and number of an identification document (CPF, RG, CNH, passport, or other);
  • an image of the identification document, submitted as a photo or PDF;
  • a face photo, used for visual confirmation at the gate.

This data is submitted by the person themselves or by whoever registers them as an authorized pickup person. By registering a third party and uploading their documents, you represent that you have that person's authorization to do so.

Purpose. This information is used exclusively to confirm, at the moment of dismissal, that the person picking up the student is the authorized person. We do not use it for advertising, and we do not apply facial recognition or any automated biometric processing — the check is visual, performed by a school staff member.

Who has access. At the moment of pickup, the staff member responsible for releasing the child views the face photo, the document image, and the document number, for verification. Outside that moment, school managers see only the document type and the partially masked number (for example, •••.•••.123-45). Every access to these images is recorded in an audit log containing who accessed it, when, and about whom the data refers.

Storage. The images are stored separately from the main database and can only be accessed through temporary links, generated individually and valid for short periods.

3. How We Use Your Information

We use collected information to: verify the identity of authorized guardians during school dismissal, facilitate communication between school and family, maintain pickup records for security purposes, improve our services and user experience, and comply with legal obligations.

4. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes.

We share data only with: your child's school, for verification and dismissal management purposes; the service providers (processors) listed below, who help us operate the platform; and authorities, when required by law.

Processors we use:

  • Cloudflare, Inc. — storage of document images and face photos;
  • Asaas — billing and payment processing for schools;
  • Expo — delivery of push notifications;
  • Cockroach Labs, Inc. (CockroachDB) — hosting of the platform database;
  • Brevo — delivery of transactional emails.

International transfer. Part of our infrastructure is operated by companies based outside Brazil, which may involve storing or processing your data abroad. In such cases, we require processors to provide contractual protection safeguards compatible with the LGPD, under article 33 of Law No. 13.709/2018.

5. Data Security

We implement technical and organizational security measures, including: encryption of data in transit (HTTPS/TLS) and at rest, role-based access control, audit logging of all access to identification documents, access to sensitive images only through short-lived temporary links, and compliance with the LGPD.

6. Your Rights

You have the right to: access your personal data, correct inaccurate data, request deletion of your data, withdraw consent at any time, and receive your data in a portable format.

7. Data Retention

We retain your data only for as long as necessary to provide our services or as required by law. Specifically:

  • Identification documents and face photos: retained while the person remains registered as a guardian or authorized pickup person. They are deleted when the registration is removed, when the person replaces the document, or when the account is closed.
  • Document access logs: retained for 24 months, for audit purposes, and then automatically deleted.

When you close your account, we delete or anonymize your personal data, except where retention is legally required.

8. Legal Bases for Processing

We process your personal data on the following legal bases set out in article 7 of the LGPD:

  • performance of a contract, to provide the service contracted by the school;
  • compliance with a legal or regulatory obligation;
  • legitimate interest, to verify the identity of the person picking up the student and to prevent fraud in pickup authorization;
  • protection of the physical safety of the student;
  • consent, where applicable, such as for access to device location.

9. Location Data

Kidsflow collects location data from your device to: verify guardian proximity to the school during the pickup process, improve security and prevent authorization fraud, optimize the dismissal queue and estimate arrival times, and send relevant location-based notifications. Location collection occurs only when the app is actively in use and you can disable this feature in your device settings, although some features may be limited. We do not store location history. When it receives your location signal, Kidsflow updates the trip in progress for communication with the school and then discards the information.

10. Contact Us

For privacy questions or to exercise your rights, contact us at contato@kidsflow.com.br or through our contact form.