Security & safety
Childcare programs trust CentreBloom with sensitive information about children, families and staff. Here's how we help keep it safe.
Encrypted in transit
All traffic between your browser and CentreBloom is protected with TLS (HTTPS) encryption.
Encrypted at rest
Your data is stored on managed cloud infrastructure that encrypts it at rest on disk.
Secure sign-in
Authentication is handled by a dedicated provider; passwords are stored only as salted hashes, never in plain text.
Role-based access
Staff see only what their role and department allow — parents see only their own children.
Canadian data residency
CentreBloom's primary application database and customer records are hosted in Canada. Certain supporting services process limited information through third-party sub-processors, some outside Canada — see the list below.
Secure payments
Payments run through Stripe, a PCI-DSS Level 1 provider. Card numbers never touch our servers.
Automated backups
The database is backed up automatically so your records are protected against loss.
Least-privilege access
Only the small number of people who operate the service can access systems, and only as needed.
Sub-processors we rely on
To run CentreBloom we use a small number of trusted service providers that process data on our behalf. We choose established providers and share only what each needs to do its job. For the full list — including the information involved and where each provider processes it — see our Sub-processors page.
| Provider | Purpose |
|---|---|
| Supabase | Application database & authentication, hosted in Canada |
| Stripe | Payment processing (PCI-DSS Level 1) — card data is handled by Stripe |
| Email delivery provider | Sending transactional email (reminders, receipts, notifications) |
| Twilio | Sending SMS text reminders — only when a centre enables SMS |
| OpenAI | Optional features only — drafting assessment questions from a topic you enter, and reading timesheets or calendars from a free-form file. Only that submitted content is processed. |
Your data — export & deletion
Your centre owns the information it enters into CentreBloom. You can request an export of your data, and you can request deletion when you close your account — subject to the legal, tax and payroll record-keeping periods described in our Privacy Policy.
Reporting a vulnerability
If you believe you've found a security vulnerability, please tell us before disclosing it publicly. Email hello@centrebloom.comwith the details and steps to reproduce, and we'll investigate promptly. We appreciate responsible disclosure and will work with you on a fix.
A note on scope
We're a small Canadian team and we describe our security practices plainly rather than claiming certifications we don't hold. If your organization needs specific documentation (for example, a data-processing agreement or answers to a security questionnaire), please get in touch and we'll do our best to help.
Have a security question or want to report a concern? Get in touch — we take it seriously. See our Privacy Policy for how we handle personal information.