Capricent ("Capricent," "we," "us," or "our") operates capricent.com and related software that helps licensed childcare centers run websites, capture enrollment interest, schedule tours, message families, collect certain payments, and manage parent communications.
This Privacy Policy explains how we handle personal information. It should be read with our Terms of Service. If you disagree with this Policy, do not use Capricent.
1. Who this Policy covers
- Website visitors to capricent.com (marketing and login pages).
- Center customers — directors, owners, and authorized staff who use the Capricent director portal.
- Parents and guardians who interact with a childcare center's Capricent-powered website (enrollment, tours, reviews) or parent portal under that center's domain (for example
centerdomain.com/parents).
Capricent is primarily a B2B platform. When a center stores family or child information in Capricent, that center is usually the organization that decides why the data is collected. Capricent processes that data to provide the product. See Section 3.
2. Roles: controller vs. service provider
Where Capricent is the controller
We decide how to process:
- Account and billing information for center customers (name, work email, login credentials, plan, usage meters).
- Support tickets and communications you send to Capricent ops.
- Marketing-site analytics and security logs for capricent.com.
Where Capricent is a service provider / processor
On behalf of a childcare center customer, we process Customer Content, including:
- Enrollment leads and tour requests from the center's site.
- Parent/guardian contact details, SMS/email consent timestamps, and message delivery logs.
- Enrolled-child roster fields the director enters (child name, reference code, classroom, parent contacts).
- Holiday/closure calendar entries, broadcast alerts, progress notes, and parent feedback submitted through the parent portal.
- Website CMS content (pages, blog posts, FAQs, teachers, pricing) the center publishes.
- Domain, DNS, hosting, TLS, and business-email setup metadata needed to operate the center's public site and mail DNS.
For Customer Content, the center is responsible for providing parents any required privacy notices, obtaining lawful consents (including SMS), and responding to parent access or deletion requests. Capricent will assist the center as needed to operate the Service. Parents who want changes to enrollment or child records should contact their center first.
3. Information we collect
3.1 Provided by center staff
- Name, email, password (stored hashed), role, and center affiliation.
- Center profile: name, phone, email, address, hours context, branding, programs, and public website content.
- Operational settings: Twilio number assignment where used, SendGrid domain authentication records, Stripe Connect account linkage, Google Business Profile identifiers when connected, registrar/DNS status.
- Family-comms roster and templates directors create or edit.
3.2 Provided by parents (via a center's site or portal)
- Enrollment inquiry and tour forms: parent name, email, phone, child name/age or related notes, program interest, and SMS consent.
- Parent portal access: email used for a magic link, child last name and child reference number for verification, and session cookies for that child only.
- Feedback, questions, or complaints submitted in the parent portal.
- Optional review content where the center enables it.
3.3 Generated or collected automatically
- Technical logs (IP address, user agent, timestamps, error traces) used for security, debugging, and abuse prevention.
- Message metadata: channel (SMS/email), status (queued/sent/failed), provider message IDs, and approximate send times — not full card numbers.
- Usage metering for plan quotas (SMS, email, leads, tours, storage).
- Cookies or similar technologies for authentication (director sessions; parent portal sessions) and basic site operation. We do not sell personal information and do not use Capricent product data to run third-party advertising networks on client sites.
3.4 Payments
Registration fees or tuition deposits (when enabled) are processed by Stripe under Stripe Connect. Capricent stores Stripe account and payment status metadata. Card numbers and bank details are handled by Stripe, not stored in Capricent databases. Stripe's privacy policy applies to payment-card processing.
3.5 Children's information
Capricent is not directed to children under 13 as end users. We do not knowingly collect personal information directly from children under 13 for Capricent's own purposes. Child-related information (name, age/classroom, reference code, progress notes) is provided by parents/guardians or center staff so the center can operate enrollment and communications. Parent portal authentication is for parents/guardians, not children. If you believe we have collected a child's information inappropriately, contact support@capricent.com and we will work with the relevant center to investigate.
4. How we use information
- Provide, host, secure, and improve the Capricent platform and each center's public website.
- Deliver transactional SMS and email that a center initiates (lead follow-up, tour reminders, holiday/closure alerts, progress notifications, magic-link access) subject to consent and law.
- Authenticate directors and verified parents; prevent fraud and abuse.
- Bill customers, enforce plan quotas, and provide support.
- Comply with law, respond to lawful requests, and enforce our Terms.
- Optionally generate draft website/blog content with AI tools using center-supplied prompts and public-facing content — not for selling parent lists.
We do not sell personal information. We do not share Customer Content with other childcare centers. Parent inquiry data is available to the center that collected it (and to Capricent staff who need access to operate or support the Service).
5. SMS and email communications
5.1 SMS (text messaging)
Capricent helps centers send SMS through providers such as Twilio. Typical message types include enrollment follow-up, tour scheduling/reminders, center closures and holiday notices, and similar transactional updates.
- Centers must obtain appropriate consent before messaging (for example, the enrollment-form checkbox that discloses Capricent as the technical sender on behalf of the center).
- Message frequency varies based on the family's activity and center-configured alerts.
- Message and data rates may apply.
- Reply STOP to opt out of SMS; reply HELP for help. Consent is not a condition of purchase where that rule applies.
- Capricent and carriers may block or suspend traffic that violates carrier, CTIA, or TCPA rules (including unsolicited marketing).
5.2 Email
Transactional email (confirmations, alerts, magic links, director notifications) may be sent via SendGrid or similar, often from or on behalf of the center's authenticated domain when configured. Business mailboxes (Migadu, provisioned in the director portal) are operated under the center's own email provider terms once provisioned; Capricent may store setup status and DNS guidance, not the contents of the center's mailbox. A few legacy centers still use Zoho MX until they are re-provisioned.
6. Sharing and subprocessors
We share information with vendors only as needed to run Capricent, under contracts that restrict use of the data to providing their service to us. Current subprocessors typically include:
| Vendor | Purpose | Region (typical) |
|---|---|---|
| Cloud host / VPS provider | Application hosting, databases, Redis job queues, TLS | United States |
| Twilio | SMS delivery and related messaging infrastructure | United States |
| SendGrid (Twilio) | Transactional email delivery | United States |
| Stripe | Stripe Connect payments and billing metadata | United States |
| Namecheap / Spaceship | Registrar DNS APIs when Capricent syncs DNS for a center | United States |
| Business Profile / Maps / review features when connected | United States | |
| OpenAI or similar LLM | Optional assisted blog/website draft generation | United States |
| Migadu | Business email hosting when Capricent provisions hello@ / director@ | Switzerland / EU (Migadu) |
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required). A current list is available on request at privacy@capricent.com.
7. Data storage, security, and retention
- Customer Content and account data are stored in Capricent-operated databases and application servers (typically U.S.-hosted cloud infrastructure unless we notify otherwise).
- We use administrative, technical, and organizational measures appropriate to a multi-tenant SaaS product (access controls, hashed passwords, TLS for public sites where provisioned, segmented worker processes). No method of transmission or storage is 100% secure.
- Retention: we keep account and Customer Content for as long as the center subscription is active and as needed for backups, disputes, security, and legal compliance. Centers may request deletion of specific Customer Content subject to technical and legal limits. In particular, Capricent soft-archives vault files and does not currently offer permanent hard-delete of signed enrollment-packet documents and other retention-held child file records (common childcare recordkeeping practice). Message logs and audit records may be retained longer for abuse prevention and billing integrity. See our Data Processing Addendum §7.
8. Cookies
Capricent uses cookies and similar technologies that are necessary to sign directors in, keep parent-portal sessions, and operate the Service securely. We do not use Capricent product cookies to run third-party advertising networks on client sites. Details, cookie categories, and retention notes are in our Cookie Notice.
9. Your rights
- Directors: update profile and center content in the portal; contact support to close an account.
- Parents: contact your childcare center to correct or delete enrollment/child data; use STOP for SMS; use parent-portal sign out on shared devices.
- Depending on your location (for example certain U.S. state privacy laws), you may have rights to access, delete, or correct personal information Capricent controls, or to appeal a denial. Submit requests to privacy@capricent.com. For Customer Content we process for a center, we may route the request to that center or fulfill it as their service provider.
10. Your privacy choices
We do not sell or share personal information for cross-context behavioral advertising as those terms are commonly defined under California law (CCPA/CPRA). Because we do not sell or share in that sense, we do not offer a separate "opt-out of sale" toggle — this page is the conspicuous notice of that practice.
- SMS opt-out: reply STOP (HELP for help).
- Access / delete / correct requests for Capricent-controlled data: privacy@capricent.com.
- Family/child records held for a center: contact that center first; we will assist them as their service provider.
- Cookie preferences: see the Cookie Notice. Essential auth cookies are required to use signed-in features.
11. International visitors
Capricent is built for U.S. childcare operators by default. If you access the Service from outside the United States, you understand information may be processed in the United States, where laws may differ from those in your country.
12. Changes
We may update this Policy from time to time. The "Last updated" date will change, and material changes may be communicated via the director portal or email. Continued use after an update means you accept the revised Policy to the extent permitted by law.
13. Contact
Privacy requests: privacy@capricent.com
General support: support@capricent.com
Phone: (844) 987-2328
Web: https://capricent.com
Centers that need a signed Data Processing Addendum (DPA) for Customer Content can use the published template at /dpa or request a countersigned PDF at privacy@capricent.com.