Legal

Privacy Policy

ThreeLillies holds information about children and their families. This page says exactly what we collect, why, who else sees it, and what you can ask us to do about it — in plain language, and specific to this product rather than copied from anywhere.

Last updated August 28, 2026

Who we are, and which data is whose

ThreeLillies is waitlist and enrollment software for childcare providers. Two different kinds of organisation use it, and the distinction decides who is answerable for what.

  • Childcare providers — the daycares, preschools and centres that hold an account. For the family and child information they enter or collect through ThreeLillies, the provider decides what is collected and why. We hold and process that information on their instruction, as their service provider. If you are a parent, your provider is the first place to ask about your records.
  • ThreeLillies — us. For the account information of the people who administer a provider's account, for our billing records, and for enquiries sent through this website, we decide what is collected and why, and this policy governs it directly.

Both roles are covered below. Where a right or a request depends on which one applies, we say so.

What we collect

We collect only what the product needs to run a waitlist. There is no advertising network in ThreeLillies, no third-party tracking pixel, and no profile built for any purpose other than delivering the service.

CategoryWhat it includesWhy we have it
Provider accountName, email address, password (stored only as a hash), role, and the organisation and sites you belong to.To sign you in and decide what you are allowed to see.
Business detailsBusiness name, phone number, website, logo, brand colour, site addresses, opening details and the classrooms you set up.To run your waitlist and to show families a page that looks like your business.
Family contact detailsParent or guardian name, email address, phone number, relationship to the child, and postal address where given.To place a family on a waitlist and to tell them when their position changes or a place opens.
Child detailsFirst, last and preferred name, date of birth, gender where given, and any notes the family or your staff add.Date of birth decides which room a child is eligible for and drives every capacity and age-out projection. The rest identifies the child to your staff.
Registration answersThe answers a family gives to the intake questions each provider writes for itself.The provider chose these questions; we store the answers for them.
DocumentsFiles a family or your staff upload against a waitlist record, with their file name, type and size.To keep a family's paperwork with their record.
Messages and commentsComments written by staff, comments written by families, and a log of automated emails we send — subject, body, the address used and whether it was delivered.So both sides can see what has been said, and so an email that never arrived can be traced.
Payment recordsAmount, currency, status, card brand and last four digits, and the identifiers Stripe gives us. We never receive or store full card numbers — those go directly to Stripe.To take a registration fee and to answer questions about it later.
Technical recordsIP address and browser user-agent recorded against a sign-in session, a password reset request, and a consent acceptance. Server logs that record requests without their contents.Security. These are what let us investigate a compromised account or an abused reset link.
EnquiriesName, email, phone, business name and message when you use a form on this website.To reply to you.

We do not collect payment card numbers, government identity numbers, biometric data, precise device location, or health records as a defined feature. A provider may of course type sensitive information into a free-text note or upload it as a document; where they do, it is their decision and it is held under the same protections as everything else.

Children's information

ThreeLillies holds information about children, but it is never collected from children. A child's details reach us in one of two ways: a parent or guardian enters them when joining a waitlist, or a provider's staff enter them on the family's behalf.

ThreeLillies is not directed to children and has no feature a child would use. There is no account type for a child, no way for a child to sign in, and no interface addressed to one.

A child's record is visible to the staff of the provider that holds it, and to the parent or guardian on the account. It is not visible to any other provider on the platform, it is not sold, and it is not used for advertising or shared for anyone else's marketing — ever, and regardless of consent.

How we use it

  • Running the waitlist. Ordering the queue, matching a child's age to a room, projecting when places will open, and recording who was offered what.
  • Telling families what changed. Confirmation when they join, notice when their position moves, a spot offer and its deadline, a receipt when they pay. These are part of the service, not marketing, and a family can switch them off with the unsubscribe link every one of them carries.
  • Taking payments. Passing the amount and the provider's connected account to Stripe, and recording what came back.
  • Keeping accounts secure. Signing people in, ending sessions, and investigating anything that looks like an account being misused.
  • Supporting you. Answering a question you have asked us, which sometimes means looking at the record you are asking about.
  • Keeping the product working. Diagnosing errors and understanding load.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use family or child information to train machine-learning models.

Who we share it with

Four service providers, each doing one job, each bound to use the data only to do it:

ServiceWhat it doesWhat reaches it
Amazon Web ServicesHosting, the database and document storage, in the United States (us-east-1).Everything the product stores.
StripePayments — both the registration fee a family pays a provider and the provider's own subscription to us.Card details (directly, never through us), the amount, and the payer's name and email.
ResendDelivering the emails the product sends.The recipient's address and the message.
Google Maps PlatformAddress autocomplete when a provider enters a site address, and an optional map so a family can confirm they have picked the right site.The address text being looked up. No family or child information is sent to Google.

Beyond those, we share personal information only in three situations: with the provider whose waitlist the record belongs to; when the law requires it, or to protect someone's safety or our rights; and if ThreeLillies is ever acquired or merged, in which case the information transfers with the business and this policy continues to apply until it is replaced by one you are told about.

How we protect it

  • Traffic to and from ThreeLillies is encrypted in transit (HTTPS).
  • The database is encrypted at rest, sits inside a private network with no public route to it, and is backed up daily.
  • Uploaded documents live in private storage with public access blocked at the bucket, encrypted at rest, and are reachable only through short-lived links issued to someone already signed in and entitled to the record.
  • Passwords are stored as bcrypt hashes, never as text we could read. Session tokens and password-reset links are stored only as hashes, so a copy of our database is not a set of working keys.
  • A password reset link works once and expires within an hour, and using it signs out every other device.
  • Every request is scoped to one organisation, so one provider cannot read another's families. The single exception is our own platform administrators, described below.
  • Changes to a family's record are written to an audit trail showing who did what and when.

A small number of ThreeLillies staff hold platform administrator access, which can read across providers. It exists to operate and support the service — investigating a fault, answering a support request, or acting on a legal obligation — and it is used for those reasons only.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your information we will tell you and the relevant authorities as the law requires, and we will tell you what we know rather than waiting until we know everything.

How long we keep it

While a provider's account is open, we keep the information they have entered, because deleting a family's history would take the waitlist with it. When a provider removes a family or a document, it is marked as removed and stops appearing anywhere in the product; the underlying row is retained for a limited period so an accidental deletion can be reversed and so the audit trail remains coherent.

Some records outlive the account by design: payment records, because we and the provider have tax and accounting obligations; email delivery logs, because “was this family ever told?” has to remain answerable; and audit entries, for the same reason. Backups roll off on their own schedule, so a record can persist in a backup for a short period after it is deleted from the live system.

If a provider closes their account and asks us to delete their data, we will delete or anonymise it, except where we are required to keep it.

Your choices and rights

Depending on where you live you may have the right to ask for a copy of your personal information, to have it corrected, to have it deleted, to object to or restrict certain uses, and not to be discriminated against for exercising any of these.

  • If you are a parent or guardian, ask your childcare provider first. They control the record, and they can correct or remove it directly. If you cannot reach them, contact us and we will help — but we will normally act on the provider's instruction rather than change their records ourselves.
  • If you administer a provider account, contact us directly and we will act on your request.
  • Automated emails can be stopped at any time with the unsubscribe link in any of them. Doing so does not close your account and does not remove you from a waitlist — you will still see everything in your portal.
  • Your own password can be changed from your account settings, or reset from the sign-in page if you have lost it.

We will ask you to verify your identity before acting on a request, and we will respond within the time the applicable law allows.

Cookies and tracking

ThreeLillies uses one cookie, and it is strictly necessary: an encrypted, HTTP-only cookie that keeps you signed in. It carries no advertising identifier and cannot be read by scripts on the page.

There is no advertising or analytics tracker on this website or in the product. Fonts are loaded from Google Fonts, and a map is loaded from Google Maps only on the pages that show one — both mean your browser contacts Google directly, and Google receives your IP address as it would for any site that loads a resource from them.

Where your information is held

ThreeLillies is operated from the United States and all of its data is stored there, in Amazon Web Services' us-east-1 region. If you use ThreeLillies from outside the United States, your information is transferred to and processed in the United States, where privacy law differs from your own.

Changes to this policy

We will update this page when the product changes what it collects or how it is used, and the date at the top will change with it. If a change materially affects how we handle your information, we will tell account holders directly rather than relying on you to re-read this page.

Separately, when you create a provider account or join a waitlist you are shown the consent notice in force at that moment and asked to agree to it. We keep a record of which version each person agreed to, so what you agreed to remains retrievable exactly as it was shown to you.

Contact us

Questions about this policy, or a request about your information: privacy@threelillies.ai. For anything else, support@threelillies.ai.

If you are a parent or guardian asking about a child's record, please tell us the name of the childcare provider so we can route your request to the right account.