Privacy Policy
Effective October 5, 2026
Who We Are
Mariam's Footsteps Inc. is a care services organization operating group homes and childcare programs in the Edmonton, Alberta. This policy describes how we collect, use, and protect personal information in connection with our staff management systems, staff mobile apps and public website.
Information We Collect
| Category | Examples | Purpose |
|---|---|---|
| Staff identity | Name, employee ID, job title | Employment administration |
| Contact | Email address, phone number | Operational notifications, scheduling |
| Scheduling | Shift assignments, availability | Workforce management |
| Device | Device identifiers for managed work devices, and push notification identifiers for staff who use our mobile apps (see Staff Mobile Apps). | IT security and device management |
| Website | IP address, browser type, pages visited | Site functionality and security |
We do not collect personal information from the general public beyond standard website analytics.
Information about the people we support is part of our care records and is described under Staff Mobile Apps.
How We Use Information
- Scheduling staff shifts and sending operational reminders
- Communicating safety alerts and emergency notifications
- Managing IT equipment and ensuring device security
- Processing payroll and human resources administration
- Procurement and supply chain operations
- Maintaining the security of our systems and data
SMS Notifications
Staff who provide a mobile phone number during onboarding may receive operational SMS messages including shift reminders, safety alerts, and appointment confirmations. Staff may opt out at any time by replying STOP or contacting Human Resources. See our SMS Terms for full details.
Staff Mobile Apps
This section covers the Mariam's Staff app for iPhone and Android. The apps are for Mariam's Footsteps staff only. You sign in with your Mariam's Footsteps Microsoft work account, and only staff we have given access to can sign in. The apps can be installed on a work device or on your own phone.
The apps do not have a database of their own. They show and send information to our staff systems (HR, house operations and programming), and what you see depends on your role and your house or program.
Information the apps handle
| Category | Examples | Purpose |
|---|---|---|
| Sign-in | Microsoft work account, name, employee ID, program, access level | Signing you in and showing the right screens |
| HR records | Staff badge and photo, certifications, compliance items, evaluations, leave information, date-of-birth change requests | Showing you your own HR information |
| Attendance | Clock-in and clock-out: the house, the shift, the time, and a reason if you give one | Recording hours worked for payroll |
| Requests | HR, IT and access requests, replies, satisfaction ratings, and files you attach | Handling your requests |
| House operations | Tasks, temperature logs, kit checks, fire drills, safety checklists, work orders and photos | Running our homes safely |
| Petty cash (house Team Leads) | Expense amounts, dates, vendors, categories, notes, receipt photos, and who approved them | Reimbursing house expenses and keeping financial records |
| Client and resident information | See "Information about the people we support" below | Providing care |
| App diagnostics (iPhone) | Crash, hang, launch-time and memory reports from Apple's built-in diagnostics, with a random installation ID and a coded (hashed) version of your account | Finding and fixing problems in the app |
| Notification registration | On iPhone, an Apple push token. On Android, a Firebase Cloud Messaging token. On both, a random installation ID created by the app and your notification permission setting. | Delivering work notifications |
Information about the people we support
As part of their work, staff use the apps to view and record information about the children, youth and adults in our programs. This can include profile details, allergies, diagnoses, care protocols, goals, daily notes, contact notes, activities, appointments, contacts, belongings, whereabouts and incident reports.
This information is part of Mariam's Footsteps' care records. Staff enter it on our behalf, for the care of that person, and we protect it as described in this policy. The apps only show client information to staff who are authorized for that home or program. Clients, guardians or their representatives who want access to these records should contact us directly, not through a staff member.
What the apps do not collect
- Location. The apps do not ask for or read your device's location. Clock-in and clock-out record the house and shift, not your GPS position.
- Contacts, microphone, calendar or browsing activity.
- Advertising or tracking. The apps contain no advertising, no advertising IDs, and no third-party analytics or tracking software. Crash and performance reports go only to our own systems (see "App diagnostics" below).
- Face or fingerprint data. See "App PIN, Face ID, Touch ID and fingerprint" below.
If you have chosen to share analytics with app developers in your phone's settings, Apple or Google may send us anonymous crash reports about the app. These do not include your name, and you can turn this off in your phone's settings.
App diagnostics
To find and fix problems, the iPhone app uses Apple's built-in diagnostics (MetricKit) to send us crash, hang, launch-time and memory reports. They go only to our own Microsoft Azure monitoring, not to any third party. Each report carries a random ID for that installation of the app and a coded (hashed) version of your account, so we can tell whose app had a problem without storing your name or sign-in ID with the report. Reports contain no client information, notes or screen content, and are deleted after 90 days.
App PIN, Face ID, Touch ID and fingerprint
After you first sign in, the apps ask you to create a 4-digit PIN. You enter it to open the app, which keeps client information private if your phone is left unlocked.
- Your PIN never leaves your phone. The app keeps only a protected, one-way version of it in your phone's secure storage, tied to your work account. We cannot see your PIN.
- The app counts wrong attempts. After 5 wrong PINs in a row it signs you out and deletes the stored PIN. You then sign in again and create a new one.
- If you turn on Face ID, Touch ID or fingerprint unlock, your phone does the check. The app is told only whether the check passed. It never receives or stores your face or fingerprint data.
- Signing out, or signing in with a different account, deletes the stored PIN and your unlock settings.
Sample data
The sign-in screen offers "Explore with sample data", a demonstration of the app that anyone can try. It shows only invented information, does not connect to Mariam's Footsteps systems, and sends nothing to us. Anything you enter in the demonstration stays on your phone and is erased when you leave it.
Camera, photos and files
The apps only use these when you choose to attach something. On iPhone, the app asks for camera access only when you choose to take a photo for an HR request, an incident report, a work order or a petty cash receipt. On Android, the app uses the system photo and file pickers and does not ask for camera or storage permission. Before a photo is uploaded, the app rebuilds the image from its pixels, which removes hidden details such as GPS location and camera information. Other files, such as PDFs, are sent as they are.
Photos added to an incident report become part of that person's care record and are kept for as long as the care record is kept, which is indefinitely. A photo that has not finished uploading is kept only in the app's memory and is lost if the app closes. Cancelling an upload stops it but does not delete a photo that was already stored. Petty cash receipt photos are kept with our financial records for as long as we are required to keep them.
What stays on your phone
The apps keep as little as possible on your phone:
- Your Microsoft sign-in, kept by Microsoft's sign-in library on this device only. Signing out removes it.
- A short summary of your name, employee ID, program and access level, so the app works where the signal is weak.
- Reference numbers for a save whose result is not yet known, never what you typed. These are deleted after 24 hours for attendance and 30 days for other records.
- On iPhone, an unfinished incident report draft. It is encrypted, can only be read while the phone is unlocked, and cannot be moved to another device.
- On Android, shift reminder times and your reminder settings.
- Display settings, such as light or dark mode.
- The protected version of your app PIN, the count of wrong attempts, and whether you turned on Face ID, Touch ID or fingerprint unlock.
Client records and other screens are held in memory while you use them. The apps turn off network caching. Files you open for preview are kept briefly in protected storage and then deleted. On Android, app data is excluded from cloud backup and device transfer, and screenshots of the app are blocked. Both apps ask for your app PIN, or Face ID, Touch ID or fingerprint if you turned it on, when they open and after 5 minutes away. Both apps hide their contents in the app switcher.
Push notifications and reminders
- If you allow notifications, the app registers your phone with our notification service so we can send work notifications, such as updates on your requests. Registration goes through Apple on iPhone and Google on Android. When you sign out, the app asks our service to remove the registration.
- On Android, the app also creates shift reminders on your phone from your own schedule. These reminders are not sent from our servers.
- Notifications use general wording only, for example "Your request status has changed. Open Requests to review it." They never include client names, health information, or the content of HR requests. You open the app to see details.
- Notification content is deleted from our notification service once it is delivered or expires. Records of which notifications were sent are deleted after 30 days.
- You can turn notifications off in your phone's settings at any time.
Service providers for the apps
In addition to the providers listed under "How We Share Information":
| Provider | Role |
|---|---|
| Microsoft Entra ID | Staff sign-in |
| Microsoft Azure (Canada Central region) | Hosting, databases, and Azure Notification Hubs for relaying push notifications |
| Apple Push Notification service | Delivering notifications to iPhones |
| Google Firebase Cloud Messaging | Delivering notifications to Android phones |
| Apple App Store and Google Play | Distributing the apps, under their own privacy policies |
Some authorized supervisors can view the app as another staff member would see it, to provide support.
How We Share Information
We do not sell, rent, or trade personal information. We may share information with:
- Service providers — cloud hosting (Microsoft Azure), email delivery, and SMS services that process data on our behalf under contractual safeguards
- Legal obligations — when required by law, regulation, or valid legal process
- Safety — when necessary to protect the safety of our staff, clients, or the public
Data Security
We protect personal information using industry-standard measures including:
- Encryption in transit (TLS) and at rest
- Multi-factor authentication for staff accounts
- Role-based access controls
- Regular security reviews and monitoring
- Managed device policies with remote wipe capability
Remote wipe applies to managed work devices. On personal phones, signing out of the staff apps removes the sign-in and cached information.
Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, or as required by law. When information is no longer needed, it is securely deleted or anonymized.
HR, attendance and care records, and our server logs, are kept for 15 years. Specific periods for information on staff phones and for notification records are listed under Staff Mobile Apps.
Your Rights
Under applicable Canadian privacy legislation (including PIPEDA and Alberta's PIPA), you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Ask us to delete personal information we no longer need. Some records, such as HR, attendance and care records, must be kept for the periods described under Data Retention.
- Withdraw consent for non-essential processing
- File a complaint with the Office of the Privacy Commissioner of Canada
To make a request, contact us using the details under Contact Us. We will confirm your identity before acting on it. Staff app accounts are created by Mariam's Footsteps, so there is no sign-up or account deletion inside the apps. When your employment ends, your access to the apps is removed. You can also remove the app from your phone at any time, which deletes everything it stored there.
You may also file a complaint with the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca), which oversees Alberta's Personal Information Protection Act (PIPA).
Children's Privacy
Our staff systems and apps are not directed at children, and staff users must be 18 or older. Our programs serve children and youth, so our care records include information about minors. Staff record it for their care, and we protect it as described under Staff Mobile Apps.
Changes to This Policy
We may update this policy from time to time. Changes take effect when posted on this page. The "Effective" date at the top reflects the most recent revision.
Contact Us
For privacy-related questions or to exercise your rights:
Mariam's Footsteps Inc.
[email protected]
(780) 462-7426