Privacy Policy

Last updated: August 16, 2026

Carelyst is software that homecare agencies use to run their operations. This policy explains what data we collect, why, and how it is protected: in plain language, because the people this data describes deserve that.

The short version. Carelyst is operated by Techalyst Software Inc., a British Columbia company, and all persistent data is stored in Canadian data centres in Toronto. We collect what a homecare agency needs to run: accounts, care records, the GPS position of each clock-in and clock-out, and, for agencies using attendance kiosks, encrypted fingerprint templates that are never images. We do not sell data, we do not use care records for advertising or AI training, and every agency's data lives in its own isolated database.

If you want a copy of your data or want it deleted, email legal@carelyst.ca; if the data lives in an agency's workspace, your agency is the right first contact and we support them in responding. Our specific commitments under Canadian privacy law, including retention windows and the formal request process, are on our PIPEDA & PIPA BC Compliance page.

1. Who we are, and whose data this is

Carelyst is operated by Techalyst Software Inc., a software company based in Vancouver, British Columbia, Canada. When this policy says "we" or "us", it means Techalyst Software Inc., the organization accountable for personal information under PIPEDA and PIPA BC.

Carelyst (carelyst.ca) provides a platform to homecare agencies ("agencies"). Two kinds of data exist here:

  • Account data we control: agency owner accounts, billing details, and platform usage. For this data, Carelyst is the data controller.
  • Care data the agency controls: client records, caregiver records, schedules, visits, messages, and attendance data that an agency enters or generates while using Carelyst. The agency is the custodian of this data; Carelyst processes it only to provide the service, on the agency's instructions. Questions about this data should go to the agency first: we support them in answering.

2. What we collect

  • Account information: name, email, password (hashed), and optional two-factor secrets for anyone with a login: agency staff, caregivers, and family contacts.
  • Care records: the client, caregiver, scheduling, visit, incident, billing, and payroll records agencies create in the product.
  • Location data: when a caregiver clocks in or out of a visit, the app records the GPS position of that punch to verify the visit happened at the client's home. Location is captured only at the moment of a punch. Carelyst does not track anyone's movements continuously or in the background. Attendance kiosk devices similarly attach a location to each punch when the device has a GPS fix.
  • Biometric data (attendance kiosks only): agencies using Carelyst Kiosk enroll staff fingerprints on a shared kiosk device. What is stored is a mathematical fingerprint template (ISO 19794-2 minutiae data), not an image of the fingerprint. Templates are encrypted at rest on the kiosk device (hardware-backed keys) and on our servers, are used solely to identify staff at clock-in/clock-out, and are never used for any other purpose, shared, or sold. Enrollment happens in person, with the staff member present, operated by their agency's manager.
  • Photos: profile photos, and photos sent in office-to-field messages (for example wound care or medication labels). Message photos live on the agency's private storage and are streamed only to the conversation's participants, never at a public URL.
  • Device and technical data: push notification tokens, device names for session management, and standard server logs (IP address, timestamps) kept for security and troubleshooting.
  • Marketing site data: contact form submissions, and usage analytics on marketing pages unless you decline the cookie banner. See "Cookies and the marketing site" below.

3. What we never do

  • We never sell data: anyone's, ever.
  • We never use care data, location data, or biometric data for advertising or profiling.
  • We never let one agency see another agency's data: every agency runs on its own physically separate database.
  • We never track location outside of the clock-in/clock-out moment.

4. How data is protected

  • Every agency has a dedicated, isolated database, not shared tables with filters.
  • All persistent data, including backups, is stored in Canadian data centres, in DigitalOcean's Toronto region. The narrow cases where content transits non-Canadian networks (push notifications, map lookups) are listed on our PIPEDA & PIPA BC page.
  • Changes to core records (clients, caregivers, schedules, care plans, compliance documents, incidents, invoices, payments, and payroll) are logged with who changed what and when.
  • All traffic is encrypted in transit (TLS). Fingerprint templates and platform credentials are additionally encrypted at rest.
  • Access inside an agency is permission-gated screen by screen and API by API; families see only the deliberately limited family portal.
  • Sensitive actions (like disconnecting a sign-in provider) require re-confirming your identity.

If a breach ever creates a real risk of significant harm, we notify affected agency owners within 72 hours of confirming it; our full breach commitments are on the PIPEDA & PIPA BC page.

5. Third parties we rely on

We use a small set of processors to run the service: cloud hosting and file storage (DigitalOcean, in its Toronto, Canada region, where all persistent data lives), payments (Stripe: card details never touch our servers, and we keep only the card's brand and last four digits for display), transactional email (Resend), push notification delivery (Apple's and Google's push services, via Firebase on Android), and optional sign-in with Google or Apple (we receive only your name, email, and a verified identifier, never your password). Map previews and address lookups in the agency dashboard use OpenStreetMap: the address being shown or searched travels from your browser to OpenStreetMap Foundation servers to draw the map, with no names or care records attached. Each provider receives only what its function requires, and each link above is that provider's own privacy policy. Beyond these processors, we disclose personal information only when legally required to, under a subpoena, court order, or other valid legal process. The full sub-processor list, with what each one handles, is on our PIPEDA & PIPA BC page.

6. Cookies and the marketing site

Inside the application we set only the cookies needed to keep you signed in. On the public marketing pages of carelyst.ca, three more things run, and none of them can reach care data:

  • Usage analytics: we use Google Analytics on marketing pages to understand which pages visitors read. A cookie banner lets you decline, and declining stops analytics for your visit. Analytics never runs inside the application.
  • Contact form protection: the contact form uses Cloudflare Turnstile to filter out automated submissions. Cloudflare sees your IP address and browser signals during that check, and nothing else.
  • The voice assistant: the assistant on our home page is powered by 1n1.ai, which is operated by the same company as Carelyst. It runs only when you choose to start a conversation, and it has no connection to any agency's data. How 1n1.ai handles voice conversations is described in its privacy policy and its PIPEDA page.

7. Retention and deletion

Care records are retained as long as the agency's account is active, because they are the agency's operational and legal records. When an agency leaves Carelyst, it can export its data; the agency's database is then deleted after a wind-down period. Fingerprint templates are deleted when a staff member is deactivated by their agency or on request to the agency. You can ask your agency, or us at the address below, about data held on you. The complete retention table and the formal deletion process are on our PIPEDA & PIPA BC page.

8. Your rights

Depending on where you live (including under Canada's PIPEDA), you may have rights to access, correct, or delete personal data about you. For care data, contact your agency (the data custodian); for account data, contact us. We answer either way and will help route requests to the right place. We respond to requests addressed to us within 30 days.

9. Children

Carelyst is a workplace tool and is not directed at children. Account holders must be at least 18. Client care records may describe people of any age under an agency's duty of care; those records are the agency's responsibility as custodian.

10. Changes

If this policy changes in a way that matters, we will say so on this page with a new "last updated" date and email active agency owners at least 30 days before significant changes take effect.

11. Contact

Techalyst Software Inc.

Suite 1047, 1055 West Georgia Street, Unit 220
Vancouver, BC V6E 3P3, Canada

Privacy questions or requests: legal@carelyst.ca