Last updated: 24 September 2026
Traqmon is check-in and check-out software for Kumon centers. This page explains what the software holds, why, who else can see it, and how long it stays.
Not legal advice, and not yet reviewed by a lawyer. This describes what the software actually does, written by the people who built it. Have it reviewed before relying on it for a compliance obligation of your own.
Your center decides what goes in and why. We hold it on your behalf. In data-protection language your center is the controller and Traqmon is the processor. Practically: we do not decide which children are enrolled, which guardians may collect them, or what a note says. Your center does, and your center answers a parent who asks about their own child's record.
If you are a parent and want to see, correct or remove your child's information, ask the center — they can do all of it from inside the app. If they need us, we will help them.
About students: name, date of birth, grade, subjects and level, and the times they arrived, finished their work and were collected. Class notes and achievement or placement test results, if the center records them. Which physical QR sticker belongs to them.
About guardians: name, phone number, email if given, relationship to the student, and whether they are authorised to collect that child.
About staff: name, username, email, a password that is stored only as a hash we cannot reverse, and a record of which devices are signed in.
About the center: its name and address, its settings, and — once billing exists — the records needed to charge for the service. Card details are never stored by us. They go directly to Stripe, who are certified to hold them.
What we do not hold: your K-SIS password. The roster sync runs inside your own browser on a K-SIS session you are already signed in to. There is no login form and nothing to store. If a vendor's sync runs on their servers, they hold a Kumon login; ours does not.
Names, dates of birth and phone numbers are encrypted field by field inside the database, not merely on the disk underneath it. Someone with a copy of the database still cannot read them without a key held separately.
QR stickers carry a meaningless code. A sticker found on the floor tells a stranger nothing about the child it belongs to.
Attendance records cannot be edited or deleted — they are only ever added to. That is what makes them worth something when Kumon asks to see them.
Staff see only their own center. A request for another center's data does not return an error that confirms the center exists; it returns nothing at all.
We use other companies to run the service. Each sees only what its job needs, and none of them sell it or use it for their own purposes.
| What they do | What they can see | |
|---|---|---|
| Fly.io | Runs the application | Everything the application processes, in transit |
| Neon | Runs the database | The stored data, with personal fields encrypted |
| Cloudflare | Serves the app to your browser | Network traffic; no database access |
| Resend | Sends account emails — verification, password reset | The recipient's email address |
| Twilio or Vonage | Sends pickup text messages, only if your center turns them on | The guardian's phone number and the text of the message, which contains the student's first name and your center's name |
| Stripe | Takes payment, once billing exists | Your center's billing details and card. Not student or guardian data |
| Sentry | Reports application errors, if enabled | Technical diagnostics. Configured not to carry personal fields |
The text-message line is the one to read twice. If your center enables pickup texts, a guardian's phone number and the child's first name are handed to a messaging provider in order to deliver the message. There is no way to send a text without doing that. If your center never enables texting, no phone number ever leaves our systems for that purpose.
We do not sell personal information, and we do not use it to advertise anything.
Texting is off until your center switches it on, and switching it on requires your center to confirm it has permission from the guardians it intends to text. That confirmation is recorded, with who made it and when.
We record the claim. We do not verify it. Obtaining consent from parents is your center's responsibility, and it is the sort of thing that should already be part of enrolment.
A guardian can stop the texts at any time by replying STOP. That takes effect immediately and permanently for that center until they ask to start again, and the center is shown that it happened so staff phone them instead. A pickup text is a notice, not an agreement — it does not sign anything away, for anybody.
Two clocks run independently, and neither is affected by whether a center has paid.
Class notes are deleted 90 days after they are written, by default. A center can set a different period.
A withdrawn student's personal details are erased two years after withdrawal. The attendance record itself stays, because it has to — but the name, date of birth and contact details are removed from it.
Attendance and audit records are kept for at least the two years Kumon requires, and are never edited.
If a center stops paying or cancels, the data is not deleted. Access changes; the clocks above carry on exactly as they were. Nobody's child's record is held hostage to an invoice, and nobody's is deleted early to settle one.
The software holds information about children because that is what it is for — but it is given to us by the center, never collected from a child. A child is never asked to create an account, type their details or answer anything. A student scanning their own folder at the front desk produces a time and a sticker code, nothing more.
The center's relationship with the family, and any permission required for it, sits with the center.
In the United States.
Parents and guardians: ask your center first — they hold the relationship and can act immediately.
Centers: email us and we will help with anything you cannot do from inside the app, including exporting or deleting a center's data in full.
Contact: the address shown on the sign-in screen and in Settings → Get help.
If this page changes in a way that affects what we do with personal information, centers will be told before it takes effect rather than after. The date at the top always reflects the current version.