brightwheel Security FAQs (2023)

Trust is a key building block in brightwheel’s promise to put you first, with ongoing improvements to ensure the safety, privacy, security, and reliability of your experience. We are proud to offer:

  • Enhanced account safety with two-factor authentication, strict password requirements, and cloud-based storage using Amazon Web Services.

  • A stringent Privacy Policy that dictates no personal information can be sold to third parties.

  • Highest financial data security and compliance levels (PCI Level 1) for invoicing and processing payments, so no confidential banking information is stored on brightwheel.

  • Ongoing reliability with 99.9% uptime and fraud protection with 24x7 monitoring by a dedicated in-house team. For a real-time update on brightwheel’s availability, see here.

If you need to print the FAQs contained in the article for your program, right-click in your browser window and select Print!

Table of Contents

  • What is brightwheel's approach to data security?

  • What is brightwheel's data infrastructure?

  • What is brightwheel's approach to application security?

  • Does brightwheel sell/share data with third parties?

  • How does brightwheel safeguard my billing and payment information?

  • Is brightwheel HIPPA or FERPA compliant?

    (Video) Brightwheel: Product Demonstration

  • Does brightwheel use single sign-on?

  • How would brightwheel handle a data breach?

  • How does brightwheel handle a fraudulent charge(s)?

  • What access do parents have when they leave a program?

  • What is the best way to manage staff accounts when they leave a program?

  • What are some tips administrators, staff, or families can follow to protect their accounts and keep their data secure?

    • Tips for Admins, Staff, and Families

    • Tips for Admins and Staff

    • Additional Tips for Admins Only

What is brightwheel's approach to data security?

Brightwheel has the largest engineering team in the early education industry. In addition to 24x7 monitoring of all production data and infrastructure, there is an ongoing investment to employ the latest technology to keep your data safe.

What is brightwheel's data infrastructure?

All brightwheel application servers and databases are hosted within Amazon Web Services (AWS) data centers. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. AWS data center operations are accredited under:

(Video) Brightwheel: How to Add Staff Members

  • ISO 27001

  • SOC1 and SOC2 SSAE 16/ISAE 3402 (Previously SAS 70 Type II)

  • PCI Level 1

  • FISMA Moderate

  • Sarbanes-Oxley (SOX)

Data center staff monitor electrical, mechanical, and life support systems and equipment so issues are immediately identified. Preventative maintenance is performed to maintain the continued operability of equipment.

View AWS SOC Compliance information here.

What is brightwheel's approach to application security?

All brightwheel software is under continuous review. Brightwheel also undergoes periodic third-party security audits to ensure the safety of our application and infrastructure.

Does brightwheel sell/share data with third parties?

We do not sell any personal information to third parties, and your personal data is only used in accordance with our Privacy Policy. Programs can upload data, and they can access, download, or request that data from us at any time.

How does brightwheel safeguard my billing and payment information?

Brightwheel has partnered with a payment processor (Stripe) that is certified as PCI Level 1, the most stringent level of certification available. See their security site for detailed information about their security measures.

No one at brightwheel has any access to any customer banking records, and all families using brightwheel for payment have to go through a two-step authentication process to verify their accounts.

(Video) Brightwheel: Mobile App Basics for Teachers

Is brightwheel HIPPA or FERPA compliant?

Brightwheel enables programs to stay compliant with FERPA. The Terms of Service and Privacy Policy have been written to protect student information in accordance with the FERPA requirements.

For HIPAA guidance, it is recommended you contact a HIPAA compliance officer directly. Although brightwheel meets many of the requirements of HIPAA, brightwheel does not certify HIPAA compliance for its platform. It’s important to note that the U.S. Department of Health & Human Services (HHS) has stated that HIPAA regulations do not apply to the type of information stored and collected in brightwheel or similar software. HHS explains that HIPAA does not apply to schools in most cases because a school: “(1) is not a HIPAA covered entity or (2) is a HIPAA covered entity but maintains health information only on students in records that are by definition “education records” under FERPA and, therefore, is not subject to the HIPAA Privacy Rule.

Does brightwheel use single sign-on?

At this time, single sign-on is not a feature available on the brightwheel application. However, brightwheel is the most secure all-in-one childcare and preschool software, setting the standard as the first and only early education app to offer two-factor authentication at sign-in for enhanced account protection.

How would brightwheel handle a data breach?

There is 24x7 monitoring by an in-house dedicated team, and if there is any suspicious activity observed, there are protocols in place to investigate and take action immediately, depending on the situation.

To catch any unusual account activity, there are email notices sent to admins anytime a new admin is added to the program and to parents anytime a new student contact has been added for their student. These email notices are immediate security measures in place to alert you of any unusual activity. Ensure you review these security notices to determine the appropriate steps to follow in the event you do not recognize the activity.

How does brightwheel handle a fraudulent charge(s)?

We have a full team dedicated to monitoring payments and use industry-leading software to pre-emptively block high-risk charges. Our payment processor, Stripe, uses a machine learning model and has a vast network of data to determine if cards or individuals have been involved in fraud or disputes in the past.

If a payer uses a fraudulent card that is later disputed, we will work with the program one-on-one to determine the best path forward. We understand how devastating this scenario can be, so our payment operations team looks at each case individually and communicates with your program to support you.

What access do parents have when they leave a program?

Activated parents can access their accounts until they are deactivated or removed from the student’s profile by the program. Activated parents and admins can request a parent’s account be deactivated, but the parent will ultimately have to finalize the deactivation using a link sent to them via email. Admins can remove a parent from a student’s profile at any time as well.

What is the best way to manage staff accounts when they leave a program?

We suggest that a program administrator export any profile attachments and timecard/payroll reports needed for the staff member and then delete the profile.

It’s important to make sure that you export any information needed prior to deleting the profile to make this process as smooth as possible. It’s also important to note that once a staff member has been removed from brightwheel, their name will no longer appear in the drop-down menu when viewing Timecards and Payroll reports. If a report needs to be run after an employee has already been removed, please see our payroll for removed staff resource.

What are some tips administrators, staff, or families can follow to protect their accounts and keep their data secure?

💡Tips for Admins, Staff, and Families

What actions can I take to keep my account as secure as possible?

(Video) Brightwheel: Learning Observations

  • Keep your brightwheel app up to date to ensure you are using the most secure version of brightwheel. It can be updated manually or set up for automatic updates to be downloaded each time a new version is released.

  • Use two-factor authentication at sign-in and do not disable it. This is a security best practice and is designed to make sure that you’re the only person who can access your account, with the use of two different forms of verification.

  • Frequently rotate passwords and make sure it meets minimum security requirements. Ensure it’s unique, long, and memorable with symbols, letters, and numbers.

  • Set up a passcode on your device’s lock screen to prevent anyone from being able to just pick up your device and dig into your data.

💡Tips for Admins and Staff

How should I manage any photos and videos I’ve taken on my personal device and uploaded to brightwheel?

We recommend establishing a weekly practice of deleting all photos and videos you’ve taken on your personal device once they’ve been uploaded and shared to a student’s feed. This is a best practice to ensure photos and videos that don’t need to be don’t continue to be stored on your device.

What are the best practices for shared logins?

We strongly recommend you avoid sharing login information at your program. If multiple staff are using the same device, use Room Device Mode. If staff already share a login, remember to change passwords at the time of termination.

💡Additional Tips for Admins Only

How can I best manage staff access at my program?

Review our Teacher and Staff Permissions resource to understand what role options are available to use in your program and then assign staff the appropriate role depending on your program’s needs.

How can I leverage brightwheel further to improve my program’s security and offerings?

(Video) Mark Cuban And Chris Sacca Fight Over A Deal With Brightwheel | Shark Tank US | Shark Tank Global

If you’re not already using brightwheel Billing, we highly recommend implementing this feature in your program! You can encourage families to pay online using brightwheel, and they can add their own payment details. This way, families directly enter their payment details, and your program is not responsible for storing their information or safeguarding checks/cash until deposited.

If you have questions related to brightwheel security or similar topics, please contact our Support team for further assistance!


How secure is brightwheel? ›

Highest financial data security and compliance levels (PCI Level 1) for invoicing and processing payments, so no confidential banking information is stored on brightwheel. Ongoing reliability with 99.9% uptime and fraud protection with 24x7 monitoring by a dedicated in-house team.

How do I remove my child from brightwheel? ›

We recommend downloading any billing information, such as your Tax Summary, before removing yourself.
  1. Log in to your account on the web.
  2. Select My Children and click on the student profile to be removed.
  3. Select the Profile tab.
  4. Scroll down to the Contacts section and click Edit.

How do I change my brightwheel pin? ›

Customize Your Check-in Code

Here's how to do this from your profile in the app: Tap the Edit icon next your check-in code. You will see a red-orange screen with your current code displayed. Enter a new 4-digit code.

Why is my brightwheel app not working? ›

The most likely reason the platform will not load is due to a local network or connectivity issue. In order to have a good experience using brightwheel, you should at least have a 50Mbps per second connection.

Can parents send pictures on brightwheel? ›

Parent contacts can upload photos of activities, milestones, and more! Student contacts that have been added as a Parent contact may have the ability to add a photo of a student to the student's feed using the mobile app. This allows contacts to share photos of activities, projects, milestones, and more!

What can parents see on brightwheel? ›

Depending on the school's settings and the activities they choose to log, parents and families can see check-in/out records, photos, videos, food & potty tracking, and learning milestones! To view the student's feed on the mobile app, simply tap on the student's name from the home screen.

Does brightwheel report to the IRS? ›

The IRS form 1099-K is issued for all programs that process more than $20K and 200 ONLINE transactions in the given tax year. This form reports the total gross volume of online payment transactions made through brightwheel. Brightwheel will mail a 1099-K for each program that meets these requirements by January 31st.

Who can see brightwheel messages? ›

Please note: Only parents listed on the child's profile will be able to view the messages sent between parents and staff. Other parents not listed as a contact on the child's profile will not be able to view these messages.

What is the difference between parent and family on brightwheel? ›

Parents can send and see messages, Family can only send messages, and Approved Pickups/Emergency Contacts cannot see or send messages at all.

Can you delete a message on brightwheel? ›

Similar to text messages or emails, while brightwheel messages can be deleted by Admins, they can't be edited once they're sent.

Can I check my hours on brightwheel? ›

Log in on the web. Navigate to the Reporting section. Click on the Timecards option under Staff Reports.

Can you use a credit card on brightwheel? ›

Brightwheel also allows payers to pay via credit and debit cards. Accepting credit card payments is disabled by default, but this option can be turned on in the Billing Settings. Turn this setting ON if you would like to accept credit card and debit card payments.

Why can't i log into brightwheel? ›

This can occur if an incorrect code is entered too many times in a small timeframe and is a precaution we will take to ensure no one is trying to enter your account besides you. If you have tried all available options to get logged in but are still having trouble, please Contact Support for assistance.

Can parents see calendar on brightwheel? ›

Use the built-in calendar to schedule events. Parents can view this calendar anytime from their child's profile. There is no need to have a separate calendar to keep track of all the important events at your program because brightwheel has one built-in!

Is there a way to download all photos from brightwheel? ›

Photos and videos on a child's feed can be downloaded from within the app or on the web. Simply locate the media to be downloaded and tap the download icon.

Can I sue my parents for posting pictures of me? ›

An ordinary photo, or photos that may be embarrassing for kids but common for parents to take-- such as nude baby photos-- likely won't get very far in a court. "It would be a hard case in the U.S." Chander said. "There'd be no special privacy invasion claims a child would have against a parent."

Can parents post pictures of their kids without permission? ›

People and businesses cannot post your child's likeness for any commercial purposes without the express, written permission of the child's guardian. Contact your child's school, daycare, and any place your child regularly visits to request no photos of your child be reproduced by the institution.

Can someone take photos of my child without permission? ›

There is no law preventing people from taking photographs in public. This includes taking photos of other people's children. If you are taking photographs from private land, you need to have the land owner's permission.

What can Parental Controls see? ›

Parental controls are features or software that allow you to monitor and restrict what a person does online. There are a wide variety of programs that do such things as block and filter websites and content, record their activities, limit their time online, and view their browsing history and communications.

What do Parental controls allow you to see? ›

Parental controls allow parents to filter and block websites and apps, limit the amount of time spent on online devices, restrict screen time, and even track browsing history minute-by-minute.

What can Smart family see? ›

Verizon Smart Family does, however, allow you to:
  • See incoming and outbound text and call activity from any child device on the account.
  • See the times associated with each text and call received.
  • View contact rank (ranking is based on the frequency of texts and calls in a 7-day period).

How does IRS verify child care expenses? ›

The IRS goes about verifying a provider's income by evaluating contracts, sign-in sheets, child attendance records, bank deposit records and other income statements. Generally, the actual method the IRS uses to verify a child-care provider's income is determined on a case-by-case basis.

What Money Can the IRS not touch? ›

Federal law requires a person to report cash transactions of more than $10,000 to the IRS.

Can you get audited for donations? ›

Claiming too many charitable donations

The government offers income tax deductions to encourage charitable giving—after all, helping others is beautiful. If you donate what appears to be too much, though, your charitable donation deductions can trigger an audit.

Can someone read all your text messages? ›

Yes, it's definitely possible for someone to spy on your text messages and it's certainly something you should be aware of – this is a potential way for a hacker to gain a lot of private information about you – including accessing PIN codes sent by websites used to verify your identity (such as online banking).

Can I read my child's text messages? ›

View Text Message With Google Family Link. Google family link can allow you to see your kid's text messages, SMS text, and social media texts and block some activities. Step 1. Download the Google family link (parent) on your device.

Can text messages be tracked and read? ›

Text messages trackers can monitor when a text message was queued, sent, and delivered successfully on Android or iOS. SMS trackers are typically external applications that can track exactly where an applicable message is throughout the sending process.

What is the difference between parent 1 and parent 2? ›

For example, if you know that match is your maternal aunt, and you see that we assigned her to parent 1, then parent 1 is your maternal side–which makes parent 2 your paternal side. Parent 1 in ethnicity inheritance will always be parent 1 in your matches, and parent 2 in one will be parent 2 in the other.

What is a lighthouse parent? ›

Unconditional love, not unconditional approval: lighthouse parents believe in giving their child unconditional love, but they will set boundaries and disapprove of unacceptable behaviour.

How much does brightwheel premium cost? ›

Brightwheel's pricing beings at $125 USD per month for 50 children. They offer a free trial and also have a free version.

Can delete text messages be recovered? ›

If you simply delete a text, they are still available. And there are common forensics tools used by both law enforcement and civil investigators to recover them.

How do I permanently delete unwanted messages? ›

Touch and hold the message you want to delete. Optional: To delete multiple messages, touch and hold the first message, then tap more messages. Tap Delete to confirm.

How can I check my employee hours? ›

Tools like Microsoft Excel and Google Sheets are widely used to track employee hours. Typically, employees will add their work hours each day and submit the timesheet for approval at the end of the week. Their total working hours will be calculated automatically if the spreadsheet is set up with the correct formulas.

How do staff check in on brightwheel? ›

Check-in via Quick Scan
  1. Log in to the staff brightwheel account on the app.
  2. Tap the ≡ menu in the top left corner.
  3. Tap the Check in/out button at the top of the menu.
  4. Use the QR scanner that's opened to scan the program's QR code and continue checking in.

How do I track payroll hours? ›

Businesses with hourly employees, for example, need to track employee hours for accurate payroll numbers.
  1. Pen and paper. ...
  2. Desktop or kiosk time clocks. ...
  3. Mobile apps. ...
  4. Geofencing and GPS tracking. ...
  5. Biometric clock-in. ...
  6. Browser plug-ins and URL tracking.
May 18, 2022

Does brightwheel charge a credit card fee? ›

Please Note: There may be processing fees associated with either payment method. Please contact the childcare provider for more details on the difference in credit card or ACH fees.

Does brightwheel do payroll? ›

Under Staff reports, select Payroll or Timecards. Leave the Select Employee field blank to run the report for all staff members. Select the needed date range. Click Apply to generate the report.

Can I be a parent and a teacher on brightwheel? ›

It is quite common across providers using brightwheel for parents or other student contacts to also operate as a teacher or staff member. In order to facilitate this, the user will be required to set up TWO brightwheel accounts. Each account offers a different level of access for a teacher compared to student contacts.

What is room device mode on brightwheel? ›

Room Device Mode

This feature allows: Administrators to lock the device by room, allowing multiple staff members to use the same device. Teachers assigned to a specific classroom will be able to check kids in and post activities without having to log into their own accounts.

Can admins see private calendars? ›

Why is this happening? Only administrators, who have either the Super Admin role or the Google Meet hardware privilege, have full access to all calendars in a domain and can see all event details. This occurs regardless of whether individual users have shared calendars with them.

How do I stop people from seeing my calendar? ›

  1. To prevent other users from seeing event details, you can set individual events as private. To do this, select Private in the Visibility section when you create an event.
  2. To manually select who can see your calendar, you can override the default sharing settings set by your administrator. To do this:

Can you delete a child from brightwheel? ›

With this in mind, deleting or erasing a student profile is not an option. Instead, administrators can use student enrollment statuses to organize and filter out archived students.

Who can see messages on brightwheel? ›

Send a Message on the App

Please note: Only Parents can see the messages in a student's profile. Family Contacts can send but not receive messages. Approved Pickups and Emergency Contacts have no access to messages.

How much does brightwheel cost per month? ›

Pricing Overview

Brightwheel's pricing beings at $125 USD per month for 50 children. They offer a free trial and also have a free version.

How much does daycare cost per week? ›

National average weekly child care rates
One childOne child
Child care center*$226$215
Family care center*$221$201
1 more row
Jun 15, 2022

Can you delete students on brightwheel? ›

With this in mind, deleting or erasing a student profile is not an option. Instead, administrators can use student enrollment statuses to organize and filter out archived students.

How do you get all your old photos back? ›

Restore photos & videos
  1. On your Android phone or tablet, open the Google Photos app .
  2. At the bottom, tap Library Trash .
  3. Touch and hold the photo or video you want to restore.
  4. At the bottom, tap Restore. The photo or video will be back: In your phone's gallery app. In your Google Photos library. In any albums it was in.

Does brightwheel charge a fee on payments? ›

It's important to note that brightwheel is not responsible for any overdraft or processing fees due to processed payments.


1. Brightwheel: Lessons
2. Brightwheel: Admin-Parent messaging
3. Brightwheel: Parent Notifications
4. brightwheel Review: My daycare rocks for using this!
5. Brightwheel: Web Basics for Teachers
6. Brightwheel: Teacher / Staff Sign-up
Top Articles
Latest Posts
Article information

Author: Kieth Sipes

Last Updated: 13/05/2023

Views: 6536

Rating: 4.7 / 5 (67 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Kieth Sipes

Birthday: 2001-04-14

Address: Suite 492 62479 Champlin Loop, South Catrice, MS 57271

Phone: +9663362133320

Job: District Sales Analyst

Hobby: Digital arts, Dance, Ghost hunting, Worldbuilding, Kayaking, Table tennis, 3D printing

Introduction: My name is Kieth Sipes, I am a zany, rich, courageous, powerful, faithful, jolly, excited person who loves writing and wants to share my knowledge and understanding with you.