Privacy Policy
This document is current and complete for everyday use. We are awaiting final review by qualified counsel before removing the noindex directive. Substance is accurate; final wording may be tightened.
Last updated: June 16, 2026
1. Who we are
Parent Paleontology Society ("PPS", "we", "us") operates the subscription service at parentpaleo.org. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over it.
2. Data we collect
Account data: when you create an account we collect your email address and a hashed password (we never store your password in plain text).
Child profile data: you may create up to three child profiles per subscription. Each profile contains only a nickname, an age range (4–7 or 8–12 — never a birthdate or birth year), an optional avatar choice, and activity completion records. We never collect children's real names, email addresses, photos, or location data.
Subscription & billing: Stripe collects and processes your payment information. We receive only a customer reference, the subscription status, and the last four digits of your card to display in your account.
Communication preferences: we record your opt-in choices for optional emails (e.g., the Monday teaser, achievement notifications). The weekly Friday pack email is part of the service and is sent to all active subscribers.
Usage data: we record which packs were downloaded, which online activities were completed, and basic page-view analytics. We do not use behavioural advertising profiles.
3. How we use your data
- To deliver expedition packs and operate your account
- To process payments and prevent fraud
- To send transactional emails (welcome, weekly pack, payment receipts)
- To send preference-based emails you have opted into
- To improve the product through aggregated usage analytics
- To comply with legal obligations
We do not sell your data, share it with advertisers, or use it for targeted advertising.
4. Third-party services
- Stripe — payment processing. Stripe stores card details under its PCI-DSS-certified infrastructure. We never see raw card numbers. See Stripe's Privacy Policy.
- Supabase — database and authentication. Account data is stored in Supabase's US-East region under industry-standard encryption at rest and in transit.
- Resend — transactional email delivery. Resend processes your email address solely to deliver the messages we send.
- PostHog — privacy-respecting product analytics. Configured with essential-cookies-only persistence and IP anonymisation. We do not enable session recording or behavioural advertising features.
- Sentry — error monitoring. Captures technical error data (timestamps, stack traces) without personally identifying content.
- Vercel — hosting infrastructure. Standard server logs are retained for 30 days.
5. Children's privacy (COPPA)
PPS is a service for parents. Children cannot create accounts. Child profiles are created and controlled by a parent and contain only a nickname, an age range, an avatar choice, and activity completion data. We never collect children's real names, email addresses, photos, audio, location, or device identifiers tied to a child. We do not use behavioural advertising. Parents may view, edit, or delete any child profile and all associated data at any time from account settings, or by emailing privacy@parentpaleo.org.
Under the Children's Online Privacy Protection Act (COPPA), we obtain parental consent through verified payment as a condition of subscribing. If we ever extend the service to permit direct child interaction beyond parent-mediated activity completion, we will update this policy and seek additional parental verification at that time.
6. Data retention
We retain your account data for as long as your subscription is active. After cancellation we retain account data for 90 days to enable easy re-subscription, then delete or anonymise it, except where retention is required by law (e.g., financial records retained for seven years for tax purposes). You may request immediate deletion at any time via privacy@parentpaleo.org.
7. Cookies
We use essential cookies required for authentication, payment session continuity, and CSRF protection. We may also use privacy-conscious analytics to understand aggregate site performance and conversion health. We do not sell your data or use child profile data for advertising. Advertising or retargeting tags should not be enabled until our privacy and consent notices are updated for that use.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request a copy of your data in a portable format
- Delete your account and associated data
- Object to or restrict certain processing
- Withdraw consent for preference-based emails at any time
To exercise these rights, email privacy@parentpaleo.org. We will respond within 30 days.
9. Security
We use industry-standard encryption (HTTPS/TLS in transit, AES-256 at rest), enforce row-level security in our database to isolate each family's data, and follow the principle of least privilege for our staff and contractors. We will notify affected users without undue delay in the event of a data breach involving personal data.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email and noted at the top of this page. The "Last updated" date above always reflects the current version.
11. Contact
For any privacy questions or to exercise the rights listed above: privacy@parentpaleo.org