Privacy Policy
DRAFT — Review with attorney before launch. Ensure COPPA compliance is verified by qualified counsel.
Last updated: [PLACEHOLDER — requires legal review before launch]
1. Data we collect
We collect the information you provide when creating an account (email address, password hash), child profiles (nickname, age range, avatar), subscription and billing data (via Stripe), and activity completion records tied to child profiles.
[PLACEHOLDER — requires legal review before launch]
2. How we use it
We use your data to provide the subscription service, send expedition packs and optional preference-based emails, process payments, detect fraud, and improve the product. We do not sell your data or use behavioural advertising.
[PLACEHOLDER — requires legal review before launch]
3. Third-party services
- Stripe — payment processing. Stripe stores your card details; we never see raw card numbers.
- Supabase — database and authentication. Data is stored in the EU West (Ireland) region. [PLACEHOLDER — requires legal review before launch]
- Resend — transactional email delivery.
- PostHog — product analytics. Data is self-hosted / EU-hosted. [PLACEHOLDER — requires legal review before launch]
4. Children's privacy (COPPA)
PPS is a service for parents. Children cannot create accounts. Child profiles are created and controlled by a parent and contain only a nickname, an age range (4–7 or 8–12 — never a birthdate), an avatar choice, and activity completion data. We never collect children's email addresses, and we do not use behavioural advertising. Parents may delete any child profile and all associated data at any time from account settings.
5. Data retention
We retain your account data for as long as your subscription is active or as required by law. You may request deletion at any time; see "Your rights" below.
[PLACEHOLDER — requires legal review before launch]
6. Cookies
We use only essential cookies required for authentication and payments. No tracking or advertising cookies.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, email privacy@parentpaleosociety.com.
[PLACEHOLDER — requires legal review before launch]
8. Contact
For privacy questions or data requests: privacy@parentpaleosociety.com