Back to PlayPivot
COPPA & GDPR Compliant

Complete Privacy Policy

We believe families deserve transparency. This document details exactly how we handle and protect your information.

Updated: Feb 26, 2025 Version 1.0

1. Overview & Scope

PlayPivot Inc. is a youth activities directory service operating in the United States. We help parents and guardians discover, research, and connect with activities for children ages 0-18. This policy applies to our website, mobile apps, and all related services.

2. Information We Collect

We collect information to help families find the best programs:

  • For Parents: Name, email, zip code, account password, and payment info (via Stripe).
  • About Children: Age, general interests, and any special needs a parent explicitly chooses to share to find better matches.
  • Technical Data: IP address, device type, and basic usage logs for security and performance.

What we never collect:

  • • Children's emails
  • • Children's phone numbers
  • • Real-time geolocation
  • • Biometric data

3. COPPA Compliance

The Children's Online Privacy Protection Act (COPPA) is a federal law that protects children under 13. PlayPivot complies by:

Parental Consent

Requiring confirmation of age (18+) and explicit consent for data collection at signup.

Parental Access

Providing a dashboard for parents to view, edit, or delete any data linked to their family.

Data Minimization

Only collecting the minimum necessary information to provide the service.

No Behavior Profiling

We do not create behavioral profiles of children for advertising.

4. Your Rights & Control

You have total control over your family's data. You can exercise these rights instantly via your Parent Portal:

  • 1
    Right to Access (GDPR/GDPR)

    Download a full JSON export of all information linked to your account.

  • 2
    Right to Erasure / Withdraw Consent

    Permanently delete your entire profile or choose to specifically withdraw consent and clear children's data while keeping your account active.

5. Data Security

We use industrial-grade AES-256 encryption at rest and TLS 1.2+ for all data in transit. Our database is hosted with Supabase (Google Cloud Infrastructure), protected by row-level security (RLS) policies that ensure only parents can access their own children's information.

6. Data Sharing

We DO NOT sell your data or your children's data to third parties. We only share information with essentials providers (Stripe for payments, Supabase for storage) under strict data processing agreements that prohibit them from using your data for their own marketing.

7. Data Retention

We keep family profile data as long as your account is active. Inactive accounts (no login for 24 months) are automatically flagged for deletion. Backups are rotated every 90 days, meaning your data is fully purged from our systems within 120 days of account deletion.

Questions?

If you have any concerns regarding your child's data or our privacy practices, please contact our Data Protection Officer immediately.

privacy@playpivot.org

PlayPivot Inc. • Las Vegas, NV 89144