Privacy Policy
Last Updated: January 20, 2026
1. Introduction
ParentPeers ("we," "us," or "our") operates a platform that connects parents and caregivers ("Seekers") with experienced parent guides ("Guides") who have firsthand experience raising children with specific conditions. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) for California residents, and other applicable U.S. federal and state privacy laws.
By using ParentPeers, you consent to the data practices described in this policy. If you do not agree with our policies, please do not use our services.
2. Information We Collect
2.1 Information You Provide Directly
Account Information:
- Name and email address
- Phone number (optional)
- Profile photo
- Password (stored securely using bcrypt hashing)
Guide Profile Information (for Guides only):
- Professional headline and biography
- Information about your child(ren), including age and diagnosis year
- Conditions you have experience with (e.g., autism, ADHD, Down syndrome)
- Topics you can help with
- Introductory video (uploaded to our cloud storage)
- Availability schedule and timezone
- Hourly rate and session preferences
Booking and Session Information:
- Booking details (date, time, duration)
- Messages exchanged with Guides or Seekers
- Reviews and ratings
- Session outcome information
Payment Information:
- Payment card details (processed securely by Stripe; we do not store full card numbers)
- Billing address
- Transaction history
- For Guides: Bank account information for payouts (managed by Stripe Connect)
2.2 Information Collected Automatically
Device and Usage Information:
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Pages visited and features used
- Date and time of access
- Referring website
2.3 Information from Third-Party Services
Google OAuth (if you sign in with Google):
- Google account ID
- Email address
- Name
- Profile picture URL
- Email verification status
Stripe (Payment Processing):
- Payment confirmation and status
- Stripe account status for Guides
Daily.co (Video Sessions):
- Session participation data (join/leave times)
- Session duration
- Note: Video calls are NOT recorded
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing Our Services
- Creating and managing your account
- Facilitating connections between Seekers and Guides
- Processing bookings and payments
- Enabling video sessions
- Sending booking confirmations, reminders, and notifications
3.2 Improving Our Services
- Analyzing usage patterns to improve user experience
- Developing new features
- Troubleshooting technical issues
3.3 Safety and Security
- Verifying Guide applications
- Detecting and preventing fraud
- Enforcing our Terms of Service
- Responding to user reports and disputes
- Maintaining audit logs for security purposes
3.4 Communications
- Sending transactional emails (booking confirmations, reminders)
- Responding to inquiries and support requests
- Sending service-related announcements
3.5 Legal Compliance
- Complying with applicable laws and regulations
- Responding to legal requests and preventing harm
4. Legal Basis for Processing (GDPR)
For users in the EEA, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services to you
- Legitimate Interests: Processing for fraud prevention, security, and service improvement
- Legal Obligation: Processing required by applicable laws
- Consent: Where you have given explicit consent (e.g., marketing communications)
5. Information Sharing and Disclosure
We may share your information in the following circumstances:
5.1 With Other Users
- Guide profiles (headline, bio, conditions, ratings, availability) are visible to Seekers
- When you book a session, your name and contact information are shared with the Guide
- Messages are shared between booking participants
- Reviews are publicly visible on Guide profiles
5.2 With Service Providers
We share information with third-party service providers who help us operate our platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing and Guide payouts | Name, email, payment details, transaction amounts |
| Daily.co | Video call infrastructure | Session tokens, participant IDs, session duration |
| Google Cloud Storage | Video storage for Guide intro videos | Uploaded video files |
| Email Service (SMTP) | Sending transactional emails | Email address, name, booking details |
5.3 For Legal Reasons
We may disclose your information if required by law or if we believe disclosure is necessary to:
- Comply with legal process or government requests
- Protect our rights, privacy, safety, or property
- Prevent fraud or other illegal activities
- Protect the safety of any person
5.4 Business Transfers
If ParentPeers is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
6. Cookies and Tracking Technologies
6.1 What We Use
ParentPeers uses minimal cookies and tracking technologies. We primarily use browser localStorage to store authentication tokens for your session.
6.2 Types of Storage
| Type | Purpose | Duration |
|---|---|---|
| localStorage (accessToken) | Authentication - keeps you logged in | 15 minutes (refreshed automatically) |
| Essential Cookies | Security and session management | Session-based |
6.3 Third-Party Cookies
Our third-party service providers may use their own cookies:
- Stripe: For payment processing and fraud prevention
- Daily.co: For video session functionality
- Google: If you use Google Sign-In
6.4 Managing Cookies
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our services. Clearing localStorage will log you out of your account.
7. Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account Information | Until account deletion request + 30 days |
| Guide Profile | Until account deletion request + 30 days |
| Booking Records | 7 years (for tax and legal compliance) |
| Payment Records | 7 years (for tax and legal compliance) |
| Messages | 1 year after last activity, then anonymized |
| Reviews | Retained while Guide account is active |
| Audit Logs | 3 years |
| Intro Videos | Until Guide removes or account deleted |
8. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS
- Password Security: Passwords are hashed using bcrypt with strong salt rounds
- Token Security: Refresh tokens are hashed before storage; access tokens expire after 15 minutes
- Payment Security: Payment card data is handled entirely by Stripe (PCI DSS compliant)
- Access Controls: Database access is restricted and monitored
- Database Security: Row-Level Security (RLS) policies enforce data isolation
- Audit Logging: Security-relevant actions are logged for monitoring
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
9. Your Rights and Choices
9.1 All Users
- Access: View your account information in your dashboard
- Update: Edit your profile information at any time
- Delete: Request deletion of your account by contacting us
- Download: Request a copy of your data
9.2 EEA Residents (GDPR Rights)
If you are in the European Economic Area, you have the following additional rights:
- Right to Access: Obtain confirmation of whether we process your data and request a copy
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint: File a complaint with your local data protection authority
9.3 California Residents (CCPA Rights)
If you are a California resident, you have the following rights:
- Right to Know: Request information about categories and specific pieces of personal information collected
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the "sale" of personal information (Note: We do not sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
9.4 Exercising Your Rights
To exercise any of these rights, please contact us at support@parentpeers.com. We will respond to your request within 30 days (or 45 days for complex requests, as permitted by law).
10. International Data Transfers
ParentPeers is based in the United States. If you access our services from outside the U.S., your information will be transferred to, stored, and processed in the United States.
For users in the EEA, we rely on the following mechanisms to ensure adequate protection for international data transfers:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Service providers who participate in recognized data transfer frameworks
- Your explicit consent where appropriate
11. Children's Privacy
ParentPeers is designed for adults (parents and caregivers). We do not knowingly collect personal information from children under 13 (or 16 in the EEA). Our services are intended for parents seeking guidance about their children, not for use by children themselves.
If we learn that we have collected personal information from a child under the applicable age, we will delete that information promptly. If you believe we may have collected information from a child, please contact us at support@parentpeers.com.
12. Video Sessions and Recording
Video sessions on ParentPeers are facilitated through Daily.co. Important information about video sessions:
- No Recording: ParentPeers does not record video sessions. Recording is explicitly disabled.
- Session Data: We collect only session metadata (start/end times, duration) for service and billing purposes
- Privacy During Calls: What you discuss in sessions is between you and your Guide/Seeker
- Your Responsibility: You should not record sessions without the other party's consent
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top
- Sending an email notification for significant changes
We encourage you to review this Privacy Policy periodically. Your continued use of ParentPeers after any changes indicates your acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: support@parentpeers.com
Phone: +1 (833) 588-8475
For GDPR-related inquiries, you may also contact your local data protection authority if you are unsatisfied with our response.