Legal
Privacy Policy
Takes effect September 27, 2026 · version 2026-09-27
This policy explains what information Sitterz handles, why, how long we keep it, and the choices you have. Because Sitterz is software that a business runs on, it also explains the difference between the information we collect to run the platform and the information a business enters about its own families, children, and staff.
The short version: for your account with us, we are responsible. For the records inside a business's workspace, that business is responsible and we act on its instructions. We never sell information, never use it for advertising, and never use it to train an AI model. If your child's records are held by a business, that business is who to contact — and we will help it answer you.
1. How to read this policy
Sitterz sells software to family-service businesses — babysitting, nanny, pet-sitting, dog-walking, elder-companion, tutoring, household-staffing and daycare businesses. That means information reaches us in two very different ways, and your rights differ depending on which one applies.
| Situation | Who decides what happens to the information | Where to look |
|---|---|---|
| You visit sitterz.com, ask for an invite, or run a business account with us | Sitterz decides. We are the controller. | Part 1, below |
| You are a family, a child, or a staff member whose records live inside a business's workspace | That business decides. Sitterz processes on its instructions. | Part 2, below |
If you are not sure which applies to you, the practical test is simple: if you found us through a business you already work with or send your child to, that business holds your records and is who to contact. We will help them, and we will pass your request to them.
2. Part 1 — Information Sitterz collects as controller
Account and business information
The name, email address, business name, and the kind of work selected at signup, plus authentication data — a hashed password, and, if enabled, an encrypted two-factor secret and hashed recovery codes. If you sign in with Google, we receive your Google account identifier, email address, name, and profile picture. We use the identifier, not the email address, to recognise you.
Billing information
Billing contact and email, subscription status, and the platform's own record of fees. We do not collect or store full payment card numbers. Card details go directly to our payment processor, and we hold only what it returns to us for display: card brand, last four digits, and expiry.
Agreement records
When you accept these documents we record who accepted, which document, which version, when, and the IP address the acceptance came from. That record is deliberately permanent — it is the evidence that an agreement was formed, and deleting it would destroy the only proof either of us has.
Security and operational records
Server logs and diagnostics generated as the Service runs. Rate-limiting counters, which are keyed on an IP address or an email address to stop password-guessing and abuse; these expire automatically. An append-only audit record of actions taken inside a workspace — who did what, to which record, and when. Security-notification emails include a coarse device description and an IP address reduced to a network block, such as “Chrome on macOS · 203.0.113.x”, which is deliberately not precise enough to track anyone.
Support and enquiries
What you send us by email, and what you submit through the contact or invite-request forms on sitterz.com.
Published-site visitor measurements
When a business publishes a website through Sitterz, a first-party, cookie-free beacon records a measurement of each page view so that business can see traffic in Web analytics. Per view we store: the path (query strings discarded), the referring site's hostname, campaign tags (utm_source, utm_medium, utm_campaign) from links the business published, a coarse device class (phone, tablet, or desktop), the browser and operating-system families without versions, an approximate country / region / city supplied by the hosting provider from the connection (often the internet provider's town, not the visitor's), and a visitor identifier that is a daily-rotating hash of the connection and browser. Engagement pings, when they fire, store a scroll milestone (25, 50, 75, or 100 percent), time on the page in whole seconds capped at 30 minutes, a named button click, or the hostname of an outbound link — never the full URL. The raw IP address and user-agent are used in memory to compute that hash and the coarse families, and are never stored. Announced bots are not recorded. When the visitor's browser sends a Global Privacy Control or Do Not Track signal, we skip even this first-party counting and the visit is not recorded at all. These measurements are that business's, kept for 400 days, and are not used to identify a person across days or across businesses.
sitterz.com visitor measurements
The same first-party, cookie-free beacon runs on sitterz.com so Sitterz can see traffic to its own marketing site. The columns, the 400-day retention, and the Global Privacy Control / Do Not Track skip are the same as Published-site visitor measurements. These rows are Sitterz's, kept apart from any customer's book, and are not used to identify a person across days.
3. Why Sitterz uses that information
We use the information in Part 1 to provide, secure, support, and improve the Service; to authenticate you and protect accounts; to process subscription and transaction fees; to communicate with you about your account, security, and changes to these documents; to detect and prevent abuse and fraud; to keep the financial and agreement records the law requires us to keep; and to respond to legal process.
We send account, security, and service messages because they are necessary to provide the Service; you cannot opt out of those while you hold an account. Any marketing email carries a working unsubscribe link, and unsubscribing does not affect service messages.
4. Part 2 — Information inside a business's workspace
When a business uses Sitterz, it enters records about its own clients, the families it serves, the children and pets in its care, and its own staff. That business decides what to collect, why, who may see it, and how long it stays. We act only on that business's instructions. We do not decide what goes in, we do not use it for our own purposes, and we do not use it to make any judgment about the people it describes.
What a workspace can contain
- Household and family records — names, address, phone, email, emergency contacts, the family's own care instructions and preferences, and the people a family names on its pick-up list.
- Child records — a name, a preferred name, an approximate age from a birth year, pronouns and the language a family says it speaks in the family's own words, and free-text notes the family or the business writes.
- Pet records — name, species and breed as the family described them, notes, and the family's vet contact details.
- Attendance, check-in and daily logs — arrival and departure times, who a child was collected by as typed by staff, and entries for meals, naps, nappy or toilet changes, activities, notes and photos.
- Photographs and documents — photos of children or visits, household documents, and staff-uploaded certificates or licences.
- Staff records — name, email, phone, position, availability, uploaded documents, and an hourly rate.
- Bookings, visits, invoices, payments, and messages between the business and its families.
What the Service deliberately does not hold
These are not oversights. Each is enforced in the software, and adding one would be a decision, not an accident.
- No full date of birth for a child. The Service stores a birth year, so that someone meeting a child knows roughly who they are meeting. A full date of birth is a government-grade identifier for a minor and the Service has no field for one.
- No Social Security number, date of birth, home address, or bank or routing number for staff. These are blocked at the level of the data model, and a build fails if one is added.
- No medical, allergy, medication, immunisation, dosage, or symptom field. There is no such field anywhere, and importing a spreadsheet whose column headings look like one causes the Service to drop that column and tell the operator it did.
- No location tracking of any person. A check-in is a timestamp. The application blocks location access at the browser level, and location data embedded in a photograph is stripped in the browser before the photo is ever uploaded.
- No biometric information. The Service does not create, collect, capture, or store a scan of face or hand geometry, a fingerprint, a voiceprint, or a retina or iris scan, and does not use a photograph to generate a biometric identifier or template. There is no face recognition, face grouping, or auto-tagging.
- No score, rating, ranking, or assessment of any person. Sitterz never computes a judgment about a caregiver, a family, or a child.
The Service provides no health-data field and never classifies, interprets, or acts on health information. It cannot, however, stop a family or a business from typing something health-related into a free-text note — “carries an inhaler, in the blue bag” is exactly the kind of thing families write, and the field exists so they can. Where that happens, the note is the business's record, held under its instructions and subject to the protections in this policy and in our Data Processing Addendum.
Exercising your rights over records in a workspace
The business that holds your records is responsible for answering your request. Contact it first. If you contact us instead, we will pass your request on and help that business answer it, and we will not answer it ourselves without its instruction — we have no way to confirm what it agreed with you.
5. Children's information
This deserves a plain statement, because the product holds records about children.
- Sitterz is business software. It is not directed to children, is not intended for use by children, and has no feature designed to appeal to children.
- Children do not have accounts. There is no child login, no child session, and no child credential anywhere in the Service. Our Terms prohibit a business from provisioning one, and prohibit anyone under 18 from holding credentials at all.
- Sitterz collects nothing from a child. Information about a child reaches the Service because an adult — the business, or the child's own parent or guardian — types it in as part of that business's record-keeping.
- Sitterz does not obtain parental consent and does not verify it. Obtaining any notice, consent, or photo release that the law requires is the business's responsibility, and our Terms require the business to warrant that it has done so before entering a child's information or uploading a child's photograph.
- Children's information is never used for advertising, for profiling, or to train any AI model. It is used to provide the Service to the business that entered it, and for nothing else.
- Sitterz never sells information about a child, and never shares it for advertising of any kind.
If we learn that someone under 18 has created an account, we will close it and delete the associated account information within 30 days, subject to routine backup expiry.
A parent or guardian who wants to see, correct, or delete a child's record should contact the business that holds it. We will help that business respond.
6. What Sitterz never does with information
- We do not sell personal information, and we have never done so.
- We do not share personal information for cross-context behavioural advertising, and we do not use it for targeted advertising.
- We do not use personal information to profile anyone, or to make automated decisions that produce legal or similarly significant effects.
- We do not use your information, or the information in your workspace, to train, fine-tune, or improve any artificial-intelligence model — ours or anyone else's — and we grant no provider the right to do so. Engaging a model provider under terms that prohibit training on what we send is a condition of using it at all.
Two honest qualifications on the last point. A model provider generally retains a limited amount of what it receives for its own abuse monitoring, as every provider does; that is not training. And separately, we look at aggregated, de-identified usage measurements — counts and timings, never content about a person — to understand whether the Service is working. That aggregated use excludes child records, daily logs, photographs, free-text notes, and incident notes entirely. Sitterz platform administrators can also view a business's own operational and revenue metrics — never child records, daily logs, photographs, free-text notes, or incident notes — through an internal console in which every such view is written to an audit record.
Where we create aggregated and de-identified data, we commit publicly to maintain and use it only in de-identified form, not to attempt to reidentify it except to test that the de-identification works, to contractually require the same of any recipient, and to monitor compliance. The same commitment appears under Your data in our Terms of Service.
No feature of the Service currently sends any information to an AI model. The AI Features Schedule lists every such feature; it is empty today, and a feature that uses a model is added there — with exactly what it receives — before it ships.
8. How long information is kept
The retention periods below are the ones we publish and hold ourselves to. A business can ask us to delete sooner, and some of it can be deleted on request at any time.
Retention schedule
| Information | Kept for | Measured from |
|---|---|---|
| Children's daily logs, photographs, and attendance records | 12 months | The family leaving the business |
| Household profiles, family and child records, pick-up lists, and messages | While the family is active, then 12 months | The family leaving the business |
| Staff records | While the person is on the roster, then 12 months | Removal from the roster |
| Invoices, payments, refunds, disputes, and the platform's fee ledger | 7 years | End of the tax year of the transaction |
| Billing and renewal-consent records | The longer of 3 years or 1 year after the account closes | Collection |
| Agreement acceptance records, including the IP address | Life of the account, then 7 years | Account closure |
| Audit records of actions inside a workspace | Life of the workspace; removed in full when the business leaves | — |
| Login credentials | Deleted with the family or the business | — |
| Rate-limiting counters | Expire automatically, within days | Creation |
| Website visitor measurements on a business's published site | 400 days | The visit |
Two honest notes on this schedule. First, it is carried out by hand today — a scheduled job enforces only the last two rows, and the rest is executed by us on a schedule until that job covers them. Second, the audit record cannot be edited or partially removed: each entry is cryptographically chained to the one before it, so changing any part of any entry would break the chain and destroy the integrity of the whole log. Audit entries hold operational metadata — who acted, on which record, when — and not the substance of the records themselves, which are deleted normally.
Backups expire on their own rotation, so deleted information can persist in a backup for a bounded period after deletion. We do not restore a backup to recover something a person asked us to delete.
9. How information is protected
The measures we actually operate, described plainly:
- Separation between businesses is enforced by the database, not by application code. Every workspace table carries a row-level security policy that the database applies to every query.
- Encryption in transit using TLS; encryption at rest through our hosting provider.
- Passwords are hashed and never stored in a readable form. Two-factor secrets are encrypted. Recovery codes are stored only as hashes. Session cookies are signed.
- Uploaded files are stored privately and served only through short-lived signed links. Location data in a photograph is removed in the browser before upload.
- An append-only, cryptographically chained audit record of actions inside a workspace.
- Role-based access, least privilege on production systems, and a documented incident-response procedure.
Our security programme is aligned to the NIST Cybersecurity Framework 2.0 and the CIS Critical Security Controls. We do not hold a SOC 2 report or any security certification today, and we will say so plainly rather than imply otherwise.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. If there is a security incident
If we determine that a security incident has affected personal information we process for a business, we will notify that business without undue delay and give it the information reasonably necessary to meet its own notification obligations. The specific timeline we commit to is in our Data Processing Addendum.
The business decides whether and how to notify the people affected and any regulator — it holds the relationship and the context, and we do not. Where the law requires us to notify individuals or regulators directly, we will.
We will describe what happened once we know it, rather than guessing early and correcting later.
11. Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you and how we use it; to get a copy of it; to correct it; to delete it; to opt out of sale, sharing, targeted advertising, and certain profiling; and to be free from discrimination for exercising any of these rights. We do not sell or share personal information or use it for targeted advertising, so those opt-outs have nothing to act on — but the right exists and we will honour it.
These rights are recognised in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and elsewhere, with details that vary by state.
How to make a request
Email support@sitterz.com, or write to us at the address in Changes, and how to reach us. We will acknowledge promptly and respond within 45 days, and will tell you if we need a further 45 days. We will take reasonable steps to verify who you are before acting, and we may need to ask for information to do that — we use it only to verify the request.
An authorised agent may act for you with written permission that we can verify.
If your request concerns records held inside a business's workspace — your family's records, your child's records, or your own staff record — please contact that business. It decides those questions, not us. If you cannot reach it, tell us and we will pass your request on and help it respond.
If we say no
You may appeal by replying to our decision or emailing support@sitterz.com with “Appeal” in the subject line. We will review and give you a written answer, with our reasons, within 45 days. If we deny the appeal we will give you a way to complain to your state Attorney General.
Browser opt-out signals
We honour the Global Privacy Control and Do Not Track signals as a valid opt-out for the browser or device that sends one. We do not sell or share personal information. We go one step further: when a browser sends either signal, we skip even our own first-party published-site page counting, and that visit is not recorded at all.
12. Notice at collection — categories
The categories of personal information we have collected in the last 12 months, in the terms California law uses. Retention for each is in How long information is kept. We disclose these categories to the service providers on our Subprocessor List for the business purposes described in Why Sitterz uses that information and Part 2. We have not sold or shared any category, and we do not use sensitive personal information for any purpose beyond providing and securing the Service.
| Category | Do we collect it? | Examples in Sitterz |
|---|---|---|
| A. Identifiers | Yes | Name, email address, postal address, phone number, account identifier, IP address |
| B. Customer records (Cal. Civ. Code §1798.80) | Yes | Name, address, telephone number, billing contact |
| C. Protected classification characteristics | Only if typed | A birth year gives an approximate age; a free-text pronouns or language field may reveal a characteristic. There is no field that asks for one. |
| D. Commercial information | Yes | Subscription and plan, invoices, payment records, services a business offers |
| E. Biometric information | No | None. No face, fingerprint, or voice data is created or stored. |
| F. Internet or network activity | Yes | Server logs, diagnostics, security events, rate-limiting counters, first-party published-site measurements (path, referrer host, campaign tags, device/browser/OS families, coarse city/country from the host) |
| G. Geolocation data | No precise location | No location of any person is collected. An IP address implies a coarse region, as it does for every website. On a business's published site, the hosting provider's country/region/city estimate from the connection may be stored — often the internet provider's town, not the visitor's. |
| H. Audio, visual, or similar information | Yes | Photographs of children, pets, or visits, and documents, uploaded by a business or a family |
| I. Professional or employment information | Yes | A staff member's position, availability, uploaded certificates, and hourly rate, entered by their employer |
| J. Non-public education information | No | None. |
| K. Inferences drawn to create a profile | No | None. Sitterz draws no inferences and builds no profiles about anyone. |
| Sensitive personal information | Only if typed | Account credentials, which we hold hashed. Free-text notes may contain health information a family or business chose to write. We use none of it beyond providing and securing the Service. |
Sources: you, the business whose workspace holds the record, the families and staff that business invites, and our own systems.
15. Where information is held
Sitterz is a United States company and the Service is offered only in and to the United States. Information is stored and processed in the United States by the providers on our Subprocessor List.
The Service is not offered to people in the European Economic Area, the United Kingdom, or Switzerland, and our Terms of Service prohibit a business from entering personal data of people in those territories. We therefore do not rely on any international transfer mechanism, and the General Data Protection Regulation and UK GDPR do not apply to our processing. If that changes, we will update this policy before it does, not after.
16. Changes, and how to reach us
We may update this policy. For a material change we will give at least 30 days' notice by email to account owners and inside the Service, and the date at the top will change. Changes apply going forward.
Sitterz LLC, a Colorado limited liability company. [our notice address — to be completed before launch]
Privacy questions and rights requests: support@sitterz.com
This policy is published as part of the Sitterz launch program and has not yet been reviewed by outside counsel. It describes what the software actually does today, including where a stated commitment is currently carried out by hand rather than by code — see the notes under How long information is kept.
Questions about this document? Email support@sitterz.com.