Legal

Privacy Policy

Takes effect September 27, 2026 · version 2026-09-27

This policy explains what information Sitterz handles, why, how long we keep it, and the choices you have. Because Sitterz is software that a business runs on, it also explains the difference between the information we collect to run the platform and the information a business enters about its own families, children, and staff.

The short version: for your account with us, we are responsible. For the records inside a business's workspace, that business is responsible and we act on its instructions. We never sell information, never use it for advertising, and never use it to train an AI model. If your child's records are held by a business, that business is who to contact — and we will help it answer you.

1. How to read this policy

Sitterz sells software to family-service businesses — babysitting, nanny, pet-sitting, dog-walking, elder-companion, tutoring, household-staffing and daycare businesses. That means information reaches us in two very different ways, and your rights differ depending on which one applies.

SituationWho decides what happens to the informationWhere to look
You visit sitterz.com, ask for an invite, or run a business account with usSitterz decides. We are the controller.Part 1, below
You are a family, a child, or a staff member whose records live inside a business's workspaceThat business decides. Sitterz processes on its instructions.Part 2, below

If you are not sure which applies to you, the practical test is simple: if you found us through a business you already work with or send your child to, that business holds your records and is who to contact. We will help them, and we will pass your request to them.

2. Part 1 — Information Sitterz collects as controller

Account and business information

The name, email address, business name, and the kind of work selected at signup, plus authentication data — a hashed password, and, if enabled, an encrypted two-factor secret and hashed recovery codes. If you sign in with Google, we receive your Google account identifier, email address, name, and profile picture. We use the identifier, not the email address, to recognise you.

Billing information

Billing contact and email, subscription status, and the platform's own record of fees. We do not collect or store full payment card numbers. Card details go directly to our payment processor, and we hold only what it returns to us for display: card brand, last four digits, and expiry.

Agreement records

When you accept these documents we record who accepted, which document, which version, when, and the IP address the acceptance came from. That record is deliberately permanent — it is the evidence that an agreement was formed, and deleting it would destroy the only proof either of us has.

Security and operational records

Server logs and diagnostics generated as the Service runs. Rate-limiting counters, which are keyed on an IP address or an email address to stop password-guessing and abuse; these expire automatically. An append-only audit record of actions taken inside a workspace — who did what, to which record, and when. Security-notification emails include a coarse device description and an IP address reduced to a network block, such as “Chrome on macOS · 203.0.113.x”, which is deliberately not precise enough to track anyone.

Support and enquiries

What you send us by email, and what you submit through the contact or invite-request forms on sitterz.com.

Published-site visitor measurements

When a business publishes a website through Sitterz, a first-party, cookie-free beacon records a measurement of each page view so that business can see traffic in Web analytics. Per view we store: the path (query strings discarded), the referring site's hostname, campaign tags (utm_source, utm_medium, utm_campaign) from links the business published, a coarse device class (phone, tablet, or desktop), the browser and operating-system families without versions, an approximate country / region / city supplied by the hosting provider from the connection (often the internet provider's town, not the visitor's), and a visitor identifier that is a daily-rotating hash of the connection and browser. Engagement pings, when they fire, store a scroll milestone (25, 50, 75, or 100 percent), time on the page in whole seconds capped at 30 minutes, a named button click, or the hostname of an outbound link — never the full URL. The raw IP address and user-agent are used in memory to compute that hash and the coarse families, and are never stored. Announced bots are not recorded. When the visitor's browser sends a Global Privacy Control or Do Not Track signal, we skip even this first-party counting and the visit is not recorded at all. These measurements are that business's, kept for 400 days, and are not used to identify a person across days or across businesses.

sitterz.com visitor measurements

The same first-party, cookie-free beacon runs on sitterz.com so Sitterz can see traffic to its own marketing site. The columns, the 400-day retention, and the Global Privacy Control / Do Not Track skip are the same as Published-site visitor measurements. These rows are Sitterz's, kept apart from any customer's book, and are not used to identify a person across days.

3. Why Sitterz uses that information

We use the information in Part 1 to provide, secure, support, and improve the Service; to authenticate you and protect accounts; to process subscription and transaction fees; to communicate with you about your account, security, and changes to these documents; to detect and prevent abuse and fraud; to keep the financial and agreement records the law requires us to keep; and to respond to legal process.

We send account, security, and service messages because they are necessary to provide the Service; you cannot opt out of those while you hold an account. Any marketing email carries a working unsubscribe link, and unsubscribing does not affect service messages.

4. Part 2 — Information inside a business's workspace

When a business uses Sitterz, it enters records about its own clients, the families it serves, the children and pets in its care, and its own staff. That business decides what to collect, why, who may see it, and how long it stays. We act only on that business's instructions. We do not decide what goes in, we do not use it for our own purposes, and we do not use it to make any judgment about the people it describes.

What a workspace can contain

  • Household and family records — names, address, phone, email, emergency contacts, the family's own care instructions and preferences, and the people a family names on its pick-up list.
  • Child records — a name, a preferred name, an approximate age from a birth year, pronouns and the language a family says it speaks in the family's own words, and free-text notes the family or the business writes.
  • Pet records — name, species and breed as the family described them, notes, and the family's vet contact details.
  • Attendance, check-in and daily logs — arrival and departure times, who a child was collected by as typed by staff, and entries for meals, naps, nappy or toilet changes, activities, notes and photos.
  • Photographs and documents — photos of children or visits, household documents, and staff-uploaded certificates or licences.
  • Staff records — name, email, phone, position, availability, uploaded documents, and an hourly rate.
  • Bookings, visits, invoices, payments, and messages between the business and its families.

What the Service deliberately does not hold

These are not oversights. Each is enforced in the software, and adding one would be a decision, not an accident.

  • No full date of birth for a child. The Service stores a birth year, so that someone meeting a child knows roughly who they are meeting. A full date of birth is a government-grade identifier for a minor and the Service has no field for one.
  • No Social Security number, date of birth, home address, or bank or routing number for staff. These are blocked at the level of the data model, and a build fails if one is added.
  • No medical, allergy, medication, immunisation, dosage, or symptom field. There is no such field anywhere, and importing a spreadsheet whose column headings look like one causes the Service to drop that column and tell the operator it did.
  • No location tracking of any person. A check-in is a timestamp. The application blocks location access at the browser level, and location data embedded in a photograph is stripped in the browser before the photo is ever uploaded.
  • No biometric information. The Service does not create, collect, capture, or store a scan of face or hand geometry, a fingerprint, a voiceprint, or a retina or iris scan, and does not use a photograph to generate a biometric identifier or template. There is no face recognition, face grouping, or auto-tagging.
  • No score, rating, ranking, or assessment of any person. Sitterz never computes a judgment about a caregiver, a family, or a child.

The Service provides no health-data field and never classifies, interprets, or acts on health information. It cannot, however, stop a family or a business from typing something health-related into a free-text note — “carries an inhaler, in the blue bag” is exactly the kind of thing families write, and the field exists so they can. Where that happens, the note is the business's record, held under its instructions and subject to the protections in this policy and in our Data Processing Addendum.

Exercising your rights over records in a workspace

The business that holds your records is responsible for answering your request. Contact it first. If you contact us instead, we will pass your request on and help that business answer it, and we will not answer it ourselves without its instruction — we have no way to confirm what it agreed with you.

5. Children's information

This deserves a plain statement, because the product holds records about children.

  • Sitterz is business software. It is not directed to children, is not intended for use by children, and has no feature designed to appeal to children.
  • Children do not have accounts. There is no child login, no child session, and no child credential anywhere in the Service. Our Terms prohibit a business from provisioning one, and prohibit anyone under 18 from holding credentials at all.
  • Sitterz collects nothing from a child. Information about a child reaches the Service because an adult — the business, or the child's own parent or guardian — types it in as part of that business's record-keeping.
  • Sitterz does not obtain parental consent and does not verify it. Obtaining any notice, consent, or photo release that the law requires is the business's responsibility, and our Terms require the business to warrant that it has done so before entering a child's information or uploading a child's photograph.
  • Children's information is never used for advertising, for profiling, or to train any AI model. It is used to provide the Service to the business that entered it, and for nothing else.
  • Sitterz never sells information about a child, and never shares it for advertising of any kind.

If we learn that someone under 18 has created an account, we will close it and delete the associated account information within 30 days, subject to routine backup expiry.

A parent or guardian who wants to see, correct, or delete a child's record should contact the business that holds it. We will help that business respond.

6. What Sitterz never does with information

  • We do not sell personal information, and we have never done so.
  • We do not share personal information for cross-context behavioural advertising, and we do not use it for targeted advertising.
  • We do not use personal information to profile anyone, or to make automated decisions that produce legal or similarly significant effects.
  • We do not use your information, or the information in your workspace, to train, fine-tune, or improve any artificial-intelligence model — ours or anyone else's — and we grant no provider the right to do so. Engaging a model provider under terms that prohibit training on what we send is a condition of using it at all.

Two honest qualifications on the last point. A model provider generally retains a limited amount of what it receives for its own abuse monitoring, as every provider does; that is not training. And separately, we look at aggregated, de-identified usage measurements — counts and timings, never content about a person — to understand whether the Service is working. That aggregated use excludes child records, daily logs, photographs, free-text notes, and incident notes entirely. Sitterz platform administrators can also view a business's own operational and revenue metrics — never child records, daily logs, photographs, free-text notes, or incident notes — through an internal console in which every such view is written to an audit record.

Where we create aggregated and de-identified data, we commit publicly to maintain and use it only in de-identified form, not to attempt to reidentify it except to test that the de-identification works, to contractually require the same of any recipient, and to monitor compliance. The same commitment appears under Your data in our Terms of Service.

No feature of the Service currently sends any information to an AI model. The AI Features Schedule lists every such feature; it is empty today, and a feature that uses a model is added there — with exactly what it receives — before it ships.

7. Who we share information with

We share information with the service providers that run the platform — hosting and database, file storage, email delivery, payment processing, sign-in, error tracking Each is bound to protect it and to use it only to provide its service to us. They are named individually, with what each receives, on our [Subprocessor List](/subprocessors), which also explains how we give notice before adding one.

We may disclose information where required by law or legal process. Where the request covers a business's workspace, we will tell that business before disclosing unless we are legally prohibited, we will try to redirect the requester to it, and we will challenge demands that are unlawful or overbroad. We do not voluntarily disclose personal information to civil immigration enforcement.

If Sitterz is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will give notice, and the information stays subject to this policy or to a policy at least as protective until it is changed with notice.

A business can add its own third-party tools to the website it publishes through Sitterz, and can send data to systems of its own choosing. Those are that business's vendors, not ours, and they are described separately on the Subprocessor List.

8. How long information is kept

The retention periods below are the ones we publish and hold ourselves to. A business can ask us to delete sooner, and some of it can be deleted on request at any time.

Retention schedule

InformationKept forMeasured from
Children's daily logs, photographs, and attendance records12 monthsThe family leaving the business
Household profiles, family and child records, pick-up lists, and messagesWhile the family is active, then 12 monthsThe family leaving the business
Staff recordsWhile the person is on the roster, then 12 monthsRemoval from the roster
Invoices, payments, refunds, disputes, and the platform's fee ledger7 yearsEnd of the tax year of the transaction
Billing and renewal-consent recordsThe longer of 3 years or 1 year after the account closesCollection
Agreement acceptance records, including the IP addressLife of the account, then 7 yearsAccount closure
Audit records of actions inside a workspaceLife of the workspace; removed in full when the business leaves
Login credentialsDeleted with the family or the business
Rate-limiting countersExpire automatically, within daysCreation
Website visitor measurements on a business's published site400 daysThe visit

Two honest notes on this schedule. First, it is carried out by hand today — a scheduled job enforces only the last two rows, and the rest is executed by us on a schedule until that job covers them. Second, the audit record cannot be edited or partially removed: each entry is cryptographically chained to the one before it, so changing any part of any entry would break the chain and destroy the integrity of the whole log. Audit entries hold operational metadata — who acted, on which record, when — and not the substance of the records themselves, which are deleted normally.

Backups expire on their own rotation, so deleted information can persist in a backup for a bounded period after deletion. We do not restore a backup to recover something a person asked us to delete.

9. How information is protected

The measures we actually operate, described plainly:

  • Separation between businesses is enforced by the database, not by application code. Every workspace table carries a row-level security policy that the database applies to every query.
  • Encryption in transit using TLS; encryption at rest through our hosting provider.
  • Passwords are hashed and never stored in a readable form. Two-factor secrets are encrypted. Recovery codes are stored only as hashes. Session cookies are signed.
  • Uploaded files are stored privately and served only through short-lived signed links. Location data in a photograph is removed in the browser before upload.
  • An append-only, cryptographically chained audit record of actions inside a workspace.
  • Role-based access, least privilege on production systems, and a documented incident-response procedure.

Our security programme is aligned to the NIST Cybersecurity Framework 2.0 and the CIS Critical Security Controls. We do not hold a SOC 2 report or any security certification today, and we will say so plainly rather than imply otherwise.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. If there is a security incident

If we determine that a security incident has affected personal information we process for a business, we will notify that business without undue delay and give it the information reasonably necessary to meet its own notification obligations. The specific timeline we commit to is in our Data Processing Addendum.

The business decides whether and how to notify the people affected and any regulator — it holds the relationship and the context, and we do not. Where the law requires us to notify individuals or regulators directly, we will.

We will describe what happened once we know it, rather than guessing early and correcting later.

11. Your privacy rights

Depending on where you live, you may have the right to know what personal information we hold about you and how we use it; to get a copy of it; to correct it; to delete it; to opt out of sale, sharing, targeted advertising, and certain profiling; and to be free from discrimination for exercising any of these rights. We do not sell or share personal information or use it for targeted advertising, so those opt-outs have nothing to act on — but the right exists and we will honour it.

These rights are recognised in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and elsewhere, with details that vary by state.

How to make a request

Email support@sitterz.com, or write to us at the address in Changes, and how to reach us. We will acknowledge promptly and respond within 45 days, and will tell you if we need a further 45 days. We will take reasonable steps to verify who you are before acting, and we may need to ask for information to do that — we use it only to verify the request.

An authorised agent may act for you with written permission that we can verify.

If your request concerns records held inside a business's workspace — your family's records, your child's records, or your own staff record — please contact that business. It decides those questions, not us. If you cannot reach it, tell us and we will pass your request on and help it respond.

If we say no

You may appeal by replying to our decision or emailing support@sitterz.com with “Appeal” in the subject line. We will review and give you a written answer, with our reasons, within 45 days. If we deny the appeal we will give you a way to complain to your state Attorney General.

Browser opt-out signals

We honour the Global Privacy Control and Do Not Track signals as a valid opt-out for the browser or device that sends one. We do not sell or share personal information. We go one step further: when a browser sends either signal, we skip even our own first-party published-site page counting, and that visit is not recorded at all.

12. Notice at collection — categories

The categories of personal information we have collected in the last 12 months, in the terms California law uses. Retention for each is in How long information is kept. We disclose these categories to the service providers on our Subprocessor List for the business purposes described in Why Sitterz uses that information and Part 2. We have not sold or shared any category, and we do not use sensitive personal information for any purpose beyond providing and securing the Service.

CategoryDo we collect it?Examples in Sitterz
A. IdentifiersYesName, email address, postal address, phone number, account identifier, IP address
B. Customer records (Cal. Civ. Code §1798.80)YesName, address, telephone number, billing contact
C. Protected classification characteristicsOnly if typedA birth year gives an approximate age; a free-text pronouns or language field may reveal a characteristic. There is no field that asks for one.
D. Commercial informationYesSubscription and plan, invoices, payment records, services a business offers
E. Biometric informationNoNone. No face, fingerprint, or voice data is created or stored.
F. Internet or network activityYesServer logs, diagnostics, security events, rate-limiting counters, first-party published-site measurements (path, referrer host, campaign tags, device/browser/OS families, coarse city/country from the host)
G. Geolocation dataNo precise locationNo location of any person is collected. An IP address implies a coarse region, as it does for every website. On a business's published site, the hosting provider's country/region/city estimate from the connection may be stored — often the internet provider's town, not the visitor's.
H. Audio, visual, or similar informationYesPhotographs of children, pets, or visits, and documents, uploaded by a business or a family
I. Professional or employment informationYesA staff member's position, availability, uploaded certificates, and hourly rate, entered by their employer
J. Non-public education informationNoNone.
K. Inferences drawn to create a profileNoNone. Sitterz draws no inferences and builds no profiles about anyone.
Sensitive personal informationOnly if typedAccount credentials, which we hold hashed. Free-text notes may contain health information a family or business chose to write. We use none of it beyond providing and securing the Service.

Sources: you, the business whose workspace holds the record, the families and staff that business invites, and our own systems.

13. Do not sell or share

Sitterz does not sell personal information and does not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information beyond the purposes permitted for providing and securing the Service. Because that is true, there is nothing for a “Do Not Sell or Share My Personal Information” link or a “Limit the Use of My Sensitive Personal Information” link to switch off, and we publish this statement instead of a link that would do nothing.

We have not sold or shared personal information — including personal information of anyone under 16 — in the preceding 12 months, and we have no plan to.

14. Cookies

sitterz.com uses only the cookies needed to sign you in and keep the site working. There is no analytics vendor, no advertising vendor, and no tracking pixel on sitterz.com. Our Cookie Policy names each cookie and what it does.

Independently of cookies, a first-party, cookie-free beacon records the measurements described under sitterz.com visitor measurements and Published-site visitor measurements. When the visitor's browser sends a Global Privacy Control or Do Not Track signal, we skip even that first-party counting.

Websites that businesses publish through Sitterz are different: a business can add its own analytics or advertising tags to its own site. Those load only after a visitor accepts them, and they are that business's choice and responsibility.

15. Where information is held

Sitterz is a United States company and the Service is offered only in and to the United States. Information is stored and processed in the United States by the providers on our Subprocessor List.

The Service is not offered to people in the European Economic Area, the United Kingdom, or Switzerland, and our Terms of Service prohibit a business from entering personal data of people in those territories. We therefore do not rely on any international transfer mechanism, and the General Data Protection Regulation and UK GDPR do not apply to our processing. If that changes, we will update this policy before it does, not after.

16. Changes, and how to reach us

We may update this policy. For a material change we will give at least 30 days' notice by email to account owners and inside the Service, and the date at the top will change. Changes apply going forward.

Sitterz LLC, a Colorado limited liability company. [our notice address — to be completed before launch]

Privacy questions and rights requests: support@sitterz.com

This policy is published as part of the Sitterz launch program and has not yet been reviewed by outside counsel. It describes what the software actually does today, including where a stated commitment is currently carried out by hand rather than by code — see the notes under How long information is kept.

Questions about this document? Email support@sitterz.com.