Privacy Policy
Growin Roots · Eau Claire, Wisconsin · Effective September 14, 2026
1. Who we are
Growin Roots operates this customer portal for enrolled families in Eau Claire, Wisconsin. The portal lets guardians manage children in care, request care, view attendance, and pay balances, and lets staff run day-to-day childcare operations.
Contact for privacy questions: amanda@growinroots.com. Website: https://growinroots.com.
2. Information we collect
We collect only what is needed to provide care, bill for it, and keep children safe:
- Account information: name, email address, password (stored as a salted hash, never plaintext), and whether you are staff or a guardian.
- Family information: guardian names, family account link, and co-guardian relationships you set up via invite links.
- Child information: name, birth date, and notes you provide such as allergies or special needs, plus emergency contacts and authorized pickup persons (name, phone, relationship).
- Care records: schedule requests, approvals, and attendance punch in/out times with the rate applied.
- Billing records: charges, payments, method used (cash, check, Venmo recorded by staff, card online, or another method recorded by staff), amounts, and balances. Card numbers are never stored by us — see Stripe below. Online card payments include a card convenience fee shown before checkout.
- Technical information: sign-in session cookie, invite-token status, and — only if you opt in — push-notification subscriptions for your devices. The server also reads your IP address transiently to rate-limit sign-in attempts (kept in memory only, not persisted to the database) and may write short-lived HTTP access logs at the hosting layer.
We do not collect information directly from children. All child information is provided by a parent, guardian, or staff member.
3. Children's privacy
This service collects personal information from parents and guardians about children under 13 — we have actual knowledge of collecting from children. We follow the Children's Online Privacy Protection Act (COPPA):
- We never ask children to create accounts or submit information; only parents, guardians, or staff enter child information.
- Providing child information is voluntary, but is required to enroll and provide care. We collect it with verifiable parental consent obtained at enrollment.
- Child information is used only for childcare, safety, and billing.
- Child records are visible only to linked guardians on that family account and to staff.
- A parent/guardian may review, correct, or request deletion of their child's information at any time by contacting amanda@growinroots.com (we respond within 30 days of a verifiable request).
4. How we use information
- Enroll families, link guardians to children, and manage pickup authorization.
- Schedule and approve care, record attendance, and compute charges.
- Maintain a running family balance, record payments, and show receipts in the portal.
- Send service notifications you opt into (schedule approved/denied, punch in/out, payment recorded).
- Keep the service secure, prevent misuse, and meet legal/record-keeping duties.
5. How we share information
- Staff: staff members can access family, child, schedule, attendance, and billing records to operate the childcare program.
- Stripe (online card payments): when you pay by card, you are redirected to Stripe Checkout. Card details go directly to Stripe; we receive only the payment confirmation, amount, and reference ID. A card convenience fee is added to online payments and shown before checkout. Stripe's handling is governed by Stripe's Privacy Policy.
- Hosting: the portal and database are self-hosted on systems we operate (app + PostgreSQL). Data stays on systems we control; there is no advertising use. Backups may retain deleted data for a limited time before being overwritten (see Retention below).
- Legal: we disclose information only when required by law or to protect a child's safety.
We do not sell personal information and do not share it for marketing or cross-context behavioral advertising. We therefore honor Global Privacy Control (GPC) opt-out signals as a valid do-not-sell/share request: there is nothing to opt out of, so your experience does not change and no further action is needed.
6. Cookies, sessions & notifications
- Session cookie: a strictly necessary sign-in cookie keeps you logged in and enforces staff/guardian access. It is not used for tracking or advertising.
- Push notifications: optional and off by default. If you enable them, your browser/device push subscription is stored so we can send service updates. You can turn them off in your browser settings or from the dashboard.
- No third-party analytics or advertising trackers are used.
7. Retention
Care, attendance, and billing records are kept while your family is enrolled and for as long as needed for tax, accounting, and licensing record-keeping — typically up to 7 years after the family's last enrollment. When you ask us to delete information, we remove what we legally can from the live database and retain only what the law requires us to keep; copies inside backups may persist until those backups are overwritten or expire.
8. Your rights & choices
- Review and correct your account, child, contact, and pickup information in the portal or by asking staff.
- Request a copy, correction, or deletion of your family's information via amanda@growinroots.com. We respond to verifiable requests within 30 days and confirm the requester's link to the family account before acting.
- Disable push notifications at any time; core portal functions still work.
- Pay by cash, check, or staff-recorded Venmo if you prefer not to use online card payment.
- Send a Global Privacy Control (GPC) signal from your browser — we treat it as a do-not-sell/share request. Because we do not sell or share personal information, the signal simply confirms your existing opt-out status.
You must be 18 or older to create a guardian account. Wisconsin does not have a comprehensive consumer-privacy statute; we comply with applicable Wisconsin and federal law, including COPPA and Wisconsin's breach-notification law (Wis. Stat. § 134.98).
9. Security & breach notification
We protect information with hashed passwords, invite links that are single-use and expire in 7 days, role-based access (guardians see only their own family account; staff see what operations require), encrypted (HTTPS) connections, and signature-verified payment webhooks. No method is perfectly secure, so please keep your password private and tell us promptly of any suspected misuse.
If a breach of personal information occurs, we notify affected Wisconsin residents as required by Wis. Stat. § 134.98 — without unreasonable delay, and by mail or substitute notice where applicable.
10. Changes to this policy
If this policy changes materially, we will post the updated version here with a new effective date and, where appropriate, notify you in the portal before the change takes effect.
11. Contact
Questions or requests about privacy: amanda@growinroots.com. Please include the family account name so we can verify your link to it. We respond to verifiable requests within 30 days.
See also our Sick Policy and Terms of Service.