Privacy policy
Family data should stay family business.
This policy explains what TidyHop collects, why we need it, who can see it and the choices parents have.
Last updated
1. Who this policy is for
This policy applies to the TidyHop website and family routine service. “TidyHop”, “we” and “us” refer to the operator of TidyHop in New South Wales, Australia. Parents and guardians create and control household accounts. Children use the service only through a household set up by a parent or guardian.
2. Information we collect
Parent and household information
We collect a parent’s name, email address, hashed password, multi-factor authentication information, household name and settings, invitations to other parents, notification preferences, support messages and security or audit records.
Child and routine information
A parent may provide a child’s first name or display name, household-only username, preset avatar and hashed PIN. We store the chores, schedules, check-offs, excused periods, reviews, streak-related history, awards and real-world rewards needed to provide the service.
Technical information
We use essential cookies and session tokens to keep people signed in securely. Our systems may record IP address, browser or device information, request time and security events in operational logs. We do not use this information for advertising.
Payment information
If you buy a paid plan, the payment provider processes card and payment details. TidyHop receives information such as the selected plan, payment status and billing reference; we do not need to store full card numbers.
3. Information we deliberately do not ask from children
Children do not need an email address, date of birth, profile photograph, phone number, school, precise location or social profile. TidyHop has no photo or video evidence, public profiles, social feed, sibling leaderboard or behavioural advertising.
4. How we use information
- Provide each household’s chores, schedules, reviews, progress and rewards.
- Authenticate parents and children, protect accounts and investigate security issues.
- Send account, invitation, security and optional parent notification emails.
- Process subscriptions and keep billing records when paid plans are used.
- Answer parent support and feedback requests.
- Maintain, troubleshoot and improve the reliability and accessibility of TidyHop.
- Meet legal obligations and enforce our terms.
We do not use child data to target advertising or make automated decisions that significantly affect a child’s rights or interests.
5. Who can see or receive information
- Your household: children see only their own child-facing data. Parents in the household have equal access to household management and family records.
- Service providers: carefully selected hosting, database backup, email delivery, security and payment providers process only the information needed to deliver their service.
- Legal and safety reasons: we may disclose information where required by law, to protect a person’s safety, or to investigate fraud, abuse or a security incident.
We do not sell or rent personal information. Some providers may process information outside Australia, including in the European Union or United States. We take reasonable steps to use providers with appropriate privacy and security protections.
6. Security
TidyHop scopes private records to the authenticated household on the server. Parent passwords and child PINs are hashed, parent accounts require verified email and a second factor, remembered child sessions can be revoked, production traffic uses HTTPS, and database backups are encrypted and kept separately from the live service.
No online service can promise absolute security. If we identify a data breach, we will investigate, contain it and notify affected people and regulators where required.
7. Retention and deletion
We keep information while it is needed to provide the household service, meet legal obligations, resolve disputes and maintain security records. Parents can delete individual children, their own account or the whole household using protected controls. A household deletion removes active household records permanently. Encrypted backups are kept on a rolling schedule for disaster recovery and expire through that schedule rather than being edited record by record.
Some limited billing, audit or legal records may need to be retained after an account closes. We will not use retained records for a new purpose that is incompatible with the reason they were kept.
8. Access, correction and export
Parents can view and correct household information in TidyHop and download a machine-readable household export. A parent may ask for access to or correction of personal information, or raise a privacy concern, by emailing [email protected]. We may need to verify identity before acting on a request.
9. Children’s privacy
TidyHop is designed for parents to establish a private service for children aged 5–10. We use data minimisation and privacy-protective defaults because children deserve a higher standard of care. A parent can explain the service, supervise access, change a child’s details, revoke sessions and delete the child’s account.
Australia’s Children’s Online Privacy Code is due to be registered in December 2026. We will review this policy and TidyHop’s practices against the final Code before it applies.
10. Complaints and questions
Please email [email protected] with “Privacy” in the subject line. Tell us enough to understand the issue, but do not send a password, PIN, recovery code or authenticator secret. We will acknowledge and investigate the concern within a reasonable time.
If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner.
11. Changes to this policy
We may update this policy as TidyHop, our providers or the law changes. We will update the date above and give parents reasonable notice inside the service or by email when a change materially affects how personal information is handled.