Draft — pending legal review
Privacy Policy
Last updated July 13, 2026
Rally Laneprovides child check-in and check-out software to schools, after-school programs, camps, clubs, and childcare providers (“organizations”). This policy explains what we collect, why, and the choices you have. The short version: we collect the minimum needed to run a safe custody record, we never sell data, we never use children’s data for advertising, and organizations — not Rally Lane — decide whose data is in the system.
Our role
For child and family records, Rally Lane acts as a service provider / data processoron behalf of the organization that enrolled the child. The organization is the data controller: it decides which children are enrolled, which adults are authorized, and when records are corrected or removed. If you are a parent with questions about your child’s data, your first stop is your program’s administrator; we support them (and you) in fulfilling any request.
What we collect
- Children (entered by the organization): name, date of birth, group/room, guardian contact details, and any care notes (such as allergies) the organization records. Optionally a photo, if the organization uses photo verification. We do not collect data from children directly, and children do not have accounts.
- Adults (account holders): name, email, phone number, and password credentials (stored hashed). Parents may set a pickup PIN — stored only as a cryptographic hash, never readable by staff or by us in plain form.
- Custody events: a tamper-evident, append-only record of every check-in and check-out — who, when, and by which method. This ledger is the core safety feature of the product: it deliberately cannot be edited or deleted, by anyone, including us.
- Location: only if a parent chooses to share an arrival ETA, and only while the app is in use. We never track location in the background.
- Billing: handled by Stripe. We never see or store card numbers.
- Error reports: when something goes wrong in the app or on this site, we record a short technical description of the error, the screen it happened on, and the account involved, so support can find it from the code you are shown. Email addresses, phone numbers and access tokens are removed automatically before it is stored. Reports stay in our own database — never a third-party tracking service — and are deleted after 90 days.
What we never do
- No sale of personal data, of any kind, ever.
- No advertising, ad tracking, or profiling — and especially none involving children.
- No use of children’s data for any purpose other than operating the service.
- No collection from children directly (the app is used by adults and staff).
Children’s privacy (COPPA)
Children’s records are entered and controlled by the enrolling organization, which obtains the necessary parental consent as part of its own enrollment process. We process those records solely to provide the check-in/check-out service to that organization, retain them only as long as the organization requires, and support deletion requests routed through the organization. We collect no more information about a child than is reasonably necessary for safe custody handoff.
Sharing
Data is visible only inside your organization, according to role: staff see their program’s roster; parents see only their own children. We share data with subprocessors strictly as needed to run the service — currently Supabase (database and authentication hosting), Stripe (billing), Expo (push notification delivery), and Resend (transactional email). Each processes data under contract and only on our instructions. We disclose data if required by law, and we will notify the affected organization unless legally barred.
Retention and deletion
Account holders can delete their account in the app (Settings → Account). Personal details are erased or pseudonymized immediately; the custody ledger itself is retained in de-identified form because it is a legal-safety record for the organization. Organizations can remove children and families from their roster at any time, and can request full account deletion by contacting support. Backups roll off on a fixed schedule after deletion.
Security
All data is encrypted in transit and at rest. Access is enforced row-by-row in the database (not just in the app), credentials and PINs are stored only as cryptographic hashes, and every administrative action of consequence is written to an append-only audit log. We review our access-control surface with an executable regression suite on every change.
Your rights
Depending on where you live (GDPR, CCPA, and similar laws), you may have rights to access, correct, export, or delete your personal data. Account holders can export their data and delete their account directly in the app; for anything else — or for requests concerning a child’s record — contact your organization’s administrator or email us and we will help route the request.
Contact
Questions or requests: support@getrallylane.com. We will update this policy as the product evolves and note material changes here.