Privacy policy
Effective 15 August 2026 · Last updated 15 August 2026
The short version
- We collect what a carpool needs and nothing else: who is in your family, where you start from, when practice is, and who is driving.
- We do not sell or share your data with advertisers, and there are no analytics, advertising or tracking scripts on this site at all.
- Your street address is shown to another family only once there is an actual carpool link between you. Not to the whole team, and not by default.
- Children do not have accounts. Their information is entered by you, and you can change or delete it at any time.
- Schedules you upload are read by an AI model to pull out the events. That content is not used to train anyone's model.
- Delete your account and the data goes with it.
Carpoolish is operated by Headquarters for AI (“we”, “us”), a [ENTITY TYPE] registered in [STATE/COUNTRY] — to confirm. This policy explains what we collect, why, who else sees it, and what you can do about it. It applies to carpoolish.ai and the Carpoolish application.
On this page
1. What we collect
All of it comes from you, or is created by you using the app. We do not buy data, and we do not collect anything from you before you create an account beyond what any web server necessarily sees.
| Category | What it is | How we get it |
|---|---|---|
| Account | First and last name, email address, hashed password (or a Google account identifier if you sign in with Google) | You, at signup |
| Profile | Mobile phone number, timezone, profile picture if Google supplies one | You |
| Household | Family name, one or more home addresses with their approximate coordinates, which adult lives at which address | You, during onboarding |
| Children | First and last name, birth year, whether a booster seat is needed | You — see section 2 |
| Vehicles | A label you choose and how many seats are available for riders | You |
| Teams & schedules | Team names, seasons, rosters, events, times, venues and their addresses | You, or a schedule you import |
| Rides | Who needs a ride, who offered to drive, who is seated where, one-off drop-off addresses | You and other families on your team |
| Messages | Team chat messages, support tickets, replies to messages we send you | You |
| Uploads | Calendar links, files, emails and photographs you submit so a schedule can be read out of them | You |
| Technical | A one-way salted hash of your IP address, used only to rate-limit schedule imports and address lookups. We do not store the address itself for this purpose. | Automatic |
| Calendar token | A private random token that lets your calendar app subscribe to your own driving schedule | Generated for you |
We do not collect: payment card details (there is nothing to pay for yet), precise device location, contact lists, biometrics, or anything about your browsing elsewhere.
2. Children's information
This is the part we take most seriously, so it is worth being precise about how it works.
- Children do not have accounts and cannot sign in. A child in Carpoolish is a record on a parent's household, not a user.
- We collect a child's first and last name, birth year, and whether they need a booster seat. Nothing else. No date of birth, no photograph, no school, no medical information, no contact details for the child.
- The birth year is there because teams are organised by it and because it determines whether a booster seat is required by law in most places. We do not use it for anything else.
- A child's information is entered by their parent or guardian, and can be edited or removed by that parent at any time from Account → Family.
- A child's name is visible to other families on the same team roster, because coordinating a carpool requires knowing whose child is in which car. Their birth year and booster requirement are visible only to your household and to a driver who has been assigned to carry them.
- We never show a child's home address to anyone outside their household except under the carpool-link rule in section 4, and that rule is about the household's address, not the child.
Because the parent supplies this information about their own child and the child is not a user of the service, we do not knowingly collect personal information directly from children under 13. If you believe a child has created an account, contact us at info@hqforai.com and we will delete it.
Being straight with you: children's privacy law — COPPA in the United States, and the equivalents elsewhere — is genuinely complicated, and this policy is written by the people who built the product, not by lawyers. If you are a club or a league considering Carpoolish at scale, tell us and we will get you a reviewed answer rather than an improvised one.
3. Why we hold it
Every category above exists because a specific part of the product cannot work without it:
- To provide the service — showing your week, matching a driver to a trip, working out whether a booster seat is needed, sending your driving to your own calendar.
- To route a pickup — addresses and their coordinates are what make “who is on the way” answerable.
- To let families reach each other — a phone number is how another parent tells you they are outside.
- To keep the service standing up — rate-limiting imports so one script cannot exhaust the service for everyone.
- To answer you — support tickets and the messages attached to them.
If you are in the UK or the EEA, our lawful bases are contract (we cannot run your carpool without this), legitimate interests (keeping the service secure and working), and consent where we ask for it explicitly.
4. Who can see what
Carpoolish is a shared tool, so some of your information is visible to other families by design. What is not visible is enforced by the database itself, not merely hidden in the interface.
| Information | Who sees it |
|---|---|
| Your family name | Everyone on a team you share |
| Your children's names | Families on the same team roster |
| Your name | Families on the same team |
| Your phone number | Families on the same team, so they can reach you at a pickup |
| Your street address | Only families you have an actual carpool link with — someone driving your child, or whose child you are driving. Everyone else on the team sees your town, not your street. You can also choose to share the exact address with the whole team. |
| Your fair-share record | Only you. Nobody else on the team can see what you have driven or received. |
| Team chat | Families on that team |
| Support tickets | You and Carpoolish staff |
We do not sell personal information, we do not share it with advertisers, and we do not allow third parties to place advertising or tracking on this site. There are no analytics scripts on carpoolish.ai.
5. How AI is used
When you import a schedule from a file, an email, a photograph or a link, the contents are sent to Anthropic and read by a Claude model, which returns the events it found. This is the feature that lets Carpoolish accept whatever format your club happens to use.
- What is sent is the schedule content you supplied — the text of the file, email or image. Your household address, your children's records and your phone number are not sent with it.
- Anthropic processes it to produce the extraction and, under its commercial API terms, does not use it to train models.
- The result is shown to you for review before anything is added. An extraction is a suggestion, not a fact, which is why the app asks you to check it.
- We keep the uploaded content only as long as needed to complete the import and to let you correct it.
We also use a model to invent a name for a car you did not name. It receives the number of seats and nothing else.
6. Companies that process data for us
We use a small number of established providers. Each acts on our instructions, and each receives only what its job needs.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, accounts and sign-in | Everything in section 1 — it is where your data lives |
| Netlify | Serves the website | Standard web request data, including your IP address |
| Anthropic | Reads imported schedules | The schedule content you upload — see section 5 |
| Optional sign-in; address auto-complete; web fonts | Your Google account identity if you use Google sign-in; the partial address you type when looking one up; your IP address when the page loads fonts | |
| Resend | Sends our email | Your email address and the content of the message |
| jsDelivr / unpkg | Serve a JavaScript library the app needs | Your IP address when the app loads |
Links to Google Maps in the app are ordinary links. Nothing is sent to Google until you choose to tap one, at which point Google's own terms apply.
7. How long we keep it
- While your account exists — your household, children, teams and schedules, so the app works when you come back.
- Deleted when you delete your account — your profile, household, children, vehicles, addresses, ride records and calendar token.
- Rate-limit records — the salted IP hashes are kept for a short rolling period and cannot be turned back into an address.
- Support tickets and admin actions — kept as a record of what was asked and what was done, including after account deletion, because a log you can delete is not a log.
- Team content you contributed — messages you posted and events you imported remain with the team, because removing them would break the schedule other families depend on. Your name is removed from them.
8. How it is protected
- Everything travels over HTTPS.
- Access is enforced in the database with row-level security, so a request for data you are not entitled to returns nothing — it does not rely on the app asking politely.
- Particularly sensitive columns — street addresses, email addresses and phone numbers — have their read permission revoked outright, and are returned only through narrow, audited paths that apply the rules in section 4.
- Passwords are hashed by Supabase Auth. We never see them.
- Administrative access to member data is limited, and every administrative action is written to an audit log.
No system is perfectly secure. If we discover a breach affecting your personal information, we will tell you and any regulator we are required to tell, without undue delay.
9. Your rights and choices
Most of these you can exercise yourself, immediately, inside the app:
- See and correct — Account → Family, Cars, Locations.
- Control your address sharing — choose between sharing your exact address with the whole team or only with families you are actually carpooling with.
- Delete — Account → Delete my account.
- Revoke your calendar feed — Account → Calendar sync generates a new link and kills the old one.
- Turn off notifications — Account → Notifications.
Depending on where you live you may also have rights to a copy of your data in a portable form, to object to or restrict processing, and to complain to a data protection authority. To exercise any of these, email info@hqforai.com and we will respond within 30 days. We will not charge you or treat you differently for asking.
Residents of California, and of other US states with similar laws, have the right to know what is collected, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is no opt-out to offer — there is nothing to opt out of.
10. Where it is stored
Carpoolish is hosted in the United States. If you use it from outside the US, your information is transferred there and handled under this policy. Where a transfer out of the UK or EEA requires a safeguard, we rely on our providers' standard contractual clauses.
11. Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle your information — a new category collected, a new provider, a new way it is shared — we will tell you in the app and by email before it takes effect, not afterwards.
12. Contact
Questions, requests, or something here that does not match what you see in the app: info@hqforai.com. A person reads it.