Last Updated: September 10, 2026
WizHippo LLC (“WizHippo,” “we,” “our,” or “us”) understands that childcare organizations are entrusted with sensitive information concerning children, families, staff, and their businesses.
This Privacy Policy explains how WizHippo collects, uses, discloses, stores, and protects Personal Information in connection with our websites, hosted applications, Partner Portal, and related services (collectively, the “Services”).
This Privacy Policy should be read together with the WizHippo Terms of Service.
The Privacy Policy is primarily a notice describing our privacy practices. Except where applicable law or an express contractual provision provides otherwise, this Privacy Policy does not independently create warranties or contractual obligations beyond those contained in the applicable Terms of Service, Order, Data Processing Addendum, or other agreement.
Nothing in this Privacy Policy limits privacy rights that cannot lawfully be waived.
1. Scope
This Privacy Policy applies to Personal Information WizHippo collects directly or otherwise processes for its own purposes from or about:
- website visitors;
- prospective customers;
- trial users;
- Customers;
- Authorized Users and staff;
- Parent Users and other Individual End Users;
- Partners and Partner Users;
- prospective Customers referred by Partners;
- individuals who communicate with WizHippo;
- business contacts; and
- other individuals who interact directly with WizHippo.
Customer Data
WizHippo also processes information that childcare providers and their authorized users place within Customer-controlled WizHippo environments (“Customer Data”).
Customer Data may include information concerning children, parents, guardians, employees, contractors, childcare operations, licensing, compliance, health, attendance, billing, incidents, documents, communications, and other records.
For Customer Data, WizHippo generally acts on behalf of and under the instructions of the applicable Customer.
The Customer determines the purposes for which Customer Data is collected and used and who is authorized to access it, subject to applicable law and Platform functionality.
Customer Data is governed primarily by the applicable Customer’s privacy practices and the data-processing provisions of the WizHippo Terms of Service or another applicable agreement.
This Privacy Policy nevertheless describes WizHippo’s handling of Customer Data at a high level for transparency.
Parents, guardians, employees, or other individuals seeking access to, correction of, or deletion of Customer-controlled information should generally contact the applicable childcare provider first.
WizHippo may assist the Customer as required by applicable law or applicable contractual obligations.
2. Our Privacy Roles
WizHippo may process information in different legal capacities depending upon the information and context.
Information WizHippo Processes for Customers
For Customer Data, WizHippo generally acts as a processor, service provider, contractor, or comparable service provider acting on behalf of the Customer.
We process such information according to Customer instructions reflected in the Customer’s use and configuration of the Platform, applicable permissions, Partner Authorizations, support requests, and the Terms of Service.
Information WizHippo Processes for Its Own Purposes
WizHippo may independently determine the purposes and means of processing Personal Information relating to:
- WizHippo account administration;
- website operation;
- authentication;
- security;
- fraud prevention;
- WizHippo Subscription billing;
- Partner Program administration;
- Partner applications and approvals;
- support;
- marketing of WizHippo’s own Services;
- business operations;
- legal compliance; and
- enforcement of WizHippo agreements.
In those circumstances, WizHippo may act as a controller, business, or comparable entity under applicable privacy law.
3. Information We Collect and Process
The particular information we collect depends upon how an individual interacts with WizHippo.
3.1 Account and Contact Information
We may collect:
- name;
- email address;
- telephone number;
- organization name;
- job title or role;
- account identifier;
- Center affiliation;
- Partner affiliation;
- login credentials or authentication information; and
- communication preferences.
Passwords are not intended to be stored in readable plaintext.
3.2 Partner and Referral Information
For Partners and Partner applicants, we may collect:
- Partner name;
- business or organization name;
- business contact information;
- business profile;
- service information;
- service area;
- Partner application information;
- training or orientation status;
- Partner approval status;
- referral activity;
- prospective Center contact information submitted through referral functionality;
- connected Centers;
- Partner Authorization information;
- Partner Group Profile assignments;
- permission and access records; and
- Partner Portal activity.
Some Approved Partner business-profile information may be displayed to Customers for Partner discovery and authorization as described in the Terms of Service.
3.3 Technical and Device Information
When you use WizHippo, we or our service providers may automatically collect:
- IP address;
- browser type;
- operating system;
- device type;
- login date and time;
- session information;
- authentication events;
- referring pages or URLs;
- approximate location derived from IP address where applicable; and
- technical diagnostic information.
We do not treat an IP-derived approximate location as precise geolocation.
3.4 Usage, Security, and Audit Information
We may collect information concerning interactions with the Services, including:
- pages or features accessed;
- login activity;
- activity history;
- permission changes;
- Partner authorizations;
- export activity;
- print activity where recorded by the Platform;
- administrative actions;
- error logs;
- security events;
- audit logs; and
- diagnostic information.
We use this information to operate, secure, troubleshoot, audit, and improve the Services.
3.5 Communications and Support Information
If you communicate with WizHippo, we may collect:
- your contact information;
- the contents of your communication;
- support requests;
- attachments provided to support;
- troubleshooting information; and
- related correspondence.
3.6 Customer Data
Depending upon how a Customer uses WizHippo, Customer Data may include:
- child names and profiles;
- dates of birth or age information;
- parent and guardian information;
- family information;
- emergency contacts;
- authorized pickup information;
- enrollment information;
- attendance;
- health information;
- allergy information;
- immunization information;
- medication information;
- incident records;
- photographs;
- staff information;
- employment-related records;
- training and certification information;
- facility records;
- licensing information;
- regulatory and compliance records;
- inspections;
- findings and follow-up records;
- billing information;
- transaction records;
- documents;
- communications; and
- other information entered or uploaded by the Customer, its Authorized Users, Parent Users, or Customer-authorized Partners.
Customers determine which Customer Data they place in WizHippo, subject to the Terms of Service.
3.7 Payment Information
WizHippo uses third-party payment providers to process Subscription payments and, where available, childcare-related payments.
WizHippo does not intentionally store complete payment-card numbers or card security codes within general WizHippo application databases.
Depending upon the payment functionality, WizHippo may receive or maintain limited payment information such as:
- payment-provider tokens or identifiers;
- last four digits of a payment method;
- payment-method type;
- payment status;
- transaction identifiers;
- payment amount;
- dates;
- refunds;
- disputes; and
- reconciliation information.
Payment providers process payment information according to their own privacy policies, agreements, and regulatory obligations.
3.8 Information From Other Sources
We may receive Personal Information from:
- Customers;
- Parent Users;
- Partners;
- Partner referrals;
- payment providers;
- communications providers;
- authentication or security providers;
- publicly available business sources;
- business contacts; and
- other sources where permitted by law.
4. Notice at Collection
Depending upon your interaction with WizHippo, we may collect the following general categories of Personal Information.
| Category | Examples | Primary Purposes | Retention Criteria |
|---|---|---|---|
| Identifiers and contact information | Name, email, telephone number, IP address, user ID | Accounts, authentication, communications, support, security | Account relationship plus reasonable security, legal, and operational retention |
| Commercial information | Subscription, transaction and payment records | Billing, accounting, payment administration, fraud prevention | Required business, tax, payment, dispute and legal periods |
| Internet or electronic activity | Login records, browser/device information, feature usage, website activity | Security, operations, analytics, troubleshooting | Based on security, analytics and operational needs |
| Professional/business information | Organization, job title, Partner profile, business affiliation | Customer administration, Partner Program, business communications | Duration of relationship plus reasonable business/legal retention |
| Communications | Emails, support communications and submitted messages | Support, operations, dispute resolution, legal compliance | As reasonably required for the communication and related business/legal purpose |
| Partner/referral information | Partner applications, approval, referrals, Center relationships | Partner administration, referrals, authorization and security | Duration of Partner relationship and reasonable audit/legal retention |
| Sensitive information | Authentication credentials and certain Customer Data such as health information | Authentication, security and Customer-requested Services | Only as reasonably necessary for the specific permitted purpose and applicable retention obligations |
| Customer Data | Child, family, staff, health, compliance and operational records | Providing Services to the Customer | While Customer account is active and according to Section 12 after termination |
We consider the nature and sensitivity of the information, applicable legal requirements, security and fraud needs, account status, contractual requirements, backup cycles, and the purposes for which information was collected when determining retention periods.
5. How We Use Information
WizHippo may use Personal Information to:
- provide and operate the Services;
- create and administer accounts;
- authenticate users;
- manage permissions;
- process Customer-authorized Partner access;
- operate the Partner Program;
- review and administer Partner applications;
- process referrals;
- provide customer and technical support;
- process Subscription billing;
- facilitate Customer-selected payment functionality;
- send transactional and service communications;
- maintain and improve system performance;
- diagnose errors;
- maintain records and audit trails;
- detect and prevent unauthorized activity, fraud, and abuse;
- protect the security and integrity of the Services;
- perform backups and disaster-recovery functions;
- generate reports requested by Customers;
- conduct analytics regarding use of WizHippo;
- improve and develop the Services;
- create aggregated or de-identified information;
- enforce agreements and policies;
- establish, exercise, or defend legal claims;
- comply with legal obligations; and
- perform other purposes disclosed when the information is collected or with appropriate authorization.
WizHippo does not use identifiable child, family, or staff Customer Data for unrelated behavioral advertising.
6. Customer Data and Customer Instructions
Customers control Customer Data and determine who may access their Center environments.
WizHippo processes Customer Data only as reasonably necessary to:
- provide the Services selected by the Customer;
- carry out Customer instructions;
- maintain Platform security;
- provide support;
- perform authorized technical operations;
- comply with applicable law; and
- enforce applicable agreements.
A Customer is responsible for obtaining notices, authorizations, permissions, and consents required for information the Customer places in WizHippo.
WizHippo does not independently determine whether a Customer is legally entitled to collect a particular child, family, employee, medical, custody, or other record.
7. Partner Access to Customer Data
WizHippo may permit Approved Partners to assist childcare Customers through the Partner Portal.
Partner approval by WizHippo does not itself provide access to Customer Data.
A Partner obtains access to a Center only after the applicable Customer affirmatively authorizes that Partner through WizHippo’s Partner Authorization functionality.
The Customer determines the Partner Group Profile and effective permissions available to that Partner.
Depending upon those permissions, a Partner may be able to view, enter, update, upload, download, manage, or otherwise interact with particular Customer Data.
The same Partner may receive different permissions from different Customers or Centers.
Customers may modify or revoke Partner access.
Partners are independent third parties. Unless WizHippo separately engages a Partner as a service provider in writing, a Customer-authorized Partner is not a WizHippo Subprocessor merely because the Partner accesses Customer Data through the Platform.
Partners are subject to confidentiality, security, data-use, and other obligations contained in the WizHippo Terms of Service.
8. How We Disclose Information
WizHippo may disclose Personal Information only as reasonably appropriate for the purposes described in this Privacy Policy.
Customers and Authorized Users
Information within a Customer environment may be made available to the applicable Customer and persons the Customer authorizes according to Platform permissions.
Parent Users
Customer-controlled information may be made available to Parent Users according to the Customer’s configuration and permissions.
Customer-Authorized Partners
Customer Data may be made available to an Approved Partner after the Customer affirmatively authorizes access and subject to the Customer’s Partner Group Profile.
Service Providers and Subprocessors
We may disclose information to companies that assist us with:
- cloud infrastructure and hosting;
- network and security services;
- communications;
- email or SMS delivery;
- payment processing;
- analytics;
- support;
- backup and disaster recovery;
- fraud prevention; and
- other operational functions.
Service providers receive information only as reasonably necessary for their applicable functions and are subject to contractual or other legally appropriate obligations where required.
Payment Providers and Financial Institutions
Payment-related information may be transmitted to payment processors, banks, card networks, ACH networks, fraud-prevention providers, and other financial-service participants necessary to process transactions.
Professional Advisors
We may disclose information to attorneys, accountants, insurers, auditors, and other professional advisors where reasonably necessary and subject to appropriate obligations.
Legal Requirements and Protection
We may preserve or disclose information where we reasonably believe disclosure is necessary to:
- comply with applicable law;
- respond to valid legal process;
- enforce agreements;
- investigate fraud or abuse;
- protect the security of the Services;
- establish or defend legal claims; or
- protect the rights, property, or safety of WizHippo, our users, or others.
Where reasonably practicable and legally permitted, WizHippo seeks to disclose only information reasonably necessary for the applicable legal purpose.
Business Transactions
Information may be disclosed or transferred in connection with an actual or proposed:
- merger;
- acquisition;
- financing;
- reorganization;
- sale of assets;
- corporate transaction;
- insolvency; or
- transfer of the WizHippo business.
Any successor’s processing of Personal Information remains subject to applicable law.
At Your or the Customer’s Direction
We may disclose information when an authorized user or Customer instructs us to do so, including through integrations, Partner Authorization, payment functionality, or other user-selected Services.
9. Sale, Sharing, Targeted Advertising, and Sensitive Information
9.1 Customer Data
WizHippo does not sell Customer Data.
WizHippo does not share identifiable child, family, or staff Customer Data for cross-context behavioral advertising or targeted advertising unrelated to providing the Services.
9.2 Personal Information Collected Directly by WizHippo
WizHippo does not sell Personal Information for monetary consideration.
Some privacy laws define “sale,” “sharing,” or “targeted advertising” more broadly than a transaction involving money.
Public website analytics technologies may disclose device identifiers, cookie identifiers, IP information, or Internet activity to analytics providers.
Depending upon the jurisdiction, provider relationship, and technical configuration, such disclosures may be treated as a sale, sharing, or targeted-advertising activity under applicable law.
Where applicable law gives you the right to opt out, WizHippo will provide or honor legally required opt-out methods as described under Cookies and Privacy Choices below.
9.3 Sensitive Personal Information
WizHippo uses Sensitive Personal Information only for purposes reasonably necessary to:
- provide requested Services;
- authenticate users;
- secure accounts;
- process authorized transactions;
- process Customer Data on behalf of a Customer;
- prevent fraud;
- comply with law; or
- perform other permitted purposes.
WizHippo does not use Sensitive Personal Information to infer characteristics about individuals for unrelated advertising or marketing purposes.
9.4 Minors
WizHippo does not knowingly sell or share Personal Information of persons under 16 for cross-context behavioral advertising.
10. Aggregated and De-Identified Information
WizHippo may create aggregated or de-identified information from information processed through the Services.
We may use properly aggregated or de-identified information for lawful purposes including:
- analytics;
- security;
- reliability;
- capacity planning;
- product improvement;
- research concerning general Platform use; and
- development of Services.
Where applicable law imposes requirements concerning de-identified information, WizHippo will maintain appropriate safeguards and will not attempt to re-identify the information except where permitted by law for security, testing, validation, or another authorized purpose.
11. Cookies, Analytics, and Privacy Choices
11.1 What Cookies Are
Cookies and similar technologies are small files or technical identifiers placed or accessed through a browser or device.
They may be used to maintain sessions, authenticate users, protect security, remember preferences, understand website performance, or perform analytics.
11.2 Necessary Cookies
WizHippo uses cookies and comparable technologies that are necessary to:
- maintain login sessions;
- authenticate users;
- protect security;
- prevent fraud or abuse;
- operate website and application functionality; and
- remember essential settings.
Disabling necessary cookies may prevent portions of the Services from functioning properly.
11.3 Analytics
As of the Last Updated date, WizHippo uses Google Analytics on public WizHippo website pages and landing pages to understand website traffic, usage patterns, and performance.
Analytics technologies may collect information such as:
- IP address;
- browser and device information;
- cookie or device identifiers;
- pages visited;
- referring source;
- approximate location; and
- interaction information.
WizHippo does not intentionally provide identifiable Customer Data, child records, medical information, or authenticated Center records to Google Analytics for advertising purposes.
11.4 Authenticated Application Data
WizHippo does not intentionally use Customer Data from authenticated Center, Parent, Staff, or Partner workspaces for behavioral advertising.
Analytics or marketing providers should not be intentionally configured to receive sensitive Customer Data from authenticated application records.
11.5 Cookie Choices
Where required by applicable law, WizHippo provides choices regarding non-essential cookies or similar technologies.
You may also configure your browser to block or delete cookies, although this may affect Service functionality.
11.6 Global Privacy Control and Universal Opt-Out Signals
Certain jurisdictions recognize browser-based universal opt-out mechanisms such as Global Privacy Control (“GPC”).
Where applicable law requires WizHippo to honor a recognized GPC or similar opt-out preference signal, WizHippo will treat a valid signal as an applicable opt-out request for the browser or device from which the signal is received.
If no processing activity subject to such an opt-out is occurring, receiving a signal may not change the operation of the Services.
11.7 Do Not Track
Some browsers offer a “Do Not Track” or “DNT” setting.
DNT is distinct from legally recognized opt-out preference signals such as GPC.
WizHippo may not respond to legacy DNT signals where applicable law does not require it.
11.8 Changes in Tracking Technologies
If WizHippo materially changes the categories of cookies, advertising technologies, or tracking practices it uses, we will update this Privacy Policy and provide additional choice or consent mechanisms where required by law.
12. Data Retention
WizHippo retains Personal Information only as reasonably necessary for legitimate purposes, applicable contractual obligations, security, dispute resolution, and legal requirements.
Retention depends upon the category and context.
Customer Data
Customer Data is generally maintained while the applicable Customer account remains active.
Following termination or cancellation of a paid Customer account, Customer Data may remain available or retained in active systems for approximately 30 days, unless a different period applies under an Order, legal requirement, security requirement, dispute, or other permitted circumstance.
Customer Data may then be deleted from active systems.
Backups
Deleted information may remain temporarily in backup and disaster-recovery systems until those backups are overwritten or expire through ordinary backup rotation.
Backup retention may vary by system.
WizHippo does not use backups as an indefinite archive of Customer Data.
Account Information
Account and business information may be retained for the duration of the account relationship and thereafter as reasonably necessary for:
- legal obligations;
- accounting;
- taxation;
- security;
- fraud prevention;
- disputes; and
- enforcement.
Payment and Transaction Records
Payment-related records may be retained according to applicable accounting, tax, processor, fraud, chargeback, dispute, and legal requirements.
Security and Audit Records
Security, authentication, and audit information may be retained as reasonably necessary to:
- maintain security;
- investigate incidents;
- prevent fraud;
- resolve disputes;
- demonstrate authorization;
- comply with law; and
- preserve appropriate business records.
A deletion request does not necessarily require deletion of audit, security, transaction, or legal records that WizHippo is permitted or required to retain.
Partner Authorization Records
Partner approvals, Center authorizations, Partner Group Profiles, permission changes, and revocation records may be retained for reasonable security, administrative, contractual, legal, and evidentiary purposes.
Retention Criteria
In determining retention periods, WizHippo considers:
- applicable legal requirements;
- contractual requirements;
- account status;
- nature and sensitivity of information;
- security risks;
- fraud and dispute needs;
- applicable statutes of limitation;
- backup cycles; and
- whether information remains necessary for the purpose for which it was collected.
13. Security
WizHippo maintains administrative, technical, and organizational measures designed to protect Personal Information and Customer Data against unauthorized access, acquisition, destruction, use, alteration, or disclosure.
Depending upon the applicable system and configuration, safeguards may include:
- HTTPS/TLS encrypted communications;
- secure password hashing;
- individual user authentication;
- role-based access controls;
- Customer-managed permissions;
- Partner-specific permission controls;
- logical separation of Customer environments;
- authentication and failed-login protections;
- audit logging;
- backup and recovery controls;
- infrastructure and network-security protections; and
- multi-factor authentication where offered or enabled.
Security measures evolve and may change as technology, threats, and the Services change.
No Internet transmission, hosted application, electronic storage system, or security program can guarantee complete security.
Customers, Partners, and End Users are responsible for protecting their credentials, devices, exported data, and information outside WizHippo’s reasonable control.
Illinois law requires entities that maintain information concerning Illinois residents to implement reasonable security measures, and it also requires appropriate security provisions when that information is disclosed to another party.
14. Security Incidents
If WizHippo discovers or reasonably suspects unauthorized access affecting Personal Information or Customer Data, we will take steps appropriate to the circumstances, which may include:
- investigation;
- containment;
- remediation;
- security review;
- restoration of affected functionality;
- preservation of relevant evidence; and
- measures intended to reduce recurrence.
Where required by applicable law or applicable contractual obligations, WizHippo will notify the affected Customer or other legally required party without unreasonable delay or within another legally mandated period.
Information may be provided in stages as an investigation progresses.
Where WizHippo processes Customer Data on behalf of a Customer, the Customer may remain responsible for notices to parents, employees, regulators, licensing authorities, or others unless applicable law assigns that responsibility directly to WizHippo.
For example, Illinois law requires a data collector maintaining information it does not own to notify the owner or licensee following discovery of a qualifying breach and cooperate regarding the incident.
15. Children’s Privacy
WizHippo’s Services are designed for use by adults, childcare organizations, their personnel, parents or guardians, and authorized professional users.
Children do not create or independently operate WizHippo accounts.
WizHippo does not knowingly operate the Services as a child-directed account service for children under 13.
Information concerning children is generally supplied by:
- childcare providers;
- parents or guardians;
- authorized adults; or
- Customer-authorized Partners
and is processed as Customer Data on behalf of the applicable childcare provider.
If WizHippo learns that Personal Information has been collected directly from a child in circumstances where applicable law requires parental authorization or other action, WizHippo will take appropriate steps consistent with applicable law, which may include deleting the information or obtaining legally required authorization.
The FTC’s revised COPPA Rule imposes strengthened requirements concerning children’s information, including data minimization and retention requirements for covered child-directed services.
Nothing in this Section transfers to WizHippo the Customer’s responsibilities concerning notices or authorizations required for child records maintained by that Customer.
16. Consumer Health Data Privacy Notice
This Section provides additional information regarding health-related Personal Information and is intended to address, where applicable, laws such as the Washington My Health My Data Act and Nevada consumer-health-data requirements.
Where WizHippo processes health-related Customer Data solely as a processor or service provider on behalf of a childcare Customer, the Customer remains responsible for privacy obligations legally assigned to that Customer as the entity determining the purpose of processing.
To the extent WizHippo independently qualifies as a regulated entity or small business under an applicable consumer-health-data law, the following disclosures apply.
16.1 Categories of Consumer Health Data
Health-related information that may be processed through WizHippo includes:
- allergies;
- medical conditions identified by the Customer or Parent User;
- immunization information;
- medication information;
- health-related incident information;
- health restrictions;
- emergency health information; and
- related records entered into the Platform.
WizHippo does not intentionally infer unrelated health conditions from non-health information for advertising purposes.
16.2 Sources
Consumer health information may be received from:
- childcare Customers;
- Parent Users or guardians;
- Authorized Users and staff;
- Customer-authorized Partners; and
- documents or records those parties submit.
16.3 Purposes
Health-related Customer Data may be processed to:
- provide Customer-requested recordkeeping functionality;
- maintain child records;
- support Customer administrative and childcare processes;
- provide Customer-selected compliance functionality;
- permit access to persons authorized by the Customer;
- provide technical support;
- protect Platform security;
- maintain backups; and
- comply with law.
16.4 Disclosure
Depending upon Customer instructions and Platform permissions, health-related Customer Data may be available to:
- the applicable childcare Customer;
- authorized Customer staff;
- Parent Users authorized by the Customer;
- Customer-authorized Partners;
- WizHippo service providers necessary to operate the Services; and
- legal or governmental authorities where disclosure is lawfully required.
WizHippo does not sell consumer health data.
16.5 Advertising and Cross-Site Collection
WizHippo does not intentionally provide consumer health data or identifiable health-related Customer Data to advertising providers for targeted or cross-context behavioral advertising.
WizHippo does not intentionally permit third-party advertising technologies to collect consumer health data from authenticated WizHippo Customer records over time and across unrelated websites.
16.6 Rights
Where applicable law provides rights regarding consumer health data, individuals may have rights to:
- confirm whether qualifying health data is being collected or processed;
- access qualifying health data;
- request deletion;
- withdraw applicable consent;
- request information concerning sharing;
- request correction where available under applicable law; and
- appeal certain denied requests.
If the information is Customer Data, WizHippo may direct the request to the applicable Customer and assist that Customer as required.
16.7 Changes to Health Data Practices
WizHippo will not materially expand categories or purposes of consumer health data processing in circumstances requiring affirmative consent without obtaining the legally required consent.
Washington law expressly requires disclosure of health-data categories, sources, sharing and rights, and restricts new categories or purposes without required consent. Nevada imposes similar health-data privacy-policy requirements.
17. Your Privacy Rights
Depending upon where you reside and how WizHippo processes your Personal Information, applicable law may provide rights to:
- confirm whether we process your Personal Information;
- access Personal Information;
- obtain a copy of Personal Information;
- correct inaccurate Personal Information;
- request deletion;
- obtain Personal Information in a portable format;
- opt out of sale of Personal Information;
- opt out of sharing for cross-context behavioral advertising;
- opt out of targeted advertising;
- opt out of certain profiling that produces legal or similarly significant effects;
- restrict or limit certain processing of Sensitive Personal Information;
- withdraw consent where processing depends upon consent;
- obtain information concerning third parties receiving Personal Information where required by law; and
- appeal certain decisions concerning a privacy request.
WizHippo does not use Personal Information to make solely automated decisions producing legal or similarly significant effects concerning Individual End Users unless separately disclosed.
Customer Data Requests
If your request relates to information maintained by a childcare provider in its Customer environment, contact that childcare provider first.
The Customer generally controls that information.
If you submit the request directly to WizHippo, we may forward or refer the request to the applicable Customer where appropriate.
Direct WizHippo Information
Requests concerning Personal Information WizHippo controls directly may be submitted through the contact information in Section 22.
18. U.S. State Privacy Disclosures
Where applicable comprehensive U.S. state privacy laws apply to WizHippo, this Section supplements the rest of this Privacy Policy.
Categories Collected
During the preceding twelve months, depending upon the individual’s relationship with WizHippo, we may have collected categories generally corresponding to:
- identifiers;
- customer-record information;
- commercial information;
- Internet or electronic-network activity;
- professional or employment information;
- communications;
- education or training information where applicable;
- sensitive Personal Information;
- information concerning Customer relationships; and
- Customer Data processed on behalf of Customers.
The specific information and purposes are described in Sections 3 through 5.
Sources
Sources are described in Sections 3 and 4 and may include individuals, Customers, Partners, devices and browsers, service providers, payment providers, and permitted public or business sources.
Business-Purpose Disclosures
During the preceding twelve months, applicable categories may have been disclosed to the categories of recipients identified in Section 8 for operational and business purposes.
Sale and Sharing
WizHippo has not sold Customer Data for monetary consideration.
WizHippo does not share identifiable child, family, or staff Customer Data for cross-context behavioral advertising.
WizHippo does not knowingly sell or share Personal Information of persons under 16 for targeted or cross-context behavioral advertising.
As explained in Section 9, certain analytics disclosures involving the public website may potentially fall within broader statutory definitions of “sale,” “sharing,” or “targeted advertising,” depending upon the applicable law and configuration.
Sensitive Personal Information
WizHippo does not use Sensitive Personal Information for the purpose of inferring unrelated characteristics about consumers or for unrelated behavioral advertising.
Financial Incentives
WizHippo does not currently offer financial incentives in exchange for Personal Information in a manner requiring a Notice of Financial Incentive under the California Consumer Privacy Act.
If that practice changes, we will provide the legally required disclosure before implementing the program.
California
If the California Consumer Privacy Act applies to our processing of your Personal Information, California residents may exercise the applicable rights provided by that law.
California’s 2026 regulations require covered businesses’ privacy policies to describe categories collected during the previous twelve months, sources, purposes, sale/sharing practices, rights, and relevant retention information.
Other U.S. States
Residents of jurisdictions including Colorado, Oregon, and other states with applicable comprehensive privacy laws may have additional rights regarding Personal Information.
WizHippo will process qualifying requests in accordance with the applicable law.
19. Privacy Requests, Verification, Authorized Agents, and Appeals
Submitting a Request
You may submit a privacy request using the contact information at the end of this Privacy Policy.
Please identify the type of request and provide enough information for us to determine whether WizHippo or a childcare Customer controls the relevant information.
Verification
WizHippo may need to verify your identity before processing certain requests.
Verification may involve matching information you provide against information associated with your account or requesting additional information reasonably necessary to prevent unauthorized disclosure or deletion.
We will not request more information than reasonably necessary for verification.
Authorized Agents
Where applicable law permits an authorized agent to submit a request, WizHippo may request documentation reasonably necessary to verify the agent’s authority and, where permitted, may separately verify the identity of the individual.
Appeals
Where applicable law gives you a right to appeal denial of a privacy request, you may submit an appeal by contacting us and identifying the prior request and that you are requesting an appeal.
We will respond in accordance with applicable law.
Non-Discrimination
WizHippo will not unlawfully discriminate against an individual for exercising privacy rights.
Exceptions
Privacy rights may be subject to legal exceptions, including where information is reasonably necessary to:
- provide requested Services;
- complete transactions;
- maintain security;
- prevent fraud;
- exercise legal rights;
- comply with law;
- maintain legally required records; or
- protect another person’s rights.
20. Marketing and Communications Choices
You may unsubscribe from WizHippo promotional email communications using an unsubscribe mechanism included in applicable messages or by contacting WizHippo.
Opting out of marketing does not prevent WizHippo from sending:
- account messages;
- security alerts;
- billing communications;
- legal notices;
- Partner Authorization notices;
- support communications; or
- other non-promotional messages reasonably necessary to provide the Services.
If WizHippo provides SMS communications, applicable consent and opt-out requirements will apply.
WizHippo does not sell SMS consent records or mobile-number opt-in information to third parties for their independent marketing purposes.
Service providers may receive such information only as reasonably necessary to deliver communications or otherwise provide authorized services.
21. International Access and Data Transfers
WizHippo is based in the United States, and the Services are primarily operated from the United States.
If you access WizHippo from outside the United States, your information may be transferred to, stored in, or processed in the United States, where privacy laws may differ from those in your jurisdiction.
Where applicable law requires a legally recognized transfer mechanism or other safeguard for international Personal Information, WizHippo will use an appropriate mechanism or otherwise limit processing as required by law.
The availability of WizHippo in a jurisdiction does not itself represent that every Service has been configured for every privacy or data-localization requirement in that jurisdiction.
22. Changes to This Privacy Policy
WizHippo may update this Privacy Policy to reflect changes in:
- our Services;
- Partner functionality;
- payment functionality;
- cookies and analytics;
- privacy laws;
- security practices;
- service providers; or
- business practices.
We will update the Last Updated date when this Privacy Policy changes.
Where required by applicable law, we will review and update applicable privacy disclosures at least annually.
For material changes, we may provide additional notice through the website, Platform, email, login process, or another reasonable method.
Where applicable law requires affirmative consent before a materially different use of particular information, updating this Privacy Policy alone will not substitute for that required consent.
23. Contact Us
Questions concerning this Privacy Policy or WizHippo’s privacy practices may be directed to:
WizHippo LLC
Email: wizhippo@wizhippo.com
Support: support@wizhippo.com
Website: www.wizhippo.com
