Privacy
What we collect, what we don't, and why.
Last updated May 26, 2026. Plain-English overview below; the full text is below that.

Template pending legal review.
This policy reflects how MyPopover actually operates today, but the language hasn’t been reviewed by counsel yet. We’ll publish the finalized version before we process any real bookings or payments.
In one paragraph
We collect what we need to introduce a vetted companion to your family member: your contact info, your family member’s details, your visit history. We send transactional emails (confirmations, launch notes, waitlist updates). We don’t sell your data, ever. We use a small set of third-party services (auth, database, email, analytics) and we’re explicit about which below. You can delete your account by emailing us at hello@mypopover.com.
Who we are
MyPopover is a service operated by [Company entity name — to be confirmed]. Contact: hello@mypopover.com. This policy covers everything on mypopover.com and any future subdomains.
What we collect
We collect different things depending on what you do on the site:
- Visitors: a session-stable visitor ID cookie (so our A/B tests stay consistent between page loads), plus aggregate analytics (page views, referrers, approximate location via IP) through Vercel Analytics.
- Waitlist signups:the email address you provide, the ZIP code of the person you’re booking for, the urgency answer (within a month / 1–3 months / just curious). Optionally a phone number, only if you’ve checked the SMS-consent box.
- Account holders (bookers):your name, email, password (stored as a one-way hash — we never see the plaintext), session cookie. Optionally phone number.
- Care recipient profiles:the older adult’s name, address, date of birth (optional), interests, mobility notes, and anything else you choose to share with companions.
- Companion applicants:name, email, phone, age, location, work-history references, why you’re applying, your availability summary. Once approved, additional info needed to deliver visits (background-check status, agreement signature, Stripe Connect account details for payouts).
- Bookings:who, where, when, optional notes, status history (pending, confirmed, cancelled, completed). Future: payment authorization details from Stripe (we don’t store card numbers ourselves).
- In-app communication: messages between bookers and companions, kept inside our chat (Phase 6+).
What we don't collect
We don’t store payment card details on our servers (those go directly to Stripe). We don’t collect any health information beyond what you choose to put in optional “mobility notes.” We don’t use third-party advertising or retargeting trackers.
How we use it
- To match families with companions— searching, ranking, and connecting based on availability, location, and the activities the family chose.
- To run the visit— sharing the care recipient’s address and visit notes with the companion only after the booking is confirmed.
- To send transactional email— booking confirmations, applicant status updates, waitlist launch notes, password resets. We don’t send marketing emails without your explicit opt-in.
- To pay companions— through Stripe Connect (Phase 5/7).
- To improve the site— reviewing aggregate analytics, running A/B tests on the waitlist landing variants via Statsig.
- To prevent abuse— identifying fake signups, repeat applications, or other patterns that suggest something other than honest use.
Third-party services
We use a small set of vendors to operate the service. Each receives only the data they need:
- Vercel— hosting + edge network + aggregate visitor analytics. Privacy: vercel.com/legal/privacy-policy.
- Neon (Postgres)— database for accounts, profiles, bookings. Privacy: neon.tech/privacy-policy.
- Better Auth— authentication library running on our own servers; sessions live in our Neon database. No data leaves to a Better Auth vendor.
- Resend— transactional email delivery. Privacy: resend.com/legal/privacy-policy.
- Statsig— A/B test variant assignment. We send an anonymous visitor ID; no PII. Privacy: statsig.com/privacy-policy.
- Stripe (Phase 5/7)— payments + companion payouts. Stripe holds card data directly; we never see it. Privacy: stripe.com/privacy.
- Checkr (Phase 3 follow-up)— background checks for companion applicants. Only used once an applicant has been approved at the interview stage and has consented. Privacy: checkr.com/privacy-policy.
Cookies
We use a small number of cookies, all functional — none for advertising. Specifically:
mp_visitor— a random ID set on first visit to keep A/B test variants consistent across page loads. HttpOnly, lasts a year.- Better Auth session— identifies you when you’re signed in. HttpOnly + secure, lasts until sign-out or the configured session expiry (30 days).
- Vercel analytics— aggregate page views via a first-party cookie.
Retention
We keep waitlist signups indefinitely until you ask us to delete (we’re still small enough that retention isn’t a meaningful cost). Account data persists until account deletion. Booking records persist for tax, dispute, and audit purposes (typically 7 years after the visit). Server logs that include IP addresses are kept up to 90 days.
Your rights
You can ask us to do any of the following by emailing hello@mypopover.com:
- Get a copy of the data we have about you.
- Correct anything that’s wrong.
- Delete your account and associated data (booking history stays in our records for the retention period above, but we’ll redact it from any active views).
- Unsubscribe from any non-transactional email.
- Object to specific processing (e.g. analytics) — we’ll honor it if it doesn’t break the service for you.
Children's privacy
MyPopover isn’t designed for use by people under 18. We don’t knowingly collect data about minors. Care-recipient profiles describe an adult and are maintained by an adult booker.
Changes to this policy
When we materially change this policy, we’ll update the “last updated” date at the top and, for substantive changes, email account holders so you have a chance to read it.
Contact
Questions, requests, complaints: hello@mypopover.com.
See also: Terms of Service.
