Privacy Policy
Jump to section
Biraea ("we," "us," or "our") provides a platform for creating baby announcement and family event websites. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data. By using Biraea, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use our services.
Information We Collect
Account Information
When you create a Biraea account, we collect:
- Name (first and last)
- Email address
- Password (stored as a secure hash, never in plain text)
- Avatar URL (if you choose to upload one)
Site Content
When you build a site on Biraea, you may provide:
- Baby details -- name, due date, partner names
- Event information -- titles, dates, times, venue names and addresses, host names
- Blog posts -- titles, content, images
- Registry links -- store names, URLs, item descriptions and prices
- Photos and images -- hero images, blog cover images, fund images
- Baby name suggestions and votes -- suggested names, voter identifiers
- Baby guesses -- predictions about birth date, weight, length, gender, hair/eye color
- Social posts -- saved drafts with titles, content, and hashtags
- Notification presets -- message templates and delivery preferences
- Meal train details -- dates, delivery notes, meal descriptions
- Games -- game configurations, questions, and settings
Guest Information
Site owners may add guests to their guest lists. Guest data may include:
- Full name
- Email address
- Phone number
- Mailing address (street, city, state, zip, country)
- Dietary restrictions
- Notes
- Guest tags (for organizing guests into groups)
If guest authentication is enabled on a site, guests may also create a password to access gated content. Guest passwords are stored as secure hashes.
Visitor-Submitted Information
People who visit Biraea sites may submit:
- RSVPs -- name, email, dietary restrictions, plus-one count, messages
- Baby name suggestions -- suggested name, submitter name and email, messages
- Baby guesses -- name and email of the guesser, along with their predictions
- Cash fund contributions -- donor name, email, contribution amount, and messages
- Messages -- content posted on site message boards
- Meal train sign-ups -- name and email of the person signing up
- Game session data -- display name, avatar emoji, and answers submitted during games
Payment Information
We use Stripe to process payments for subscriptions, cash fund contributions, and shop purchases. When you make a payment:
- Stripe collects and processes your payment card details directly. We never see or store your full card number.
- We store Stripe account IDs, session IDs, and payment intent IDs to track transaction status.
- For shop orders, we store customer name, email, and shipping address as needed for fulfillment.
- For cash fund contributions, we store donor name, email, amount, and status.
Cookies and Session Data
We use the following cookies and browser storage:
- Session cookie (
babyjoy_session) — keeps you logged in. Contains a session token (not your password or personal data). This is a strictly necessary cookie and does not require consent. Sessions last a maximum of 72 hours and also expire after 8 hours of inactivity. You can end your session at any time by logging out. The cookie is set with theHttpOnlyflag (not accessible to JavaScript),SameSite=Lax(protects against cross-site request forgery), andSecurein production (only sent over HTTPS). You can view your current session details (sign-in time, last activity, and expiration) on your Account Settings page. - Cookie consent (
hearth_cookie_consent) — stores your cookie preferences (which categories you accepted). Stored in localStorage. Persists until you clear your browser data. - Guest authentication — uses session storage to remember your identity while visiting a site. Cleared when you close your browser tab.
- Access codes — stored in session storage for the duration of your visit. Cleared when you close your browser tab.
- Session-scoped voter identifier (
babyjoy_voter_id) — used to prevent duplicate votes on name suggestions. Stored in session storage and cleared when you close your browser tab.
If you accept advertising cookies, third-party ad networks (such as Google AdSense) may set additional cookies to serve relevant advertisements. See the "Advertising" section below for details and your opt-out options.
Automatically Collected Information
We may collect standard server logs that include:
- IP address
- Browser type and version
- Pages visited and timestamps
- Referring URLs
This information is used for security, debugging, and improving our service.
Analytics
Biraea does not currently use third-party analytics services (such as Google Analytics, Mixpanel, or Amplitude). We rely solely on server-side logs for operational monitoring. If we add analytics tools in the future, we will update this policy and, where required, obtain your consent before activating them.
Social Login Data
If you sign in using a social provider (Google, Apple, or Facebook), we receive the following information from that provider:
- Google Sign-In: Google account ID, email address, display name, profile photo URL
- Sign in with Apple: Apple user ID, email address (which may be an Apple relay address), display name
- Facebook Login: Facebook user ID, email address, display name, profile photo URL
We store this information to link your social account to your Biraea account. We do not receive or store your social media password, friend lists, or other social account data beyond what is listed above. You can view and manage your linked social accounts in your Account Settings.
Mobile Application Data
If you use the Biraea mobile app (not yet released — this section applies once it is available), the following data is stored locally on your device:
- Authentication tokens -- stored in the device's secure keychain (iOS Keychain / Android Keystore) and cleared on logout
- Cached site data -- stored in the app's local database for offline viewing. Cache is refreshed when you open the app and cleared on logout
- User preferences -- stored in local app storage (e.g., theme selection, notification preferences)
All locally stored data is cleared when you log out of the mobile app or delete the app from your device. The mobile app communicates with the same servers as the web platform and is subject to the same data handling practices described in this policy.
How We Use Your Information
We use the information we collect to:
- Provide our services -- create and host your sites, manage guest lists, process RSVPs, run games, send notifications, and process payments
- Authenticate you -- verify your identity when you log in, manage sessions, and protect your account with optional two-factor authentication
- Send notifications -- deliver email and SMS notifications you configure (such as birth announcements or event updates) to your guests via Brevo. Every notification includes an unsubscribe link. Guests who unsubscribe are automatically excluded from future notifications. Opt-out requests are honored immediately
- Process payments -- handle subscriptions, cash fund contributions, and shop orders through Stripe
- Improve our platform -- understand how features are used so we can make Biraea better
- Provide support -- respond to your questions and help troubleshoot issues
- Ensure security -- detect and prevent fraud, abuse, and unauthorized access
We will never use information from our mental health support pages for advertising, profiling, or analytics purposes.
How We Share Your Information
We do not sell your personal information. We share data only in these limited circumstances:
Service Providers (Sub-Processors)
We use the following third-party services to operate Biraea. Each processes personal data on our behalf under a Data Processing Agreement (DPA) or equivalent contractual terms:
- Stripe (United States) -- processes payments for subscriptions, cash fund contributions, and shop orders. Stripe receives payment card details (processed directly by Stripe), customer names, email addresses, shipping addresses, and transaction amounts. Stripe Privacy Policy.
- Brevo (France) -- delivers email and SMS notifications on your behalf. Brevo receives recipient names, email addresses, phone numbers, and notification message content. Brevo Privacy Policy.
- Google (United States) -- provides social login via Google Sign-In. Google receives and shares your Google account ID, email address, display name, and profile photo URL during authentication. Google Privacy Policy.
- Apple (United States) -- provides social login via Sign in with Apple. Apple shares your Apple user ID, email address (which may be a relay address), and display name. Apple Privacy Policy.
- Facebook / Meta (United States) -- provides social login via Facebook Login. Meta shares your Facebook user ID, email address, display name, and profile photo URL. Meta Privacy Policy.
- Vercel (United States) -- provides hosting and infrastructure for the Biraea web platform. Vercel processes server requests which may include IP addresses, browser information, and page URLs. Vercel Privacy Policy.
- Google AdSense (United States) -- displays advertisements on certain platform pages (never on your visitor-facing sites). When advertising cookies are accepted, AdSense may collect IP addresses, browser identifiers, and page context. Google Privacy Policy.
We will notify users at least 14 days before adding new sub-processors. A complete register of our data processors, including DPA status and data categories, is maintained internally and reviewed every 6 months.
Guest Data: Controller and Processor Roles
When you add guests to your Biraea site (names, email addresses, phone numbers, mailing addresses, dietary restrictions, etc.), you are the data controller for that guest data. This means:
- You decide what guest information to collect, why you collect it, and who can access it
- You are responsible for having a lawful basis to store your guests' personal data (e.g., their consent, or your legitimate interest in managing your event)
- Biraea acts as a data processor, storing and handling guest data on your behalf according to your instructions
Biraea will:
- Process guest data only as needed to provide our services to you
- Maintain appropriate security measures to protect guest data
- Delete all guest data when you delete your site or your account
- Not use guest data for our own marketing or advertising purposes
- Assist you in responding to data subject requests from your guests
Guests who wish to exercise their data rights (access, correction, deletion) should contact the site owner directly, since the owner is the data controller for their information. If a guest contacts Biraea, we will forward the request to the relevant site owner. If the site owner cannot be reached within a reasonable time, we will act on the request ourselves — limited to the specific site the guest identified — by removing or anonymizing that guest's personal information for that site.
Site Visitors
When you publish a site on Biraea, the content you add (baby details, events, blog posts, registry links, etc.) becomes visible to anyone who visits your site URL or who has the appropriate access code. You control what pages are visible and who can access them through your site settings, guest tags, and access codes.
Legal Requirements
We may disclose your information if required to do so by law or if we believe in good faith that such action is necessary to comply with legal obligations, protect our rights, or ensure the safety of our users.
Business Transfers
If Biraea is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
International Data Transfers
Biraea's primary data storage is in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data is transferred to the United States and other countries where our sub-processors operate. We ensure that these transfers are protected by appropriate safeguards as required by GDPR:
| Service | Country | Transfer Mechanism |
|---------|---------|-------------------|
| Stripe | United States | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs). Stripe DPF certification. |
| Brevo | France (EEA) | No cross-border transfer required for EEA data. Brevo stores data within the EU. |
| Vercel | United States | EU-US Data Privacy Framework (DPF); SCCs. Vercel DPA. |
| Google (Sign-In, AdSense) | United States | EU-US Data Privacy Framework (DPF); SCCs. Google DPF certification. |
| Apple (Sign in with Apple) | United States | SCCs incorporated into Apple's Developer Agreement. Apple privacy commitments. |
| Facebook / Meta | United States | EU-US Data Privacy Framework (DPF); SCCs. Meta DPF certification. |
What this means for you: Your data may be processed in countries with different data protection laws than your home country. The safeguards above (DPF certifications, SCCs) ensure that your data receives equivalent protection regardless of where it is processed.
If a sub-processor's Data Privacy Framework certification is invalidated or withdrawn, we will work with that processor to implement alternative transfer mechanisms (such as updated SCCs) or cease transfers to that processor.
A detailed transfer impact assessment is maintained internally and reviewed alongside our processor register every 6 months.
Advertising and Cookie Consent
- Biraea may display advertisements on certain platform pages, including the Nook (our content hub), the Shop, and the dashboard for free-tier users.
- We never display ads on your visitor-facing sites (pages under
/s/your-site-slug). Your guests will not see ads when visiting your site. - Paid-tier users do not see ads on their dashboard.
Advertising Cookies
When you first visit Biraea, we ask for your cookie preferences. Advertising cookies are only loaded after you consent. If you choose "Necessary only," no advertising cookies are set and no third-party ad scripts are loaded.
If you accept advertising cookies, we may use a third-party ad network (such as Google AdSense) to serve ads. These networks may set cookies on your device to serve relevant advertisements. You can manage your ad preferences through:
- Our cookie banner — appears on your first visit. You can change your preference at any time by clearing your browser's local storage for this site, which will show the banner again.
- Your browser settings — most browsers allow you to block or delete cookies.
- Google's ad settings — https://adssettings.google.com to manage Google ad personalization.
We do not share your personal information with advertisers. Any ad targeting is handled by the ad network based on their own data, not ours.
Data Retention and Deletion
Active Accounts
We retain your account data and site content for as long as your account is active.
Site Retirement (Soft Delete)
When you retire (delete) a site, it enters a 30-day grace period during which:
- The site is no longer visible to visitors
- You can restore the site at any time from your dashboard
- After 30 days, the site and all associated data (events, guests, RSVPs, blog posts, games, messages, etc.) are automatically and permanently deleted by our purge process
Account Deletion
You may delete your account at any time from your Account Settings page on the web dashboard. For your protection, deletion happens in two steps: you confirm your password, and we email a confirmation link to your account address. Nothing is deleted until you open that link, and it expires after one hour. Once you confirm, the following data is permanently removed:
- All of your sites and their associated data (events, RSVPs, blog posts, registry links, cash funds, messages, game configurations, name suggestions, baby guesses, meal train details, notifications, social posts, and all other site content)
- Your guest lists and all guest information
- Your task lists and checklist items
- Your user account, sessions, and authentication data (including two-factor authentication secrets)
- Your connected Stripe account records (note: this removes our record of the connection only; your actual Stripe account remains active and is managed independently by Stripe)
Data that may be retained after account deletion:
- Payment transaction records processed through Stripe may be retained for up to 7 years as required by tax and accounting law. These records include Stripe payment intent IDs, transaction amounts, dates, and status — but never your full card number, CVV, or card expiration date, which are processed and stored exclusively by Stripe
- Anonymized, aggregated usage data that cannot be used to identify you
- Server logs containing your IP address may be retained for up to 90 days for security purposes
Account deletion is permanent and cannot be undone. If you wish to keep your data, please export it before deleting your account. If you only wish to remove individual sites, you may retire them instead, which provides a 30-day grace period for restoration.
Data Retention Schedule
We retain different categories of data for different periods:
- Active account data -- retained while your account is active
- Retired sites -- permanently deleted after 30-day grace period
- User sessions -- 72-hour maximum lifetime, 8-hour inactivity timeout; expired sessions purged daily
- Guest sessions -- expire after 24 hours; purged daily
- Password reset tokens -- expire after 1 hour; purged daily
- Pending payments -- abandoned pending contributions and orders purged after 48 hours
- Game player data -- display names and avatars anonymized after 90 days
- Payment transaction records -- retained for up to 7 years as required by tax and accounting law
- Server logs -- retained for up to 90 days for security purposes
Formal Erasure Requests
You may submit a formal data erasure request ("right to be forgotten") by emailing privacy@hearthsites.com. We will verify your identity, process the request, and confirm completion within 30 days (45 days for requests submitted under CCPA). All erasure requests are logged internally for compliance audit purposes.
Sensitive Deletion
If you retire a site due to pregnancy loss or a similarly sensitive reason, we:
- Suppress future marketing communications to your account
- Handle the deletion process with the same 30-day grace period, allowing you to restore if needed
- Store the deletion reason only as a category code (e.g., "loss"), never as free-text detail
- Do not use or reference the reason for deletion for any purpose other than suppressing marketing
- Permanently delete the deletion reason along with all site data when the 30-day grace period expires
Data Security
We take reasonable measures to protect your information:
- Passwords are hashed using bcrypt before storage. We never store passwords in plain text.
- Session tokens are cryptographically hashed before storage. Sessions have a 72-hour maximum lifetime and an 8-hour inactivity timeout. Expired and inactive sessions are automatically deleted. All sessions are invalidated when you change your password.
- Two-factor authentication (TOTP) is available for additional account security.
- Access codes and guest authentication allow you to control who can view your site content.
- Payment processing is handled entirely by Stripe, a PCI-compliant payment processor.
Internal Access Controls
Administrative access to user data is:
- Restricted to authorized personnel only
- Protected by strong authentication including time-limited, cryptographically signed session tokens
- Limited by the principle of least privilege -- administrative functions are separated from regular user accounts
- Used only for platform operation, support, and compliance purposes
Backup and Recovery
We maintain regular automated backups of our database to protect against data loss. Backups are:
- Encrypted at rest
- Retained for a maximum of 30 days before automatic deletion
- Used only for disaster recovery purposes
- Subject to the same access controls as our production data
When you delete your account or a site's 30-day grace period expires, the data is removed from our production database. Deleted data may persist in backup copies for up to 30 days after deletion, after which it is permanently removed from all backup systems.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
Data Breach Notification
In the unlikely event that your personal data is compromised in a security breach, we will:
- Notify affected users within 72 hours of becoming aware of the breach, via the email address associated with your account
- Notify relevant supervisory authorities as required by applicable law (e.g., GDPR, state breach notification laws)
- Describe the nature of the breach, including what categories of data were affected and the approximate number of users impacted
- Explain what we are doing to address the breach, mitigate potential harm, and prevent future incidents
- Provide guidance on steps you can take to protect yourself, such as changing your password
If a breach affects only data that is encrypted or otherwise unintelligible to unauthorized parties, notification may not be required under applicable law. We will document all breaches internally regardless of whether notification is required.
Children's Privacy
Biraea is a platform about babies and families, but it is designed for use by adults (parents, family members, and friends). We do not knowingly collect personal information from children under the age of 18.
Information about babies (names, birth details, photos) is provided by their parents or guardians, not by the children themselves.
Health-Related Data
Biraea collects certain information that may be considered health-related under some privacy frameworks:
- Due dates and birth dates — provided voluntarily by you to display on your site
- Pregnancy loss information — if you retire a site for this reason, we store only a category code ("loss") and suppress marketing communications. This category code is permanently deleted with the site data after the 30-day grace period
We treat this information with heightened sensitivity. It is used only to provide the features you requested and is never used for advertising, profiling, or shared with third parties beyond what is described in this policy.
If you believe a child under 18 has provided us with personal information without parental consent, please contact us and we will delete it promptly.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access -- You can view your account information and site content at any time through your dashboard.
- Correction -- You can update your account details, guest information, and site content directly in the platform.
- Deletion -- You can retire individual sites (with a 30-day grace period) or permanently delete your entire account through your Account Settings. See Section 6 for details on what data is deleted and what may be retained.
- Data Portability -- You can download a copy of all your personal data in JSON format from your Account Settings page, or request a copy by contacting us.
- Opt Out of Marketing -- You can suppress marketing communications through your account settings or by contacting us. Marketing is also automatically suppressed if you retire a site for a sensitive reason such as pregnancy loss.
- Withdraw Consent -- Where we rely on consent to process your data, you may withdraw that consent at any time.
You have the right to lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, please contact us at the email address listed below.
California Consumer Privacy Act (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.
Categories of Personal Information We Collect
Under CCPA categories, we collect:
- Identifiers -- name, email address, IP address, account ID
- Customer records -- name, address, phone number (for guests and shipping)
- Commercial information -- subscription tier, payment history, shop order history
- Internet activity -- pages visited, browser type, referring URLs
- Geolocation data -- general location inferred from IP address
- Professional information -- not collected
- Education information -- not collected
- Biometric information -- not collected
- Sensory data -- photos and images you upload to your sites
- Inferences -- not collected
Your CCPA Rights
- Right to Know -- You may request details about the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Delete -- You may request deletion of your personal information. You can delete your account and all associated data at any time from your Account Settings.
- Right to Opt-Out of Sale/Sharing -- You may opt out of the sale or sharing of your personal information. Biraea does not sell personal information. However, third-party advertising cookies may constitute "sharing" under CCPA. You can opt out via our Do Not Sell or Share My Personal Information page or in your Account Settings under Privacy Choices. We honor the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we automatically treat it as an opt-out of the sale or sharing of personal information.
- Right to Data Portability -- You can download a copy of all your data in JSON format from your Account Settings.
- Right to Correct -- You may request correction of inaccurate personal information. You can update most information directly in your Account Settings, or contact us at privacy@hearthsites.com.
- Right to Non-Discrimination -- We will not discriminate against you for exercising any of your CCPA rights. You will not receive different pricing, quality, or service levels for exercising your rights.
How to Submit a Request
You can exercise your rights by:
- Visiting our Do Not Sell or Share My Personal Information page
- Using the Privacy Choices section in your Account Settings
- Emailing us at privacy@hearthsites.com
We will verify your identity before processing requests. We will respond to verified requests within 45 days. If we need additional time, we will notify you of the extension and the reason.
Authorized Agents
You may designate an authorized agent to submit a request on your behalf. We may require verification of both your identity and the agent's authorization.
Other U.S. State Privacy Laws
In addition to the CCPA/CPRA, residents of certain other U.S. states have specific privacy rights under their state laws, including the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), and Texas Data Privacy and Security Act (TDPSA).
If you reside in one of these states, you may have rights to:
- Access your personal data
- Correct inaccuracies in your personal data
- Delete your personal data
- Obtain a copy of your personal data in a portable format
- Opt out of the processing of your personal data for targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects
Biraea does not sell personal data or use personal data for profiling that produces legal or similarly significant effects. You can exercise your rights through your Account Settings or by contacting us at privacy@hearthsites.com. We will respond within the timeframe required by your state's law (generally 45 days, with extensions as permitted).
If you are not satisfied with our response, you may appeal by contacting us at privacy@hearthsites.com with the subject line "Privacy Appeal." We will respond to appeals within the timeframe required by applicable law.
Lawful Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), we rely on the following lawful bases under GDPR Article 6 for processing your personal data:
| Processing Activity | Lawful Basis |
|---------------------|-------------|
| Account creation and authentication | Contract — necessary to provide the service you signed up for |
| Hosting and displaying your site content | Contract — core service delivery |
| Processing payments via Stripe | Contract — fulfilling your subscription or purchase |
| Sending notifications you configure | Contract — feature you activated and control |
| Guest data storage on your behalf | Contract — you (as controller) instruct us (as processor) |
| Security monitoring and fraud prevention | Legitimate interest — protecting our platform and users |
| Server logs (IP, browser, timestamps) | Legitimate interest — debugging, security, and service stability |
| Advertising (when consent given) | Consent — only activated after explicit opt-in via cookie banner |
| Email marketing communications | Consent — you may withdraw consent at any time |
| Tax and accounting record retention | Legal obligation — required by tax law |
Where we rely on legitimate interest, we have assessed that our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interest by contacting us at privacy@hearthsites.com.
Where we rely on consent, you may withdraw your consent at any time without affecting the lawfulness of processing performed before withdrawal.
Data Protection Officer
For all privacy inquiries, data protection questions, or to exercise your rights under GDPR, please contact our Data Protection Officer:
- Email: dpo@hearthsites.com
- Mailing Address: Attn: Data Protection Officer — Hearth, 7345 164th Ave NE STE i145 - 1773, Redmond, WA 98052
EU Representative
In accordance with GDPR Article 27, users in the European Economic Area may also contact our EU representative:
- Email: eu-representative@hearthsites.com
Automated Decision-Making and Profiling
Biraea does not use automated decision-making or profiling that produces legal or similarly significant effects on you. Specifically:
- We do not use algorithms to make decisions about your access to services, pricing, or eligibility
- We do not build behavioral profiles based on your activity on the platform
- We do not use automated systems to score, rank, or categorize users
- Ad targeting, if enabled, is handled entirely by the third-party ad network (e.g., Google AdSense) based on their own data and policies, not on profiles we create
If we introduce any form of automated decision-making in the future, we will update this policy, notify affected users, and provide a mechanism to request human review of any such decision.
Third-Party Links
Your Biraea site may contain links to external websites, such as registry links to third-party stores. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email or through a notice on our platform for significant changes
Your continued use of Biraea after changes are posted constitutes your acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Email: privacy@hearthsites.com
Mailing Address:
Hearth, 7345 164th Ave NE STE i145 - 1773, Redmond, WA 98052
We will respond to your inquiry within 30 days.
Version History
- v1.1 -- March 3, 2026 -- Added data retention schedule, U.S. state privacy laws, response time consistency
- v1.0 -- March 3, 2026 -- Initial policy
Questions about your privacy?
We are here to help. Reach out and we will respond within 30 days.
privacy@hearthsites.com