Privacy Policy
How Viva Longer LLC, doing business as Ashby Care, collects, uses, and protects information on ashbycare.com and in the Ashby Care apps. Version privacy-2026-08-29.
Effective: 29 August 2026. Version: privacy-2026-08-29.
This Privacy Policy describes how Viva Longer LLC, a California limited liability company doing business as Ashby Care (“we,” “us,” “our,” “Ashby”), collects, uses, and discloses information in connection with ashbycare.com, the Ashby Care staff and parent applications, and related services (collectively, the “Services”).
Please read this Privacy Policy carefully. If you do not agree, do not use the Services. Centers accept this notice, together with the Terms of Service and Data Processing Addendum, by clickwrap at organization signup or when we publish a new version.
1. Who we are
Viva Longer LLC d/b/a Ashby Care 548 Market St PMB 649504 San Francisco, CA 94104-5401 United States
Privacy: privacy@ashbycare.com
We provide software to licensed childcare programs in the United States. We are not a childcare provider, school district, or health plan.
2. Who this notice covers
This notice covers three audiences. The rules are not the same for each.
Website visitors. If you browse ashbycare.com without an account, we are the business that collects limited information about that visit (see Section 4).
Center staff and owners. If you have an Ashby Care account for a childcare organization (the “Center”), we process your account information to run the Services. For child and family records the Center stores in the product, we act as the Center’s service provider / processor. The Center decides what to collect.
Parents and guardians. If a Center invited you, that Center is your vendor for your child’s program. We store records for the Center. We are not your childcare provider. Ask the Center to access, correct, or delete your family’s records, or to change a consent. We will assist the Center.
3. Our roles
State comprehensive privacy laws (including the California Consumer Privacy Act as amended by the CPRA, and similar state laws). For Customer Data the Center submits, the Center is the Business (or controller). Ashby is a Service Provider / Processor. We process that information only to provide the Services, on the Center’s documented instructions, and not for our own commercial purposes. Details are in the DPA.
COPPA (15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312). The Center operates the childcare program and is the primary operator vis-à-vis parents. Ashby provides software as a service provider to that Center. We still implement notice, verifiable parental consent in the product, a written retention policy, and security appropriate to children’s personal information. We do not claim that COPPA is inapplicable. We do not claim the school-authorization exception. We do not claim FERPA coverage. Typical licensed childcare is not a “school” for those purposes.
We never collect children’s data on our own initiative for advertising, sale, or training AI on children.
4. Information we collect
Information you or the Center provide
From Center staff and owners: name, email, authentication identifiers (Firebase UID), role, work contact details, schedules, and billing identity for the Center’s subscription.
From guardians, because the Center invited them: name, email, phone, relationship to a child, consents, messages, and payment tokens if the Center uses in-product tuition payments (card numbers go to Stripe, not to us).
About children, because staff or guardians entered it: legal name, date of birth, room or group, attendance, authorized pickup, emergency contacts, allergies and care notes the Center needs, incident notes, immunization dates the Center stores, and photos or short videos if a guardian opted in.
Care notes and allergy information may be health-related. We process them only as the Center’s service provider so the Center can provide care. We do not operate a consumer health app for families.
Information we collect automatically
We may collect device and log information such as IP address, browser type, approximate general location derived from IP, pages viewed, and error events. On the marketing site this helps us operate the site. In the product, operational logs are used for security and reliability.
We do not put children’s names, photos, or other child-sensitive information into product analytics. Product telemetry, if enabled, is limited to feature events and error identifiers with no child or adult personal information (“T0”).
Information from other sources
Authentication is provided by Firebase Authentication (Google). Payments may involve Stripe. Email delivery may involve Twilio SendGrid. Cloud hosting is Google Cloud. See subprocessors.
What we do not collect in the current product
We do not collect child biometrics for recognition (face templates, fingerprints, voiceprints), live camera streams of children, government-issued identification numbers or Social Security numbers, precise child geolocation, or children’s data for our own advertising or product analytics.
5. How we use information
We use information to:
- Operate the Center’s roster, attendance, ratios, licensing records, billing, and parent communication as the Center directs.
- Authenticate users and keep the Services secure.
- Provide customer support to the Center.
- Improve the product using T0 telemetry only (feature clicks, errors) with no child or adult personal information.
- Comply with law, enforce our Terms, and protect the Services, our rights, and others.
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising as those terms are used in the CPRA. We do not use Customer Data to train AI models. We do not send children’s profiles, medical records, or photos to an AI provider.
6. Children’s privacy (COPPA)
The public marketing site is for adults shopping for software. The parent and staff apps are for adults. Children should not create accounts.
Almost every child record in the Services is a child under 13. Staff and guardians enter that information. Guardians see notice and give verifiable parental consent through signed electronic forms at invite, as described in Section 7.
We keep children’s personal information only as long as reasonably necessary for the purposes in this notice, and not indefinitely. See Section 11 (written retention policy, 16 C.F.R. § 312.10).
Parents may request access, correction, or deletion of their child’s personal information through the Center. We will assist the Center. Declining optional photo or extra-sharing consents still leaves a working parent account for required recordkeeping if enrollment consent is granted.
7. Consent
When a Center invites a guardian, the guardian sees three separate screens:
- Enrollment / recordkeeping (required to use the child record in the app).
- Photo and video (optional; off until the guardian says yes).
- Sharing with non-integral third parties (optional).
Each grant is versioned. The Center is responsible for presenting notice and obtaining consent. We provide the screens and the audit trail. Revoking photos removes that child from photo features on the next request.
Hosting, authentication, and (where used) payment processing are integral to providing the Services the Center asked us to run. They are named on the subprocessor list and are not a separate parent toggle.
8. Photos, video, and public pages
Photos of children are visible only to that child’s authorized guardians and relevant staff — not a public link. Public Center websites on Ashby Care must not include children’s personal information or images. Photo consent inside the logged-in parent experience is not consent to put a child on the public internet.
9. AI
If the Center uses drafting features, we send the provider only non-child-sensitive inputs (for example activity type and a short staff note), never the child’s profile, medical record, or photo. A person at the Center approves before a parent sees a draft. The provider is contracted not to train on that content. Optional extra sharing of child-linked content, if we ever offer it, is covered by the third-party consent screen.
10. Sharing and subprocessors
We disclose information to:
- Subprocessors that help us provide the Services (hosting, authentication, payments, email), under contracts no less protective than the DPA for the data they receive. Current list: ashbycare.com/legal/subprocessors.
- The Center and users the Center authorizes (staff with a role, guardians linked to a child).
- Professional advisors (legal, accounting, insurers) under confidentiality.
- A buyer or successor in a merger, acquisition, or asset sale, subject to this Policy and the DPA.
- Law enforcement or regulators when the law requires it, or to protect the Services, a child, or others from harm.
We do not sell children’s personal information.
11. Written retention policy
Children’s personal information is kept only as long as reasonably necessary for the purposes in this Policy, and not indefinitely.
Each record type has a clock. The clock is the longer of (a) what is reasonably necessary for that purpose under COPPA and (b) the Center’s state childcare licensing hold period for that record type. The product shows the Center its table. We do not apply one state’s licensing numbers to every Center. We do not delete a record before the applicable licensing floor. We do not keep child-sensitive data forever because a round number is convenient.
When a valid deletion request is made through the Center, or when the clock expires, we hard-delete from primary storage. Backups expire on a defined cycle. The Center can export a family’s data before deletion.
Consent records are kept long enough to prove what was agreed. Incident records may be kept longer where reasonably necessary to defend legal claims, but not shorter than the licensing floor.
12. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the information, including encryption in transit and at rest for personal information, tenant isolation so one Center cannot query another Center’s records, role-based access, and audit of access to child-sensitive records. No method of transmission or storage is perfectly secure. We cannot guarantee absolute security.
We do not browse production child records as a casual practice. Access is limited to people who need it to operate or secure the Services.
13. Your choices and rights
Parents. Ask the Center to access, correct, or delete your family’s records, or to revoke a consent. We will assist the Center. We do not become another Center’s parent help desk for a different program’s records.
Center owners and staff. You may update account details in the product. An owner may export or delete the organization subject to the Terms and DPA.
Website visitors. You may control cookies in your browser. Blocking cookies may affect site functions. Like many sites, ashbycare.com is not designed to respond to browser “Do Not Track” signals. Learn more at allaboutdnt.com.
14. State privacy rights
If you are a consumer under a US state comprehensive privacy law (including California, Texas, Virginia, Colorado, Connecticut, and others that have similar statutes), you may have rights to know, access, correct, delete, or opt out of sale or sharing.
Customer Data (child, family, and staff records in a Center’s tenant): exercise those rights through the Center. The Center is the Business. We will not sell or share that information. Sensitive personal information (including children’s data and care notes) is used only to provide the Services.
Marketing-site visitors: we collect limited device and usage information as described above. We do not sell it. We do not share it for cross-context behavioral advertising. To request access or deletion of marketing-site information we hold as a business, email privacy@ashbycare.com. We will not discriminate against you for exercising a privacy right.
California notice at collection (site visitors). Categories: internet or other electronic network activity (pages viewed, IP address, device type). Purposes: operate and secure the site, understand aggregate use. Retention: as reasonably necessary for those purposes, then deleted or de-identified. Sold or shared: no. Sensitive personal information collected on the marketing site: none intended.
Washington My Health My Data Act / similar health-privacy statutes. We do not offer a consumer health product. Allergies and care notes in a Center’s tenant are processed only as that Center’s service provider. Parents should send health-data requests to the Center.
15. Changes
If we make material changes to this Policy, we will publish a new version and require Center owners to re-accept through the product. We will update the effective date and version string at the top. We will not treat continued browsing alone as acceptance of a material change to the Center contract.
16. Contact
Questions about this Policy: privacy@ashbycare.com
Viva Longer LLC, d/b/a Ashby Care 548 Market St PMB 649504 San Francisco, CA 94104-5401 United States
17. California consumer notice
If you are a California resident, in accordance with Cal. Civ. Code § 1789.3, you may report complaints to the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.
Terms · Privacy · DPA · Subprocessors