Legal

Privacy Policy

Last updated: March 16, 2026. Effective date: March 16, 2026.

1. Introduction and Scope

Read The Order ("Company," "we," "us," or "our") operates www.readtheorder.com and the Read The Order web application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. This policy applies to all users worldwide, including residents of the United States, the European Union, and the State of California. By using the Service, you consent to the practices described in this policy. If you do not agree, please discontinue use immediately.

2. Information We Collect

We collect the following categories of information: (a) Account Information: Name, email address, and password when you register. (b) User Content: Documents you upload (including parenting plans and legal orders), incident logs, notes, and any other content you submit through the Service. (c) Payment Information: Billing name and payment method details processed by Stripe, Inc. We do not store full card numbers or CVV codes on our servers. (d) Usage Data: IP address, browser type, operating system, pages visited, time spent, and other diagnostic data collected automatically. (e) Communications: Any messages you send to our support team.

3. How We Use Your Information

We use collected information to: • Provide, operate, and maintain the Service • Process payments and manage subscriptions • Generate AI-powered analysis of your documents and incidents • Send transactional emails (account confirmations, receipts, security alerts) • Respond to support requests • Monitor and analyze usage to improve the Service • Detect, prevent, and address fraud, abuse, or security incidents • Comply with legal obligations We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

4. AI Processing and Third-Party Services

Read The Order uses Anthropic's Claude AI API to analyze documents and generate responses. Content you submit may be transmitted to Anthropic's servers for processing. Anthropic's privacy policy governs their handling of this data. We transmit only the minimum necessary content to generate responses and do not instruct Anthropic to store your content beyond what is required for processing. We also use: • Supabase (database and authentication) • Stripe (payment processing) • Vercel (hosting and infrastructure) • Google (authentication via OAuth) Each third party is bound by their own privacy policies and data processing agreements.

5. Data Storage and Security

Your data is stored on servers provided by Supabase and Vercel, located in the United States. We implement industry-standard security measures including: • TLS/SSL encryption for all data in transit • Encryption at rest for stored data • Row-level security policies ensuring users can only access their own data • Access controls limiting employee access to user data Despite these measures, no transmission over the internet is 100% secure. We cannot guarantee absolute security of your data. In the event of a data breach affecting your rights, we will notify you within 72 hours of becoming aware of the breach, as required by applicable law.

6. California Privacy Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA): • Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell. • Right to Delete: Request deletion of your personal information, subject to certain exceptions. • Right to Opt-Out: We do not sell personal information. However, you may submit an opt-out request at any time. • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. To exercise these rights, contact us at privacy@readtheorder.com. We will respond within 45 days.

7. GDPR Rights (European Users)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR): • Right of Access: Obtain a copy of your personal data. • Right to Rectification: Correct inaccurate or incomplete data. • Right to Erasure ("Right to be Forgotten"): Request deletion of your data where there is no legitimate reason for continued processing. • Right to Restrict Processing: Request limitation of processing in certain circumstances. • Right to Data Portability: Receive your data in a structured, commonly used format. • Right to Object: Object to processing based on legitimate interests or for direct marketing. Our legal basis for processing is your consent and the performance of our contract with you. To exercise your rights, contact privacy@readtheorder.com. You also have the right to lodge a complaint with your local data protection authority.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically: • Account data: Retained for the duration of your account plus 30 days after deletion • Payment records: Retained for 7 years as required by financial regulations • Usage logs: Retained for 90 days • Support communications: Retained for 2 years Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

9. Children's Privacy

The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately. If you believe we have inadvertently collected such information, contact us at privacy@readtheorder.com.

10. Cookies and Tracking

We use essential cookies and local storage to maintain your session and authentication state. We do not use advertising cookies or third-party tracking pixels. You may disable cookies in your browser settings, but this may affect the functionality of the Service.

11. Disclosure of Information

We may disclose your information in the following circumstances: • With service providers who assist in operating the Service, bound by confidentiality obligations • If required by law, court order, or governmental authority • To protect the rights, property, or safety of Read The Order, our users, or the public • In connection with a merger, acquisition, or sale of assets, with advance notice to affected users • With your explicit consent

12. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. For material changes, we will provide at least 30 days' notice via email or a prominent notice on the Service prior to the change becoming effective. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact and Data Controller

Read The Order is the data controller for information collected through the Service. For privacy inquiries, to exercise your rights, or to submit a complaint: Email: privacy@readtheorder.com Website: www.readtheorder.com We will respond to all requests within 30 days.