These documents are placeholders written to the right structure so that nothing is missing when they go to a lawyer. They are not final, they are not legal advice, and they must be reviewed by licensed counsel in every state we operate in before the platform takes a real booking.
Privacy policy
How we handle information about families, care recipients, caregivers and employer administrators. Written to be readable; the operative commitments are the ones in bold.
Last updated: placeholder — set on publication. Status: draft pending counsel review.
Who we are
Backstop Care, Inc. provides an employer-sponsored back-up care service. When your employer buys the benefit, we act as a processor for the eligibility data they give us, and as a controller for the account and booking data you create with us directly.
What we collect
From your employer: the minimum needed to establish eligibility — name, work email, employee identifier, and plan assignment. Not compensation, not performance, not anything else on their HRIS record.
From you, when you create an account: name, contact details, home address and any other care address you use, payment method, and the care recipients you add.
About care recipients: name, date of birth, allergies, conditions relevant to safe care, emergency contacts, and — where you provide it — medical and cognitive notes. This is the most sensitive data we hold and it is treated accordingly: encrypted at the column level under a dedicated key, access logged, and structurally excluded from analytics, application logs and any employer-facing view.
From caregivers: identity documents, background-check status and identifier (never the report contents), credentials, references, work authorisation and payout details.
Automatically: device and usage data, and approximate location at clock-in for the geofence check. We do not track caregiver location outside of a booking window.
What your employer can and cannot see
Your employer can see: that a booking happened, its care type at a category level, its cost, and which entitlement it consumed.
Your employer cannot see: who the care was for, their name, age or condition, any medical or cognitive note, any care note written by a caregiver, or any message between you and a caregiver. This is enforced by database-level access rules and a dedicated reporting view, not by an internal policy — and there is an automated test asserting it that runs on every change we make.
Why we process it
To match and dispatch caregivers; to verify that caregivers are safe to place; to operate entitlements and billing; to notify both sides of state changes; to investigate incidents; and to meet legal obligations including mandatory reporting. We do not sell personal information, and we do not use care-related data to train models.
Who we share it with
Our subprocessors, each for a specific purpose: hosting and database, background checks, identity verification, payments, SMS and voice, email, mapping, error monitoring and product analytics. The current list is published on our security and compliance page and we give 30 days' notice before adding one that processes personal data.
We share with a caregiver only what a specific confirmed booking requires — and before confirmation they see a neighbourhood, not an address, and no family surname or phone number.
How long we keep it
- Bookings and audit events: 7 years, matching the liability window.
- Message bodies and attachments: purged 30 days after a booking completes. The message record survives with its content removed so the audit trail stays intact.
- Care note photos: 90 days, unless attached to an incident.
- Background check reports: never stored. We hold the status and the report identifier only.
- Incident records: retained indefinitely and immutable. Corrections are appended, never edited.
Your rights
Depending on where you live you may request a copy of your data, correction, deletion, or restriction of processing. Export and deletion are self-service in the app rather than an email queue. Audit events are retained under legal hold where deletion would destroy a record we are required to keep; we tell you exactly what that covers when you make the request.
To exercise any right, use the controls in your account or email hello@backstopcare.com.
Children
We collect information about children from their parents. We do not offer any child-facing account or interface, and children do not interact with our software.
Security
TLS in transit, AES-256 at rest, dedicated key encryption on health-classified columns, private storage buckets accessed only through short-lived signed URLs, mandatory multi-factor authentication for every privileged role, and annual third-party penetration testing. Fuller detail on the security and compliance page.
Changes
We will post changes here and, for anything that materially affects how we use your data, tell you directly rather than relying on you noticing a new date at the top of a page.