Privacy Policy

Last updated: [DATE]

Ypath ("we," "us") is a Canadian service that helps teens and their parents explore career paths and Ontario post-secondary options. This policy explains what we collect and why.

Who this is for

Ypath accounts are created and controlled by a parent or guardian. Teen profiles are added by the parent within their household account — teens do not create their own login. If you are a teen using Ypath, it's because a parent or guardian set up your profile.

What we collect

How we use it

Where data is stored

Data is stored with Supabase (hosted on AWS infrastructure) and Stripe for payments. [CONFIRM REGION — check Supabase dashboard → Project Settings → General → Region, and state it here, e.g. "hosted in [region]." Not a legal blocker, but should be accurate.]

Sharing

We don't share personal data with third parties except the service providers needed to run Ypath (Supabase for data storage, Stripe for payments, Google Analytics for usage analytics). We don't share data with school boards or third-party advertisers.

Your rights

Parents/guardians can request a copy of their household's data, request correction, or request deletion of an account and all associated teen profiles, by contacting [CONTACT EMAIL]. We'll respond within a reasonable time and delete data within [X days] of a verified request, except where we're required to retain records (e.g., payment records for tax/accounting purposes).

Children's privacy

Ypath is designed to be used by teens under a parent's account, not directly marketed to or independently signed up by children. If you believe a child has provided us data without appropriate parental involvement, contact us at [CONTACT EMAIL] and we'll address it.

Changes to this policy

We'll update the "Last updated" date above when this changes, and note material changes on this page.

Contact

[CONTACT EMAIL]