Nanny Placement — $200 to start, balance when we place your nanny. Now open across British Columbia.See how it works →
Puffin Services · Legal

Privacy Policy

Effective date: July 3, 2026 · Last updated: July 3, 2026

Puffin Enterprises Ltd., doing business as "Puffin Services" ("Puffin", "we", "us"), is a British Columbia–based home care platform. We take the privacy of families seriously — you trust us with information about your home and your children, and this policy explains in plain language what we collect, why, who processes it on our behalf, and the choices you have. It is written to meet the disclosure expectations of BC's Personal Information Protection Act (PIPA) and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Who we are

Puffin Enterprises Ltd., doing business as "Puffin Services", operates puffinservices.com from British Columbia, Canada, holding an intermunicipal business licence covering 16 Lower Mainland and Fraser Valley municipalities and a BC employment/placement agency licence for our nanny placement service. For anything in this policy, our privacy contact is admin@puffinservices.com.

2. What we collect, and why

We collect only what we need to deliver care coordination. By category:

  • Contact details — your name, email address, and phone number, so we can respond to inquiries, confirm bookings, and reach you about your care.
  • Home address — so caregivers can be dispatched to the right place and so we can confirm you're within our licensed service area.
  • Care details — the information you provide in booking and inquiry forms (schedules, preferences, special instructions), used solely to match and brief the right caregiver.
  • Children's information — see section 4 below.
  • Photo ID — see section 3 below.
  • Payment information — payments are processed by Square. Your card number never touches our servers and we do not store it; we hold only Square's payment references (for example a payment ID and card brand/last four) needed to manage your booking.
  • Consent records — when you create an account we store whether you accepted our Terms, whether you opted into marketing email, the date and time, and the version of the consent text you saw.
  • Waitlist emails — if you join a "Notify Me" list, we store your email and the service you asked about, only to tell you when it launches.

3. Photo ID and identity verification

Before a caregiver is dispatched to a family's home for the first time, we ask the booking adult to upload a piece of photo identification. Why: our caregivers work alone inside private homes, and verifying who they are meeting is a safety measure that protects both your family and them.

  • Who sees it: your ID is reviewed by a Puffin administrator only. It is never shared with caregivers, other families, or third parties.
  • Where it's stored: in Google Firebase Cloud Storage under access rules that restrict it to your account and our administrator. Administrator access to view it uses short-lived, expiring links.
  • What we record: the outcome of the review (verified / needs resubmission) and the review date on your profile.
  • Retention and deletion: government-issued photo ID is collected strictly for identity verification purposes. We retain the record securely while your account is active so you don't need to re-verify for future bookings. ID records are manually deleted by platform administration — either upon your request (section 9) or at administration's discretion during routine data audits. If your ID record is deleted, re-verification will be required before a future booking.

4. Children's information

We collect information about children only from a parent or guardian, and only what is needed to provide safe, appropriate care: age or date of birth, feeding and sleep routines, allergies and medical notes, temperament, and similar care details you choose to share. This information is used exclusively to match caregivers and brief them for your booking. We never use children's information for marketing, never sell it, and never collect information directly from a child. Our website and services are directed at adults.

5. Third-party service providers

We use a small number of well-established providers to run the platform. Each receives only what it needs for its function:

  • Google Firebase / Google Cloud — our database, sign-in, and file storage (including photo ID uploads).
  • Square — payment processing, card storage, and invoicing. Card data is handled entirely by Square under its own privacy policy.
  • Resend — sending our transactional and marketing email.
  • Vercel — website hosting and the server functions behind our forms.
  • Google Analytics — if enabled, anonymized usage analytics (see section 7).

These providers may store data on servers outside Canada (typically in the United States). Where that happens, your information is subject to the laws of those jurisdictions while stored there.

6. Marketing emails and consent (CASL)

  • Marketing email is optional and opt-in. The marketing checkbox at account creation is never pre-ticked, and declining it has no effect on your service.
  • Every marketing email we send includes a one-click unsubscribe link (and supports your mail app's built-in unsubscribe button). Unsubscribing takes effect immediately.
  • Transactional emails — booking confirmations, verification status, receipts, and similar service messages — are sent regardless of marketing preference, because they are part of delivering the service you asked for.
  • We record when and how you gave or withdrew consent, as CASL requires.

7. Cookies and analytics

We use a small amount of browser storage to keep you signed in (Firebase Authentication) and to remember preferences like a dismissed banner. If Google Analytics is enabled, it sets its own cookies and we configure it with IP anonymization; we use it only in aggregate to understand which pages and features are used. We may also use an error-monitoring service (Sentry) that receives technical details of errors (browser type, the page involved) to help us fix problems — not for advertising. We do not run third-party advertising cookies.

8. Retention and security

We keep personal information only as long as needed for the purposes above or as the law requires (for example, financial records connected to payments). Booking and inquiry records are retained while your account is active and for a reasonable period afterward to handle follow-ups, disputes, and legal obligations. Access to systems holding your information is restricted, administrator actions on sensitive data (like photo ID review and payment capture) are authenticated, and data in our providers' systems is encrypted in transit.

9. Your rights: access, correction, deletion

Under PIPA and PIPEDA you may ask us: what personal information we hold about you, to correct it if it's inaccurate, or to delete it. Send any request to admin@puffinservices.com from the email address on your account, and we will respond within 30 days. We may need to keep certain records where the law requires it (for example payment records), and we'll tell you if that applies. You can also update most profile information yourself from your member portal. If you're not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia.

10. Changes to this policy

If we change this policy in a meaningful way, we'll update the "last updated" date above and, for significant changes, notify account holders by email. Continued use of the service after a change takes effect means the updated policy applies.

Questions about this document? Email admin@puffinservices.com or call (604) 283-2829.