Legal & Privacy

Legal documents. Plain-English summaries.

Every legal document we publish has a short, honest summary at the top. The fine print is still binding — but you shouldn't have to read a 14-page PDF to understand what we will and won't do with your data.

We don't sell data.

Not aggregated, not anonymized, not in any form. Disclosed plainly in our privacy policy.

You own your records.

Export everything, anytime, in structured formats. Termination triggers a 60-day export window.

Camp is the controller.

We're the processor. You decide what's collected, who sees it, and when it's deleted.

30 days' notice on changes.

Material changes to any agreement get 30 days' written notice, every time.

Document library

Every agreement, versioned and dated.

The full, current text of each agreement. Older versions are archived and available on request — we'll send the exact version that was in effect when your camp signed up.

01 · Privacy
Effective 2026-01-15
v4.2 · EN / FR

Privacy Policy

What we collect, why, and who can see it. Plain English: we collect what camps log about incidents and what their staff use to access the product. We don't track campers — they don't have accounts. We don't sell data. Parents can request access or deletion through their camp.

02 · Service
Effective 2026-01-15
v3.1

Terms of Service

The contract between PineReport and your camp. Plain English: we provide the service, you pay for it, both sides can terminate with notice. Annual plans pro-rated on early termination. We don't use your data for anything except providing the service. Limitation of liability is reasonable.

03 · Processing
Effective 2025-11-04
v2.0 · countersign on request

Data Processing Agreement

Required if your jurisdiction needs one (Quebec, EU equivalent regs, several US states). Plain English: camp is data controller; PineReport is data processor. Covers PIPEDA, Quebec Law 25, CCPA/CPRA, and state-equivalents. Sub-processor list is incorporated by reference. Available pre-signed; we'll counter-sign yours.

04 · HIPAA
Effective 2025-09-22
v1.4 · available on request

Business Associate Agreement

For camps that are HIPAA covered entities or treated as such by their carriers. Plain English: aligns our handling of medical incident data with HIPAA standards. Breach notification within 72 hours of confirmed exposure. Available on request — included on Standard and Large tiers at no extra cost.

05 · Sub-processors
Updated 2026-04-08
v17 · 30-day change notice

Sub-processor List

Every third-party we use to deliver PineReport. Plain English: AWS (hosting · US/CA regions), Sentry (error logging), Resend (transactional email), Stripe (billing), Notion (internal docs only, no customer data). Customers get 30 days' advance notice for additions or replacements.

06 · Acceptable use
Effective 2025-06-01
v1.2

Acceptable Use Policy

What you can and can't use PineReport for. Plain English: you can use it to log incidents at your camp. You can't use it to harass anyone, store records outside the camp-safety scope, attempt to break our security controls, or share login credentials across multiple staff accounts.

07 · Cookies
Effective 2025-06-01
v1.0

Cookie Policy

What cookies the marketing site and app use. Plain English: session cookies for staying logged in. Analytics cookies (Plausible, self-hosted, no cross-site tracking). Zero third-party advertising cookies. Configurable on the marketing site via the consent banner.

08 · Parents
Effective 2025-08-15
v2.1 · EN / FR

For Parents

A non-legal page for camp parents who want to understand what's stored about their child. Plain English: what gets recorded if an incident involves your child, who can see it, how long it's kept, and how to request access or deletion through your camp. Designed to be readable in five minutes.

Your rights, exercised

How to actually use your rights under these documents.

Every right we promise comes with a concrete path to exercise it. If any of these don't work as described, write us — we'll fix it the same week.

Jurisdictions

Compliance posture by law and region.

The full security and compliance write-up is on the security page. This is the lawyer-friendly summary.

Law / framework Region Our posture Status
HIPAA United States Aligned safeguards · BAA available Live
CCPA / CPRA California Compliant · no data sales Live
COPPA United States Not child-directed · camps as proxy Live
State privacy (TX, CO, CT, VA, OR) United States Compliant under unified framework Live
PIPEDA Canada (federal) Compliant · DPO designated Live
Law 25 Quebec Full · PIA on file · FR consent text Live
PIPA Alberta · BC Compliant · breach thresholds tracked Live
SOC 2 Type II Independent attestation Audit period closes August 2026 In progress