Effective: August 6, 2026
Applies to Olive websites, accounts, and services.
This Privacy Policy explains how Granite Security LLC ("Granite," "we," "us," or "our") handles personal information through Olive, our childcare operations software, and the Olive website.
Childcare organizations use Olive to manage their own operations and records. For information that an organization enters or directs us to process, that organization decides why and how the information is used, and Granite acts as its service provider or processor. Granite separately decides how to use limited information for Olive account administration, subscriptions, security, support, and legal compliance.
1. Scope and roles
This Policy applies to Olive websites, organization accounts, parent and guardian accounts, administrative workspaces, attendance stations, support interactions, and related communications. It does not govern a childcare organization's own website, offline practices, or services outside Olive.
If you are a parent, guardian, family member, employee, or other person whose information was entered by a childcare organization, contact that organization first about its privacy practices or a request concerning its records. Granite will assist the organization as required by our agreement and applicable law.
2. Information we handle
The information Olive handles depends on how an organization configures and uses the service. It may include:
- Account and contact information, such as names, email addresses, phone numbers, authentication details, roles, and organization or location information.
- Family and childcare records, such as child names and birth dates, parent or guardian details, emergency and authorized-pickup contacts, care notes, allergies, medications, profile and child-update photos, short child-update audio, staff identity, child supply status, policies, bookings, and attendance.
- Commerce records, such as orders, payment status, receipts, balances, receivables, refunds, disputes, tax statements, and payment-provider identifiers. Olive does not collect or store full payment-card numbers.
- Technical and support information, such as browser and device details, IP address, authentication and security events, service logs, communications, and information submitted in a support request.
3. How we use information
We use personal information to provide and secure Olive, authenticate users, apply organization permissions, process requested workflows, maintain records, deliver communications, provide support, diagnose failures, prevent fraud and misuse, meet legal obligations, and enforce our agreements.
We may use aggregated or de-identified information to understand and improve Olive when that information cannot reasonably identify a person. We do not use customer-controlled child or family records to train general-purpose artificial intelligence models.
4. Child and family information
Olive is intended for authorized adults acting for a childcare organization or family. It is not directed to children, and children should not create Olive accounts or submit information directly.
Child and family information is entered and managed by authorized adults under the childcare organization's policies and instructions. The organization is responsible for providing required notices and obtaining any permissions or consents needed for its collection and use of that information.
When an organization enables private child updates, a family owner controls each child's consent for the current child-care-updates policy version. Withdrawing that consent immediately blocks new publication and access to existing update content while exact private objects are deleted asynchronously.
5. Payments
Organizations may connect their own payment account so families can complete payments through a hosted provider flow. Stripe and Clover may collect payment-card and transaction information under their own privacy policies. Olive receives the status and identifiers needed to reconcile the transaction, update receipts and balances, and support refunds or disputes.
The childcare organization is the merchant for parent payments. Granite separately uses a payment provider for an organization's Olive subscription.
8. Retention
We keep information while it is needed to provide Olive, follow the childcare organization's instructions, protect the service, and meet legal or contractual obligations. Published child-update photos, audio, and captions expire exactly 90 days after publication. Consent or staff withdrawal blocks access immediately even if private object deletion finishes asynchronously. Child supply records remain until archived or removed through the organization's data lifecycle.
When an Olive organization subscription ends, operational customer data is scheduled for deletion after a separate 90-day recovery period. Deleted database records may remain in disaster-recovery copies for up to seven additional days before aging out.
We may retain commercial, agreement, security, audit, dispute, fraud-prevention, and legal records longer when reasonably necessary. The childcare organization may also have its own legal retention duties for childcare and financial records.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including tenant-scoped authorization, encrypted connections, restricted provider credentials, security logging, and service recovery controls. No system is completely secure, so we cannot guarantee that unauthorized access or loss will never occur.
Users must protect their account and device credentials and promptly tell Granite or their childcare organization about suspected unauthorized access.
10. Privacy choices and requests
Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information, or to appeal a decision about a request. These rights may have exceptions under applicable law.
For child, family, attendance, booking, or organization records, contact the childcare organization that controls the record first. For Granite-controlled account, subscription, website, or support information, contact Granite through the support channel shown in Olive or on the organization's invoice or written order form. We may need to verify identity and authority before completing a request.
11. United States processing
Olive is currently offered for United States operations. Information may be processed and stored in the United States, where privacy laws may differ from those in another jurisdiction.
12. Changes to this Policy
We may update this Policy as Olive, our providers, or applicable law changes. We will post the updated Policy with a new effective date and provide additional notice when a material change requires it.
13. Contact Granite
Questions about this Policy or Granite's privacy practices may be sent through the support contact shown in Olive or on the organization's invoice or written order form. Parents, guardians, and other family members should contact their childcare organization first about organization-controlled records.