Privacy Policy

Last Updated: January 15, 2026

1. Introduction

Welcome to 2ok ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services.

2ok is a marketplace platform that connects families with trusted childcare and service providers. By using our platform, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Personal Information You Provide

We collect information you voluntarily provide when using our services, including:

  • Account Information: Name, email address, phone number, password, and profile photo
  • Profile Information: For providers: qualifications, certifications, experience, service areas, and rates. For clients: family information and care preferences
  • Payment Information: Billing address and payment method details (processed securely through Stripe)
  • Communications: Messages exchanged through our platform between providers and clients
  • Booking Information: Event details, schedules, locations, and service requirements

Information Collected Automatically

When you access our platform, we automatically collect certain information:

  • Device Information: Device type, operating system, browser type, and unique device identifiers
  • Usage Data: Pages visited, features used, time spent on the platform, and interaction patterns
  • Location Data: General location based on IP address; precise location only when you grant permission for location-based features
  • Log Data: IP address, access times, and referring URLs

Information from Third Parties

We may receive information from third-party services you connect to your account:

  • Calendar Services: When you connect Google Calendar or Microsoft Outlook, we access calendar data to sync your bookings
  • Background Check Services: Verification results for providers who opt into background screening
  • Payment Processors: Transaction confirmations and payment status from Stripe

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide Services: Facilitate bookings, enable communication between users, and process payments
  • Improve Our Platform: Analyze usage patterns to enhance features and user experience
  • Safety and Trust: Verify identities, prevent fraud, and maintain platform integrity
  • Communications: Send booking confirmations, reminders, and important service updates
  • Customer Support: Respond to inquiries and resolve issues
  • Legal Compliance: Comply with applicable laws and respond to legal requests
  • Marketing: With your consent, send promotional materials about our services (you can opt out at any time)

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Between Users: Providers and clients can see each other's profiles and communicate through the platform to facilitate bookings
  • Service Providers: We share information with trusted third parties who assist in operating our platform (see Section 5)
  • Legal Requirements: When required by law, court order, or government request
  • Safety: To protect the rights, safety, or property of 2ok, our users, or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly authorize sharing

5. Third-Party Services

We use the following third-party services to operate our platform:

Payment Processing

Stripe: We use Stripe to process payments securely. Stripe collects and processes payment information according to their Privacy Policy. We do not store complete credit card numbers on our servers.

Cloud Infrastructure

Amazon Web Services (AWS): Our platform is hosted on AWS, which provides secure data storage and processing. Data is stored in accordance with AWS's security standards and Privacy Notice.

Calendar Integration

Google Calendar: If you choose to connect your Google Calendar, we access your calendar data to sync 2ok bookings. This integration follows Google's Privacy Policy.

Microsoft Outlook: If you connect Microsoft Outlook/Office 365, we access your calendar through the Microsoft Graph API in accordance with Microsoft's Privacy Statement.

Authentication

AWS Cognito: We use AWS Cognito for secure user authentication and account management.

Analytics

Google Analytics: We use Google Analytics to understand how users interact with our platform. You can opt out using Google's opt-out tool.

6. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically:

  • Account Data: Retained while your account is active and for 3 years after account deletion for legal and business purposes
  • Booking Records: Retained for 7 years for tax and legal compliance
  • Messages: Retained for 2 years after the last activity in a conversation
  • Payment Records: Retained for 7 years as required by financial regulations
  • Usage Logs: Retained for 1 year for security and analytics purposes

You can request deletion of your data (see Section 7), subject to legal retention requirements.

7. Your Rights

For All Users

You have the right to:

  • Access and receive a copy of your personal data
  • Correct inaccurate information in your account
  • Delete your account and associated data
  • Opt out of marketing communications
  • Disconnect third-party integrations (calendar sync)

For European Users (GDPR)

If you are located in the European Economic Area, you have additional rights under GDPR:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

Our legal basis for processing under GDPR includes: contract performance, legitimate interests, legal obligations, and consent.

For California Residents (CCPA/CPRA)

California residents have the following rights under CCPA/CPRA:

  • Right to Know: Request information about data collection and sharing practices
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information (note: we do not sell personal information)
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights

To exercise any of these rights, contact us at privacy@2ok.app.

8. Children's Privacy

2ok is designed for use by adults. We do not knowingly collect personal information directly from children under 13 years of age.

While our platform facilitates childcare services, the personal information we collect is provided by parents/guardians about their children for the purpose of arranging care. This information includes:

  • Child's name and age
  • Care preferences and special requirements
  • Allergies or medical considerations

Parents/guardians maintain control over this information and can update or delete it at any time through their account settings.

If we learn that we have collected personal information directly from a child under 13 without parental consent, we will promptly delete that information. If you believe a child has provided us with personal information, please contact us at privacy@2ok.app.

9. Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Strict access controls limit who can access personal data
  • Secure Infrastructure: Our platform is hosted on AWS with industry-standard security measures
  • Payment Security: Payment processing is handled by PCI-compliant Stripe
  • Regular Audits: We regularly review and update our security practices

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use strong passwords and protect your account credentials.

10. Cookies and Tracking

We use cookies and similar technologies to:

  • Keep you logged in to your account
  • Remember your preferences
  • Understand how you use our platform
  • Improve our services

Types of cookies we use:

  • Essential Cookies: Required for basic platform functionality
  • Analytics Cookies: Help us understand usage patterns (Google Analytics)
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling certain cookies may affect platform functionality.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email or through a notice on our platform
  • Where required by law, obtain your consent to the changes

We encourage you to review this policy periodically to stay informed about how we protect your information.

12. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

For GDPR-related inquiries, you may also contact your local data protection authority.