Privacy Policy
Version 2.15 — Last updated October 3, 2026
ORYN Quest, Inc. ("ORYN Quest," "Company," "we," "our," or "us"), a Delaware corporation, operates an online marketplace that helps Parents and Guardians discover, book, and manage children's activities offered by independent Vendors. This Privacy Policy ("Policy") explains what personal information we collect, how we use it, with whom we share it, and the rights and choices available to you when you access or use the ORYN Quest platform, including our websites, mobile applications, artificial intelligence features, communications systems, and related services (collectively, the "Platform").
By creating an account, accessing, or using the Platform, you acknowledge that you have read and understood this Policy. Where the Platform asks you to accept this Policy, your acceptance is recorded together with the version of the Policy you accepted.
Capitalized terms used but not defined in this Policy have the meanings given to them in the ORYN QUEST — TERMS OF USE and the ORYN QUEST — PARENT & GUARDIAN TERMS AND CONDITIONS.
ARTICLE 1 — SCOPE, ROLES, AND RELATED POLICIES
1.1 Who This Policy Covers
This Policy applies to all users of the Platform, including Parents and Guardians, Vendors, and administrative users, as well as visitors who browse public areas of the Platform without an account.
1.2 Children Do Not Have Accounts
Accounts may be created only by adults eighteen (18) years of age or older. Children never have accounts on the Platform. Information about a Child that appears on the Platform is provided by that Child's Parent or Guardian within the Parent's own account, supplemented only by the Vendor session feedback described in Article 3. Our practices concerning children are described in detail in the ORYN QUEST — CHILDREN'S PRIVACY POLICY, which supplements this Policy.
1.3 The Kid Zone Pledge
The Platform includes a dedicated children's play area at /play (including games and the ORYN Town experience) (the "Kid Zone"). The Kid Zone collects no personal information: no accounts, no advertising, no tracking technologies, and no error-monitoring sessions. See Article 7 for the full Kid Zone commitment.
1.4 Related Policies
This Policy is supplemented by, and should be read together with, the following documents, each of which is incorporated into the Platform's legal framework:
- ORYN QUEST — CHILDREN'S PRIVACY POLICY (children's information and COPPA practices);
- ORYN QUEST — COOKIE POLICY (cookies and similar technologies);
- ORYN QUEST — DATA RETENTION POLICY (how long information is kept);
- ORYN QUEST — CALIFORNIA PRIVACY ADDENDUM (rights of California residents);
- ORYN QUEST — STATE PRIVACY ADDENDA (rights under other U.S. state privacy laws);
- ORYN QUEST — INTERNATIONAL PRIVACY ADDENDUM (users located outside the United States);
- ORYN QUEST — AI FEATURES TERMS (terms governing AI Services);
- ORYN QUEST — CHILD SAFETY POLICY (safety expectations and reporting).
If this Policy conflicts with the ORYN QUEST — TERMS OF USE, the Terms of Use control as to contractual matters; this Policy controls as to descriptions of our information practices.
1.5 Our Approach
We describe in this Policy what the Platform actually does today. Where we reserve the right to introduce a new practice in the future (for example, a new category of cookies), we say so expressly, and we will update the relevant policy and any associated consent mechanisms before the practice begins. The current version of every Platform policy is always available at https://orynquest.com/legal.
ARTICLE 2 — INFORMATION WE COLLECT FROM PARENTS AND GUARDIANS
2.1 Account Information
When a Parent or Guardian creates an account, we collect the information needed to establish and secure it, including name, email address, and password credentials. Authentication is operated by our identity provider, Clerk. If you sign in using a supported social sign-in provider (such as Google or Facebook, and additional providers as offered), we receive basic profile information from that provider (such as your name, email address, and profile image) in order to create and authenticate your account. We do not receive your social account password. An account is created as either a Parent account or a Vendor account; a person who wants both uses a separate account under a different email address for each (ORYN QUEST — VENDOR TERMS & CONDITIONS, Section 2.6).
How you heard about us (optional). After you create an account we may ask, once, "How did you hear about ORYN Quest?" If you choose to answer, we record your choice from a short list (for example, a social network, a search engine, a friend, a school, a class or Vendor, a flyer, or an event) and, if you choose "Other," any short note you type. We use this only to understand which channels bring families to the Platform; it is never used for advertising to you and is never shown to other users. You may skip the question, in which case we record only that you skipped so that we do not ask again. Your answer is deleted with your account.
2.2 Profile and Household Information
You may add optional information to your account, such as a phone number, a street address you type yourself (address suggestions are fetched from the OpenStreetMap Foundation's Nominatim service as you type, as described in Section 9.2), a profile photo or avatar, and preferences that help us tailor the Platform to your family.
2.3 Membership, Credits, and Transactions
We collect records of your Memberships, Credit balances and Credit transactions, Bookings, waitlist activity, cancellations, refunds, referral activity and rewards, and related transaction history.
2.4 Communications
We collect the messages you send and receive through the Platform's in-app messaging (including messages between Parents and Vendors), your posts and comments in community features, your reviews and ratings, your support requests, and your responses to Platform emails. When a Vendor has left a message you sent unread for some time, the alert email we send that Vendor quotes the beginning of your message (up to its first one hundred (100) characters).
Launch waiting list (optional; no account required). If you ask us to tell you when ORYN Quest launches in your area — as a Parent or as a prospective Vendor — we collect your name, email address, ZIP code, the role you chose, and any city or neighborhood you type; a prospective Vendor also provides a business name and the category of activity offered. We record when you gave that consent, which version of this Policy you were shown, and whether and when your email address was confirmed. We use this information only to tell you when we launch near you and to decide where to launch next; it is not a Vendor application, we do not request credentials, documents, or banking information, and joining does not create an account. When you join, we email you a link to confirm your address; until you tap it, your sign-up does not count toward opening your area and you will not get the launch email. If your address is entered again before you confirm, we may send that link again, at most once every fifteen minutes, and we never send one inbox more than three of these emails in any thirty days. If you join while signed in to an Account whose verified email is the same address, your sign-up is confirmed at once, and if you are new to the list we send a plain receipt instead. After that, we email you again only about a launch in your area. To decide where to launch, we count each confirmed inbox once for each role, however the address is spelled (for example with a "+" tag or, for Gmail, with dots), and in each three-digit ZIP area we count no more than two sign-ups per role from any one email domain other than the large free email providers. To limit abuse of the form, we keep records of sign-up attempts and confirmation emails keyed to a one-way hash of your inbox rather than the address itself, used only for these limits, and our email log records the address each of these emails was sent to. You may ask to be removed at any time by replying to any of these emails or by the request route described in Section 12.2; removal also deletes those records and those email log entries. We keep the entry until you ask us to remove it.
Newsletter signup (optional; no account required). If you enter your email address in the newsletter signup, for example in the Help Center, we store the address, the page the signup came from and the time, and we send that address a confirmation email (entering the address again re-sends it at most once every fifteen minutes and never more than three times in all unless the address holder asks us in writing; each one carries a link that stops them) — unless the address already receives ORYN news, has unsubscribed, or belongs to an Account that has turned marketing email or ORYN news off or that may not receive ORYN news, in which case nothing is stored or sent; the signup box shows the same message either way. Only if the link in the confirmation email is tapped do we add the address to the newsletter list and record the time of the confirmation; an unconfirmed address is never sent the newsletter, and nothing else is sent to it. Addresses entered before this confirmation step was introduced are kept only as unconfirmed requests: they are not on the newsletter list and are never sent the newsletter unless the link in a confirmation email is tapped, and that email is sent only if the address is entered in the signup again or at the address holder's written request to support@orynquest.com. We use this information only to send the news email you asked for, and every issue carries a one-click unsubscribe link that works without signing in. An unsubscribed address is kept, marked as unsubscribed with the time, so that it is not added again unless you choose to rejoin (ORYN QUEST — MARKETING CONSENT POLICY, Section 1.3).
2.5 Calendar Information (Optional)
If you choose to connect a Google Calendar to the Platform's family calendar feature, we request only the Google OAuth scopes needed for that feature: the calendar events scope (to create and manage activity events on your calendar) and your email address (to identify the connected account). We do not request access to your wider Google account, contacts, or files. You may disconnect calendar access at any time, including through your Google account security settings.
2.6 Device Location (Optional; Rounded Before Use)
If you allow your device or browser to share your location with the Platform (for example, to find Activities near you), the coordinates your device reports are rounded to three decimal places — a neighborhood-level area of roughly one hundred ten (110) meters — before they are stored and before they are transmitted to any service. The exact coordinates your device reports are never retained. Location at this resolution is still classified as precise location by the Apple App Store and Google Play, and the CCPA treats any location more precise than a circle with a radius of 1,850 feet (about 565 meters) as precise geolocation; our app store listings and the ORYN QUEST — CALIFORNIA PRIVACY ADDENDUM describe it that way. The rounded coordinates are used to center your search and map results and are sent to the OpenStreetMap Foundation's Nominatim reverse-geocoding service to identify a nearby city, state, and ZIP code; that request contains no name or account information. We do not derive or save a street address from your device location (you may type your own address if you choose), and we do not collect location in the background. You may decline or withdraw location permission at any time in your device or browser settings and instead search by typing or selecting a city, neighborhood, or map area.
2.7 Push Notification Subscriptions (Optional)
If you enable push notifications in your browser or on your device, we store the push subscription endpoint or device token needed to deliver them and, for a browser subscription, the browser identification (user-agent string) your browser reported when you subscribed. Notifications to the iOS and Android apps are delivered through Expo's push service and then Apple or Google, and browser notifications through your browser vendor's push service, as described in Section 9.2. Push notifications carry the same kinds of service notices as our emails, such as booking reminders. You can disable push notifications at any time in your browser or device settings, which stops delivery to the stored subscription.
2.8 Automatically Collected Information
When you use the Platform, we and our infrastructure providers automatically receive technical information such as device type, browser type, operating system, IP address, and log information about requests to the Platform. When you electronically sign a waiver through the Platform, the signature record also includes the date and time of signature and, where the signing surface reports them, the IP address and browser identification (user-agent string) reported for the device used to sign, to corroborate and evidence the execution. We also record in-app activity events (such as searches performed, listings and Vendor pages viewed, filters and favorites used, bookings made, and interactions with recommendations) as described in Article 5; you may opt out of that activity-event collection as described in Section 5.4. Cookies and similar technologies are described in the ORYN QUEST — COOKIE POLICY; the Platform sets essential cookies, and analytics cookies only after you choose "Accept All" on the cookie banner (Section 10.1).
2.9 Payment Information
Payments on the Platform are processed by Stripe. Your full payment card number is provided directly to Stripe and is never stored on ORYN Quest systems. We retain limited payment-related records, such as the fact and amount of a transaction, subscription status, and non-sensitive payment identifiers needed to manage your Membership, process refunds, and meet our legal obligations.
2.10 What We Do Not Collect
We do not collect biometric identifiers or facial-recognition data. We do not retain your device's exact coordinates: when you allow device location, coordinates are rounded to three decimal places (a neighborhood-level area of roughly one hundred ten (110) meters) before they are stored or transmitted anywhere, as described in Section 2.6 — a resolution the app stores and the CCPA nonetheless classify as precise location. We do not maintain medical records. We do not purchase data about you from data brokers, and we do not embed third-party advertising technology in the Platform.
2.11 Finding Friends by Contacts (Optional; Website Only)
On the website, you may choose to check whether people in your contacts already use ORYN Quest. If you do, your browser converts each contact's email address and phone number into a one-way SHA-256 hash (of the lower-cased email address and of the digits of the phone number) before anything leaves your device; the names and raw contact details in your address book are never sent to us. Our servers compare the hashes you send with the same one-way hashes of the email address and phone number on each ORYN Quest account and return only the display name, profile avatar and an internal account identifier for each account that matches. The hashes you send are used only to answer that request and are not stored; what we keep is a record of the check itself — its source, how many contacts were checked, how many matched, and how many invitations you sent — in your account, and it is deleted with your account. To limit misuse, each account may check a limited number of contacts per request and per hour. This feature is not offered in the iOS or Android apps, which request no contacts permission. Because matching works from the email address and phone number on an account, any account holder whose contact details you hold can appear as a match, and there is currently no setting that excludes an account from matching (your community profile's discoverability setting does not affect it); a phone number on your account is optional (Section 2.2) and can be removed in your profile settings, and deleting your account ends matching.
2.12 Gift Cards
If you buy an ORYN Quest gift card, we collect the recipient's email address and, if you choose to add them, the recipient's name (up to 120 characters) and a personal message (up to 450 characters). We use them only to deliver the gift. They travel with the purchase as metadata on the Stripe checkout session, so that the gift card can be issued once the payment succeeds (Section 9.2); they are stored on the gift card record together with your account as the purchaser; and the recipient's name, your name as it appears on your account, your message and the gift code are placed in the email we send the recipient through Resend. The recipient's address is also recorded in our email log and in our record of the payment event. The gift card record is a payment record retained under Article 4 of the ORYN QUEST — DATA RETENTION POLICY, so it remains after your account is deleted, attributed to the "Deleted User" placeholder; the recipient's address, name and message on it are not removed by your deletion.
ARTICLE 3 — CHILD PROFILE INFORMATION PROVIDED BY PARENTS
3.1 Sources and Control
Child profiles are records created and maintained by a Parent or Guardian inside the Parent's own account. Child profile information is provided by the Parent, who controls what is entered, may edit it at any time, and may delete it. Children do not enter information into the Platform themselves.
One additional, limited source of information about a Child exists. After a session a Child attended, the Vendor who delivered it may submit session feedback about that Child: ratings on a one-to-five scale for engagement, focus, social interaction, and confidence; strength and challenge tags; whether the Vendor recommends repeating the Activity (yes, no or neutral); and a short note. We use this feedback only to operate the family-facing developmental insights described in Section 5.4, where it is visible to the Child's Parent; it is not published to other users and is never used for advertising. The personalization opt-out described in Section 5.4 stops the computation of developmental insights from this feedback and deletes stored insight scores and behavioral signals.
3.2 Child Profile Contents
A Child profile may include, at the Parent's option: the Child's name, date of birth or age, gender (optional; used to render the Child's avatar and as one signal for activity recommendations), a profile picture, interests, school type, goals, behavior traits and notes, and accessibility and support information.
The profile picture is either the avatar the Platform renders from the gender selection or a photograph of the Child that the Parent chooses to add from the Parent's own photo library or device (the app asks for photo-library permission only when you tap to add one, and never opens the camera). An uploaded photograph is stored in our application file storage (operated by Convex, Section 9.2) under a long random identifier that cannot be guessed; the resulting link is not listed anywhere public, but anyone who has the link could open it, which is why we delete the file itself rather than merely unlinking it. The photograph is shown to the Parent inside their own account and — for a session the Parent has booked — to the Vendor delivering that session, so that staff can recognise the Child at check-in (Section 9.1). It is never published on public pages, never shown in the Kid Zone, never used for advertising, never used for facial recognition or any other biometric processing, and never used to train any AI model. It is deleted when the Parent replaces or removes it, when the Child profile is deleted, and when the account is deleted.
3.3 Sensitive Accessibility and Support Information
To help match a Child with suitable Activities and communicate Accommodation needs, a Parent may choose to record accessibility and support information in a Child profile, such as: an autism-friendly preference, a neurodivergence indicator, sensory support needs and tags, general support needs, vision or hearing impairment indicators, and wheelchair accessibility needs. This information is sensitive. It is optional, provided solely by the Parent, and used only for the purposes described in Section 3.5.
3.4 Insurance Information (Optional)
For Activities that may be covered by insurance (such as certain therapy-related services offered by qualified Vendors where legally permitted), a Parent may optionally provide insurance details for a Child, including the insurance provider, policy number, and group code. This information is used solely to support insurance verification for such Activities, is shared only in connection with that verification process, and is never used for advertising or unrelated purposes.
3.5 Purpose Limitation for Child Profile Information
We use Child profile information only to:
- help discover, match, and recommend Activities suitable for the Child (including through the AI Services described in Article 5);
- communicate Accommodation and support needs in connection with Bookings;
- support insurance verification for insurance-based Activities where the Parent initiates it;
- operate Bookings, attendance, and waivers;
- compute the family-facing developmental insights described in Section 5.4, subject to the personalization opt-out; and
- comply with legal obligations and enforce our agreements.
We do not use Child profile information for advertising. We never engage in behavioral advertising directed at children. Child profile information is never displayed in the Kid Zone.
3.6 Further Detail
The ORYN QUEST — CHILDREN'S PRIVACY POLICY describes our children's-information practices, including our approach to the Children's Online Privacy Protection Act (COPPA), in detail.
ARTICLE 4 — INFORMATION WE COLLECT FROM VENDORS
4.1 Vendor Business Information
Vendors provide business information to join and operate on the Platform, including business name and description, contact details, listing content, scheduling information, pricing in Credits, and the categories of services offered. Our Vendor approval process reviews business information; as described in the ORYN QUEST — VENDOR AGREEMENT and our help resources, ORYN Quest does not run criminal background checks and does not independently verify certifications, insurance, or accommodation capabilities that Vendors self-report. The Vendor application also asks, optionally, "How did you hear about ORYN Quest?"; if you choose to answer, we record your choice from a short list and, if you choose "Other," any short note you type, and we use it only to understand which channels reach activity providers. The question is asked once per account and is never required; the answer is deleted with the account.
Automated application pre-screen. When a Vendor application is submitted, the Platform runs an automated pre-screen on it. It (1) checks that the website address given answers — a request for the page's headers only; the page content is not read; (2) looks up when the website's domain name was registered, through the public registry lookup service rdap.org, which forwards the request to the registry for that domain's ending; (3) sends the business address typed in the application to the OpenStreetMap Foundation's Nominatim service to find its map location; (4) searches Foursquare for a business of that name near that location (the business name and the map coordinates are sent, not the address text); and (5) sends the business information typed into the application — business name, category, description, address, phone number, website, tags, amenities, and the accessibility and insurance declarations — together with the results of those checks (which may name the domain of the applicant's email address, for example gmail.com, but never the address itself or the applicant's personal name) to Google's Gemini model under the terms described in Section 5.5, which returns a short plain-English summary, a low/medium/high risk read, concerns and suggested questions. The results are stored with the application and shown to ORYN Quest's reviewers. Every application is checked this way, and most are then reviewed and decided by a person on the ORYN Quest team. An application may instead be approved automatically, without a person, but only when it is a first application, its details have not changed since the pre-screen read them (a one-way fingerprint of those details is stored with the results to check this), and every automated check passes: the pre-screen finished, the AI's risk read and the overall risk are both low, and no check or AI concern raised a warning; the website answers, is the business's own domain rather than a page on a shared website platform, and was registered at least 365 days earlier; the applicant's email address is on that same domain; the address is found on the map, and Foursquare lists a business of that name near it; no other Vendor account has the same or a similar business name, or the same phone number, website or street address; the business name, description, phone number and address are complete and pass basic checks; and the Vendor Participation Agreement was accepted and general liability insurance acknowledged. This automatic approval is a decision about a business account. The ORYN Quest team is notified of each automatic approval, reviews it, and, until a family has a booking, enrollment or held seat with the business, can reverse it, which returns the application to pending review; after that, the team can suspend the business instead. The pre-screen never declines an application: every rejection, and every approval of an application that does not pass every check, is decided by a person on the ORYN Quest team. To ask a person to reconsider how your application was handled, write to support@orynquest.com. The pre-screen records are deleted with the Vendor's account (Section 12.2).
4.2 Vendor Credentials and Attestations
Vendors may self-report credentials, qualifications, and insurance types. These attestations are stored and may be displayed to Parents as Vendor-provided information.
4.3 Vendor Financial Information
We maintain records needed to calculate and administer Vendor payouts (including payout rates, payout-basis records, the status of each payout, and the reason for and review of any payout hold), and tax-related information required for reporting obligations (for example, information required for IRS Form 1099 reporting where legal thresholds are met). Vendor payouts are sent in one of two ways, as described in the ORYN QUEST — VENDOR PARTICIPATION AGREEMENT. Until Stripe payouts are enabled on the Platform (a platform setting that ORYN Quest may switch on, telling Vendors by email and through the Platform when it does), and afterwards only as an approved exception, ORYN Quest's finance team sends payouts by bank transfer; for that, the Platform stores only the last four digits of the account and routing numbers, together with the account type, so that ORYN Quest can identify the correct account; before the first transfer, our finance team confirms the Vendor's full account and routing numbers with the Vendor directly, outside the Platform, and they are kept, together with any taxpayer information collected for tax reporting, in ORYN Quest's banking and accounting records and used only to pay that Vendor and to meet tax obligations. The Platform does not store full Vendor bank account numbers. Once Stripe payouts are enabled, payouts are made through Stripe Connect: a Vendor opens a Stripe connected account through the Platform and provides bank account, identity verification and tax information (such as a Social Security number or EIN) directly to Stripe, which processes that information under its own privacy policy (stripe.com/privacy); ORYN Quest keeps from Stripe only the connected account identifier, its status and outstanding requirements, and the bank name and last four digits of the payout account. To decide whether a payout needs a review before it is sent, we look at the booking family's account age and Credit history and, to detect a Vendor paying itself, compare one-way hashes of the email addresses and phone numbers on Parent and Vendor accounts and in our welcome-credit records. Parent payments for subscriptions and credit purchases are also processed by Stripe.
ARTICLE 5 — AI FEATURES, PERSONALIZATION, AND ACTIVITY SIGNALS
5.1 The ORYN Quest Assistant
The Platform includes an AI assistant available by text chat and by voice, designed both as a convenience and as a primary accessibility surface for users who prefer or require conversational control of the Platform. When you use the assistant, your messages, the assistant's responses, and the actions you ask it to take are processed to provide the service.
5.2 Voice Processing
When you use voice features, the audio from your microphone is streamed directly from your device to our AI provider (Google's Gemini Live service) over an encrypted connection and processed in real time to understand your speech and respond. The audio does not pass through ORYN Quest's own servers, and ORYN Quest does not record or store it. What we keep is the text: a transcript of what you said and what the assistant replied, saved into your assistant conversation history, together with a session handle that lets an interrupted voice session resume. The processing runs on Google's paid API service tier, under terms providing that Google does not use the prompts or responses to improve its products, and that Google logs prompts and responses for a limited period solely to detect and prevent violations of its prohibited-use policy and to make any legally required disclosures. Voice interactions are part of your assistant conversation history and are covered by the deletion rights in Article 12.
5.3 Conversation Summaries and Assistant Memory
To make the assistant more helpful over time, conversations are summarized and stored as personalization memory associated with your account. Memory items lose confidence when they go unreferenced for thirty (30) or more days and are deprioritized over time; short-lived AI response caches are cleaned daily. For cost and reliability monitoring we also keep a usage log of each AI request — the task, the model used, token counts, an estimated cost, timing and whether it succeeded — together with the first two hundred (200) characters of the prompt; when your account is deleted, the prompt excerpt and the link to your account are removed from these log entries. You may request deletion of your data, including assistant memory, as described in Article 12.
5.4 Activity Signals, Interest Profiles, and Developmental Insights
To power recommendations, the Platform records in-app activity events — such as searches, listing and Vendor-page views, filters, favorites, bookings, and interactions with recommendations — and computes them into an interest profile associated with your parent account (for example, your top activity categories, your recent searches, and Activities you viewed but did not book). Child profiles may also include an AI embedding (a numerical representation generated from profile information using Google Gemini embedding models) used for recommendation matching.
The Platform also computes family-facing developmental insights. A weekly process derives, for each Child profile, skill scores across eight developmental domains, with trends over time — drawing on the session feedback Vendors submit (Section 3.1) and the Child's activity history — together with behavioral signals such as a preferred activity category and typical session frequency. These insights are visible only within your account: to you on your family's Progress page, and to your family's AI assistant so it can personalize its help. They are never used for advertising, and they are not medical, psychological, developmental, or educational evaluations (Section 5.6).
You may opt out of this personalization at any time in your account settings. When you opt out, activity events are not stored, interest profiles are not computed for your account, developmental insight scores and behavioral signals are no longer computed for the Children in your account — and any previously stored scores and signals are deleted no later than the next weekly processing run — and the assistant stops storing new personalization memories from your conversations (existing memories remain until deleted on request). Opting out does not affect your ability to use the Platform.
5.5 AI Providers
AI features are powered by third-party model providers acting on our behalf: Google (Gemini models, including voice audio processing, embeddings, and place-data enrichment) and additional large-language-model providers accessed through OpenRouter. These providers process the content of your AI interactions to generate responses for you; the same Gemini models also process the message text routed to the AI-assisted moderation pass described in Section 6.1 and the Vendor application pre-screen described in Section 4.1. Our Google Gemini processing runs on Google's paid API service tier, under terms providing that Google does not use the content we submit to train its models. When Google's service is unavailable, the same request may be sent to the same Google model through OpenRouter; every request we send through OpenRouter — that mirror, and the fallback language models — instructs OpenRouter to route only to providers that do not store or train on prompts, and a request that no such provider can serve fails rather than being sent elsewhere.
5.6 Nature of AI Outputs
AI outputs are recommendations and assistance only. The AI Services do not provide medical, psychological, developmental, educational, legal, or diagnostic conclusions, and no AI output should be treated as professional advice. The ORYN QUEST — AI FEATURES TERMS govern your use of AI Services.
ARTICLE 6 — MESSAGING, COMMUNITY, AND AUTOMATED MODERATION
6.1 Automated Message Moderation
To protect families and maintain marketplace integrity, in-app messages are automatically screened at the time of sending. A first pass runs on our own servers: messages containing offensive language are blocked and not delivered, and messages that attempt to steer payments off the Platform, improperly disclose costs outside the Credits system, or share contact details in order to move a conversation off the Platform are delivered with a warning to the sender and flagged for human review. Where that first pass finds a soft signal it is not confident enough to act on, the message text (up to its first one thousand (1,000) characters) is sent to Google's Gemini model, under the terms described in Section 5.5, to classify it; this second pass can only add a flag for human review — it never blocks or deletes a message, and if it fails the message simply goes unflagged. Flags are reviewed by ORYN Quest administrators (ORYN QUEST — TRUST & SAFETY POLICY, Article 4). Vendors are also subject to limits on unsolicited outreach to Parents.
A blocked message is not delivered and is not stored as a message, but we keep a moderation record of the attempt: the sender's account, the conversation, the matched terms and the first five hundred (500) characters of the attempted text. These are moderation and safety records (Section 6.3): they have no automatic deletion window and are retained under Section 4.4 of the ORYN QUEST — DATA RETENTION POLICY, including after the sender's account is deleted, when the sender is shown as the "Deleted User" placeholder.
6.2 Community Content Moderation
Posts and comments in community features are subject to automated and human moderation consistent with the ORYN QUEST — COMMUNITY GUIDELINES. Comments are screened automatically at the moment of submission: comments containing offensive content are refused, and comments containing personal contact details (phone numbers, email addresses, or street addresses) are refused. Posts are additionally screened and may be flagged for review where they appear to contain personal information.
6.3 Moderation Records
Moderation events and safety reports are logged and may be reviewed by authorized administrators. We retain moderation and safety records as described in the ORYN QUEST — DATA RETENTION POLICY, including where needed to investigate conduct, enforce our policies, or cooperate with law enforcement under the ORYN QUEST — CHILD SAFETY POLICY.
6.4 Public Content
Reviews and ratings you publish, community posts you share to public groups, and public share pages (such as referral pages and listing share cards) are visible to others. Do not include information in public content that you do not want to be public. Child profile information is not published on public pages by the Platform.
ARTICLE 7 — THE KID ZONE (ORYN PLAY AND ORYN TOWN)
7.1 Zero-Collection Commitment
The Kid Zone at /play and all pages beneath it is designed for children to enjoy without any data collection:
- no accounts and no sign-in;
- no advertising of any kind;
- no analytics and no tracking technologies;
- no cookie banner, because no non-essential cookies are used there;
- error monitoring (Sentry) is fully disabled for sessions that begin in the Kid Zone and is stopped when a session navigates into the Kid Zone; and
- game and town progress is stored only in the browser's local storage on the device, under five keys: "oryn-play" (game progress and badges), "oryn-play-art" (art studio creations), "oryn-town-quests" (town quest progress), "oryn-town-spot" (the last place visited in the town), and "oryn-town-sparks" (the day's collected sparks) — and none of it is ever transmitted to our servers.
One thing is sent to our servers from the Kid Zone, stated here so the list above can be read literally. ORYN Town keeps two town-wide counters for the current calendar day: how many times the town was opened, and how many sparks all visitors collected together. This is what lets the town show a child playing alone that others are playing too. These counters are plain numbers in a single shared daily record. No account, device identifier, session identifier, cookie, or IP address is stored with them; nothing is written per visitor; and nothing about them can be attributed to any person or device. They are never used for advertising, recommendations, or profiling of any kind. The same disclosure appears in the ORYN QUEST — CHILDREN'S PRIVACY POLICY, Article 3.
7.2 Main Street and Vendor Doors
The ORYN Town "Main Street" experience displays Vendor business names (and a city line on a door card) only. It displays no child data and no personal information. Vendor doors open ORYN Quest's own games. Every link from the Kid Zone to a Vendor page, and every other link that leaves the Kid Zone, sits behind a grown-up gate designed for adults (the grown-up types three numbers shown only as words). Vendor placement in the Kid Zone is never paid.
ARTICLE 8 — HOW WE USE INFORMATION
8.1 We use the information described in this Policy to:
- (a) operate the Platform, including accounts, Memberships, Credits, Bookings, waitlists, waivers, attendance, completion certificates, and Vendor payouts;
- (b) match families with Activities, including surfacing Accommodation-compatible options and supporting insurance verification the Parent initiates;
- (c) provide AI Services and personalization as described in Article 5, honoring your opt-out choices;
- (d) enable communications between Parents and Vendors and operate community features, subject to moderation as described in Article 6;
- (e) send service communications by email and, if you enable them, by web or mobile push notifications, including booking confirmations and reminders (typically about twenty-four hours before an Activity), receipts, waitlist and waiver notices, policy notices, weekly digest emails, and re-engagement emails if your account has been inactive; every digest and re-engagement email carries a visible unsubscribe link and supports one-click unsubscribe in your email client, unsubscribed accounts are skipped from those mailings, and you may unsubscribe from non-essential email at any time; and, only if you turned on "Send me ORYN news" in Account settings or your email address is on the newsletter list (a public signup, which puts an address on the list only after it has been confirmed through the link in a confirmation email), send an occasional ORYN news email about new classes and events, each carrying a one-click unsubscribe link that works without signing in — turning the switch off or using that link stops it, and we record when you turned news on and off and which versions of this Policy and the Marketing Consent Policy were shown to you;
- (f) protect the safety and integrity of the Platform, including fraud prevention, enforcement of our policies, quality monitoring of Vendors, and responses to safety reports;
- (g) debug, secure, and improve the Platform, including error monitoring through Sentry (disabled in the Kid Zone); and
- (h) comply with legal obligations, including tax reporting, and establish, exercise, or defend legal claims.
8.2 No Sale; No Behavioral Advertising
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. The Platform contains no third-party advertising technology. We never direct advertising of any kind at children.
8.3 Push Notifications; No Text Messaging
If you enable push notifications, we deliver service notices through your browser or device as described in Section 2.7, and you may disable them there at any time. We do not send SMS text messages, other than the one-time verification code our identity provider, Clerk, texts to a mobile number when you add or verify it (message and data rates may apply); providing a phone number is optional unless the sign-up form asks for one.
ARTICLE 9 — HOW WE SHARE INFORMATION
9.1 With Vendors, to Deliver Booked Activities and Administer Waitlists
When you book an Activity, the Vendor receives the information reasonably necessary to deliver it: the Child's name, age and profile picture (the avatar or the photograph the Parent added, so staff can recognise the Child at check-in — Section 3.2), relevant participation details from the Child profile, Accommodation and support information the Parent has provided for matching and participation, required waiver acknowledgment status, and the Parent's name and profile avatar together with the Parent's messaging channel on the Platform. Vendors do not receive the Parent's phone number, and receive the Parent's email address in one case only: where a Parent signs a Vendor's waiver in the app, the Vendor's record of that signature shows the signing Parent's name and account email address, the name typed as the signature, the Child it was signed for (if any), and the date and time of signature, as part of the legal record of signature. The technical signature metadata described in Section 2.8 — where reported by the signing surface, the IP address and browser identification of the signing device — is retained as evidence of execution and to prevent fraud; it is not displayed to Vendors. For insurance-based Activities, the insurance details a Parent submits are visible to that Parent and to reviewing ORYN Quest administrators for coverage checking; the Platform does not show them, or their verification status, to Vendors. Vendors are contractually required to use this information only to deliver the booked Activity. When you place a Child on the waitlist for a Vendor's session, that Vendor can see the roster for that session's waitlist: your name, the first name of the Child you added, and the entry's position and status in line. Vendors do not receive your email address, phone number, or any other contact details through the waitlist, and they are contractually required to use waitlist information only to plan capacity and administer that session and its waitlist.
9.2 With Service Providers (Processors)
We share information with service providers that process it on our behalf, under contracts limiting their use to providing services to us:
- Convex — application database and backend infrastructure; stores and processes Platform data in real time.
- Clerk — identity and authentication; manages account credentials, sign-in (including social sign-in), and sessions.
- Stripe — payment processing for Memberships, credit purchases and gift cards (handles payment card data; we never store card numbers; for a gift card, the recipient's email address and any recipient name and personal message travel with the checkout as metadata — Section 2.12) and, once Stripe payouts are enabled on the Platform, Vendor payouts through Stripe Connect, for which Stripe collects Vendor bank account, identity and tax information (we never store full bank account numbers). Until then — and afterwards only as an approved exception — Vendor payouts are sent by ORYN Quest's finance team by bank transfer.
- ORYN Quest's bank — sends Vendor payouts by bank transfer until Stripe payouts are enabled, and afterwards as an approved exception; it receives the Vendor's name, account and routing numbers and the amount of each transfer.
- Resend — delivery of transactional and relationship email.
- Expo Application Services (EAS) — delivery of push notifications to the iOS and Android apps: when you enable notifications in the app, we send Expo's push service your device's push token together with the title and text of each notification and the in-app link it opens; Expo relays the notification to Apple (Apple Push Notification service) or Google (Firebase Cloud Messaging), which deliver it to your device under their own terms. Browser push notifications on the website are sent to the push service operated by your browser vendor (for example Google, Apple or Mozilla) at the subscription endpoint your browser gave us.
- Sentry — error monitoring and diagnostics so we can find and fix defects; disabled entirely in the Kid Zone; error reports are configured not to include IP addresses or request headers; on non-Kid-Zone surfaces, session-replay diagnostics capture only sessions in which an error occurs (up to a minute before the error, held until then in the browser's memory, and the rest of that session), to help reproduce defects — replay begins for a session only after the visitor has responded to the cookie banner, and recordings mask text and media content; in our iOS and Android apps Sentry performs error diagnostics only — there is no session replay, no screenshots, no capture of the screen or view hierarchy, and no performance tracing — and app error reports carry no free-form diagnostic detail, with dates, email addresses, telephone numbers, record identifiers and quoted values removed from the error text before it is sent; Sentry is not used to set advertising or cross-site tracking cookies.
- Google Analytics (Google LLC) — website usage measurement (page views, referring sites, device type, approximate city-level location), only after you choose "Accept All" on the cookie banner and never in the Kid Zone; configured with Google Signals and every advertising feature switched off; Google Analytics 4 does not log or store individual IP addresses; event-level data is retained for fourteen months; Google processes this data as our service provider under the Google Ads Data Processing Terms.
- Google — AI model processing (Gemini chat, voice, embeddings, place-data enrichment, the AI-assisted message moderation pass in Section 6.1 and the Vendor application pre-screen in Section 4.1), on Google's paid API service tier under terms providing that Google does not use the submitted content to train its models; Google Calendar synchronization when you connect it (limited to calendar events and email scopes) — when you disconnect it, or delete your account, we also ask Google to revoke the access you granted; and social sign-in if you choose Google sign-in.
- OpenRouter — additional AI model processing for assistant responses, and the same Google Gemini models when Google's own service is unavailable; every request instructs OpenRouter to route only to providers that do not store or train on prompts (Section 5.5).
- Foursquare — place and venue data. Today Foursquare receives one kind of request from the Platform: during the Vendor application pre-screen (Section 4.1), a search for the applicant's business name around the map location of its business address. The Platform also holds place-discovery code that can search Foursquare for places near a map area a user is looking at; no page or app screen uses it at present, and if one does we will update this Policy first. Foursquare never receives your name, account or profile.
- rdap.org — a public domain-registry lookup service, used only in the Vendor application pre-screen (Section 4.1): it receives the domain name of the applicant's website and forwards the request to the registry for that domain's ending, which returns the registration date.
- The Vendor applicant's own website — during the pre-screen (Section 4.1) it receives a request for its page headers, identified as coming from ORYN Quest; the page content is not read.
- OpenStreetMap Foundation — geocoding through its Nominatim service and map imagery from its tile servers, public services that the Foundation operates rather than a contracted processor of ours. It receives four kinds of requests: (1) if you use device location, the rounded, neighborhood-level coordinates (roughly 110-meter precision) needed to return a nearby city, state, and ZIP code; (2) if you use an address search box — for example, to type your own street address or a Vendor business address — the text you have typed, sent as you type so matching addresses can be suggested; (3) whenever the map is displayed, on the website or in the apps, a request to tile.openstreetmap.org for the map tiles covering the area you are looking at; and (4) during the Vendor application pre-screen (Section 4.1), the business address typed in the application, to find its map location. Each request carries the technical information any web request carries (such as an IP address, and for tiles the map area requested) but no name or account information, and it may be processed on servers outside the United States.
- unpkg — a public content delivery network for open-source packages, served through Cloudflare's network. The map inside the iOS and Android apps loads the open-source Leaflet map library and its stylesheet from unpkg.com; the website bundles that library itself and loads only Leaflet's map-marker images from unpkg.com. Those requests carry your IP address and the file requested, nothing else.
- Google Fonts — the map inside the iOS and Android apps loads its map-marker icon font from fonts.googleapis.com and fonts.gstatic.com; those requests carry your IP address and the font requested. The website serves its fonts from our own servers and does not make this request.
- YouTube (Google) — some blog articles may show a video through YouTube's privacy-enhanced player (youtube-nocookie.com), a service Google operates under its own terms rather than a contracted processor of ours. Where a video is shown, your browser loads the player from Google when the video comes close to the part of the page you are viewing (for a video near the top of an article, as soon as the article opens), sending your IP address, which video to show, and our website's address (not the article you are reading); once loaded, the player may contact other Google servers and store data on your device under YouTube's domain even before you press play. Google states that in this mode a viewer's watching is not used to personalize their YouTube experience and that any ads shown in the player are non-personalized; what YouTube stores and receives is governed by Google's policies (policies.google.com/privacy). We receive nothing from YouTube about you.
- Vercel — web hosting and content delivery.
9.3 With Other Users and the Public
Information you choose to publish — reviews, ratings, community posts in public groups, and public share pages — is visible to other users and, for public pages, to anyone with the link. If you create an account after visiting a community group's page on ORYN Quest, your signup may be counted for that group; the group's owner and moderators see only counts — how many people joined through the page and how many of them went on to book — never who.
9.4 For Legal, Safety, and Enforcement Reasons
We may disclose information where we believe in good faith that disclosure is required or permitted by law, including: to comply with a subpoena, court order, or lawful request; to protect the safety of a child or any person, consistent with the ORYN QUEST — CHILD SAFETY POLICY (including cooperation with law enforcement and child protective agencies); to detect, prevent, or address fraud, security, or technical issues; and to enforce our agreements and policies.
9.5 Corporate Transactions
If ORYN Quest is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy or to a successor policy with notice of material changes.
9.6 With Your Direction or Consent
We share information in other ways when you direct us to or otherwise consent — for example, when you connect your Google Calendar or share a referral page.
ARTICLE 10 — COOKIES AND SIMILAR TECHNOLOGIES
10.1 The Platform sets essential cookies — those required for authentication, session security, and core operation. Our identity provider, Clerk, sets the sign-in and session cookies on every visit, and ORYN Quest itself sets one short-lived security cookie, only while you connect Google Calendar (see the ORYN QUEST — COOKIE POLICY). If you choose "Accept All" on the cookie banner, the website also uses Google Analytics 4 to count visits and understand which pages and articles are useful; it is configured with Google Signals and every advertising feature switched off, Google Analytics 4 does not log or store individual IP addresses, and it never runs in the Kid Zone, inside the ORYN Business app, or when your browser sends a Global Privacy Control signal. We do not use advertising cookies and we do not engage in cross-site tracking. Certain preferences (such as your light/dark theme) and Kid Zone game progress are stored in your browser's local storage. A few short-lived notes — how you arrived (a printed card, a community group page or a referral link), the choices you made while signing up and, in the ORYN Business app, sign-in hand-off timings — are kept in the tab's session storage until they have been used or you close the tab (ORYN QUEST — COOKIE POLICY, Section 3.3). None of these are cookies.
10.2 Full details — the cookies set, what Google Analytics collects, its fourteen-month retention, how to change your choice, and the categories we still do not use — appear in the ORYN QUEST — COOKIE POLICY.
10.3 Do Not Track and Opt-Out Signals
The Platform does not track users across third-party sites or services, and we do not sell or share personal information. A universal opt-out preference signal (such as Global Privacy Control) is honored as a choice of "Essential Only" on the website: when your browser sends it, the analytics described in Section 10.1 does not load even if you choose "Accept All" on the cookie banner. Browser "Do Not Track" settings are not a standardized signal, and our default operation already matches what they request. Where a law requires us to treat such a signal as a formal opt-out request, we honor it.
ARTICLE 11 — DATA RETENTION AND SECURITY
11.1 Retention
We retain personal information while your account is active and as needed for the purposes described in this Policy, and we honor deletion requests as described in Article 12. Certain records are retained longer where required for legal, tax, safety, or dispute purposes (for example, payment and payout records, policy acceptance records, waiver signature history, and moderation and safety records). Specific automated retention windows that exist today (such as the seven-day place-data cache, daily AI cache cleanup, 24-hour waitlist claim windows (with expired holds swept about every 15 minutes), and 30-day assistant memory confidence decay) are described in the ORYN QUEST — DATA RETENTION POLICY.
11.2 Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including role-based access separation between parent, vendor, and administrative surfaces, authentication through a dedicated identity provider, payment handling isolated to Stripe, and managed infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and regulators as required by Applicable Law.
ARTICLE 12 — YOUR RIGHTS AND CHOICES
12.1 Access and Correction
You may access and update your account information and Child profiles at any time through your account settings.
12.2 Deletion
You may request deletion of your account and associated personal information — including Child profiles and data associated with social sign-in — at any time:
- immediately, from inside the Platform: open Account, choose Delete account and confirm (the steps are at https://orynquest.com/account-deletion). Deletion takes effect at once; what it does to an active Membership, your Credits and your Bookings is stated in Section 5.6 of the ORYN QUEST — REFUND & CANCELLATION POLICY;
- through the instructions at https://orynquest.com/legal/data-deletion; or
- by emailing support@orynquest.com. Send the request from the email address on your account where you can; if you cannot — for example, because you signed in with Apple using Hide My Email — say so, and we will verify you by replying to the address on file (Apple's private relay forwards our reply to you) or by asking you to confirm the request from inside your account while signed in.
We will act on verified deletion requests and will explain any information we must retain under the legal and safety carve-outs described in the ORYN QUEST — DATA RETENTION POLICY. One such record is stated here so it is not a surprise: when an account receives Welcome Credits or Referee Credits, we keep a record of that grant made of one-way SHA-256 hashes of the email address (as entered and in the standard form described in Section 12.8 of the ORYN QUEST — REFUND & CANCELLATION POLICY) and of the verified mobile number on the account at the time, the account's internal identifier, the type of grant, the number of Credits and the date. It survives account deletion — it is what prevents a second grant to a new account created with the same email address or mobile number, and it lets payout reviews recognize an account that has since been deleted (Section 4.3). It holds no email address or number in readable form, but, like any such hash, it can be matched against an email address or number that is already known (ORYN QUEST — DATA RETENTION POLICY, Section 4.5).
12.3 Personalization Opt-Out
You may opt out of behavioral activity-event collection, interest profiling, and developmental insights at any time in your account settings, as described in Section 5.4. The opt-out is honored end-to-end: while it is enabled, no new activity events are stored, no interest profiles are computed, no developmental insight scores or behavioral signals are computed — and any previously stored insight scores and behavioral signals are deleted no later than the next weekly processing run — and no new assistant personalization memories are saved.
12.4 Email Choices
You may unsubscribe from digest, re-engagement, and other non-essential email using the visible unsubscribe link in each message or your email client's one-click unsubscribe. ORYN news can be turned on or off at any time with the "Send me ORYN news" switch in Account settings; unsubscribing from a digest or re-engagement email also stops ORYN news, which then resumes only if you turn the switch on again. We may still send messages necessary to operate your account, such as booking confirmations, safety notices, and legal notices.
12.5 Calendar Disconnection
You may disconnect Google Calendar access at any time in the Platform or through your Google account settings.
12.6 State and International Rights
Residents of California should read the ORYN QUEST — CALIFORNIA PRIVACY ADDENDUM. Residents of other U.S. states with privacy laws should read the ORYN QUEST — STATE PRIVACY ADDENDA. Users located outside the United States should read the ORYN QUEST — INTERNATIONAL PRIVACY ADDENDUM. Where those documents grant rights beyond this Article, the addenda control for covered residents.
12.7 No Retaliation
We will not deny you services, charge you different prices, or provide a different level of quality because you exercised a privacy right.
12.8 Accessible Formats
The AI assistant is designed as a primary accessibility surface for the Platform, and our accessibility commitments are described in the ORYN QUEST — ACCESSIBILITY & INCLUSION POLICY. If you need this Policy or a privacy process in an alternative accessible format, contact support@orynquest.com and we will accommodate you.
ARTICLE 13 — CHANGES TO THIS POLICY; CONSENT VERSIONING
13.1 We may update this Policy from time to time. When we do, we will revise the "Last Updated" date and version above.
13.2 The Platform maintains a versioned consent system. Your acceptance of each version of this Policy is recorded with the version number, the time of acceptance, how it was captured (at sign-up, with a Vendor application, in the re-acceptance prompt or with a waiver) and the browser identification (user-agent string) your device reported. When we make material changes, the Platform will present the updated Policy for your review and re-acceptance on your next visit, and we may also provide notice by email or through the Platform. Continued use of the Platform after an updated Policy takes effect constitutes acceptance of the updated Policy to the extent permitted by Applicable Law.
ARTICLE 14 — CONTACT
Questions, concerns, or requests regarding this Policy or your personal information may be directed to:
ORYN Quest, Inc. 1125 E Broadway, Suite 101B Glendale, CA 91205, USA Phone: +1 (818) 439-9127 Email: support@orynquest.com Website: https://orynquest.com
We aim to acknowledge privacy inquiries promptly and to resolve them within the timeframes required by Applicable Law.