Children's Privacy Policy
Sections 1–7 explain our handling for children under 13 and the Children's Online Privacy Protection Act (COPPA). Section 8 covers users aged 13 to 17.
Effective Date: 2026-08-20 | Version v2.1
TheAwardVault currently limits new account signup to people age 18 or older. If you are a parent or guardian, please read this policy carefully. If you believe we have collected information from a child without consent, contact us immediately.
1. Information we collect about children
Current signup posture: if a person enters a date of birth showing they are under 18, we do not create a Platform account and do not collect a display name, parent email, legal acceptance, or payment information in that signup flow. The short-lived denial record described below is the only Platform record created from that attempt.
When a child under 13 registers, we collect only the minimum information needed to operate the account if minor onboarding is made available after legal review:
- Display name — chosen by the child or their parent.
- Email address — used for account access and transactional notices. When a trophy is sent to a child who has not yet registered, that recipient email is hashed in memory to deliver one notification and is not stored (zero-retention).
- Date of birth — used only to determine age eligibility and is stored encrypted at rest; it is not displayed to others.
- Parent or guardian email address — used solely for the consent process. It is stored as a keyed hash for the consent record; the plaintext address is retained only while a consent link is pending or active and is removed thereafter.
- Trophy records — trophies awarded to the child by authorised organisations.
We do not collect more information than is reasonably necessary to participate in TheAwardVault activities.
2. Verifiable parental consent
Before a child under 13's account is activated, we send a consent request to the parent or guardian email address provided at registration. The parent must:
- Follow the link in the consent email.
- Review the data practices described in the consent portal.
- Choose a data sharing level (see Section 4).
- Actively approve or decline the account.
If a parent does not respond within 72 hours, the pending account is automatically deleted, along with the information collected to create it. As described in the following paragraph, we retain the record of the consent decision itself — including the fact that no response was received — which does not include the child's information.
We use the direct-notice-plus-email consent method to collect a child's information for the internal operation of the Platform, and we retain a record of each consent decision (the parent's typed name, the email hash, a timestamp, and the disclosure version) as evidence of consent. Consent is granted for specific purposes at the time of approval and can be withdrawn at any time (see Section 6).
3. How we use information about children
We use information about children under 13 for the following purposes only:
- To create and operate the child's account.
- To receive, store, and display trophies awarded by organisations.
- To send transactional email (account activation, trophy delivery, parental consent notifications) — sent by Oracle (OCI Email Delivery) acting as our contracted processor.
- To deliver push notifications (if enabled by the parent) — sent via Firebase acting as our contracted processor.
- To comply with legal obligations and maintain audit records.
We do not use information about children under 13 for advertising, profiling, or marketing purposes, and we do not sell or share their personal information.
Oracle and Firebase are contracted service providers that process data on our behalf only and are not permitted to use children's data for their own purposes. Encryption and hashing keys are held in a dedicated key-management service (OCI Vault).
5. Who has access to children's information
Access to a child's account data is restricted to:
- The child themselves (when logged in).
- The awarding organisation that issued a specific trophy.
- TheAwardVault staff with a legitimate operational need, on a least-privilege basis. Privileged access by a designated compliance officer is recorded to an append-only, tamper-evident audit log.
- Contracted processors listed in Section 4 of the main Privacy Policy.
Third parties do not have access to a child's personal information unless the parent has given consent for the "third-party sharing" level (which currently has no active third parties).
6. Parental rights
As a parent or guardian, you have the right at any time to:
- Review the personal information we have collected about your child.
- Correct inaccurate information.
- Delete the information and close the account.
- Refuse to allow further collection or use of your child's information.
- Change the data sharing level you previously consented to.
To exercise these rights, contact us at the address in Section 8. We verify that you control the parent or guardian email address on file before acting on a request, respond within 30 days, and do not charge a fee.
For guidance on managing your child's account, see our Guide for Parents.
7. Account deletion and data retention
For a currently denied under-18 signup, no Platform account is created. For no more than 72 hours from the first denial, we retain an encrypted date of birth, the derived age bracket, a keyed one-way hash of the verified email, and the authentication-provider identifiers needed to delete attempted identities. This is used only to prevent an immediate retry with a different birth date and to stop award notifications to that address during the same window. Repeating the attempt does not extend the deadline. We do not keep the plaintext email in our database, use the record for marketing, or retain it for a future invitation.
We request deletion of the denied authentication identity immediately where destructive processing is enabled. At 72 hours the denial record stops being usable, and an automated sweep permanently deletes it. If an operational outage delays physical deletion, the expired record remains ineligible for use and deletion is retried. Only non-identifying aggregate operational counts are retained after deletion.
When a child's account is deleted (whether by the parent, at the parent's request, or automatically due to consent expiry), we:
- Remove the child's personal information from active systems.
- Retain a hashed (non-re-identifiable) record for legal-compliance and do-not-contact purposes.
- Retain the consent / legal-acceptance ledger (without re-identifiable personal data) as required for regulatory evidence — approximately 7 years.
While an account is active, the date of birth is held encrypted at rest. Parental-consent records are kept for approximately three years after the child reaches the age of majority, and are then deleted.
8. Users aged 13 to 17
COPPA applies to children under 13. This section describes how we treat users aged 13 to 17, who are covered by different rules.
Account creation. New signup is currently limited to people age 18 or older while our minor-account architecture is under legal review. A person aged 13 to 17 who attempts signup receives the same short-lived denial handling described in Section 7; we do not ask for a parent or guardian's email address or create an account.
The one exception is an account a parent set up before the user turned 13. There, the parent's existing access continues until the user turns 18 — it is not removed automatically. This depends on how the account was created, not on the user's age now. See the Guide for Parents.
Privacy protections still apply in full until 18. Being able to sign up independently does not reduce the protections on the account. For every user under 18:
- Trophies are private by default and are not publicly discoverable.
- They cannot be made public, shared by public link, or embedded on other websites.
- Their information is never used for targeted advertising, and is never sold.
- These protections cannot be switched off by the account holder, and remain until they turn 18.
Their own data rights. From age 13, a user may exercise their own privacy rights directly — including requesting a copy of their information or asking us to delete it — without going through a parent or guardian. For a child under 13, a parent or guardian exercises those rights on their behalf (see sections above).
Why the two ages differ. Verifiable parental consent is a requirement that applies to children under 13. Applying it to teenagers would mean collecting a parent's personal information, and blocking a teenager's account on a third party's action, where no law requires either. The privacy protections above are a separate matter and deliberately extend to everyone under 18.
9. Contact us
If you have questions about this policy or wish to exercise your parental rights, please contact us. We respond to verified requests within 30 days.
Von Neumann Systems LLC
Santa Clara County, California, United States
privacy@theawardvault.com · legal@theawardvault.com
Also see: Full Privacy Policy | Guide for Parents