Skip to main content

Children's Privacy Policy

Sections 1–7 explain our handling for children under 13 and the Children's Online Privacy Protection Act (COPPA). Section 8 covers users aged 13 to 17.

Effective Date: 2026-08-20 | Version v2.1

TheAwardVault currently limits new account signup to people age 18 or older. If you are a parent or guardian, please read this policy carefully. If you believe we have collected information from a child without consent, contact us immediately.

1. Information we collect about children

Current signup posture: if a person enters a date of birth showing they are under 18, we do not create a Platform account and do not collect a display name, parent email, legal acceptance, or payment information in that signup flow. The short-lived denial record described below is the only Platform record created from that attempt.

When a child under 13 registers, we collect only the minimum information needed to operate the account if minor onboarding is made available after legal review:

  • Display name — chosen by the child or their parent.
  • Email address — used for account access and transactional notices. When a trophy is sent to a child who has not yet registered, that recipient email is hashed in memory to deliver one notification and is not stored (zero-retention).
  • Date of birth — used only to determine age eligibility and is stored encrypted at rest; it is not displayed to others.
  • Parent or guardian email address — used solely for the consent process. It is stored as a keyed hash for the consent record; the plaintext address is retained only while a consent link is pending or active and is removed thereafter.
  • Trophy records — trophies awarded to the child by authorised organisations.

We do not collect more information than is reasonably necessary to participate in TheAwardVault activities.

3. How we use information about children

We use information about children under 13 for the following purposes only:

  • To create and operate the child's account.
  • To receive, store, and display trophies awarded by organisations.
  • To send transactional email (account activation, trophy delivery, parental consent notifications) — sent by Oracle (OCI Email Delivery) acting as our contracted processor.
  • To deliver push notifications (if enabled by the parent) — sent via Firebase acting as our contracted processor.
  • To comply with legal obligations and maintain audit records.

We do not use information about children under 13 for advertising, profiling, or marketing purposes, and we do not sell or share their personal information.

Oracle and Firebase are contracted service providers that process data on our behalf only and are not permitted to use children's data for their own purposes. Encryption and hashing keys are held in a dedicated key-management service (OCI Vault).

4. Data sharing levels (consent scope)

When a parent approves an account, they choose a data sharing level. Each level is cumulative — higher levels include all permissions from lower levels:

Basic account (required)

Trophies are visible only to the child and the awarding organisation. No public display. Contracted processors (Oracle, Firebase) may process data to deliver notifications on our behalf.

Shareable links

An unguessable URL for the trophy vault may be shared by the child. The page is accessible to anyone with the link but is not indexed by search engines (noindex/nofollow enforced).

Public discovery

The child's trophy profile is publicly accessible and may be indexed by search engines. The child's display name is shown publicly.

Third-party data sharing

Data may be shared with named third parties for their own purposes. There are currently no third-party sharing arrangements. If any are added, parents will be notified and may update their consent before sharing begins.

Parents can change the consent level at any time by contacting us (see Section 6).

5. Who has access to children's information

Access to a child's account data is restricted to:

  • The child themselves (when logged in).
  • The awarding organisation that issued a specific trophy.
  • TheAwardVault staff with a legitimate operational need, on a least-privilege basis. Privileged access by a designated compliance officer is recorded to an append-only, tamper-evident audit log.
  • Contracted processors listed in Section 4 of the main Privacy Policy.

Third parties do not have access to a child's personal information unless the parent has given consent for the "third-party sharing" level (which currently has no active third parties).

6. Parental rights

As a parent or guardian, you have the right at any time to:

  • Review the personal information we have collected about your child.
  • Correct inaccurate information.
  • Delete the information and close the account.
  • Refuse to allow further collection or use of your child's information.
  • Change the data sharing level you previously consented to.

To exercise these rights, contact us at the address in Section 8. We verify that you control the parent or guardian email address on file before acting on a request, respond within 30 days, and do not charge a fee.

For guidance on managing your child's account, see our Guide for Parents.

7. Account deletion and data retention

For a currently denied under-18 signup, no Platform account is created. For no more than 72 hours from the first denial, we retain an encrypted date of birth, the derived age bracket, a keyed one-way hash of the verified email, and the authentication-provider identifiers needed to delete attempted identities. This is used only to prevent an immediate retry with a different birth date and to stop award notifications to that address during the same window. Repeating the attempt does not extend the deadline. We do not keep the plaintext email in our database, use the record for marketing, or retain it for a future invitation.

We request deletion of the denied authentication identity immediately where destructive processing is enabled. At 72 hours the denial record stops being usable, and an automated sweep permanently deletes it. If an operational outage delays physical deletion, the expired record remains ineligible for use and deletion is retried. Only non-identifying aggregate operational counts are retained after deletion.

When a child's account is deleted (whether by the parent, at the parent's request, or automatically due to consent expiry), we:

  • Remove the child's personal information from active systems.
  • Retain a hashed (non-re-identifiable) record for legal-compliance and do-not-contact purposes.
  • Retain the consent / legal-acceptance ledger (without re-identifiable personal data) as required for regulatory evidence — approximately 7 years.

While an account is active, the date of birth is held encrypted at rest. Parental-consent records are kept for approximately three years after the child reaches the age of majority, and are then deleted.

8. Users aged 13 to 17

COPPA applies to children under 13. This section describes how we treat users aged 13 to 17, who are covered by different rules.

Account creation. New signup is currently limited to people age 18 or older while our minor-account architecture is under legal review. A person aged 13 to 17 who attempts signup receives the same short-lived denial handling described in Section 7; we do not ask for a parent or guardian's email address or create an account.

The one exception is an account a parent set up before the user turned 13. There, the parent's existing access continues until the user turns 18 — it is not removed automatically. This depends on how the account was created, not on the user's age now. See the Guide for Parents.

Privacy protections still apply in full until 18. Being able to sign up independently does not reduce the protections on the account. For every user under 18:

  • Trophies are private by default and are not publicly discoverable.
  • They cannot be made public, shared by public link, or embedded on other websites.
  • Their information is never used for targeted advertising, and is never sold.
  • These protections cannot be switched off by the account holder, and remain until they turn 18.

Their own data rights. From age 13, a user may exercise their own privacy rights directly — including requesting a copy of their information or asking us to delete it — without going through a parent or guardian. For a child under 13, a parent or guardian exercises those rights on their behalf (see sections above).

Why the two ages differ. Verifiable parental consent is a requirement that applies to children under 13. Applying it to teenagers would mean collecting a parent's personal information, and blocking a teenager's account on a third party's action, where no law requires either. The privacy protections above are a separate matter and deliberately extend to everyone under 18.

9. Contact us

If you have questions about this policy or wish to exercise your parental rights, please contact us. We respond to verified requests within 30 days.

Von Neumann Systems LLC

Santa Clara County, California, United States

privacy@theawardvault.com · legal@theawardvault.com

Also see: Full Privacy Policy | Guide for Parents