Privacy Policy

Last updated: May 30, 2026

1. Introduction

Grandson Service ("Company," "we," "us," or "our") is committed to protecting the privacy of all individuals who interact with our platform, including clients, family members, companions, home service workers, and website visitors. This Privacy Policy explains how we collect, use, store, share, and protect your personal information in connection with our services. We recognize that the information you share with us is deeply personal — it may include health-related details, financial information, and identifying data about vulnerable individuals — and we treat it with the utmost care. By using our website or platform, you agree to the terms of this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our platform and contact us with any concerns.

2. Information We Collect

We collect several categories of personal information depending on your role on our platform. Personal identifiers include your full name, home address, email address, phone number, and date of birth, collected during registration or intake. Government identifiers — such as the last four digits of a Social Security Number — are collected solely where required for background check screening and Fiscal Intermediary enrollment; full Social Security Numbers are collected only when mandated by an FI partner's enrollment process and are stored using industry-standard encryption. Health-related information, including care needs, disability classifications, and medical transport requirements, is collected from clients and families and treated as sensitive data subject to heightened protections. Financial information includes banking routing and account details for companion and worker payroll processing, and payment method information for client billing. Location data in the form of GPS coordinates is captured at the time of companion clock-in and clock-out events to verify service delivery and support payroll accuracy. Device and usage data, including IP addresses, browser type, operating system, session timestamps, and interaction logs, are collected automatically when you use our platform to support security, analytics, and fraud prevention. Communications data encompasses support messages, visit notes, incident reports, and any other content you submit through our platform interfaces.

3. How We Use Your Information

We use the personal information we collect for a range of operational and compliance purposes. Matching clients with compatible companions and home service workers requires us to analyze care needs, service categories, geographic availability, and scheduling preferences. Processing Medicaid and Fiscal Intermediary enrollment requires us to share certain identifying and health-related information with authorized FI partners who are under contractual data protection obligations. Conducting background checks and identity verification is a required step for all companions and workers prior to network activation, and is performed through third-party FCRA-compliant screening providers. Processing payments and payroll requires us to transmit financial information to payment processors and banking partners. We send service-related communications — including scheduling confirmations, visit reminders, payroll notifications, and account alerts — using the contact information you provide. Maintaining visit logs and care records supports accurate payroll calculation, quality assurance, incident tracking, and regulatory compliance. We use data to comply with federal and state law, including mandatory reporting obligations, tax reporting, and legal process responses. We analyze aggregate platform usage data to improve our services, identify operational inefficiencies, and enhance the companion matching experience. We monitor for and investigate fraud, policy violations, and safety concerns using platform data and audit logs.

4. HIPAA Compliance

Grandson Service handles certain health-related information in connection with non-medical home care services. Where applicable, we treat protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the HIPAA Privacy Rule and Security Rule. We implement administrative safeguards including workforce training on privacy obligations and designated privacy responsibilities; physical safeguards including access controls over facilities and workstations; and technical safeguards including encryption, access controls, and audit logging for systems that store or transmit PHI. We do not sell protected health information under any circumstances. We share PHI only with authorized Fiscal Intermediary partners who have executed appropriate Business Associate Agreements, as required by applicable law, or with the express written authorization of the individual to whom the PHI pertains. All companions and administrative staff who have access to client health information are required to complete HIPAA training as a condition of network participation and are contractually bound to maintain the confidentiality of client information. In the event of a breach of unsecured PHI, Grandson Service will comply with the HIPAA Breach Notification Rule — notifying affected individuals, the Department of Health and Human Services, and, where required, prominent media outlets within the timeframes specified by law. If you have questions about how we handle your health information or wish to exercise rights under HIPAA, please contact us at privacy@grandsonservices.com.

5. Sharing of Information

We share your personal information only in limited circumstances and with appropriate safeguards in place. Fiscal Intermediary partners receive client and companion information necessary for Medicaid enrollment and case management, subject to your consent and to Business Associate Agreements or equivalent data protection contracts. Background check providers receive identifying information about applicants solely for the purpose of screening, under FCRA-compliant agreements. Payment processors receive the financial information necessary to execute payroll disbursements and client billing, and are subject to PCI-DSS compliance standards. Platform infrastructure providers — including cloud hosting, database, and communications services — may process data on our behalf under data processing agreements that prohibit independent use of your data. Law enforcement agencies, courts, or government regulators may receive information when we are legally required to disclose it, such as in response to a subpoena, court order, or mandatory reporting obligation. In the event of a merger, acquisition, or sale of assets involving Grandson Service, your information may be transferred to a successor entity, subject to the same privacy protections described in this policy. We do not sell, rent, or lease your personal information to third parties for marketing, advertising, or data brokerage purposes.

6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy and to comply with our legal obligations. Account and profile data is retained for the duration of your account and for a reasonable period thereafter to allow for dispute resolution and legal compliance. Background check records are retained for the period required by applicable state employment screening laws, which may vary by jurisdiction. Financial records, including payroll records, invoices, and transaction logs, are retained for a minimum of seven (7) years in accordance with federal and state tax and accounting requirements. Health-related information, including care records and visit logs involving PHI, is retained in accordance with HIPAA guidelines and any applicable state medical record retention laws. Support communications and incident reports may be retained for longer periods where they relate to ongoing legal matters or compliance investigations. When your information is no longer required for any lawful purpose, we take reasonable steps to securely destroy or anonymize it.

7. Your Rights

Depending on your state of residence, you may have rights with respect to your personal information under applicable privacy law, including state laws such as the California Consumer Privacy Act (CCPA), as amended by the CPRA, and similar state statutes. These rights may include the right to know what personal information we have collected about you and how it is used; the right to request correction of inaccurate or incomplete personal information; the right to request deletion of your personal information, subject to legal retention obligations; the right to restrict or object to certain processing activities; the right to data portability, meaning the ability to receive a copy of your data in a machine-readable format; and the right to withdraw consent for processing activities based on your consent. We do not discriminate against any individual who exercises their privacy rights. To submit a rights request, please contact us at privacy@grandsonservices.com or call (833) 425-1337. We will respond to verified requests within the timeframe required by applicable law. Please note that certain information may be exempt from deletion or access rights where retention is required by law or necessary for legitimate business purposes such as fraud prevention.

8. Cookies and Tracking

We use cookies and similar tracking technologies on our platform for limited, legitimate purposes. Session cookies are used to maintain your authenticated session and allow you to navigate the platform without re-entering your credentials on every page. Functional cookies store your preferences and settings to personalize your experience. Analytics cookies help us understand how the platform is being used in aggregate — such as which pages are visited most frequently, how long sessions last, and where users encounter errors — allowing us to improve our services. We use analytics tools that process data in accordance with their own privacy policies, and we configure these tools to minimize the collection of personally identifiable information. We do not use third-party advertising cookies, behavioral retargeting cookies, or cross-site tracking technologies. You may configure your browser to reject or delete cookies; however, disabling session cookies will prevent you from logging in to the platform. We do not respond to "Do Not Track" browser signals at this time, as there is no uniform standard for such signals.

9. Children's Privacy

Our platform is not directed to children under the age of 13 years, and we do not knowingly collect personal information from children under 13 without verifiable parental consent. Our child companion and homework help services are designed to be used by parents or legal guardians who create and manage accounts on behalf of their children. In these cases, the parent or guardian is the account holder, and the child's information is collected only as necessary to provide the requested service and with the explicit consent of the parent or guardian. If you believe that we have inadvertently collected information from a child under 13 without appropriate parental consent, please contact us immediately at privacy@grandsonservices.com so that we can take corrective action, including deletion of the information.

10. Security

We use a range of industry-standard security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. Data transmitted between your device and our platform is protected using Transport Layer Security (TLS) encryption. Sensitive data fields — including Social Security Numbers, banking information, and health identifiers — are encrypted at rest using AES-256 encryption. Access to personal information within our systems is governed by role-based access controls, ensuring that only authorized personnel with a legitimate need can view specific categories of data. We maintain audit logs of access to sensitive information and review these logs regularly for anomalies. Our platform undergoes periodic security reviews and vulnerability assessments. We require all third-party vendors with access to personal data to maintain appropriate security standards. Despite these measures, no information system is completely immune from security threats. If you believe your account has been compromised or that a security incident has occurred, please contact us immediately at privacy@grandsonservices.com or call (833) 425-1337 so that we can take prompt action.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform capabilities. When we make material changes, we will notify affected users via email to the address associated with your account, or via a prominent notice displayed within the platform, prior to the changes taking effect. The "Last updated" date at the top of this page reflects when the policy was most recently revised. We encourage you to review this policy periodically to stay informed about how we protect your information. Your continued use of the platform following notice of any changes constitutes your acceptance of the updated Privacy Policy.

12. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or to our privacy practices generally, please contact us using the information below. We are committed to addressing your inquiries promptly and transparently.

Grandson Service Phone: (833) 425-1337 Email: privacy@grandsonservices.com Available 7 days a week