CandlestickCandlestick
PrivacyTerms

Last updated August 28, 2026

Privacy Policy

This Privacy Policy explains how Candlestick (“Candlestick,” “we,” “us,” or “our”) collects, uses, and shares information when you use our websites, applications, devices, and related services (the “Services”).

We operate the Services at connecting.family and related Candlestick domains. Privacy questions: privacy@connecting.family.

1. Who this policy covers

Candlestick is a family phone product. Grown-ups are the users who create accounts and sign in. Children do not sign in and are not account users. Children may still use Candlestick phones in a household, and information about those phones and communications may be processed so the family network works.

This policy covers:

  • Account Holders and other adults who sign in to manage a family network; and
  • personal information about children that a grown-up provides or that is generated when a child uses a Candlestick phone (subject to COPPA, as described below).

Where we refer to “you,” we mean the adult Account Holder or signed-in user, unless we are clearly talking about a child’s information (in which case “you” may mean the parent or guardian acting for that child).

2. Information we collect

We collect information in these categories:

  • Account and profile information (grown-ups). Name, email address, profile image, and authentication identifiers from your sign-in provider (for example, Google via Clerk), plus household or network names you configure.
  • Family network configuration. Names or nicknames for household members (including children), line and device assignments, directory contacts and shortcuts, reachability and do-not-disturb settings, call-routing preferences, and similar settings grown-ups configure.
  • Communications metadata. Limited telephony and messaging metadata needed to operate the Services (for example, timestamps, call or message status, numbers or addresses involved, and routing outcomes).
  • Voice and message content. Features such as voicemail may record or store voice audio or message content so household members can listen later. That content is stored to provide the feature the family requested. It is not shared with third parties for their own purposes, and access is limited to the child or household member it belongs to and the grown-ups who manage that family network—not to unrelated third parties or other families.
  • Device and service data. Device identifiers, model and firmware information, IP address, browser or app type, diagnostic logs, security events, and product activity tied to an account or network.
  • Emergency and address information. Emergency or service addresses grown-ups provide for regulatory or safety purposes.
  • Communications with us. Support requests and other messages grown-ups send us.

3. Children’s privacy (COPPA)

Children are not Candlestick account users and do not sign in. We may still process personal information about children under 13 when a grown-up sets up a family network and a child uses a Candlestick phone on that network.

  • Parental consent. An Account Holder must be 18 or older (or the age of majority where they live). By creating a family network, adding a child’s information, or enabling a Candlestick phone for a child, the Account Holder represents that they are the child’s parent or legal guardian (or have authority to act for that parent or guardian) and consents to our collection, use, and disclosure of the child’s personal information as described in this policy. We may use reasonable methods to obtain or confirm verifiable parental consent consistent with COPPA, and we may refuse or disable child-related setup until consent is confirmed.
  • What we collect about children. Typically nicknames or given names provided by grown-ups, device and line settings, approved contacts, communications metadata needed to operate the network, and voice or message content if the child (or someone calling them) uses a feature that records it—such as voicemail.
  • How we use children’s information. Solely to provide and secure the family phone Services the Account Holder requested, honor parental controls, support safety features, comply with law, and prevent fraud or abuse. We do not require more personal information about a child than is reasonably necessary for those purposes.
  • Voice recordings. Voice recordings and similar content are not sold or shared for advertising or other third-party use. Access is limited to the relevant child or household member and the grown-ups on that family network.
  • No behavioral advertising to children. We do not sell children’s personal information. We do not use children’s personal information for targeted or behavioral advertising, and we do not enable third parties to collect children’s personal information from the Services for their own marketing.
  • Parent rights under COPPA. A parent or guardian may review personal information collected from their child, request that we delete it, and refuse further collection or use. Email privacy@connecting.family from the Account Holder address (or otherwise verify parental status). We may ask for information reasonably necessary to verify the request.

If we learn we collected a child’s personal information without required parental consent, we will delete it or take other appropriate steps as soon as reasonably practicable.

4. How we use information

We use personal information to:

  • provide, secure, maintain, and improve the Services;
  • authenticate grown-ups and manage accounts, networks, devices, and lines;
  • enable calling, messaging, directory, voicemail, and related family features;
  • apply parental controls and safety settings configured by grown-ups;
  • send service, security, and account notices to Account Holders (not marketing);
  • detect, prevent, and investigate fraud, abuse, and security incidents;
  • comply with law (including COPPA and telecommunications requirements) and enforce our terms; and
  • analyze aggregate or de-identified usage to understand how the Services perform.

We do not use personal information for marketing or advertising, and we do not sell personal information. We do not share personal information with third parties for their marketing.

5. How we share information

We may share information with:

  • Service providers that help us operate the Services (for example, authentication, hosting, telephony, storage, logging, and email delivery), under contracts requiring them to use the information only to provide services to us and to protect it appropriately. Providers that store voice or message content do so only to host that content for the family—not to use it for their own advertising or profiling.
  • Grown-ups on the same family network, who can manage network membership, devices, lines, directory entries, and—where the product allows—listen to or manage household voicemail and similar content.
  • Communications counterparties, such as people a household member calls or messages, to the extent needed to complete the communication (for example, delivering a call).
  • Legal and safety recipients, when we believe disclosure is required by law, regulation, legal process, or to protect the rights, safety, or security of Candlestick, Account Holders, household members (including children), or the public.
  • Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and continued use consistent with this policy (including COPPA obligations for children’s information).

We do not share children’s voice recordings or message content outside the family network except as needed for hosting/operating the feature, or when required for legal or safety reasons described above.

Authentication may be provided by Clerk and identity providers such as Google. Their privacy practices also apply to information they process for grown-up sign-in.

6. Cookies and similar technologies

We use cookies and similar technologies that are necessary for grown-ups to sign in, keep sessions secure, remember preferences (such as theme), and operate the Services. We do not use advertising cookies, and we do not sell or share cookie data for cross-context behavioral advertising.

7. Data retention

We retain personal information for as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce our agreements. Information about children—including voice recordings—is retained only as long as reasonably necessary for those purposes or as the Account Holder directs through in-product controls or a verified deletion request. When information is no longer needed, we delete or de-identify it in the ordinary course of business, subject to backup and audit retention.

8. Security

We use administrative, technical, and organizational measures designed to protect personal information, including information about children and voice recordings. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. Account Holders can update many details in the product or through the sign-in provider. Privacy requests: privacy@connecting.family. We may need to verify your identity (and parental authority, for a child’s information) before fulfilling a request.

10. California privacy rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA (“CCPA”) provides additional rights. This section supplements the rest of this policy and applies to grown-up consumers and, where applicable, to personal information about children in a household that a parent or guardian may request on the child’s behalf.

Categories collected. Depending on how the Services are used, we may collect: identifiers (such as name, email, account ID, IP address); customer records information; household membership details grown-ups provide; commercial or service information about use of Candlestick; internet or electronic network activity (such as logs and diagnostics); geolocation approximations derived from IP or service configuration; audio information when voicemail or similar features are used; and inferences drawn solely to operate the Services (not for advertising). We may also process sensitive personal information such as account log-in credentials and, where provided, precise service or emergency address information, only as needed to provide the Services requested.

Sources. Directly from Account Holders and other signed-in grown-ups; from devices and the Services automatically; from identity providers grown-ups choose; and from service providers acting for us.

Business purposes. Performing services (including maintaining accounts, providing telephony and voicemail features, debugging, securing the Services), quality assurance, and compliance—as further described in sections 4 and 5.

Your CCPA rights. Subject to verification and legal exceptions, California residents may request to: know/access the personal information we collect, use, disclose, or retain; delete personal information; correct inaccurate personal information; and receive information about our practices. You may use an authorized agent as permitted by law. We will not discriminate against you for exercising CCPA rights.

Sale and sharing. We do not sell personal information, and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under the CCPA. Because we do not sell or share, we do not offer a “Do Not Sell or Share My Personal Information” opt-out link; if our practices change, we will update this policy and provide required opt-outs. We do not sell or share personal information of consumers we know are under 16. Voice recordings are not sold or shared for advertising.

Sensitive personal information. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA beyond providing the Services requested and securing those Services.

How to submit a request. Email privacy@connecting.family with the subject line “California Privacy Request.” We will verify your request using information associated with your account or other reasonable methods. You may also contact us to appeal a decision about a privacy request.

11. International transfers

We may process and store information in the United States and other countries where we or our providers operate. Those locations may have different data-protection laws than your home country.

12. Changes

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. If changes are material, we will provide additional notice as appropriate, which may include notice to the Account Holder.

13. Contact

Candlestick
Privacy: privacy@connecting.family
Web: https://connecting.family

← Back to Candlestick