Privacy policy
Last updated 15 September 2026
The short version. We do not sell your data, we do not share it for advertising, and there are no analytics or tracking scripts on this site. The only cookie is the one that keeps you signed in. You can export everything at any time without asking.
Who this is about
PTO HQ is operated by Unstacked Apps, LLC. Contact [email protected] about anything on this page.
Your parent group is the one deciding what goes into its books and its directory. We hold and process that information on its behalf, and we do not use it for our own purposes beyond running the service and keeping it working.
What we collect
Board member accounts. Name and email address, so that an audit entry can name a person and an invitation can reach one. Sign-in itself is handled by Clerk; we never see or store a password.
Your organization. Legal name, display name, EIN, school name, whether you are a PTO, PTA unit or booster club, fiscal year, and timezone.
The books. Everything a treasurer enters: transactions, payees, amounts, categories, budget lines, funds, accounts and their opening balances, reconciliations, cash counts and the names of the two people who signed each one, reimbursement claims, and any receipts or statements uploaded as files.
The directory, if you use it. Adult first and last name, email address, and optionally a phone number, along with three separate visibility choices per person. For children: first name, grade, and classroom only — no surname, no date of birth, no contact details, and nothing that identifies a child outside their own school.
Volunteers, if you use it. Shift sign-ups, hours logged, and whether a background check is on file with its expiry date. We record the status of a check. We never receive or store the check itself.
Reimbursement claims. The public claim link can be used by any parent or teacher without an account. What is collected is what is on the form: name, email, what was bought, the amount, and a receipt.
An audit log. Who did what, and when. It is append-only by design — that is the point of it — so audit entries are not edited or deleted on request.
Bank and card transactions, only if your board connects an account. Connecting is optional and off unless you turn it on. The sign-in always happens at the provider, never in a PTO HQ form. We read transactions, balances and payouts, and nothing else. We never move money, issue a refund, or charge a card. Plaid and Square grant us read-only access. Stripe no longer offers read-only access to apps like ours, so a board connecting Stripe will see an approval screen asking for read and write; we do not use the write half, and the connection can be revoked from your Stripe dashboard at any time.
What we deliberately do not collect
- Online banking usernames or passwords — ever, by any route.
- Card numbers. Payment details go to Stripe, through Clerk Billing, and never reach our servers.
- Social security numbers or dates of birth.
- Children’s surnames, contact details, or photographs.
- Anything for advertising. There is no analytics package, no pixel, and no third-party tracker on this site.
One exception worth naming, because we would rather you read it here than assume it: the public reimbursement form counts submissions against the address they arrive from, so that nobody can flood a PTO’s inbox through a link that was printed on a poster. That count is held in memory for a few minutes and then gone. It is never written to the database, never attached to your claim, never logged, and never used to work out who you are or where you have been.
Children’s information
PTO HQ is a tool for adult volunteers running an organization. It is not directed at children, and children do not have accounts or sign in to it.
The only information about a child is what an adult on the board or an adult in the family types into the directory: a first name, a grade, and a classroom. It exists so a directory can say which family belongs to which class. If you would rather it were not there, leave those fields empty or ask your board to remove the record — and you can ask us directly at [email protected].
Who else touches it
These are the companies involved in running PTO HQ. Each one handles a specific job, and none of them is given your data for their own use.
- Clerk — accounts and sign-in, and the checkout for subscriptions.
- Neon — the Postgres database holding your records, hosted in the United States.
- Stripe — payment processing, reached through Clerk Billing. Card details go to Stripe, not to us.
- Resend — sending email: invitations, trial notices, and the like.
- Cloudflare — serving the site, and storing the encrypted nightly backups described below.
- Plaid — only if your board chooses to connect a bank.
Uploaded files — receipts and statements — are stored on the server that runs PTO HQ rather than with a third party, and are included in the encrypted backups.
We will also disclose information if the law requires it. If that ever happens and we are permitted to tell you, we will.
How long it is kept
Your records are kept for as long as your organization has an account, and you can export all of them at any time.
If a subscription lapses, the books become read-only rather than deleted. Export stays available. A nonprofit is expected to be able to produce receipts for seven years, and losing access to your own records because a renewal was missed would be an unreasonable thing to do to a volunteer.
About backups. Encrypted snapshots are taken nightly and kept on a schedule that reaches back seven years, which matches how long a nonprofit is expected to keep financial records. When you delete something, it goes from the live service straight away, but it remains in snapshots taken before the deletion until those snapshots age out. We are telling you this because most policies do not.
If you ask us to delete your organization entirely, we will remove it from the live service and confirm when that is done.
What you can ask for
You can ask us to show you what we hold about you, correct it, delete it, or give you a copy. Most of it you can already do yourself: the export is built in and needs no request.
Depending on where you live — California, Colorado, Connecticut, Virginia and a growing number of other states have their own laws — you may have additional rights, including the right not to be discriminated against for exercising them. We apply the same practices to everybody regardless of state, so asking costs you nothing.
Write to [email protected]. We answer.
One thing we will not do is edit the audit log. It exists so that next year’s treasurer can see what happened, and a log that can be rewritten on request is not one.
Cookies
The only cookie PTO HQ sets is the session cookie that keeps you signed in, placed by Clerk. There is no advertising cookie, no analytics cookie, and no consent banner, because there is nothing to consent to.
Keeping it safe
Traffic is encrypted in transit. Backups are encrypted before they leave our server, so the storage provider holds ciphertext. Organizations are separated in the database and every read is scoped to one of them. Money leaving needs two people, and the audit log records who did what.
The security page goes into more detail, including what PTO HQ deliberately does not do.
No service can promise it will never be breached. If one happens and it affects your data, we will tell you what happened and what to do about it, as promptly as we can establish the facts.
Changes
If this policy changes in a way that matters, we will email the board members on each account rather than quietly changing the date at the top.