Who this applies to
This policy applies to families who inquire with The Windermere Agency (“we,” “us”), candidates who apply with us, and anyone who emails, calls, or visits thewindermereagency.com or any subdomain we operate. We are a boutique household staffing agency founded and headquartered in Windermere, Florida.
What we collect, and why
We collect only what we need to do the work and meet the legal obligations that come with placing employees in private homes. Specifically:
- From families: names, contact details, address, household composition, the nature of the support you are seeking, and any preferences or context you choose to share with us.
- From candidates: name, contact details, work history, references, professional certifications, photo, resume, social handles where you provide them, and the consent you give us to run a background check.
- From everyone: emails and call notes that document the conversation between us and you, including the answers you give during a discovery call or screening.
- Automatically when you visit the site: standard server logs (IP address, user agent, page paths, referrer, timestamps) used for security monitoring and aggregate analytics.
We do not collect financial account numbers from families. When an invoice is paid, the payment runs through Stripe; we see that the invoice was paid and the last four digits of the card, never the full card number.
Where it lives
Our operating layer is Google Workspace. Family inquiries land in a private Google Sheet that only Katelyn and Aubree have access to. Each family and candidate has a folder in Google Drive containing the intake document, generated contracts, and any files you upload. Our dashboard is a thin presentation layer hosted on Vercel; it reads from and writes to Workspace through an HMAC-signed Apps Script web app, so credentials stay inside Google.
We do not maintain a public candidate database. Candidate profiles are visible only to Katelyn, Aubree, and (when a shortlist is presented) the specific family receiving the introduction.
Who we share it with
Two categories of third parties see your data:
- Service processors who run pieces of our infrastructure on our behalf and only on our written instruction. Today these are Google (Workspace, Drive, Gmail, Sheets), Vercel (web hosting), Stripe (payments), Resend (transactional email), and Checkr (FCRA-compliant background checks for candidates with their explicit, written consent).
- The matched party: when we present a shortlist of candidates to a family, the family sees the candidate profiles. When a candidate is being considered for a placement, the candidate sees the family's first name, household summary, and role description; not the full intake.
We do not sell your information; we do not rent it; we do not share it with advertisers; we do not feed it to any machine-learning training pipeline. If a court orders us to disclose specific records, we will comply and notify you unless legally barred from doing so.
How long we keep it
Inquiries that do not advance into a discovery conversation are deleted within 90 days. Active families and placed candidates are retained for the duration of the working relationship plus seven years (the statutory window for household-employer payroll and tax records). Candidates who do not advance through screening are deleted within 60 days of that decision unless they have asked to remain in our network for future opportunities.
Background check records returned by Checkr are retained per FCRA requirements (typically five years from the date of the report) and accessed only when relevant to a placement decision or a regulatory request.
Your rights
Wherever you live, you can ask us to:
- Show you what we have on file for you, in a copy you can read.
- Correct anything that is wrong.
- Delete it (subject to the legal retention windows above).
- Stop using it for a specific purpose, including marketing.
- Move it to another agency in a portable format.
California residents have additional rights under the CCPA and CPRA, including the right to know which categories of personal information we sold or shared in the prior 12 months. We neither sell nor share personal information for advertising, so this right is moot in practice; the formal answer is still yours on request.
To exercise any of these, email hello@thewindermereagency.com with the subject line “Privacy request.” We respond within 30 days.
Children
Our services are intended for adults arranging support for their households. We do not knowingly collect personal information from children under 13. Information about children in a household (names, ages, schedules) is provided to us by the parents and used only to facilitate the placement; we do not solicit it directly from minors.
Security
Workspace data is protected by Google's encryption-in-transit and encryption-at-rest, plus two-factor authentication on every operator account. The dashboard authenticates with Google OAuth and an explicit email allowlist; it cannot write to your records without an HMAC signature that lives only in our server-side environment. Stripe and Checkr use their own production-grade security; we never touch raw payment or background-check data.
If a breach affects your information, we will notify you (and any required regulator) within 72 hours of confirming it.
International transfers
We are a U.S. agency and our processors are predominantly U.S.-based. If you are inquiring from outside the United States, your information will be transferred to and processed in the United States; by submitting an inquiry, you consent to that transfer.
Changes to this policy
When we change this policy, we update the “Last updated” date above and, for material changes, email everyone with an open inquiry or active placement. The current version is always at thewindermereagency.com/privacy.
Contact
Questions, concerns, or requests: hello@thewindermereagency.com or (954) 508-9804. Postal mail can be addressed to The Windermere Agency, Windermere, Florida.