Privacy Policy
Last updated: August 22, 2026
1. Who we are
Take Root Abroad is operated by Ten Eleven Twelve LLC. This policy explains what we collect, why, how we protect it, and your rights. By using the Service you also agree to our Terms of Service.
2. Information we collect
We collect only what the Service needs to work:
- Account: your name, email, and password (stored only as a secure hash).
- Planning inputs: your quiz answers and segment, chosen corridor and city, household roster (adults, children, pets), and the financial figures you enter for the GO/HOLD (income, budget, cash). These are the values you type in; we do not pull your bank or brokerage accounts.
- Documents: files you choose to upload to your document vault.
- Usage and analytics: basic technical and usage data (for example, log and device information) to run and secure the Service, and a Google Analytics identifier stored in a cookie that lets us measure how the Service is used and how people arrive at it.
- Advertising measurement: if you consent, Meta (Facebook) advertising identifiers stored in cookies (
_fbp, and_fbcwhen you arrive from one of our ads) that let us measure which ads lead to sign-ups. See section 8.
3. How we use it
To provide the Service (build your plan, compute your costs and taxes, keep corridor facts current), to operate billing, to secure and support your account, to improve the product, and to comply with law. We do not sell your personal information.
4. The document vault
Documents you upload are encrypted. Each workspace has its own encryption key, and that key is itself wrapped by a PIN that only you set and hold, using a key-management service and a server-side secret. In practical terms, your documents are encrypted at rest and unreadable without your PIN. We cannot recover your PIN for you; if you lose it, the vault cannot be unlocked. When you delete your account or a document, the underlying encrypted data is deleted.
5. Who we share it with
We share data only with the service providers we need to run the Service, under their terms, and only as necessary. The first five act as our processors: they handle data on our instructions and for no purpose of their own.
- Stripe - payment processing (handles your card; we do not store full card numbers).
- Numbeo - cost-of-living data (we send a city name to retrieve prices; we do not send your personal data).
- Resend - transactional email (account verification, alerts).
- Google Cloud - hosting, database, encrypted file storage, and key management.
- Google Analytics - product and marketing analytics (page views, sign-ups, and trial starts, tied to an analytics identifier rather than to your name or email).
Meta (Facebook) is different, and we describe it separately because it is not our processor. Where you consent, we send Meta browser events from our marketing site and server-side conversion events when you sign up, start a trial, or subscribe. Those include your email address hashed (SHA-256, a one-way transformation) so Meta can match a conversion to an ad without receiving your address in readable form, together with the advertising identifiers in section 2. We never send your planning inputs, financial figures, or documents.
We use Meta only to measure and run our own advertising. We do not sell your data, we do not give it to other advertisers, and we do not let anyone else use it to target you. We are being plain about the limit of that promise: Meta receives this data as an independent company under its own Business Tools Terms, not purely on our instructions, so Meta may also use it for its own purposes such as improving how it delivers ads generally. That is true of the Meta pixel wherever you meet it, and it is the reason we ask for your consent first rather than treating it as routine.
We may also disclose data if required by law.
6. Retention
We keep your account and workspace data while your account is active and as needed to provide the Service and to meet legal, tax, and accounting obligations. Some operational records are kept only for a fixed, shorter period:
- Abuse-prevention counters (used to rate-limit sign-ups and password resets): 24 hours. These are stored as one-way hashes, not as readable addresses.
- Expired sign-in sessions: removed once they expire.
- Email delivery-failure records (so we can tell whether a message reached you): 90 days.
- Google Analytics data: retained by Google according to our configured analytics retention setting.
When you delete your account, we delete or de-identify your personal data, except where we must retain limited records by law. If you are a member of someone else's workspace, deleting your account removes your identifying details; the plan itself belongs to the workspace owner and remains with them.
7. Your rights
Depending on where you live (including under the GDPR and California's CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can delete your account and its data from your settings, or contact us to exercise any right. We will not discriminate against you for exercising these rights.
8. Cookies and sessions
We use strictly necessary cookies to keep you logged in and to secure the Service. We also use Google Analytics cookies to measure how the Service is used.
Advertising cookies. Where you consent, we use Meta (Facebook) advertising cookies (_fbp, and _fbc if you arrived from one of our ads) to measure which ads lead to sign-ups and to show our own ads to people who have visited us. These are set only after you consent, and never if you decline. In the EEA, the UK and Switzerland we ask before setting them; elsewhere you can decline at any time using the cookie banner, and declining stops them being set. We do not sell your data and we do not give it to other advertisers. Meta itself receives it under its own terms, as explained in section 5.
9. International transfers
We operate in the United States, and our providers may process data in the US and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
10. Children
The Service is for adults and is not directed to children under 16. We do not knowingly collect personal data from children. A household roster may include a child's name for planning; that is entered by the adult account holder and is treated as that adult's planning data.
11. Changes
We may update this policy. If we make a material change, we will update the date above and, where appropriate, notify you.
12. Contact
Privacy questions or requests: hello@takerootabroad.com.