Trust & Safety

Effective date: April 26, 2026

Published by Layer One IT Consultants LLC, in partnership with Ghostweave Labs LLCfor the Tag, You’re It mobile application and website (the “Service”).

We have to say something out loud

Tag, You’re It exists because we don’t trust the way the rest of the social internet works. No bots fattening up the feed. No third-party trackers hitching a ride on your profile. No quiet deals with ad networks. We are, plainly, the anti-social network.

So when we tell you that one part of the signup uses an outside company — Stripe — that sounds like a contradiction. We’re writing this page because it kind of is, and because you deserve a straight answer about why we did it.

The one thing the third party does

When a parent signs up to manage an under-16 account, federal law (COPPA) requires us to be reasonably sure an actual adult is the one giving consent — not the kid clicking through their parent’s screen. The U.S. Federal Trade Commission lists a handful of methods that count as “verifiable parental consent.” The simplest one is a small credit-card charge that gets refunded right away.

That’s the only thing Stripe does for us in this flow:

  • The parent enters a card on a Stripe-hosted page.
  • We charge $0.50.
  • We refund the $0.50 immediately. The parent keeps their money; Stripe keeps a small processing fee on our side.
  • We save a record that verification happened — which card it was, when, and the Stripe transaction ids — so we can show our work later if asked.

Stripe never tells us your card number. We never see it, store it, or pass it anywhere else. The card data lives at Stripe; what comes back to us is a yes/no plus some opaque ids.

Why a third party at all, instead of doing it ourselves

Because we are not a payments company, and pretending to be one would be worse for you than admitting we’re not. Handling card numbers correctly is a separate discipline with its own regulators, audits, and decade-deep failure modes. Stripe is better at that than we will ever be, and using them means your card data stays inside an environment specifically designed to hold it safely.

The alternatives we considered — a government-ID scan, a knowledge-based quiz, a video selfie — would have meant collecting a lot more data about you than a card check does, and either building or contracting in even more invasive third-party tooling. The credit-card method is the smallest possible footprint for the legal job we have to do.

Optional Spotify (different kind of third party)

If you choose Connect Spotify, you sign in with Spotify AB (“Spotify”) and authorize our app to read playback-related data from Spotify’s servers so we can show you optional listening status and, when you enable it, share a short “now playing” style summary with friends inside Tag, You’re It. We store Spotify tokens encrypted on our side; we do not run Spotify’s player inside a hidden frame to track you on unrelated sites. Full details, scopes, and disconnect controls are in our Privacy Policy.

What we don’t use Stripe for

  • We don’t use Stripe to track you across the web. Their tooling doesn’t run on the rest of the app — only on the verification page and, in the future, on the page where you’d subscribe to TAG Plus if you choose to.
  • We don’t share your activity, your friends list, your posts, your messages, or anything else about how you use the Service with Stripe. They never see it.
  • We don’t hand them your kid’s data. The verification is run against the parent’s card. The child’s account never goes through Stripe.

What we keep

On our side, we keep a small row tied to the parent’s account: the timestamp the verification finished, the Stripe customer / payment-intent / charge / refund ids, and the amount (currently $0.50). We need it to prove we did the COPPA check if the FTC ever asks, and to refund or re-issue if something went wrong. We do not keep the card number, the cardholder name, or any address Stripe collected.

Where this fits with the rest of our promises

This page is meant to live next to the harder commitments in our Child Safety Standards and Community Standards. Parent verification is a hinge between the two: the safety standards say minors get a different experience; the verification step is how we make sure the parent actually authorized that experience.

If the bigger rule is “don’t hand your data to anyone you don’t have to,” then this page is the exception that proves it. We picked one specialist for one specific job, told you who, told you why, and confined them to the smallest piece of the product where their expertise was clearly better than ours.

If something feels wrong

Email [email protected]. That includes “I never got my refund,” “a charge I don’t recognize is on my statement,” or “I changed my mind and want my parent record removed.” If you delete your account, the verification record goes with it on the schedule described in our Privacy Policy.

See also our Child Safety Standards, Community Standards, Code of Conduct, and Privacy Policy.

Published by Layer One IT Consultants LLC, in partnership with Ghostweave Labs LLC.