P Pasitos

Privacy Policy

How Pasitos handles family location and device data.

Version 1.1 · Effective 12 September 2026

Pasitos is a family-safety and parental-control service operated by Airstream SRL (Republic of Moldova) (“we”, “us”). It lets a parent or legal guardian see the approximate location and device status of their own child’s device, receive place and safety alerts, and respond to an SOS. This policy explains what we collect, why, and the choices you have.

Pasitos is intended to be installed and configured by a parent or legal guardian on a device used by their own minor child, under that adult’s authority and supervision. The parent is responsible for informing the child in an age-appropriate way.

1. Information we collect

CategoryExamples
Parent accountPhone number or email used to sign in, display name, chosen language, consent records.
Child profileA display name, optional birth year and colour label set by the parent. We do not require the child’s real name.
LocationPrecise and background GPS location of the child device, including accuracy, speed and timestamps, plus derived trips, stops and place enter/exit events.
Device statusBattery level and charging state, network type and Wi-Fi network name, GPS on/off, power-saving state, ringer mode, the ambient sound level as a number (no audio), app version, Android version, permission state.
ActivityStep counts and whether the child is walking or riding, used for the day’s route and weekly summaries.
App usageWhich apps were used on the child device and for how long, with their names and icons, for the parent’s report and the limits the parent sets. To enforce those limits the Pasitos Kids app sees which app is on screen, never what is inside it.
Live audio and cameraOnly during a session a parent starts: the sound around the child device or its camera is streamed to that parent for up to 10 minutes, and the child sees a notice on the screen for as long as it lasts. It is recorded only if the parent chooses to record in the web cabinet.
Safety eventsSOS signals raised from the child device and the parents’ acknowledgements.
MessagingPush notification tokens (Firebase Cloud Messaging) used to deliver alerts.
Technical logsSecurity and audit records (e.g. sign-in, device binding, deletion) with hashed identifiers; server logs for reliability and abuse prevention.
Crash reportsWhen an app crashes: the device model, Android version, app version and the technical trace of the error (Firebase Crashlytics). They contain no location.

We do not collect contacts, messages, browsing history or the child’s photos. A photo a parent picks for the child’s profile stays on that parent’s phone. The microphone and camera are used only during a session a parent starts, as described above. We do not use the data for advertising and we do not sell personal data.

The child’s part of the service, the Pasitos Kids app, works openly: before it collects anything it shows the child what it shares, and while the parents see its location, or listen or look through it, it shows a notice on the screen.

2. How we use information

  • Show the child’s current and recent location and route to authorised parents.
  • Detect entry to and exit from places/zones the parent defines, and send alerts.
  • Deliver safety notifications, including SOS, and let parents respond.
  • Show device status so a parent can tell whether the device is online, charged and reporting.
  • Show time spent in apps and apply the limits and phone-free hours the parent sets.
  • Let a parent hear the sound around the child device or look through its camera when they start a session.
  • Reverse-geocode coordinates into a readable address in the user’s language.
  • Operate, secure and improve the service, and prevent abuse.

We process family data to perform the service requested by the account holder (contract) and, where applicable law requires, on the basis of the parent’s or guardian’s consent given on behalf of the child. The account holder confirms they are the parent or legal guardian, or are otherwise authorised to monitor the child device, and that they will use Pasitos lawfully and only for a device they are entitled to monitor.

4. How information is shared

We share personal data only with service providers that help us run Pasitos, and only as needed:

  • Hosting — our own server infrastructure, where the database and application run.
  • Google Firebase — Authentication for parents’ sign-in, Cloud Messaging to deliver notifications, and Crashlytics for crash reports.
  • Maps — routes and addresses are computed on our own servers from OpenStreetMap data; the map images are loaded from OpenFreeMap, which sees only the area on screen, not whose location it is.

Additional parents can be granted access to a child only when the family owner invites them. We may disclose information if required by law or to protect the safety of a user. We do not sell personal data or share it for third-party advertising.

5. Data retention

Raw location points are deleted after 90 days, step counts after 60 days, and recordings of audio or camera sessions after 30 days. The day summaries built from them (the day’s route, places and telemetry) are kept while the account is active so the parent can review history. Account and profile data are kept until you delete them or delete the account. When you delete your account, we permanently erase your family, child profiles, bound devices, location history and related data; limited security/audit records with hashed identifiers may be retained as required for legitimate security and legal purposes.

6. Your choices and rights

  • Access & correction — view and edit family and child details in the app.
  • Deletion — delete your entire account and all owned family data at any time from Account → Delete account in the parent app, or by contacting us.
  • Unbind a device — disable a child device to stop further data collection.
  • Permissions — location and notifications can be revoked in the device settings; some features will stop working without them.

Depending on your jurisdiction you may have rights to access, rectify, erase, restrict or port your data, and to lodge a complaint with a supervisory authority.

7. Security

Data is encrypted in transit (HTTPS/TLS). Authentication tokens are stored in the Android Keystore-backed secure storage on the parent device. Access to a child’s data is restricted to authorised parents and enforced on the server. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.

8. International transfers & changes

Some providers listed above may process data outside your country; where they do, we rely on the safeguards those providers offer. We may update this policy; we will post the new version here and update the “Effective” date. Material changes may be highlighted in the app.

9. Contact

Questions or requests: [email protected]. Data controller: Airstream SRL, Republic of Moldova.