Two friends of mine just launched something lovely. After years of talking about it, they finally started a children's book brand — a playful illustrated chapter-book series with a mascot, a warm little world, and a "join our club" newsletter for young readers, all sold from a tidy Shopify store. They built the whole thing with real care, and when they showed it to me I was delighted for them.
Then, because privacy is what I do, I noticed the one thing nobody had told them — the thing that quietly changes the rules for a business like theirs. It is for children. And the moment a brand is genuinely aimed at kids, it steps inside a US federal law most first-time founders have never heard of: COPPA, the Children's Online Privacy Protection Act. I wanted to give them the heads-up a friend gives you — early, kindly, before it becomes a scramble. So here it is for you too, if you are building anything children might use.
Why "for kids" is a different game
Most privacy rules have a size cutoff somewhere — a turnover threshold, a headcount, a "you're probably too small to worry" escape hatch. COPPA does not. It is federal, it applies to the tiniest startup exactly as it applies to a giant, and there is no small-business exemption to hide behind. If your site or service is "directed to children" under 13 — or you knowingly collect personal information from them — you are inside it. Full stop.
And here is the part that surprises founders: whether COPPA applies is not about what your privacy policy says. It is about what your brand plainly is. The FTC looks at the whole picture — your subject matter, your animated characters and mascot, your visuals, your language, whether the thing is pitched at kids or at their parents. A chapter-book brand with a friendly mascot and a club for little readers sends strong "this is for children" signals. You cannot write your way out of that with a sentence.
The disclaimer that doesn't fit the brand
Which brings me to the thing I noticed first, and the reason I wanted to write this down.
Almost every store privacy policy — the one Shopify or a template drops in on day one — ships with a stock line that reads something like: "The Services are not intended to be used by children, and we do not knowingly collect any personal information about children." For a general store, that sentence is doing real work; it is the standard way a shop that isn't for kids stays outside COPPA.
On a children's brand, that same line sits awkwardly against the entire product. You have a kids' mascot on the homepage, chapter books for young readers, and a cheerful "join the club" aimed squarely at little explorers — and then a line in the footer insisting the site isn't for children. It doesn't hold, because COPPA turns on whether the content is child-directed, not on the disclaimer. You genuinely cannot disclaim your way out of it.
And there is a very practical pinch-point where this stops being abstract: the newsletter. A fun, kid-styled signup that collects a first name, last name, and email, with no age screen and no notice at the form, is exactly where a child can hand over their own personal information without anyone's consent. Name and email from a child is precisely the data COPPA governs. Nobody set out to do anything wrong — it is just the default signup, doing what signups do.
I want to be clear about the tone here, because it matters: my friends had no idea, and that is completely normal. This is the founder-to-founder heads-up nobody had given them. It is not a scolding, and it is very fixable.
The three things to get right early
Getting kids' privacy right is not a mega-project. For a brand like theirs it comes down to three moves.
Decide who your audience actually is — and design for it. You have three honest options: fully child-directed, mixed audience, or genuinely parent-facing (the parents buy and subscribe, not the kids). Most small children's brands land best on mixed audience or parent-facing. Picking deliberately is half the work, because everything else follows from it.
Put an age gate on anything a child might touch — and don't collect from under-13s without verifiable parental consent. The mixed-audience route lets you age-screen users and route children down a parents-only path. What you may not do is collect personal information from someone who tells you they're under 13 without first getting verifiable parental consent. In practice: make the newsletter clearly parent-facing, or add a neutral age screen before you collect anything, and put a short notice and a link to your policy right at the form.
Make the privacy policy match the brand. Swap the contradictory "not for children" boilerplate for a real, thought-through children's-privacy section: your audience stance, what you do and don't collect from kids, parents' rights, and a contact. A policy that actually fits a kids' product is both more honest and more reassuring to the people reading it.
What changed in 2026 — worth knowing
COPPA just had its first serious update in over a decade, and the amended Rule's compliance deadline landed in April 2026, so it is now fully in force. A few changes are worth a founder's attention. Biometric identifiers — voiceprints, faceprints, facial templates — now count as personal information, which matters the moment any kind of voice or photo feature enters the picture. Operators now need a written data-retention policy (what you keep, why, and when you delete it — no keeping kids' data forever) published in the privacy notice, plus a written information-security program. And you now need separate parental consent before sharing a child's data with third parties for non-essential purposes like targeted advertising — a single bundled "I agree" no longer covers it. None of this is onerous for a small brand; it's mostly about deciding your practices on purpose and writing them down.
One honest note so you don't over-worry: California's CCPA/CPRA has size thresholds a brand-new small store usually won't meet yet, so that law may not bind you on day one. COPPA is the one that applies regardless of your size.
The upside nobody mentions: parents' trust
Here is the reframe I gave my friends, because it is the true story. Parents are the most protective customers on earth. A children's brand that is visibly, obviously careful with kids' data isn't checking a compliance box — it is earning the exact trust it needs to grow. When a parent sees a real children's-privacy policy, a signup that asks them, and a brand that clearly thought about their kid, that is the moment they decide you're the good one. Privacy-first, for a kids' brand, is just parent-trust-first. Handle it early and it's a foundation you build on, not a fire drill later. (Yes, COPPA can carry real FTC penalties — up to $53,088 per violation — but that is the far backstop, not the reason to do this. The reason is the parents.)
How to start right — the easy version
The good news is that the whole thing can be set up in an afternoon. Starting something for kids? Get a custom privacy notice and consent form that are built for it → Dxtra generates a kids-aware privacy notice, a parent-facing and age-screened / parent-verification consent workflow, and the point-of-collection line to go with it — ready to drop straight into a Shopify store, or shown by QR code at a book fair or school event where there's no website in the moment. It builds what's missing, and you review everything before it goes live. From $10 a month. And if you want a quick read on your storefront as it stands, a free Dxtra scan will show you what's already exposed.
My friends' brand is going to do beautifully. It gets to start life as the kind of children's business parents trust on sight — which, when your customers are the most careful people alive, is the whole game. If you're building something for kids, get this bit right early. It's a lovely thing to have already handled.
This article is for general information and is not legal advice. Children's-privacy rules are detailed and depend on your specifics — confirm anything that matters with the FTC (ftc.gov) or a qualified adviser before you rely on it.

