Privacy Policy
Last updated: August 19, 2026
NestliCare LLC ("NestliCare", "we", "us") builds software for childcare organizations and the families they serve. We handle sensitive information about children, and we take that responsibility seriously. This Privacy Policy explains what information we collect through the NestliCare applications and websites (the "Service"), how we use and share it, how long we keep it, and the choices and rights you have.
1. Who We Are and Our Role
Most of the personal information in NestliCare is entered by a childcare organization: records about enrolled children, their families, and the organization's staff. For that information, your childcare organization is the data controller and NestliCare processes it on the organization's behalf under a Data Processing Agreement. If you are a parent or staff member with a question or request about those records, the fastest path is your organization; we support them in responding, and you can always contact us too.
For information we collect ourselves, such as organization signup details, visits to our public websites, and support conversations, NestliCare is the data controller.
2. Information We Collect
Account information: Name, email address, phone number, preferred language, and an optional profile photo. Parent and staff accounts are created by the organization's administrators, who invite users to the platform.
Child records: Organizations may record information about enrolled children, including name, date of birth, room assignment, photos, emergency contacts, and health-related information such as allergies, medical conditions, medications, dietary needs, immunization records, and doctor details. The Service also records attendance (check-in and check-out times), daily activities (meals, naps, diapering, learning activities, mood), incident reports, and developmental observations. This information is entered by authorized adults at the organization, not by children.
Forms and signatures: Completed enrollment and consent forms, including typed or hand-drawn electronic signatures and a signing record (such as the time of signing and device information) kept to show a form was validly signed.
Messages and posts: Messages exchanged between parents and staff, announcements, and newsletter content. Message history is stored so conversations remain available to participants.
Payment information: Online payments are processed by our payment processors (Stripe, and for some organizations Adyen). Card and bank account numbers are entered directly with the processor and never touch our servers. We store only references and display metadata, such as a payment token, card brand, and the last four digits of a card or bank account.
Staff and payroll information: For staff users, organizations may record job details, schedules, timesheets, leave, certifications, and compensation such as pay rates. Payroll itself is processed outside NestliCare by the organization's own payroll provider; bank accounts and tax information are not stored by NestliCare.
Device and technical data: Device type, operating system, push notification tokens, IP address, browser type, and log data, including an audit trail of sensitive administrative actions.
Public website analytics: Usage data about visits to our public marketing pages, described in the cookies section below.
3. How We Use Information
We use the information we collect to:
- Provide and maintain the Service, including daily activity reports, attendance, billing, and real-time updates
- Facilitate communication between parents and childcare staff
- Send notifications about a child's day, attendance, announcements, and payments
- Process payments and maintain billing records
- Keep the Service secure, including sign-in protection, bot detection, device attestation on mobile signup, fraud prevention, and audit logging
- Respond to support requests
- Understand how the Service is used and improve it
- Comply with legal obligations
Where the GDPR or UK GDPR applies to processing for which we are the controller, we rely on the performance of a contract (providing the Service), our legitimate interests (securing and improving the Service), and compliance with legal obligations as lawful bases.
4. AI Features
Some features use large language models from Anthropic to generate content, for example narrative daily summaries, lesson plan drafting, and an assistant for organization administrators. When an organization uses one of these features, the content needed to produce the result is sent to Anthropic for processing. Our AI providers are not permitted to use this content to train their models. Daily summary narratives are additionally designed so that the model works from aggregate counts rather than individual children's records. AI features are optional and controlled by the organization.
For organizations that turn on assistant actions, the assistant can also propose changes to records, for example correcting an attendance time. A proposal is only a suggestion: nothing is written unless an administrator reviews and approves it, and every approval is logged to the administrator who made it.
5. How We Share Information
We do not sell personal information, and we do not share it for third-party advertising. We share information only as follows:
- Within your organization: Information is visible to authorized parents and staff of the same organization according to their roles. Parents see their own children; staff see the rooms and records they are authorized for.
- Hosting and infrastructure: Amazon Web Services hosts our databases and media storage in the United States. Cloudflare provides content delivery, security, and bot protection for our websites.
- Payment processing: Stripe (and Adyen, where enabled) process payments and payouts. Payment processors act as independent controllers for the payment data they collect, under their own privacy policies.
- Email delivery: Transactional email (invitations, receipts, password resets, daily summaries) is delivered through SendGrid (Twilio).
- Push notifications: Notifications are delivered through Apple and Google push services and, for web browsers, browser push services. Notification content, which may include a child's first name, passes through these services in order to be delivered.
- AI processing: Anthropic processes content for the AI features described above.
- Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- Safety: We may disclose information where we believe it is necessary to protect the safety of any person, including a child, or to prevent illegal activity.
- Business transfers: If NestliCare is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy's protections.
Service providers that process personal data on our behalf are bound by contracts that limit their use of the data to providing their service to us.
6. Cookies and Website Analytics
In the app and dashboard: The signed-in product does not use advertising or third-party analytics trackers. We use only the storage needed to run the Service, such as your sign-in session and language preference.
On public marketing pages (our homepage, pricing, blog, sign-up, and public daycare listing pages) we use PostHog, the Meta (Facebook) Pixel, a Google advertising tag, and Cloudflare Web Analytics to measure how visitors find and use the site and whether our advertising works. These tools receive usage data such as IP address, browser information, pages visited, and identifiers set by their cookies. They are deliberately not loaded on the signed-in dashboard or in our mobile apps, so they never receive child, family, or daycare records, and we do not send them names or email addresses.
You can control cookies through your browser settings, and ad platforms offer their own opt-outs. PostHog is configured to respect the Do Not Track browser setting.
7. International Data Transfers
NestliCare is operated from the United States, and data is stored on Amazon Web Services infrastructure in the United States. If you use the Service from another country, including Canada, the United Kingdom, Australia, or the European Economic Area, your information is transferred to and processed in the United States.
Where the GDPR or UK GDPR applies, we rely on appropriate safeguards for these transfers, including the European Commission's Standard Contractual Clauses incorporated into our Data Processing Agreement with organizations, together with the UK Addendum where applicable.
8. Security
We protect your information with measures that include:
- Encryption in transit (TLS) and encryption at rest on AWS infrastructure
- Role-based access controls, so users only see data they are authorized to access, and strict isolation between organizations
- Photos and documents kept in private storage, accessible only through short-lived signed links issued to authorized users
- Audit logging of sensitive administrative actions, with the actor, timestamp, and IP address
- Bot protection on signup and device attestation for our mobile apps
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting personal data, we will notify affected organizations without undue delay and support them in meeting their own notification duties.
9. Data Retention
While an account is active, we retain the records the organization keeps in the Service. Childcare organizations are often legally required to retain records such as attendance, incident, and health records for a period set by their licensing rules, so we do not automatically purge those records; the organization controls them.
Some data is deleted automatically on a schedule: in-app notifications are removed after at most 180 days, AI-generated daily summaries after 30 days, and web server access logs after about 30 days. Security audit logs are retained while the organization's account exists.
Backups are encrypted and expire on a rolling schedule: database point-in-time recovery covers roughly the last 7 days, and nightly archive copies expire automatically after about 31 days.
When an organization stops using NestliCare, its records remain stored until the organization asks us to delete them, so that data can still be exported, transferred, or reactivated. When an organization's owner submits a verified deletion request, we delete the organization's records from our production systems within 90 days, after which backup copies expire on the rolling schedule above. Copies of uploaded media files may persist in cloud storage for a period after database deletion while storage cleanup completes. We may retain information we are legally required to keep, such as financial and tax records, and records needed to resolve disputes.
10. Account Deletion for Parents
Parents can request deletion of their account from the app's profile settings, or by contacting us at [email protected]. Because some records a parent appears in (such as attendance, incident, and billing records) are records your childcare organization is required to keep, deletion requests are reviewed by the organization.
When a request is approved, we disable sign-in, delete the parent profile and device tokens, remove stored payment references, and anonymize the account's identifying details so the account is no longer linked to you. Records the organization must retain, such as its attendance and billing history, remain under the organization's control. If you believe your organization has wrongly refused a deletion request, contact us and we will work with you and the organization.
11. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to withdraw consent. These rights exist under laws including the GDPR (European Economic Area), the UK GDPR, PIPEDA (Canada), the Privacy Act and Australian Privacy Principles (Australia), and various US state privacy laws.
For records your childcare organization entered about you or your child, please direct your request to the organization first; it is the controller of those records, and we assist it in responding. For information NestliCare controls, contact us at [email protected] and we will respond within the time required by applicable law. If you are in the EEA or the UK, you also have the right to lodge a complaint with your data protection authority.
Notifications: You can turn off push notifications in your device settings at any time.
12. Children's Privacy
NestliCare is designed for use by adults: childcare professionals and parents or guardians. Children do not use the Service, and we do not knowingly collect personal information directly from children under 13. All information about children in the Service is entered by authorized adults, and childcare organizations are contractually required to obtain consent from a parent or guardian for the collection of a child's information, including written consent before photos or videos of a child are uploaded.
Parents and guardians can review their child's information in the app at any time, and can ask their childcare organization, or us, to correct or delete it, subject to records the organization is legally required to keep.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date, and for material changes we will notify organizations by email or in the app. We encourage you to review this policy periodically.
14. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us:
- Email: [email protected]
- Company: NestliCare LLC
- Website: nestlicare.com
For individuals in the European Union, European Economic Area, and United Kingdom: NestliCare LLC has appointed Data Protection Representative Limited (trading as DataRep) as its data protection representative under Article 27 of the GDPR and UK GDPR. You can contact NestliCare via DataRep:
- Email: [email protected], quoting "NestliCare LLC" in the subject line
- Web form: www.datarep.com/data-request
- Post: DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Ireland (or any DataRep location in the EU/EEA or UK; mark letters for 'DataRep')
For questions about NestliCare's products or your account, please email [email protected] instead.