Privacy policy
Version 2026-01-15 · Last updated 15 January 2026
This policy explains what personal data HomeNest Child Care Ltd collects, why, who sees it, and what you can do about it. It is written to be read, not to be survived. If anything here is unclear, ask us and we will explain it.
Who we are
HomeNest Child Care, East Legon, Accra, Ghana, is the data controller for the personal data described here. You can reach our data protection contact at info@homenestcc.com.
What we collect, and why
From parents and families
- Identity and contact: your name, phone number, email and home address — so we can run your account, match caregivers near you, and reach you.
- Your children: name, date of birth, photograph and care notes — so a caregiver knows who they are caring for.
- Medical information: allergies, conditions, medication and your doctor’s details — so a caregiver can keep your child safe and act in an emergency. This is sensitive data and we treat it accordingly: it is encrypted before it is stored and is shown only to caregivers actively assigned to your child.
- Payment records: what you paid, when, and by which method. We never see or store your full card number or your mobile money PIN — those stay with our payment provider.
From caregivers
- Identity: Ghana Card number and photograph, encrypted at rest.
- Vetting records: police clearance, references, guarantors, health screening and training results.
- Work records: shifts, check-in times and locations, daily logs and reviews.
From everyone
- Device and usage information needed to keep the service secure and working.
- Messages sent through the platform, which are scanned automatically for safety signals and off-platform payment attempts. A person reviews anything flagged — no account is ever suspended by an automated decision alone.
Children’s data
We process children’s data only on the instruction of a parent or guardian who has parental responsibility, and only for the purpose of delivering care. Specifically:
- Children’s photographs are stored in a private location and are only ever served through short-lived links that expire within five minutes. There is no public URL for a photograph of a child on HomeNest.
- We do not use children’s images or data for marketing, ever.
- We do not use facial recognition on children. Attendance uses QR codes, PINs and check-in by a named adult. Where a photograph is used to confirm an authorised pickup, a person makes that comparison — the system never asserts a match itself. Our reasoning is published in our engineering decision log.
- You can withdraw consent for photographs in daily reports at any time from your settings, without affecting any other part of the service.
Consent
We ask separately for each purpose rather than bundling everything into one checkbox. Each consent records what you agreed to, the version of the policy you agreed under, and when. You can review every consent you have given, and withdraw any of them, from Settings → Consents in your account.
Some consents are necessary to deliver the service at all — we cannot arrange childcare without your contact details or your child’s name. Where that is the case we say so plainly rather than pretending the choice is free.
Who we share data with
- Caregivers assigned to your family — only the details they need, only while the assignment is active.
- Daycare centres your child attends — profile, medical and attendance data, with your consent.
- Our processors — Supabase (database and storage), Vercel (hosting), Resend (email), Paystack (payments), and our SMS and WhatsApp providers. Each is bound by contract to process data only on our instructions.
- Authorities — where we are legally required to, or where a child’s safety requires it. Child safety will always outrank confidentiality, and we will not apologise for that.
We do not sell personal data. There is no version of this business where we would.
Where data is stored
Our infrastructure providers store data outside Ghana. Where that happens, transfers are made under the safeguards required by Act 843 and the contractual protections in our processor agreements.
How long we keep it
- Account data: for as long as your account is open, then 12 months.
- Children’s care records: 12 months after your last booking or placement ends.
- Safeguarding and incident records: retained for the period required by child protection obligations, which is longer than the above and may survive a deletion request. Where that applies we will tell you exactly what is being retained and why.
- Financial records: six years, as required by Ghanaian tax law.
Your rights
Under Act 843 you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong.
- Delete your data, subject to the retention rules above.
- Stop processing your data for a particular purpose.
- Explain any automated processing we carry out.
Request an export or a deletion from Settings → Privacy, or email us. We respond within 30 days, and we will tell you plainly if a legal retention obligation prevents us from deleting something.
Security
- Ghana Card numbers and sensitive medical notes are encrypted at the application layer before they reach our database.
- Every table enforces row-level access control, so a family cannot read another family’s records even if application code were to have a bug.
- Documents and photographs are stored privately and served only through expiring links.
- Every change to a child, caregiver, incident, payment or safeguarding record is written to an append-only audit log.
Complaints
Tell us first — we would rather fix it. If you are not satisfied, you can complain to the Data Protection Commission of Ghana.
Changes
If we change this policy materially we will tell you in the app and by email, and ask you to review your consents. Each consent records the policy version it was given under, so there is always a record of what you actually agreed to.
