Privacy policy
Last updated
In force from
We collect only what the service needs: your account details, the profile information you choose to publish, the address you give us, the referees a caregiver names, and the messages you send on the platform.
Your messages are between you and the person you are writing to. Administrators can see a list of every conversation on the platform, with the facts about it and none of its text: who is talking to whom, whether either account is suspended or deleted, when it started, when it was last active, how many messages it holds, how many of those an administrator has taken down, how many reports about it are still open, how many times an administrator has opened or downloaded it, and whether it has been closed to new messages. Looking at that list is not itself recorded.
They can also open the messages in any conversation, and that is recorded. Opening one takes a written reason, and records which administrator opened it, which conversation, and the time. Those three facts cannot be edited or deleted.
An administrator can also download a copy of a whole conversation. That is recorded the same way and marked as a download rather than a read, so if you ask, we can tell you which it was. It is the one thing on this list that puts your messages somewhere this platform no longer controls, which is why we record it separately and say so here.
The reason an administrator gives can be corrected afterwards, and a record can be retired so it no longer shows in their own list. Both of those write to a second log that nothing on this platform can edit or delete, so a read can never be made to disappear. You can ask us whether your conversations have been opened, and we will tell you who opened them, when, and the reason they gave.
Your street address is different from the rest of your profile: it is never published, never in search, and never on a card. It is shared with the other side of a care request you have both agreed to, in both directions, one booking at a time. It stops being shared at once if that booking is declined, cancelled or marked as a no-show, or if either of you blocks the other; once a booking is completed it stays available for seven more days, for anything left behind, and then stops. Every time somebody opens it we record who looked and when, and unlike the conversation log above, you do not have to ask us for it: the list is in your settings.
FindNightNanny does not conduct identity verification, criminal background checks, reference checks, credential verification, or any other screening of caregivers.
That is why there is no longer a paragraph here about credential files. If you offer overnight care we used to ask you for a photo ID, a police check and a first-aid certificate, and we stored them. We stopped: those uploads are refused, what had been stored was destroyed, and there is nothing left for anybody to open. There is no longer anywhere on this platform to send a document of that kind.
The two referees you name are somebody else’s details rather than yours — their name, how they know you, and an email address or a phone number. They are never published, never in search and never on a card, and the only people who can see them are you and our administrators. Nobody here contacts them. We used to, and we stopped: there is no longer any way on this platform to record a referee as having been called.
An administrator can take a single message down. Where it was, both of you see a line saying Night Nanny removed it — the person who wrote it sees that line too — and neither of you is told why. That reason stays between administrators, like the reason behind a suspension. Taking a message down does not erase it: the words are left alone, so the message can be put back, and an administrator who opens the conversation still sees what was taken down.
An administrator can also close a whole conversation to new messages. Everything already in it stays, and you can both still read all of it; neither of you can add to it. You are both told it has been closed, and again neither of you is told why — that note is a judgement about the exchange and about the other person, so it stays with our administrators. A closed conversation can be reopened.
Taking a message down and closing a conversation are both recorded in the same log that nothing on this platform can edit or delete, under the name of the administrator who did it — as is putting the message back, or reopening the conversation.
When you delete your account, your personal information is anonymised and purged on a fixed schedule. The messages you sent are removed with it — with one exception, and it is the one worth knowing: a message of yours that somebody has reported, and that we have not finished dealing with, is held back so the report can still be answered. It is held for no more than twelve months from the day you deleted, and then it goes the same way as the rest. The messages the other person sent you are not removed at all — they are that person’s words, in that person’s copy of the conversation, and they stay. The care requests you sent or answered are not removed either: they stay on the other person’s record, with the notes, the location and any cancellation reason written on them. One more thing is kept permanently: the record of decisions our administrators made about an account — suspending it, taking a message down, closing a conversation, and the reason given. That record identifies an account by an internal reference and the name shown on it at the time. It never contains your email address or your messages.
Who else handles your information
DigitalOcean hosts this website, its database and the photos you upload. The web server is in Toronto, Canada. SMTP2GO sends the emails the platform sends you, so it handles your email address and the text of each message.
When a page shows a map, your browser fetches the map images from OpenFreeMap, which sees your IP address and the part of the map you are looking at. When you type into an address or place box, your browser sends what you type to Photon, a service run by Komoot, to suggest addresses. Neither request passes through us.
To put an address on the map, our server sends it — without any unit or apartment number — to Nominatim, the address service of OpenStreetMap. What we keep on your profile is a point rounded to within about half a kilometre. Nominatim’s exact answer, and what we asked it, are also kept in our cache for 30 days so the same address is not looked up twice, and then deleted; when Nominatim finds nothing, that is remembered for a day. If a night nanny’s address cannot be placed on the map, our server keeps what it asked Nominatim so it can try again later, and deletes it no later than 30 days after the last try.
A family or a night nanny who buys a membership pays on a page run by Stripe. Stripe receives their card number, and any billing address it asks for, directly; their full card number never reaches our servers. Stripe tells us only the card’s brand, its last four digits and its expiry date, and nobody but the member and an administrator is shown those. When a member first goes to pay, our server gives Stripe their account email address and an internal reference number for their account, so their payments can be matched to them, and it updates that email address at Stripe if they change it here. Stripe keeps its own record of them as a customer and of their payments, including that email address, after they delete their account here, under Stripe’s own privacy policy. No advertising or analytics service is used on this site.
A trial or a free pass involves no card and nothing is sent to Stripe. If you use a trial link, we record which link it was and when, because each person can use only one. If you have a trial or a free pass, we keep when it starts and when it ends; a free pass also records which administrator gave it and why, and giving, extending or ending one is a decision about your account, kept permanently like the others described above.
Cookies, and what your browser keeps
This site sets three cookies, all of them its own, and none can be read by a script on the page. Two keep you signed in, for as long as your session lasts: up to 400 days (about 13 months), or 30 days for an administrator. The third holds your answers while you sign up, for up to 7 days. There are no advertising or analytics cookies.
Your browser also keeps a few settings on your own device, and they are not sent to us: whether you chose the light or the dark theme, whether you hid the map on the search page, and that you have dismissed two notices that are shown only once.
Your children
A family profile can hold, for each child, whether they are born or on the way, their date of birth or due date, and, if you choose, their gender and up to three traits. There is no place for a child’s name. We keep the date so the age band can be worked out again when you save your profile: night nannies see the band from your last save, never the date, the gender or the traits.
A night nanny gives her date of birth when she signs up, so the form can refuse anyone under 18. It is not shown on her profile, in search, or to families.
Asking for your information, or correcting it
Most of what you have given us you can see and change yourself, on your profile and in your settings. To ask for a copy of everything we hold about you, or to correct something you cannot change yourself, email info@findnightnanny.com. We answer within 30 days.
How long logs and backups are kept
The web server’s logs record each request’s IP address, the page asked for and the time, and they are deleted after 14 days. The application’s own logs, which can include the address an email was sent to, are not yet deleted on a schedule. The database is backed up by DigitalOcean, and a copy is sometimes taken by hand before maintenance; how long those backups are kept has not been set yet.
Questions about this policy: info@findnightnanny.com.