Privacy Policy
Last updated: 11 July 2026
MinderHQ Limited ("MinderHQ", "we", "us") provides software for registered childminders. This policy explains what personal data we handle, why, and your rights under UK GDPR. It sits alongside our Terms of Service.
Who is the controller, and who is the processor
For data about your own account (you, the childminder who subscribes), we are the data controller. For the data you enter about the children and parents in your care — records, observations, photos, contact details — you are the controller and we act as your processor, only on your instructions, under our Data Processing Agreement.
What we handle
- Your account: name, business name, email, phone, plan and billing status.
- Billing data, handled by Stripe — we never store your full card number.
- The records you create: children's details, attendance, diary entries, learning-journey observations, accident and incident records, messages with parents, invoices, and the photos and videos you add.
- Parent and guardian contact details you add so you can message them and share their child's updates, plus device tokens where a parent installs the app for notifications.
- The content of your public childminding website.
- Usage and security logs.
Children's data — extra care
We only process information about children on your instructions, as your processor. Photos and videos are re-processed on upload so that location (GPS/EXIF) data is stripped outbefore storage, so a published or shared image can't reveal where it was taken. Diary and message photos and videos are automatically deleted after three months (you can download anything you want to keep first); accident/incident records and observations are retained.
Why we use it (lawful bases)
To provide the service and take payment (contract), to keep the service secure and improve it (legitimate interests), and with consent where consent is used. For information about children and parents, you (as controller) are responsible for the lawful basis and any consents — for example, parental consent for photographs.
Who we share it with
We use a small set of trusted providers to run MinderHQ: Supabase(database and file storage), Vercel (app and website hosting), Stripe (payments), Resend (email), Twilio(text messages, where that fallback is used), and Apple and Google(push notifications to the apps). We don't sell your data or the data in your care.
International transfers
Some of these providers may process data outside the UK. Where that happens, we rely on the provider's published transfer safeguards or another lawful transfer mechanism.
How long we keep it
- Account and billing records: while your account is active, and afterwards only as long as needed for accounting, security or legal reasons.
- Diary and message photos/videos: three months, then automatically removed (download to keep).
- Accident/incident records and observations: retained so your statutory records stay intact.
- When you close your account you can export everything first, after which we delete or anonymise your data in line with the data processing agreement.
Security
Data is encrypted in transit, access is restricted, card details are handled only by Stripe, and photo location metadata is stripped on upload. No system is perfectly secure, but we take the safety of children's data seriously.
Your rights
You can access, correct, export or delete your data, object to or restrict processing, withdraw consent where it's used, and complain to the Information Commissioner's Office (ICO). Where a request concerns data about children or parents in your care, that data belongs to you as controller — direct the request to yourself, and we'll help you meet it. To exercise your rights or ask a question, email privacy@minderhq.co.uk.
Cookies
We only use essential cookies — the ones needed to sign you in and keep the service secure. We don't use advertising or tracking cookies.
This is a starting template, not legal advice — please have it reviewed by a qualified solicitor before relying on it.