Skip to content

Legal

Privacy policy

What we collect, why, who touches it, and how to get it back or have it destroyed.

Last updated: July 2026

This is written in plain English to be read rather than to be bulletproof. Have a solicitor review it before you rely on it. Particularly as your agency handles children's data.

This policy explains how Rostavo ("we", "us") handles personal data when you use our software and websites. We are the data controller for your own account and billing details. For everything your agency stores about its staff, its clients and the people they care for, your agency is the controller and we are the processor, which means requests about that data go to the agency, and the agency has the tools to answer them.

What we collect

  • Your account: name, email, phone, hashed password, agency details, and payment details handled by our payment provider.
  • What your agency enters: staff records including documents, references and background-check status; client and family records; details of the people in their care, which may include children or vulnerable adults; bookings, availability, messages and invoices.
  • Technical: server logs, browser and device information, and error diagnostics.

Why, and on what basis

To provide and secure the service (performance of a contract), to meet legal obligations such as keeping financial records, and for our legitimate interest in running and improving the product. Where we need consent. Certain optional communications. You can withdraw it at any time.

Who else touches it

We use as few third parties as we can get away with. The list is:

  • Hetzner. Hosting. Servers in the EU.
  • Resend. Email delivery.
  • Stripe. Card payments, where an agency has switched them on.
  • Sentry. Error reports, so we find crashes before you report them.
  • Google Analytics, which pages of this public website get read, so we know which ones are worth keeping. Your IP address is truncated before it is stored.
  • Microsoft Clarity. Anonymous recordings of how this public website is used, so we can see where a page confuses people.

Neither of the last two loads unless you agree to it. They are not requested, not downloaded and set no cookies until you say yes on the banner, and you can change your mind at any point. Session recording is never switched on once you are signed in, so nothing about your agency, your staff, the families you work with or the people they care for is ever sent to it. Where we do count page views inside the product, the address is reduced to the shape of the screen. /workers/:id rather than the record you were looking at. There is no advertising anywhere, and we do not sell personal data.

Our webfonts are served from our own servers rather than a font CDN, so loading a page here does not hand your IP address to a third party for that.

Cookies

Two are strictly necessary and cannot be switched off: one keeps you signed in, and one protects forms against cross-site request forgery. Neither is used for advertising, and the law does not require us to ask permission for cookies without which the thing you asked for cannot work. A third remembers the choice you make below, which is the only way to avoid asking you again on every page.

Everything else is opt-in. The measurement tools above set cookies to tell one visit from another, and nothing is loaded and no such cookie is set until you have agreed. Refusing is one click, in the same place and the same size as accepting. We ask again after six months, and never as a way of wearing you down.

To change your mind: . There is also a link in the footer of every page and at the bottom of the app. Turning something off deletes the cookies it set. Your browser's own controls and any tracker blocker work too, and the site behaves identically either way.

How long we keep it

While your agency's account is active, and afterwards only where the law requires it. Invoices, payouts and the hours behind them are kept for six years as financial records; everything identifying attached to them is removed. Close your account and everything else goes immediately.

Your rights

Under UK and EU GDPR you can ask for a copy of your data, have it corrected, have it erased, object to or restrict how it is processed, and take it elsewhere. In practice:

  • If you are a member of staff, a client, or a parent. Ask the agency you deal with. They are the controller, and Rostavo gives them a one-click way to export or erase your record.
  • If you run the agency. Settings → Data protection inside the app. Download everything as a single file, erase one person's data, or close the account entirely. Erasure destroys documents, messages, notes and the login, and leaves only the anonymous financial rows the law requires us to keep.
  • Either way. You can also email us and we will help, or complain to the ICO if you think we have got it wrong.

Children's data

Agencies record information about children in their care. Ages, allergies, medical notes, schools, pickup arrangements. That is controlled by the agency, is only ever visible inside that agency's account, and is destroyed in full when the family's record is erased. We process it solely to provide the service to the agency, and for nothing else.

Security

Data is encrypted in transit, access is restricted by role, and each agency's records are isolated from every other agency's at the database level. Something we test for deliberately rather than assume. No system is perfectly secure, but nothing here is left to chance.

Contact

Questions or requests: hello@rostavo.com. A person reads these.