Last updated: June 29, 2026
NestLink.ca (“we”, “our”, “us”) is committed to protecting the privacy of individuals who use our platform, including parents, guardians, and childcare providers.
This Privacy Policy explains how we collect, use, disclose, store, and safeguard personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Our application is built on Base44, which provides secure infrastructure, encryption, and audited security controls.
This Privacy Policy applies to:
We collect only the personal information reasonably necessary to operate, support, secure, and improve the service. Depending on how you use NestLink, information may include:
We do not sell personal information. We do not use children’s personal information for third-party advertising, cross-site behavioural advertising, or marketing profiles.
NestLink allows authorized childcare providers to manually add an application for a family. This may occur, for example, after a phone call, in-person inquiry, email exchange, or other direct communication between the family and the provider.
When a provider manually adds an application, the provider must confirm that it has the parent’s or guardian’s verbal consent to enter the family’s information into NestLink for application-management purposes. NestLink records this consent attestation in an immutable audit record, including the provider user who made the attestation, the date and time of the attestation, the exact attestation wording shown at the time, and technical audit information including IP address and user agent.
After a manual application is created, NestLink may send the parent or guardian an invitation or notice so they can claim the application, review the information, correct inaccuracies, continue using the platform, or request removal where permitted by law.
We use personal information for the following purposes:
We do not sell personal information.
Under PIPEDA, we collect, use, and disclose personal information primarily on the basis of consent, together with the limited business and legal purposes permitted by law. These include:
Consent may be withdrawn at any time, subject to legal or contractual limitations.
Because NestLink supports childcare applications, some information may relate to children. We take additional care with child-related information and limit collection to information needed for application, enrolment, communication, waitlist, tour, provider-management, and related administrative purposes.
NestLink has removed health and previous education/care-history questions from its pre-enrolment application flows. To the extent legacy records contain previously submitted health or care-history information, we will retain, delete, or anonymize that information in accordance with our retention practices, legal obligations, and valid access or deletion requests.
Childcare providers may have separate legal obligations under Ontario’s Child Care and Early Years Act, 2014 (CCEYA), O. Reg. 137/15, and Ministry of Education requirements to collect and keep certain child, health, attendance, emergency, medical, immunization, or enrolment records once a child is admitted or receiving care. Those provider records are the responsibility of the childcare provider, are governed by separate provider policies, legal duties, and retention requirements, and NestLink is not the system of record for them.
NestLink may use rules-based tools to support platform operations, such as determining an initial application status, calculating age group or waitlist-related information, identifying duplicate applications, tracking tour completion, detecting unusual manual-add activity, producing provider insights, and supporting security or moderation workflows.
NestLink does not make final childcare enrolment decisions for providers. Childcare providers remain responsible for their own admissions, waitlist, tour, offer, and enrolment decisions. Where a platform-generated status, calculation, or workflow appears incorrect, users may contact NestLink or the relevant provider for review.
By using our services or creating an account, you consent to the collection, use, and disclosure of personal information as described in this policy.
You may withdraw consent by deleting your account or contacting us, subject to applicable legal requirements.
Our platform is hosted on Base44, which provides:
We also implement administrative and organizational safeguards to protect personal information against unauthorized access, disclosure, or misuse.
While no system can guarantee absolute security, we take reasonable and appropriate measures to protect personal information.
NestLink collects and generates operational information to help providers understand activity on their profile and application pipeline. This may include profile views, application counts, lead-source information, tour completion, offers, accepted offers, withdrawals, decision reasons, timing between application stages, and weekly summary information.
These insights are intended to support provider operations and service improvement. They are not legal, licensing, enrolment, or human-rights advice, and they do not replace a provider’s own obligations to make fair, lawful, and non-discriminatory enrolment decisions.
Where practical, NestLink presents insights in aggregate or summary form. Some insights are generated from underlying application, status, communication, and provider-profile activity records.
We use limited cookies and similar technologies that are necessary for the operation, security, and performance of our platform. These may include session cookies and basic analytics to help us understand how the service is used and to improve functionality.
We do not use third-party advertising cookies, cross-site tracking, or external data sources to target users.
Any promotional listings or paid placements on the platform are based solely on information provided directly by childcare providers within the service.
Users can manage or disable cookies through their browser settings.
Childcare providers may upload content to the platform, including photos, images, descriptions, or documents related to their programs.
Uploaded content may be removed or updated by the provider, and will be deleted in accordance with our data retention practices when accounts are closed or content is removed.
We rely on trusted third-party service providers (“sub-processors”) to operate and support our services. These providers process personal information only as necessary to perform services on our behalf and are contractually required to protect it.
Key sub-processors include:
We remain responsible for personal information processed by our service providers.
NestLink operates as a platform connecting families and childcare providers. The privacy role we play may depend on the context.
For parent-created accounts, searches, applications, communications, support requests, platform analytics, security logs, and NestLink-operated workflows, NestLink is responsible for its collection, use, disclosure, retention, and protection of personal information.
When childcare providers enter, upload, or manage family, child, application, listing, document, or program information through the platform, the provider remains responsible for ensuring that it has collected and submitted that information lawfully, with appropriate consent or other authority, and in compliance with applicable childcare, privacy, human rights, and Ministry of Education requirements.
NestLink processes provider-managed information to provide the platform, support application and enrolment workflows, generate provider-facing operational insights, maintain audit records, prevent misuse, secure the service, and meet legal obligations. NestLink does not sell provider-managed family or child information and does not use children’s personal information for third-party advertising.
Personal information may be stored or processed outside Canada. When this occurs, we ensure that appropriate contractual, technical, and organizational safeguards are in place to provide a level of protection comparable to Canadian privacy standards.
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law.
Different categories of information may have different retention periods, including:
When an account or application is deleted, personal information will be deleted, anonymized, or restricted within a reasonable timeframe, unless retention is required or permitted by law, necessary for security, required for audit purposes, or needed to resolve disputes or enforce agreements.
Under PIPEDA, individuals have the right to:
If a childcare provider entered your information through the manual-add feature, you may contact NestLink to request access, correction, claiming, withdrawal, or deletion of that information. Depending on the context, we may need to coordinate with the childcare provider because the provider may have separate legal, licensing, contractual, or record-retention obligations.
Requests can be made using the contact information below.
We have designated a Privacy Officer responsible for overseeing compliance with privacy laws and managing personal information practices.
Responsibilities include:
We conduct Privacy Impact Assessments (PIAs) when introducing new features, data uses, or integrations that may affect personal information, particularly where child-related information is involved. These assessments help identify and mitigate privacy risks.
We may disclose personal information where required by law, regulation, court order, or valid legal process, or where necessary to protect the rights, safety, or security of our users or the public.
If we become aware of a privacy incident involving personal information under our control, we will assess the incident and take reasonable steps to contain, investigate, and remediate it.
Where a breach of security safeguards creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as required by PIPEDA. We maintain records of all breaches of security safeguards for at least 24 months, whether or not they are reportable, and will notify other organizations or institutions where doing so may help reduce the risk of harm.
We may update this Privacy Policy from time to time. Material changes will be communicated through the platform or by email.