Privacy Policy

Last updated: June 29, 2026

Introduction & Scope

1. Introduction

NestLink.ca (“we”, “our”, “us”) is committed to protecting the privacy of individuals who use our platform, including parents, guardians, and childcare providers.

This Privacy Policy explains how we collect, use, disclose, store, and safeguard personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

Our application is built on Base44, which provides secure infrastructure, encryption, and audited security controls.

2. Scope

This Privacy Policy applies to:

  • Visitors to our website
  • Users who create accounts on our platform
  • Parents and guardians using the service
  • Childcare providers, including daycares and Montessori schools

Data Collection & Usage

3. Information We Collect

We collect only the personal information reasonably necessary to operate, support, secure, and improve the service. Depending on how you use NestLink, information may include:

  • Parent or guardian name, email address, phone number, account details, and communication preferences;
  • Child-related application information, such as child name, date of birth, age group, desired start date, sibling-enrolment status, application status, waitlist details, tour status, and related enrolment workflow information;
  • A child’s gender, where collected to support the application. This field always includes a “prefer not to say” option. NestLink does not use gender to rank, filter, or make decisions about applications;
  • Information submitted by childcare providers on behalf of a parent or guardian through the manual-add application feature, where the provider confirms it has the parent’s or guardian’s consent to enter the information;
  • Optional second parent or guardian contact details where provided;
  • Provider account, profile, licensing, program, availability, room, listing, review, message, and uploaded-content information;
  • Communications with NestLink, childcare providers, or families through the platform, including support requests, messages, notices, and feedback;
  • Lead-source and campaign information, such as how a family heard about a provider or a campaign source from a URL;
  • Operational and analytics information, including profile views, application events, status history, tour completion, offer and decision events, weekly summary information, and provider-facing insights;
  • Technical and security information, including IP address, device/browser type, user agent, logs, session identifiers, authentication events, error reports, and abuse-prevention records.

We do not sell personal information. We do not use children’s personal information for third-party advertising, cross-site behavioural advertising, or marketing profiles.

Provider-Submitted Family Information

NestLink allows authorized childcare providers to manually add an application for a family. This may occur, for example, after a phone call, in-person inquiry, email exchange, or other direct communication between the family and the provider.

When a provider manually adds an application, the provider must confirm that it has the parent’s or guardian’s verbal consent to enter the family’s information into NestLink for application-management purposes. NestLink records this consent attestation in an immutable audit record, including the provider user who made the attestation, the date and time of the attestation, the exact attestation wording shown at the time, and technical audit information including IP address and user agent.

After a manual application is created, NestLink may send the parent or guardian an invitation or notice so they can claim the application, review the information, correct inaccuracies, continue using the platform, or request removal where permitted by law.

4. How We Use Personal Information

We use personal information for the following purposes:

  • Creating, authenticating, and managing user accounts;
  • Operating the NestLink platform and providing requested services;
  • Creating, managing, claiming, updating, withdrawing, and tracking childcare applications;
  • Supporting provider manual-add workflows, parent invite workflows, consent attestation records, duplicate-application checks, and application-claiming;
  • Facilitating communication between parents, guardians, and childcare providers;
  • Managing waitlists, tour requirements, tour completion, application statuses, offers, acceptances, withdrawals, and related workflow events;
  • Generating provider-facing operational insights, such as profile views, inquiry counts, lead sources, tour activity, offer activity, accepted offers, decision reasons, and average time between application stages;
  • Sending service emails, application notices, reminders, provider summaries, support responses, and security communications;
  • Moderating messages, reviews, uploaded content, and platform conduct;
  • Detecting, preventing, and investigating fraud, misuse, spam, unauthorized access, excessive manual entry, security incidents, and platform abuse;
  • Improving platform reliability, functionality, security, and user experience;
  • Meeting legal, regulatory, contractual, accounting, dispute-resolution, and enforcement obligations.

We do not sell personal information.

5. Legal Basis for Processing

Under PIPEDA, we collect, use, and disclose personal information primarily on the basis of consent, together with the limited business and legal purposes permitted by law. These include:

  • Consent, where meaningful consent has been obtained from the individual or, for child-related information, from a parent, guardian, or authorized provider acting on their behalf;
  • Contractual necessity, to provide the services requested;
  • Permitted business purposes, such as security, fraud prevention, audit, and service operation;
  • Legal obligations, where processing is required or permitted by law.

Consent may be withdrawn at any time, subject to legal or contractual limitations.

6. Children’s Information and Sensitive Information

Because NestLink supports childcare applications, some information may relate to children. We take additional care with child-related information and limit collection to information needed for application, enrolment, communication, waitlist, tour, provider-management, and related administrative purposes.

  • We do not knowingly collect personal information directly from children. Child-related information is provided by parents, guardians, or authorized childcare providers.
  • We do not use children’s personal information for advertising, profiling, or marketing.
  • We do not use a child’s gender or any other protected-ground information to rank, filter, score, or make decisions about applications.

NestLink has removed health and previous education/care-history questions from its pre-enrolment application flows. To the extent legacy records contain previously submitted health or care-history information, we will retain, delete, or anonymize that information in accordance with our retention practices, legal obligations, and valid access or deletion requests.

Childcare providers may have separate legal obligations under Ontario’s Child Care and Early Years Act, 2014 (CCEYA), O. Reg. 137/15, and Ministry of Education requirements to collect and keep certain child, health, attendance, emergency, medical, immunization, or enrolment records once a child is admitted or receiving care. Those provider records are the responsibility of the childcare provider, are governed by separate provider policies, legal duties, and retention requirements, and NestLink is not the system of record for them.

7. Automated Tools and Human Review

NestLink may use rules-based tools to support platform operations, such as determining an initial application status, calculating age group or waitlist-related information, identifying duplicate applications, tracking tour completion, detecting unusual manual-add activity, producing provider insights, and supporting security or moderation workflows.

NestLink does not make final childcare enrolment decisions for providers. Childcare providers remain responsible for their own admissions, waitlist, tour, offer, and enrolment decisions. Where a platform-generated status, calculation, or workflow appears incorrect, users may contact NestLink or the relevant provider for review.

8. Consent

By using our services or creating an account, you consent to the collection, use, and disclosure of personal information as described in this policy.

You may withdraw consent by deleting your account or contacting us, subject to applicable legal requirements.

Security, Storage & Analytics

9. Data Storage, Security, and Safeguards

Our platform is hosted on Base44, which provides:

  • Encryption of data in transit and at rest
  • Secure access controls
  • Ongoing monitoring and vulnerability testing
  • Industry-recognized security certifications

We also implement administrative and organizational safeguards to protect personal information against unauthorized access, disclosure, or misuse.

While no system can guarantee absolute security, we take reasonable and appropriate measures to protect personal information.

Provider Insights and Operational Analytics

NestLink collects and generates operational information to help providers understand activity on their profile and application pipeline. This may include profile views, application counts, lead-source information, tour completion, offers, accepted offers, withdrawals, decision reasons, timing between application stages, and weekly summary information.

These insights are intended to support provider operations and service improvement. They are not legal, licensing, enrolment, or human-rights advice, and they do not replace a provider’s own obligations to make fair, lawful, and non-discriminatory enrolment decisions.

Where practical, NestLink presents insights in aggregate or summary form. Some insights are generated from underlying application, status, communication, and provider-profile activity records.

Cookies and Analytics

We use limited cookies and similar technologies that are necessary for the operation, security, and performance of our platform. These may include session cookies and basic analytics to help us understand how the service is used and to improve functionality.

We do not use third-party advertising cookies, cross-site tracking, or external data sources to target users.

Any promotional listings or paid placements on the platform are based solely on information provided directly by childcare providers within the service.

Users can manage or disable cookies through their browser settings.

Content & Third Parties

Content and Uploads

Childcare providers may upload content to the platform, including photos, images, descriptions, or documents related to their programs.

  • Uploaded content is visible only to authorized users as intended by the provider.
  • We do not claim ownership over provider-uploaded content.
  • Content is used solely to operate and display the service as directed by the provider.
  • Providers are responsible for ensuring they have appropriate permissions or consents for any content they upload, including photos involving children.

Uploaded content may be removed or updated by the provider, and will be deleted in accordance with our data retention practices when accounts are closed or content is removed.

10. Service Providers and Sub-Processors

We rely on trusted third-party service providers (“sub-processors”) to operate and support our services. These providers process personal information only as necessary to perform services on our behalf and are contractually required to protect it.

Key sub-processors include:

  • Base44 — application hosting, infrastructure security, and data processing
  • Cloud infrastructure providers used by Base44
  • Communication, monitoring, and security service providers

We remain responsible for personal information processed by our service providers.

Roles and Responsibility for Information

NestLink operates as a platform connecting families and childcare providers. The privacy role we play may depend on the context.

For parent-created accounts, searches, applications, communications, support requests, platform analytics, security logs, and NestLink-operated workflows, NestLink is responsible for its collection, use, disclosure, retention, and protection of personal information.

When childcare providers enter, upload, or manage family, child, application, listing, document, or program information through the platform, the provider remains responsible for ensuring that it has collected and submitted that information lawfully, with appropriate consent or other authority, and in compliance with applicable childcare, privacy, human rights, and Ministry of Education requirements.

NestLink processes provider-managed information to provide the platform, support application and enrolment workflows, generate provider-facing operational insights, maintain audit records, prevent misuse, secure the service, and meet legal obligations. NestLink does not sell provider-managed family or child information and does not use children’s personal information for third-party advertising.

Data Management & Rights

11. Cross-Border Data Transfers

Personal information may be stored or processed outside Canada. When this occurs, we ensure that appropriate contractual, technical, and organizational safeguards are in place to provide a level of protection comparable to Canadian privacy standards.

12. Retention and Deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law.

Different categories of information may have different retention periods, including:

  • Account information: retained while the account is active and for a reasonable period after closure for security, legal, audit, and dispute-resolution purposes;
  • Application information: retained while needed to manage the application, waitlist, tour, offer, enrolment, withdrawal, dispute, audit, or provider-record workflow;
  • Manual-add and unclaimed application information: retained while needed to notify the parent or guardian, allow claiming or correction, support the provider’s application workflow, prevent duplicate or abusive entries, and satisfy legal or audit requirements;
  • Consent attestation records: retained as immutable audit records to demonstrate the provider’s attestation and support privacy, security, legal, or dispute-resolution needs;
  • Messages, reviews, support tickets, and notices: retained as needed to operate the platform, enforce rules, resolve disputes, and maintain safety;
  • Analytics, profile-view, lead-source, and operational insight records: retained as needed to provide provider insights, improve the service, and maintain security;
  • Technical, security, and error logs: retained for a reasonable period for security, fraud prevention, troubleshooting, and audit purposes.

When an account or application is deleted, personal information will be deleted, anonymized, or restricted within a reasonable timeframe, unless retention is required or permitted by law, necessary for security, required for audit purposes, or needed to resolve disputes or enforce agreements.

13. Individual Rights

Under PIPEDA, individuals have the right to:

  • Access their personal information
  • Request corrections to inaccurate or incomplete data
  • Request deletion of their information, subject to legal obligations
  • Ask questions about how their information is used or disclosed

If a childcare provider entered your information through the manual-add feature, you may contact NestLink to request access, correction, claiming, withdrawal, or deletion of that information. Depending on the context, we may need to coordinate with the childcare provider because the provider may have separate legal, licensing, contractual, or record-retention obligations.

Requests can be made using the contact information below.

Accountability & Contact

14. Privacy Officer and Accountability

We have designated a Privacy Officer responsible for overseeing compliance with privacy laws and managing personal information practices.

Responsibilities include:

  • Ensuring compliance with PIPEDA and applicable provincial laws
  • Overseeing data protection safeguards
  • Managing privacy inquiries, complaints, and access requests
  • Coordinating responses to data incidents or breaches

15. Privacy Impact Assessments

We conduct Privacy Impact Assessments (PIAs) when introducing new features, data uses, or integrations that may affect personal information, particularly where child-related information is involved. These assessments help identify and mitigate privacy risks.

16. Legal and Regulatory Disclosure

We may disclose personal information where required by law, regulation, court order, or valid legal process, or where necessary to protect the rights, safety, or security of our users or the public.

Privacy Incidents and Breach Response

If we become aware of a privacy incident involving personal information under our control, we will assess the incident and take reasonable steps to contain, investigate, and remediate it.

Where a breach of security safeguards creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as required by PIPEDA. We maintain records of all breaches of security safeguards for at least 24 months, whether or not they are reportable, and will notify other organizations or institutions where doing so may help reduce the risk of harm.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the platform or by email.

18. Contact Information

Email: privacy@nestlink.ca

Location: Mississauga, ON, Canada