Privacy Policy
Last updated: 1 March 2026
1. Who we are
CareBirds is operated by CareBirds Ltd, registered in Scotland. We provide a digital staffing platform connecting care workers with care facilities across the United Kingdom. Our registered address and contact details are available on our Contact page.
2. What data we collect
We collect the following categories of personal data:
- Identity data — name, date of birth, profile photo
- Contact data — email address, phone number
- Professional data — NMC/SSSC pin, qualifications, DBS/PVG certificate number, work history
- Location data — GPS coordinates collected at check-in and check-out (with your consent)
- Financial data — bank sort code and account number for payroll purposes (stored securely via encrypted vault)
- Usage data — pages visited, actions taken, device type, browser, IP address
- Communications — messages sent through the platform
3. How we use your data
We use your personal data to:
- Create and manage your account
- Match you with suitable shifts or workers
- Process payroll and payments
- Verify your identity and professional credentials
- Send shift confirmations, notifications and platform updates
- Comply with legal obligations (HMRC, CQC, Care Inspectorate)
- Improve platform performance and user experience
4. Legal basis for processing
We process your data under the following legal bases (UK GDPR Article 6):
- Contract — to fulfil our agreement with you as a platform user
- Legal obligation — to comply with employment, tax and care regulation law
- Legitimate interests — to improve our services and prevent fraud
- Consent — for GPS location tracking and marketing communications
5. Data sharing
We share your data only where necessary:
- Care facilities — your name, photo, credentials and shift details
- Supabase — our database and authentication provider (EU/UK servers)
- Resend — transactional email delivery
- HMRC and regulators — as required by law
We do not sell your personal data to third parties.
6. Data retention
We retain your data for as long as your account is active and for up to 7 years after closure to comply with HMRC and employment law requirements. GPS check-in data is retained for 2 years. You may request deletion at any time (subject to legal retention requirements).
7. Your rights
Under UK GDPR you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Object to processing or request restriction
- Data portability
- Withdraw consent at any time
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Cookies
We use essential cookies only — for authentication sessions and security. We do not use advertising or tracking cookies. You can disable cookies in your browser settings, however this may affect platform functionality.
9. Security
We use industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, row-level security on all database tables, and regular security audits. However, no system is completely secure and we encourage you to use a strong, unique password.
10. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes by email or in-app notification. Continued use of the platform after changes constitutes acceptance.
11. Contact & complaints
For privacy queries contact [email protected]. If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.