Careloom ← Back to home

Privacy

Effective 10 August 2026 · replaces the draft summary of 27 July 2026

The short version: we collect the minimum, host it in the EU, never sell it, and never use it for advertising. Care records belong to your agency, not to us — we hold them as their processor, isolated per agency, with every access logged. Everything below is the detail behind those sentences.

Who we are

Careloom is home-care software built in Donegal, Ireland, operated by Careloom Limited, a company registered in Ireland (CRO no. 822185). For anything in this policy, the dedicated data-protection address is privacy@careloom.ie — it is monitored separately from general support so requests with a legal deadline are never missed. For anything else, contact us at hello@careloom.ie or on 086 405 6645.

Two roles, two sets of rules

Careloom wears two hats, and it matters which one applies to you. For the data described in the next sections — website enquiries, the accounts of people who log in, billing contacts — Careloom is the controller and this policy is the full story. For the care records an agency keeps inside Careloom — clients, care plans, medication, visit notes — the agency is the controller and Careloom is the processor, acting only on the agency's instructions under a Data Processing Agreement. If you are a care client or a family member and want to see, correct or erase care records, your request goes to the agency providing the care — they hold the keys, and we help them answer you.

What we collect on this website

If you request the HIQA readiness checklist we collect your email address, and use it to send you the checklist and a monthly plain-English update on the Act — unsubscribe at any time, in one click, from any email. If you book a walkthrough, you give your name, email and a few details about your agency so the call is useful. Our legal basis for both is legitimate interest in responding to people who asked to hear from us (GDPR Art. 6(1)(f)) and, for a booked call, the steps you asked us to take before a contract (Art. 6(1)(b)). No marketing lists you didn't ask for, no selling data, ever.

This site measures its traffic with Plausible, a privacy-first, EU-based analytics service that uses no cookies and builds no profile of you — we see aggregate counts (how many people read a page), never individuals. There are no advertising trackers on this site, and no consent banner because there is nothing on it that needs your consent.

What we collect when you use the app

If you hold a Careloom login — as an administrator, coordinator or carer — we hold your name, work email, phone number, role and staff ID, because that is what a login and a rota need (legal basis: our contract with your agency, Art. 6(1)(b), and our legitimate interest in operating the service, Art. 6(1)(f)). Your password is handled by our authentication provider and is never visible to us; an optional device PIN encrypts your signed-in session on your own device. For the person who pays the bill we hold billing contact details and payment status — card numbers live with our payment provider, never with us (bases: contract, and the legal obligation to keep accounting records, Art. 6(1)(c)).

The app can report its own errors to a monitoring service so faults get fixed. When enabled, error reports are deliberately starved of personal data before they leave your browser: no IP addresses, no cookies, no request bodies, no session replay, and web addresses are scrubbed of anything that could carry a token. The only thing the app stores on your device is what keeps you signed in. We do not profile you, advertise to you, or sell anything about you.

Care data in the product

Client and carer records your agency puts into Careloom are hosted in the EU and isolated per agency at the database level — one agency can never see another's data, enforced by the database itself, not by application code. Every change is logged and attributable, and every viewing of a health record is logged too: who looked at which client, and when. The family portal is read-only, opened by a link the agency controls and can revoke at any time. The agency's lawful condition for holding health data is its own — typically the provision of health and social care under GDPR Art. 9(2)(h) with the Irish Data Protection Act 2018 safeguards — and its duties to HIQA shape how long records are kept. Full export is one click and always free. The technical detail is on the security page; the contractual detail is in the Data Processing Agreement every agency accepts.

Who processes data on our behalf

These services run parts of Careloom under our instructions, each bound by a data-processing agreement. Health data lives in exactly one of them — the database — and the design deliberately keeps it out of all the others.

Supabase — the database, authentication and file storage: the one place care records live. Hosted in the EU (Ireland).

Netlify — serves the app's code to your browser; care data flows to the database, not through the web host's storage.

Resend — sends the platform's sign-in emails (confirmations, password resets) from EU infrastructure (Ireland). It never sends client information, because the platform never emails any.

Microsoft 365 — our own mailboxes, for support and correspondence. Please keep client identifiers out of support emails — refer to records in the app instead; anything sent anyway is deleted.

Stripe — subscription billing. Card numbers are held by Stripe, never by Careloom, and Stripe receives no care data.

Sentry — optional error monitoring, fed only the PII-scrubbed reports described above.

MailerLite (EU) — stores the email addresses given for the HIQA checklist and sends that list its emails.

Calendly — handles walkthrough bookings and the details you enter when booking.

Plausible (EU) — cookieless, aggregate website analytics, as described above.

Agencies get advance notice by email before we add or replace a processor that touches their data, with the right to object on data-protection grounds — and to walk away with a full export if an objection can't be resolved.

Where data lives

The database — including every care record — is hosted in the EU (Ireland), and keeping it there is a design decision, not an accident. Where a service provider processes limited, non-care data outside the EEA, the transfer is protected by an EU adequacy decision or Standard Contractual Clauses.

How long we keep it

Account data is kept for the life of the account and a short period after closure, then deleted. Billing records are kept for the period Irish tax and accounting law requires. Care records follow the agency's own retention schedule — Irish providers are required to retain care records for regulatory purposes, which is why "delete everything now" is sometimes legally the wrong answer; the agency records its retention decisions in Careloom and they are honoured on erasure. Backups are not individually edited: erased data leaves them as the rolling backup window ages out, and until then backups stay encrypted, access-restricted, and used only for disaster recovery.

If something goes wrong

If a personal-data breach affects data we process for an agency, we tell that agency without undue delay, with what they need to meet their own duties to the Data Protection Commission and to the people affected. We keep a written breach-response procedure and follow it rather than improvising.

Your rights

For data Careloom controls, you can ask us to: access what we hold about you; correct it; erase it; restrict or object to how it's used; and receive it in a portable form. Email privacy@careloom.ie and you'll have an answer within one month — usually within days. You also have the right to complain to the Data Protection Commission (dataprotection.ie). If your request concerns care records, it goes to the agency that controls them (see "Two roles" above) — and if you're not sure which applies, write to us anyway and we'll point you right.

Changes to this policy

When the service changes, this policy will change with it: we post the new version here with a new effective date, and agencies are told about material changes by email before they take effect. This version is 2026-08-10. See also the terms of service and the security page.