NannyTank

Privacy Policy

Last updated: 12 July 2026

1. Who we are

NannyTank is a web application and website that helps au pairs and nannies log their working hours and kilometres, calculate monthly claims, and submit them to their employer. Employers can create their own account and, once an au pair connects them, view that au pair's hours and claims, approve claims, and share a schedule. NannyTank also runs a marketplace: au pairs can create a public profile to be found by families and can browse and apply to jobs; families and agencies can post jobs and browse au pair profiles. It is operated by Reynard du Toit (support@nannytank.co.za). This policy applies to everyone who uses NannyTank — whether as an au pair, an employer, or an agency, and whether you use the app or the website.

2. What data we collect

  • Account data: Your email address and whether you use NannyTank as an au pair, an employer, or an agency, used to create and identify your account via Supabase Auth. You can create an account and set up a profile or listing either in the app or on the website — the data collected is the same.
  • Log data (au pairs): Hours worked, kilometres driven, trip descriptions, and dates that you enter manually into the app.
  • Settings: Your name and profile details. For au pairs this also includes employer name and email, vehicle, km rate, hourly rate, and working hours; for employers it includes your payment-reminder preferences. Entered by you in the Settings screen.
  • Connections: When an au pair generates a pairing code and an employer enters it, we store the link between the two accounts so the employer can see that au pair's information (see section 3). Either side can disconnect at any time.
  • Public profile (au pairs, optional): If you choose to create a marketplace profile, we store the display name, photo, headline, "about you" description, country and city/area, years of experience, availability, languages, skills, and the credentials you say you can provide (for example "police clearance" or "first aid") that you enter. When you publish it, this profile is shown publicly in the NannyTank directory (see section 3). It deliberately does not include your exact address, phone number or email, and your uploaded document files stay private — a profile only lists the credentials you choose to advertise, never the documents themselves.
  • Job listings (employers & agencies, optional): If you post a job, we store the job title, the family or agency name you enter, the country and city/area, hours, start date, number and ages of children, pay, the requirements you're looking for, and the description you write. When you publish it, this listing is shown publicly on the NannyTank jobs board (see section 3).
  • Contact requests and applications: When a family or agency contacts an au pair, or an au pair applies to a job, we store the name, email address, phone number (if given) and message that the sender chooses to share, and pass them to the other person so they can reply (see section 3).
  • Shared schedule (optional): Calendar entries you create in the in-house schedule — title, date and time, location and notes. These are visible to the au pair and their connected employer.
  • Comments (optional): Messages you leave on a shared schedule entry. These are visible to the au pair and their connected employer.
  • Claim status: Whether a claim has been approved and marked paid by the employer, and marked as salary received by the au pair — so both sides can keep track. No card or bank details are involved (see section 5).
  • Documents (optional, au pairs): Personal and work documents you choose to upload — for example a police clearance, first-aid certificate, driver's licence, ID or passport, CV, or contract — as PDFs or images. Because these can be sensitive identity documents, we treat them as strictly private: they are held in a private storage area with no public web address, protected by database-level access rules, and can be opened only by you and an employer you have connected — no other user and no member of the public (see section 6). You can delete any document at any time.
  • Google Calendar data (optional): If you choose to connect Google Calendar on the Schedule tab, we request read-only access to your calendar events. We use this solely to display upcoming events inside the app. We do not store your calendar events in our database.
  • Push notification subscription: A browser/device token used to deliver optional reminders and alerts you turn on — for example a daily logging reminder for au pairs, or a new-claim alert and a payment-day reminder for employers. No message content is stored beyond the subscription endpoint.
  • Profile photo (optional): By default we show the picture from your Google account. If you upload your own — as an au pair or an employer — it is stored in Supabase Storage and shown in your own profile in the app.
  • Reviews and ratings (optional): If you rate or review NannyTank in the app, we store your star rating, any comment you write, the display name you choose, and whether you've consented to your review being featured.
  • Location (optional): When you use the Quick Status feature and choose to share your location, we access your device's location to put a map link in the WhatsApp message you send your employer. Your location is not stored — it only goes into the message you choose to send.
  • Payment and subscription data: When you subscribe, your card details are entered directly with our payment processor, Paystack — NannyTank never sees or stores your full card number. We store your billing email, your subscription and trial status, and the references Paystack provides (a customer code and a subscription code) so we can manage your access and billing.

3. How we use your data

  • To display your logged hours and km on the Log and History screens.
  • To generate your monthly Excel claim and email it to your employer when you request it.
  • To show your family's shared Google Calendar events on the Schedule tab (if connected).
  • To let a connected employer view that au pair's hours, kilometres, days off, and claims, approve or record payment of claims, and share a schedule with them (see below).
  • To send optional push notifications you turn on — a daily logging reminder for au pairs, and new-claim and payment-day reminders for employers.
  • To include your live location in a status message to your employer — only when you choose to send one.
  • To manage your 14-day free trial and, if you subscribe after it, process your R59/month subscription through Paystack.
  • To collect your feedback through in-app ratings and reviews, and — only if you choose to feature it — to display your review and chosen display name publicly (see below).
  • To run the marketplace: to show a profile or job listing you choose to publish, to let you browse profiles and jobs, and to pass on a contact message or a job application to the person you send it to (see below).

We do not sell your personal information or use it for advertising. Aside from the third-party services listed below that help us run NannyTank, we share your personal information only in ways you control: with an employer you connect (below); through the marketplace, when you choose to publish a profile or job or to contact or apply to someone (below); and reviews you choose to feature (below).

Public profiles and job listings (optional). The marketplace is opt-in. A profile or job listing you create stays a private draft until you choose to publish it. Once published, it is shown publicly in the NannyTank directory or jobs board — on our website and in the app — and can be seen by anyone, including people who do not have an account, and may be cached or indexed by search engines. Published profiles and listings show only the details described in section 2 (for example a first name, city, experience and credential badges) — never your exact address, and never your uploaded document files. You can unpublish a profile or delete a listing at any time, which removes it from public view going forward.

Contacting and applying. When a family or agency gets in touch with an au pair, or an au pair applies to a job, the sender chooses to share their name, email, phone number (optional) and a message. We pass these details to the other person so they can decide whether to reply. After that introduction, the two of you communicate directly, outside NannyTank. We are not a party to and do not monitor those conversations. NannyTank does not verify the identity, background, credentials or documents of any user — please see our Terms of Service about doing your own checks before employing anyone or accepting a job.

Sharing between au pairs and employers. NannyTank lets an au pair connect an employer. The au pair starts this by generating a pairing code and giving it to their employer; nothing is shared until the au pair does so. Once connected, the employer can see that au pair's logged hours and kilometres, days off, sick and vacation days, submitted claims and their amounts, the shared in-house schedule and any comments on it, and any documents the au pair has uploaded. Both people can add, edit and delete entries in the shared schedule and post comments, which the other can see. Either side can end the connection at any time (au pair: Settings → Connect my employer; employer: Account → disconnect), which stops any further sharing. We share this information only between the two connected accounts — never with other users.

Reviews you choose to feature. When you submit a review you can tick a box to let us feature it. If you do, your review and your chosen display name may be shown publicly — on our website (such as nannytank.co.za) and in materials promoting NannyTank. Anything shown publicly can be seen by anyone and may be cached or indexed by search engines. We never feature a review without that consent, and you can withdraw it — or ask us to remove your featured review — at any time by emailing support@nannytank.co.za.

4. Google Calendar access

When you connect Google Calendar, NannyTank requests the https://www.googleapis.com/auth/calendar.readonly scope. This allows the app to read your calendar events and display them in the Schedule tab.

We do not:

  • Store your calendar events in our database
  • Share your calendar data with any third party
  • Use your calendar data for any purpose other than displaying it to you in the app

You can revoke Google Calendar access at any time by visiting myaccount.google.com/permissions and removing NannyTank.

NannyTank's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never use or transfer Google user data for serving advertisements, selling to data brokers or information resellers, determining credit-worthiness, lending, training generalised AI or machine-learning models, or any purpose other than providing and improving the calendar feature you see in the app.

5. Payments and subscriptions

After a 14-day free trial (no card required), access to NannyTank is a R59/month subscription. We use Paystack, a PCI-DSS compliant payment processor, to handle all payments. When you subscribe, your card details are entered into and stored by Paystack, not by NannyTank. We only store your subscription status and the Paystack references needed to manage your access and recurring billing. You can cancel any time from the Subscription screen in Settings. Paystack's handling of your payment information is governed by their privacy policy.

6. Data storage and security

Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. All data is encrypted in transit (HTTPS/TLS) and encrypted at rest. Access requires authentication, and each user's data is isolated using Row Level Security — you can only access your own records, except for the information you choose to make public (a profile or job listing you publish) or to share with someone else (the details you send when you contact an au pair, apply to a job, or connect an employer). Those are described in section 3.

Aside from what you choose to publish or share, your data is not accessible to other NannyTank users. If you connect Google Calendar, your events are read live and shown in the app only — they are never written to our database.

Your uploaded documents. We give the certificates and personal documents you upload extra protection, because they can include sensitive identity documents such as a driver's licence, ID or passport. They are kept in a private storage area: there is no public link to them, and they cannot be found by browsing our storage or by guessing a web address. Access is restricted by the same Row Level Security rules as the rest of your data, so the only people who can open a document are you and an employer you have personally connected — no other NannyTank user, and no member of the public, can reach them. When you or your connected employer view a document, it opens through a temporary link that expires after a short time and cannot be reused by anyone else. Deleting a document removes both the file and its record. Like all data in NannyTank, your files are encrypted in transit and at rest; as with any online service, our operator and hosting provider have the technical access needed to run, secure and back up the service, and we do not look at your documents except where genuinely necessary to operate or support NannyTank, or where the law requires it.

7. Data retention and deletion

Your data is retained for as long as you have an account. To request deletion of your account and all associated data, email support@nannytank.co.za and we will remove it within 7 days.

8. Your rights (POPIA)

NannyTank is operated from South Africa and handles your personal information in line with the Protection of Personal Information Act (POPIA). You have the right to access the personal information we hold about you, to have it corrected, to object to its processing, and to request its deletion. Most of your information you can view and change directly in the app at any time; for access, correction, or deletion requests, email support@nannytank.co.za.

9. Third-party services

  • Supabase — database and authentication. Privacy policy
  • Vercel — app hosting. Privacy policy
  • Paystack — subscription payment processing. Privacy policy
  • Resend — transactional email (claim submissions, review notifications, and marketplace messages such as when someone contacts you or applies to your job). Privacy policy
  • Google — authentication and calendar access (optional). Privacy policy

10. Cookies and local storage

NannyTank does not use advertising or tracking cookies. We use your browser's local storage to remember small preferences on your device — such as your chosen theme (light or dark), whether you've seen the welcome walkthrough, and your employer's WhatsApp number for Quick Status. This information stays on your device.

11. Contact

For any privacy questions or data deletion requests, contact:
support@nannytank.co.za