Privacy

Privacy policy

How CareSolve handles personal information across the web application, the CareSolve Carer app, and the family and client portals.

Effective 11 August 2026

About this policy

CareSolve is a care management platform used by UK home care providers. This policy explains what personal information we handle, why we handle it, and what rights you have. It covers the CareSolve web application at caresolve.co.uk, the CareSolve Carer mobile app, and the family and client portals.

CareSolve is operated by CareSolve Ltd, a company registered in England and Wales. Our full registered company details are available on request from the contact address at the end of this policy.

Our two roles

The role we play under UK data protection law depends on whose information is involved, and this determines who you should contact about it.

As a processor
For the care records inside a provider's account — client records, care plans, medication charts, visit notes, incidents, and staff files — the care provider is the data controller and decides how that information is used. We process it on their documented instructions. If you are a person receiving care, a family member, or a member of care staff, the provider is your first point of contact.
As a controller
For information about the provider's own relationship with us — account and billing details, the identities of administrators who sign up, support correspondence, and the security logs we keep to protect the service — we are the data controller.

Information we process

The categories below reflect what the platform actually stores. Not every provider uses every module, so not all of it will apply to a given account.

Account and access data
Names, work email addresses, roles and permissions, branch assignments, password hashes, and optional two-factor authentication settings.
Care recipient records
Contact and address details, admissions and discharges, care plans and preferences, next of kin and family contacts, consents, funding and contract arrangements, referrals, and case notes.
Health and care delivery records
Visit records including check-in and check-out, care tasks, medication administration (eMAR) including controlled drug records, body maps and visit photographs, incidents, safeguarding referrals, complaints, and quality audits.
Care staff records
Employment and contract details, right to work checks, certifications and competencies, training, supervisions and appraisals, references, availability, timesheets, leave, expenses, and payroll inputs.
Communications
Messages exchanged in the platform between office staff, care workers, and family portal users, along with announcements and family updates.
Security and audit data
Sign-in attempts and account lockouts, audit logs of changes to records, document access logs, portal session records, and logs of any administrator impersonation. These exist so that actions can be traced and are deliberately difficult to alter.
Billing data
Subscription and plan information. Card payments are handled by Stripe and card numbers never reach our systems.

The CareSolve Carer app

The CareSolve Carer app is issued by a care provider to its own care workers. It is not a consumer app and cannot be used without an account created by an employer. It handles some device data that the web application does not.

Location
Location is read only while the app is open and only at the moment a care worker checks in to or out of a visit, so that attendance can be evidenced. The app does not track location in the background and does not follow staff between visits.
Camera and photos
Used only when a care worker chooses to attach a photograph to a visit record or body map. Images are attached to the relevant care record and are visible to that provider's authorised staff.
Biometric unlock
If enabled, fingerprint or face unlock is verified by the device's own operating system. Biometric data is never transmitted to us and we never receive or store it.
Push notifications
A device push token is stored so that shift and visit notifications can be delivered. Notifications are routed through Expo's push service.
On-device storage
Sign-in tokens are held in the device's secure keystore, and some visit data is cached locally so the app remains usable on a poor connection. Signing out clears this.

Health data and lawful bases

Care records include health information, which UK GDPR treats as special category data requiring extra protection. Where we act as a processor, the care provider is responsible for identifying its lawful basis and its Article 9 condition, which for care delivery is typically the provision of health or social care under Article 9(2)(h).

Where we act as a controller, we rely on the performance of our contract with the provider to deliver and administer the service, our legitimate interests in keeping the service secure and in supporting our customers, and compliance with our own legal obligations.

Cookies

We use strictly necessary cookies only. These hold your signed-in session and keep it secure — hc_session for the main application, hc_portal_session for the family and client portal, and hc_platform_session for platform administration.

We do not use advertising cookies, and we do not embed third-party analytics, tracking pixels, or session-recording tools in the application.

Who we share information with

We do not sell personal information and we do not share it for advertising. We share it only with service providers who help us run the platform, each bound by contract to protect it and to use it only for the purpose we specify.

Vercel
Application hosting and content delivery.
Supabase
Database and document storage.
Stripe
Subscription billing and card payment processing.
Expo
Delivery of push notifications to the carer app.
Microsoft 365 (Exchange Online)
Delivery of transactional email such as invitations, password resets, and notifications.

A care provider may also choose to export data from its own account — for example payroll or invoice exports to its finance system. Those exports are made on the provider's instruction and under its control. We may also disclose information where we are legally required to do so.

Where information is stored

The application runs in Vercel's London (lhr1) region. Our database and uploaded documents are held with Supabase, and transactional email is handled by Microsoft 365.

Some of the providers we use may process information outside the UK. Where that happens, the transfer is governed by the data protection terms of our agreement with that provider, which incorporate the transfer safeguards required by UK data protection law. You can ask us for details of the arrangements that apply to a particular provider.

How long we keep information

The platform includes configurable retention rules, so a care provider can set how long each category of record is kept in line with its own regulatory obligations. Adult social care records generally have to be retained for a significant period after care ends, and providers should set their rules accordingly.

Where we are the controller, we keep account and billing records for as long as the provider's account is open, and afterwards for as long as we need them to meet our legal, accounting, and tax obligations. Security and audit logs are kept for as long as they remain useful for investigating security incidents and for meeting those same obligations.

When a provider closes its account, we delete or return its data, other than anything we are required to retain by law. We are happy to confirm the specific periods that apply to your account on request.

How we protect information

Security measures in the platform include the following. No system can be guaranteed completely secure, but these are the controls the product is built around.

  • Every account is separated from every other, and requests are scoped to the signed-in user's own organisation and branch.
  • Access is role-based, so staff reach only the records their role requires.
  • All traffic is encrypted in transit using HTTPS.
  • Optional two-factor authentication on user accounts.
  • Sign-in attempts are rate limited and accounts lock after repeated failures.
  • Changes to sensitive records are written to audit logs, and document access is logged.
  • Administrator impersonation, where used for support, is recorded.

Your rights

Under UK data protection law you have the right to ask for a copy of your personal information, to have inaccurate information corrected, to ask for erasure or restriction in certain circumstances, to object to processing based on legitimate interests, and to receive certain information in a portable form.

If your information is held in a care provider's account — which is the case for people receiving care, their families, and care staff — please contact that provider directly. They control those records and decide how requests are handled. We will support them in responding.

For information we hold as a controller, contact us using the details below. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to resolve matters first.

Children's information

The CareSolve applications are intended for use by care provider staff and authorised family contacts, and are not directed at children. Where a care provider delivers services to a person under 18, records about that person are processed on the provider's instructions and under its own safeguarding policies.

Changes to this policy

We may update this policy as the platform develops. The effective date at the top of this page shows when it last changed, and we will tell account administrators about material changes.

Contact us

For privacy questions, to exercise your rights over information we hold as a controller, or to request our registered company details, email privacy@caresolve.co.uk.

If you are unhappy with how we have handled your information, you can complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to put things right first.