Introduction
WardOrbit Ltd ("WardOrbit", "we", "us", or "our") is a technology company registered in England and Wales. We develop and operate the WardOrbit family safety platform, which enables parents and guardians to monitor device usage, manage screen time, and ensure the online safety of children in their care.
We are committed to protecting your privacy and handling your personal data with transparency, integrity, and in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR 2016/679).
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have in relation to it. It applies to all users of our website, mobile applications, and associated services (collectively, the "Service").
By using WardOrbit, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Service.
Information We Collect
We collect personal data in the following categories:
Account Data
When you register for a WardOrbit account, we collect your full name, email address, a hashed password, and your country of residence. If you create child profiles, we collect the child's first name and date of birth (to determine appropriate content settings).
Waitlist Data
If you join the WardOrbit waitlist, we collect your email address, IP address, the date and time of signup, and — if you arrived via a referral link — the referral code used. Your IP address is collected solely for fraud prevention and queue integrity purposes (e.g. detecting duplicate or bot signups). It is not shared with third parties for marketing purposes and is retained only for the duration of the waitlist period.
Usage Data
As you use the Service, we automatically collect information about your interactions, including pages visited, features accessed, session duration, buttons clicked, and error events. This data is used in aggregate or pseudonymised form to improve the product.
Device Data
We collect information about the devices registered to your account, including device model, operating system version, app version, and a unique device identifier. For child devices, we additionally collect application usage data (app names, usage durations) as this is core to the Service's functionality.
Location Data
Location data for child devices is collected only when you explicitly enable location features within your parental account. Location is not collected passively or without a parent's active configuration. Real-time and historical location data is encrypted end-to-end and visible only to the account holder.
Payment Data
If you subscribe to a paid plan, payment transactions are processed by our payment processor, Stripe, Inc. We do not store your full card number, CVV, or bank account details on our systems. We retain only a tokenised reference and billing metadata (subscription tier, renewal dates, invoice records) as required for financial record-keeping.
Communications Data
When you contact our support team, we retain the contents of those communications, your email address, and any attachments, for the purpose of resolving your enquiry and improving our support quality.
How We Use Your Data
We use the personal data we collect for the following purposes:
- Service Delivery: To create and manage your account, provision child profiles, enforce screen time rules, deliver real-time alerts, and provide all core features of the WardOrbit platform.
- Safety Monitoring: To analyse device activity and generate safety reports visible to the parent or guardian. This is the primary purpose for which child device data is collected.
- Product Improvement: To understand how users interact with WardOrbit, identify bugs, prioritise features, and conduct A/B testing using anonymised or aggregated usage data.
- Customer Support: To respond to enquiries, troubleshoot technical issues, and process refund or account requests.
- Communications: To send transactional emails (account creation, password resets, subscription confirmations) and, where you have consented, product updates and newsletters. You may unsubscribe from marketing emails at any time.
- Legal Compliance: To comply with legal obligations, including responding to lawful requests from courts or regulatory authorities, and to enforce our Terms of Service.
- Fraud Prevention & Security: To detect, investigate, and prevent fraudulent transactions, unauthorised access, and other malicious activity.
We will not use your personal data for purposes that are incompatible with those listed above without providing notice and, where required, obtaining your consent.
Legal Basis for Processing
Under the UK GDPR and EU GDPR, we must have a lawful basis for processing your personal data. The bases we rely on are as follows:
- Contract (Article 6(1)(b)): Processing necessary to perform the contract with you — including account creation, subscription management, and service delivery.
- Legitimate Interests (Article 6(1)(f)): Processing that is in our legitimate interests (or those of a third party), provided those interests are not overridden by your rights. This includes security monitoring, fraud prevention, and product analytics where data is anonymised or pseudonymised.
- Legal Obligation (Article 6(1)(c)): Processing required to comply with applicable law, such as retaining billing records or responding to lawful regulatory requests.
- Consent (Article 6(1)(a)): Where we rely on consent, for example, for marketing emails or the collection of child location data, you may withdraw that consent at any time via your account settings or by contacting us.
- Special Category / Child Data: Where processing relates to children's data, we additionally rely on explicit parental consent as required under Article 8 of the GDPR and the UK Children's Code.
Data Sharing
We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes. We share data only in the following limited circumstances:
- Infrastructure Providers: We use cloud hosting services (Amazon Web Services and Google Cloud Platform) to store and process data securely. These providers act as data processors under binding Data Processing Agreements.
- Payment Processing: Stripe, Inc. processes payment transactions on our behalf. Stripe is certified to PCI DSS Level 1, the highest level of payment security. Please refer to Stripe's own privacy policy for information on their data practices.
- Analytics (Anonymised): We use privacy-preserving analytics tools to understand aggregate usage patterns. No personally identifiable information is shared with analytics providers; data is aggregated or irreversibly anonymised before transmission.
- Customer Support: Our support platform (used solely for ticket management) may process your name and email address when you contact us. Support agents are bound by confidentiality obligations.
- Legal Requests: We may disclose personal data to law enforcement, courts, or regulatory authorities where required by law or where we believe disclosure is necessary to protect the safety of any person or to prevent a crime.
Any third-party processors we engage are subject to contractual obligations consistent with the UK GDPR and must implement appropriate technical and organisational security measures.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law.
- Active Accounts: Account data and child profile data are retained for the duration of your active subscription.
- Post-Deletion: When you delete your account or child profile, data is soft-deleted immediately (no longer accessible via the Service) and permanently erased from all systems within 30 days.
- Billing Records: Financial records (invoices, payment history) are retained for 7 years in accordance with UK financial regulation, even after account deletion.
- Support Communications: Support ticket records are retained for 2 years after resolution.
- Usage Logs: Aggregated and anonymised usage logs are retained indefinitely for product analytics. Pseudonymised logs are deleted within 12 months.
- Security Logs: Login and security event logs are retained for 90 days.
You may request early deletion of your personal data by exercising your right to erasure (see Section 7).
Your Rights
Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
- Right of Access (Article 15): You may request a copy of the personal data we hold about you, including information about how it is processed.
- Right to Rectification (Article 16): You may request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to Erasure (Article 17): You may request that we delete your personal data in certain circumstances, such as where the data is no longer necessary for the purpose for which it was collected.
- Right to Data Portability (Article 20): You may request a machine-readable copy of personal data you have provided to us, where processing is based on consent or contract.
- Right to Object (Article 21): You may object to processing based on legitimate interests, including profiling, or to direct marketing at any time.
- Right to Restrict Processing (Article 18): You may request that we restrict processing of your data in certain circumstances.
- Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please submit a request to [email protected]. We will respond within one calendar month. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
Children's Privacy
WardOrbit is designed for use by parents and guardians and is not directed at children. Parent or guardian accounts require the user to be aged 18 or over.
Child profiles created within a parent account involve the processing of a minor's personal data. We process this data under the lawful authority of the parent or guardian who holds the account, and on the basis of parental consent. We comply with:
- The UK Children's Code (Age Appropriate Design Code)
- GDPR provisions on children's data (Article 8)
- The Children's Online Privacy Protection Act (COPPA) for users in the United States
We collect only the minimum data necessary for each child profile. Child data is never used for marketing, advertising, or shared with third parties beyond the processors listed in Section 5. Parents may view, modify, or delete all child profile data at any time from within their account.
If you believe a child profile has been created without proper parental consent, please contact us immediately at [email protected].
Cookies
WardOrbit uses cookies and similar technologies to operate the Service, remember your preferences, and understand how our product is used. Cookies are categorised as follows:
- Essential: Required for the Service to function (session management, CSRF protection). These cannot be disabled.
- Analytics: Used to collect anonymised usage data to improve the product.
- Functional: Used to remember preferences such as your chosen theme and language.
- Marketing: Used for personalised advertising on partner networks. These are off by default and require your explicit consent.
You can manage your cookie preferences at any time on our Cookie Settings page.
Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, or destruction. Our security programme includes:
- Encryption at Rest: All personal data stored on our systems is encrypted using AES-256.
- Encryption in Transit: All data transmitted between your devices and our servers uses TLS 1.3.
- Access Controls: Access to personal data is restricted to authorised personnel on a need-to-know basis. All access is logged and audited.
- SOC 2 Type II: Our infrastructure providers maintain SOC 2 Type II certification, demonstrating ongoing security controls.
- Penetration Testing: We conduct independent penetration tests annually and remediate findings promptly.
- Vulnerability Disclosure: We operate a responsible disclosure programme. Security researchers may report vulnerabilities to [email protected].
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected users without undue delay, in accordance with Article 33 and 34 of the UK GDPR.
International Transfers
WardOrbit is headquartered in the United Kingdom. Some of our service providers (including AWS and Stripe) operate data centres globally, which may result in your personal data being processed outside of the UK or European Economic Area (EEA).
Where personal data is transferred to countries that do not provide an equivalent level of data protection, we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs): As adopted by the European Commission and incorporated into our UK GDPR-compliant transfer mechanisms (UK International Data Transfer Agreements, IDTA).
- Adequacy Decisions: Where the UK or European Commission has determined that a third country provides an adequate level of protection.
- Binding Corporate Rules: Where applicable for intra-group transfers.
You may request a copy of the relevant transfer safeguards by contacting [email protected].
Contact & DPO
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us:
- Data Protection Officer (DPO): [email protected]
- General Enquiries: [email protected]
- Postal Address: WardOrbit Ltd, Data Protection, 123 Digital Quarter, Birmingham, B1 1AA, United Kingdom
We will acknowledge your request within 5 business days and respond fully within one calendar month. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will inform you.
You also have the right to complain to the Information Commissioner's Office (ICO) if you believe we have not handled your personal data lawfully:
- Website: ico.org.uk
- Helpline: 0303 123 1113
We periodically review and update this Privacy Policy. When we make material changes, we will notify you via email or a prominent notice within the Service prior to the changes taking effect. Your continued use of the Service after such notice constitutes your acknowledgement of the updated policy.