Privacy & Data Safety
You trust us with sensitive financial information about your family. Here's exactly how we protect it and what we do — and don't do — with it.
What information we collect
To calculate your entitlements, NestWise asks for your combined household income, the number and ages of your children, the childcare fees and hours you pay, and your work or study hours per fortnight. For paid subscribers we also store your email address and billing details (handled securely by Stripe — we never see your full card number).
We do not collect your Tax File Number.
If you choose to use the secure document store, you can save identity documents — passport, Medicare card, driver's licence, concession card and similar — along with their numbers and expiry dates, so NestWise can remind you before they run out. That is yours to opt into, document by document. You can delete any of them at any time, and nothing is saved there unless you put it there.
When you photograph a card to save yourself typing, the image is read once and never stored. Only the fields you then confirm are kept.
How your data is stored
Your profile data is stored in Supabase, an enterprise-grade database platform built on PostgreSQL. All data is encrypted at rest and in transit using industry-standard AES-256 encryption. Supabase infrastructure is hosted in Australia (Sydney region) and is SOC 2 Type II certified.
We take reasonable steps to protect your personal information from misuse, interference, loss and unauthorised access. More detail is on our security page at /legal/security.
What we do with your data
Your data is used for one purpose: to calculate and display your childcare entitlement estimates. We do not use your data for advertising, profiling, or marketing to third parties.
We may use anonymised, aggregated data (for example, average CCS rates across income bands) to improve the product — but this data cannot be traced back to you or any individual family.
Who can see your data
Adelante Technologies staff can access your information where needed to provide, operate, maintain and improve NestWise, for example to help with a support request or to check that NestWise works properly. When staff view your account for these purposes, the view is read-only: they can't change anything. We do not share your data with Centrelink, the ATO, or any government body.
Our third-party service providers each have their own privacy and security certifications and only process the data required for their specific function. Current subprocessors:
• Supabase — database + storage (Sydney) • Vercel — application hosting (Sydney + Melbourne edge) • Stripe — subscription payments (PCI-DSS L1) • Resend / AWS SES — outbound transactional email • Anthropic — AI assistant for the /guides help (public guides only, no $ figures — see "In-app help and AI assistant") • Wych — bank connection via the Consumer Data Right (only when you explicitly connect an account; see "Bank connection (open banking / CDR)")
Your primary database sits in Supabase's Sydney region so your data stays in Australia.
Where your data lives
Your NestWise database, backups, and application logs are hosted in Australian data centres (Supabase Sydney region for the database; Vercel for the app, which serves Australian users from Sydney and Melbourne edge nodes). We operate under the Australian Privacy Principles (Privacy Act 1988) and treat your family's information with that standard as the floor, not the ceiling.
Some supporting services — payment processing (Stripe) and outbound transactional email delivery (Resend / AWS SES) — may transit briefly through overseas infrastructure. In every case only the minimum needed to complete that specific function is sent (e.g. a card number for Stripe, an email address for a receipt). Financial figures, entitlement amounts, and profile detail never leave the Sydney database in ordinary operation.
In-app help and AI assistant
When you're signed in, you can ask NestWise a question from the help menu. Answers are generated by our own AI assistant (Anthropic's Claude Haiku, called from our servers) trained ONLY on the public NestWise guides at /guides. It's not a third-party chatbot vendor — no Intercom, no Zendesk, no OpenAI ChatGPT sitting alongside your conversation.
The assistant runs under strict safety rules: it MUST cite the guide it's answering from, and any dollar figure or percentage in its answer is server-side validated to appear verbatim in that guide before we show it to you. If it can't answer safely, it escalates to a human at hello@nestwise.net.au.
We DO NOT send your income, your ATI, your entitlement amounts, or any dollar figure from your profile to the AI assistant — the same data discipline the rest of the product uses. What the assistant sees is your question plus the relevant public guides, nothing more.
Every question is logged to our own database (guide_questions table) so we can improve the guides. Questions are stored in Australia alongside the rest of your data and are never sold or shared.
Bank connection (open banking / CDR)
Some NestWise features (bank transaction categorisation, cashflow "actual vs planned", CSV imports) rely on transactions from your bank accounts. When bank connections arrive, they'll run through Wych, a specialist that's accredited under Australia's Consumer Data Right (CDR). That's the government-backed system that lets banks share your information safely, and only with your say-so. NestWise works under Wych's accreditation as its CDR representative, so we follow the same strict rules on consent, security and deletion. You choose which accounts to share, you can switch it off at any time, and we never see your banking password.
You will only connect a bank account after an explicit, scoped, revocable consent screen at /consent/bank-connection which tells you exactly which accounts are read, which data is collected, how long we keep it, and how to switch it off. Consent is per-connection, time-boxed, and revoking it stops future collection immediately.
What we DO with bank data: categorise transactions (utility / groceries / etc), reconcile against your planned budget, and surface deductions you might have missed at tax time. What we DON'T do: sell it, share it with lenders, initiate payments on your behalf, or make lending decisions for you.
Bank transaction data stays in the same Sydney-region Supabase database as the rest of your profile, with the same owner-only Row-Level Security. When a bank connection ends (you disconnect it, withdraw consent at your bank, or it expires), we delete the transactions it brought in, and anything worked out from them, within 24 hours. Statements you upload yourself follow the retention and delete-on-request rules described in "Your rights".
Payments and billing
Subscription payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. NestWise never stores or sees your full credit card number. Stripe handles all payment data in accordance with the highest level of payment security standards.
Your rights
You can export or delete your NestWise account and all associated data at any time by emailing hello@nestwise.net.au. We will process deletion requests within 7 business days; the full purge (including backups) completes within 90 days.
For the specific retention window by data category (profile, bank transactions, inbox attachments, audit logs, backups etc.), see our full data retention schedule at /legal/data-breach-response.
You can also update or correct any information stored in your profile at any time from the Profile page.
If something goes wrong (data breach response)
If a data breach affects your NestWise data, we commit to move faster than the Privacy Act ceiling: contain within 24 hours, initial assessment within 72 hours, affected-user email within 7 days, OAIC notification within 30 days where required, and a public post-mortem within 60 days.
We deliberately don't store your Tax File Number or your full payment card number — for those, the best defence is not to hold the data at all.
Identity documents are different: the secure document store exists precisely so you can keep them, and it is opt-in per document. That means we do hold them for people who use it, so they are covered by everything on this page — encrypted at rest and in transit, row-level security, and deleted when you delete them.
Full commitment (with the exact windows + what we tell you): /legal/data-breach-response. Suspected an incident? Email hello@nestwise.net.au with "Suspected data incident" in the subject — we respond within 24 hours.
Cookies and analytics
NestWise uses THREE kinds of analytics, all kept minimal and all first-party unless explicitly noted.
1. First-party product analytics: a small events table on our own database that records which calculators you opened and which signup steps you completed. We use this to fix bugs and decide what to build next. The events we record only ever capture the event NAME plus a few non-sensitive properties (e.g. which tool was opened, which signup step). They NEVER capture income, ATI, entitlement amounts, or any dollar figure — the /api/track route strips these defensively server-side.
2. First-party signup attribution: on your first visit we set a cookie called "nw_first_touch" recording where you arrived (the page URL you landed on, the previous site that linked to you if there was one, any utm_* / gclid / fbclid tags on the URL, your browser type + language + timezone, viewport size, and country/region/city from our edge network). At signup we save that snapshot on your account row so we can see which pages and campaigns bring people who convert vs bounce. It is stored on our own database, never shared with third parties, never combined with your financial data for advertising purposes, and never sold. You can delete the cookie at any time from your browser settings (Preferences → Cookies → find nestwise.net.au); doing so simply means we can't attribute your session, everything else keeps working.
3. Google Analytics: we use Google Analytics 4 to measure aggregate visitor traffic to our marketing pages (homepage, calculators, guides). It records standard browser-level signals — country, device type, the page URLs you opened, the source you arrived from. We have IP anonymisation enabled and advertising features turned off. Google Analytics does NOT receive any income, entitlement, or dollar figures from NestWise. You can opt out of GA tracking by installing Google's official browser opt-out (https://tools.google.com/dlpage/gaoptout) or by enabling Do Not Track in your browser.
Time zone: we also set a small cookie called "nw_tz" holding the time zone your device reports (for example Australia/Perth). It is not analytics. It lets us show today's date, days left and due dates in your own time rather than our servers' time. If it is missing we use the state in your profile, then Sydney time.
We do NOT use Meta Pixel or any other third-party advertising tracking script. The home and about pages can show a few of our Instagram posts. Nothing from Instagram loads until you tap "Show posts"; after that, Instagram (owned by Meta) serves those posts and may set its own cookies under its own privacy policy. Your choice to show them is remembered only on your device. We use session cookies required for authentication; no advertising cookies, no cross-site tracking beyond GA's standard measurement.