Privacy Policy
Last updated 12 June 2026
We are Please Check On ("we", "us"). We connect families with local helpers who check in on elderly or vulnerable people. Because of what we do, we take privacy unusually seriously β some of the information on this platform concerns people who may not use it themselves.
If you have any questions about this policy, including requests to exercise your legal rights, contact us at hello@pleasecheckon.com.
What data do you collect, and why?
- Your account. When you register we collect your name, email address and phone number so we can create your account and enter into a contract with you.
- Helper profiles. If you register as a helper we additionally collect your postcode, a photo, an optional video introduction, your skills, languages, experience, and confirmations of your right to work and any first-aid certification. We collect this so families can choose a suitable, trustworthy helper, and so we can verify helpers before they appear on the platform.
- People being checked on (recipients). Families tell us the first name, approximate location and relevant details of the person to be visited β which may include health or mobility notes the family chooses to share. This may be information about someone who never uses our website. We process it solely so that the requested visits can take place safely, and we ask families only to share what a helper genuinely needs to know.
- Visit updates and messages. Helpers write a short update after each visit, and families and helpers can message each other. We store these so there is a clear record of every visit.
- Payments. Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers. Helpers' identity and bank details for payouts are collected by Stripe under Stripe's own privacy policy; we only see whether verification succeeded.
- Contacting us. If you email us we keep your name, contact details and message so we can respond properly β it's in our legitimate interest to do so.
- Technical data. IP address and browser details at the time of requests, used for security and abuse prevention β for example rate-limiting sign-in, sign-up and password-reset attempts.
Analytics β no cookies, no tracking
We use Umami, a privacy-first analytics tool, to understand how our website is used. Umami is cookieless: it sets no cookies, stores nothing on your device, collects no personal information, and cannot follow you across other websites. It shows us anonymous, aggregated counts β like how many people visited a page β and nothing about you as an individual. Because of this, we don't need to interrupt you with a cookie consent banner for analytics.
The only cookies we use are strictly necessary ones: keeping you signed in, remembering your country choice, and protecting forms against forgery. These don't track you and don't require consent under UK law.
Who do you share my data with?
- Between users, as the service requires. Families see helper profiles; an accepted helper sees the visit details the family provided. We never show helpers a recipient's full address until a booking is confirmed.
- Service providers who help us run the platform, each processing data only on our instructions:
- Stripe β payments and helper payouts (see above).
- Amazon Web Services (Frankfurt, EU) β sending transactional email such as password resets and visit notifications.
- Cloudflare β content delivery and hosting of helper video introductions.
- Hetzner (Germany, EU) β server hosting.
- Sentry (EU) β error monitoring. When something breaks, Sentry receives the technical details of the error. We have configured it not to receive personal data such as names, emails or message content.
- postcodes.io β UK postcode lookup, used to match helpers with nearby requests. Only the postcode itself is sent β no name or other identifier β and results are cached to minimise lookups.
- Regulators, authorities or enforcement agencies if we are under a legal duty to do so, to enforce our terms, or to protect the rights or safety of our users β including safeguarding referrals where we believe someone is at risk.
- A buyer of our business, under our legitimate interest in the business being able to continue. You can object to this by contacting us.
We never sell your personal data.
How we protect your account
- Encryption in transit β the site is HTTPS-only.
- Passwords are stored only as bcrypt hashes β we never see or store your plain-text password.
- Card and bank details are handled entirely by Stripe and never touch our servers.
- Brute-force protection β repeated failed sign-ins lock the account temporarily, and sign-in, sign-up and password-reset endpoints are rate-limited.
- Browser-level protection β a strict Content Security Policy limits what code can run on our pages, defending against script injection.
Where is my data stored?
Our servers are in the EU (Germany), and our email and payment providers process data in the UK and EU. Where any provider transfers personal data outside the UK or EU, we ensure it receives the additional protection required by UK law (such as adequacy decisions or standard contractual clauses). Contact us for details of the specific safeguards.
How long do you keep my data?
We keep personal data only as long as we need it. Records of bookings and payments are kept for 6 years to meet our legal and accounting obligations. Other account information is deleted 2 years after your account becomes inactive, or sooner if you ask us to delete it. We may carefully anonymise data so it can no longer identify anyone, and use that anonymised information to improve the service.
What are my rights?
Under UK data protection law you have the right to:
- access the personal data we hold about you (a "subject access request");
- correct incomplete or inaccurate data;
- ask us to erase your personal data;
- ask us to restrict how we handle it;
- ask us to transfer it to a third party;
- object to how we are using it; and
- withdraw any consent you have given.
These rights aren't absolute and won't always apply, but if you contact us we'll explain honestly what we can do. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.
A note on information about others
If you give us information about another person β such as a relative you'd like checked on β please make sure you're entitled to share it and, wherever possible, that they know about it. If you are a recipient (or act for one) and want to know what information is held about you, contact us and we will help.
Changes to this policy
If we make material changes we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email.