Effective date: 1 July 2026
Meadow respects your privacy. This Privacy Policy ("Policy") describes the information we collect about you and how we use, process, share and protect it. It also explains your data protection rights.
Meadow Labs Limited, 7 Bearú Mhór, Cois Bhearú, Athy, Co. Kildare, R14 D363, Ireland, registered in Ireland with company number 812413 ("Meadow", "we", "us", "our"), is the entity responsible for the processing described in this Policy. We operate the website at meadowapp.ie and provide the Meadow services, meaning the Meadow childcare management platform, its web application and its app for iOS and Android. In this Policy we act as a controller for the personal data we collect, meaning we determine how and why it is used, and we process it in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Acts 1988 to 2018.
1. Who this Privacy Policy applies to
This Policy applies to you if you are a:
Customer or prospect. You represent a childcare service that uses Meadow, is trialling it, or is talking to us about it: enquiries, demos, calls, the contract, billing, and support.
Staff user of the Meadow services. You work for a childcare service that uses Meadow and have a Meadow login.
Parent user of the Meadow services. You are a parent, guardian or other family member of a child attending a childcare service that uses Meadow, and the service has invited you to Meadow.
Website visitor. You visit meadowapp.ie, read our blog or help pages, or use the contact form or waitlist.
When does this Policy not apply?
Everything a childcare service records inside Meadow about children, families and its own staff belongs to that service. The service is the controller of that data. We process it only on the service's instructions, as a processor, under the data processing agreement we have with the service. This Policy does not apply to that processing.
For information on how data is processed within the Meadow services on behalf of childcare services, including children's data, read How Meadow handles your childcare service's data, or speak directly with your childcare service.
2. Data we collect and how we collect it
The data we collect depends on how you interact with us, our website and the Meadow services. Most of it you give us directly; some we collect automatically; a little comes from third-party services such as Stripe.
Customers and prospects
| Interaction | Type of data | Data subjects |
|---|---|---|
| You enquire, book a demo, trial Meadow, or talk to us by email or video call. Provided directly by you. | Name, email, phone number, your role, the name and address of your service, and what we discussed. Demo and support calls on Google Meet are recorded and may be transcribed; we tell you at the start and you can ask us not to. | Owners and staff of prospects and customers |
| You become our customer. Provided by you or the Customer. | Name and email of the account owner and billing contact, the plan chosen, the billable-child count, invoices and payment status. Card details go directly to Stripe; we never see or store them. | Owners and staff of customers |
| Customer support and business interactions. Provided directly by you. | Your messages by email or through our support chat (Intercom), screenshots or screen shares you choose to send, and the account details needed to help you. | Owners and staff of customers |
| Marketing, when we start a newsletter. Provided by you. | Business contact details, whether you opened or clicked our emails, and your marketing preferences. We do not send a newsletter yet. | Owners and staff of prospects and customers |
Staff users and parent users
| Interaction | Type of data | Data subjects |
|---|---|---|
| You create or accept an invitation to an account. Provided by you or by the service that invited you. | Name, email, password hash or passkey, sign-in method (email, magic link or Google), email-verification and multi-factor status, profile picture, the services you belong to and your role in each, and invitations sent to you with their expiry. | Staff users and parent users |
| You use the Meadow services. Collected automatically. | Push-notification token, platform (iOS or Android), app environment, notification preferences, delivery and read state of notifications, IP address, browser or device type, request timestamps, session identifiers, rate-limit counters and error reports. | Staff users and parent users |
| Product analytics. Collected automatically, with your consent. | Pages and features used, event names and a pseudonymous identifier. Never the content of what you are viewing: session recording and screen capture are switched off. | Staff users and parent users |
| You send feedback. Provided by you. | Name, email and the content of your feedback. | Staff users and parent users |
Website visitors
| Interaction | Type of data | Data subjects |
|---|---|---|
| You browse meadowapp.ie. Collected automatically via necessary cookies and server logs. | IP address, browser type and version, device type, pages viewed, referring page, and the time and date of your visit. | Website visitors |
| You accept advertising cookies on meadowapp.ie. Collected automatically, only with your consent. | That your visit came from one of our advertisements. Not collected inside the Meadow platform. | Website visitors |
| You use the contact form or join the waitlist. Provided by you. | Name, email and your message; the email address you join the waitlist with. | Website visitors |
3. Why we collect your data
We process your data for the reasons below, on the legal bases shown.
| Who this applies to | Why we process your data | What this includes | Legal basis |
|---|---|---|---|
| Customers, prospects | To provide, manage and support the Meadow services and the business relationship | Running the trial, the subscription, the account and billing; invoicing and accounting records; answering enquiries and running demos; keeping notes of what we discussed. | Performance of our contract with you; legal obligation for tax and company records; steps at your request before a contract; our legitimate interests in running our business. |
| Customers, prospects | To record demo and support calls | Reviewing what was discussed and training our team. | Your consent, asked at the start of the call. If you decline, the call goes ahead unrecorded. |
| Staff users, parent users | To create and secure your login and deliver the service your childcare provider has chosen | Signing you in, letting you switch between services, sending invitations, sign-in codes and security alerts, and delivering the in-app, push and email notifications you are entitled to, honouring your preferences. | Performance of the terms of use you accept at sign-up. Where you have not entered into a contract with us, our legitimate interests in running the service your childcare provider has chosen, and yours in reaching it. |
| All groups | To keep Meadow secure and working | Abuse detection, rate limiting, bot protection, incident investigation, audit trails of who changed what, and fixing errors and outages. | Our legitimate interests in protecting the Meadow services and their users, including children. |
| Staff users, parent users | To understand how Meadow is used so we can improve it | Pseudonymised or aggregated usage data. Where this needs a non-essential cookie, we ask first. | Our legitimate interests in improving the Meadow services; consent for any non-essential cookie. |
| Customers, prospects | To engage in marketing | Sending business contacts information about Meadow, with an unsubscribe link in every message, once we start a newsletter. | Our legitimate interests in promoting Meadow to relevant business contacts; consent where the law requires it. |
| Website visitors | To measure our advertising | Seeing which advertisements bring childcare services to meadowapp.ie. Our website only, never the Meadow platform. | Your consent, given in the cookie banner and withdrawable at any time. |
| All groups | To use AI tools in our own operations | Drafting replies, summarising support conversations, and helping our engineers investigate a reported problem, which can involve production data. We use Anthropic's Claude and OpenAI's Codex and ChatGPT on business accounts whose terms bar the provider from using our inputs to train its models. | Our legitimate interests in operating efficiently, as long as your interests and fundamental rights do not override them. |
| All groups | To comply with legal obligations and to exercise or defend legal claims | Requests from public authorities, and protecting our operations and rights. | Legal obligation; establishment, exercise or defence of legal claims. |
We do not use your data for automated decisions that have legal or similarly significant effects on you. If we ever need to process your data on a different legal basis, we will explain it to you in a supplementary notice.
4. How we share your data
We may share your data with third parties in the following situations:
- Third-party service providers. We work with providers to host the Meadow services, send email and push notifications, take payments, report errors, and communicate with you. They process data only on our behalf and may not use it for their own purposes. They are listed in section 8.
- Business transfers. If Meadow is involved in a merger, acquisition or sale of assets, your data may be transferred to the new entity, and this Policy will continue to apply to it.
- Legal requirements. We may share your data where we believe in good faith that we must, to comply with law, regulation or an enforceable request from a public authority, or to protect our rights and property.
We do not sell or rent your data to anyone. We do not send data to the Early Years Hive, Pobal or the Department of Children, Disability and Equality; a childcare service enters or uploads its own funding returns.
We always have a written agreement with each provider covering how it processes data on our behalf and the security measures it must keep. Where data is transferred outside the EEA we take the further steps in section 5.
5. Data transfers
Our database, file storage, email sending and application hosting are in Ireland, and error reporting is in the EU. Some of our providers are headquartered in the United States and may access data from there to run or support their service, and our AI and workspace tools process data in the United States.
We do not transfer your personal data outside the EEA unless the transfer is adequately protected under the GDPR. We rely on one of the following safeguards, as applicable:
- the EU-U.S. Data Privacy Framework, where the provider is certified;
- the Standard Contractual Clauses approved by the European Commission Decision of 4 June 2021, as amended from time to time, together with a transfer impact assessment;
- other safeguards recognised by the GDPR, such as an adequacy decision.
You can ask us for a copy of the safeguards in place.
6. How long we retain your data
We do not keep your data longer than necessary for the purpose it was collected for, or as required by law. When we no longer have a valid reason to keep it, we delete it or anonymise it so that it no longer identifies you.
| Data | Retention |
|---|---|
| Customer contract, invoices and billing records | The life of the relationship, then 6 years after the end of the financial year, as Irish tax law requires |
| Prospect and sales notes | 2 years after our last contact |
| Demo and support call recordings | 12 months |
| Marketing list | While you are subscribed, then 2 years; a record that you unsubscribed is kept so we can prove we stopped |
| Your login and account | Until you delete it or it is removed from every service. Personal accounts can be deleted from account settings |
| Invitations | 90 days, then they expire and are cleared |
| Push tokens and device registrations | Removed when you sign out; unused registrations are ignored after 90 days |
| Notification history | 30 days |
| Error reports | 90 days |
| Support correspondence | 12 months after the matter closes |
| Security logs | 12 months |
| Cookies, and your choice about them | As set out in our Cookie Policy |
| AI tool inputs | Not used to train models; held by the provider only as long as its business terms allow |
How long a childcare service keeps its own records, and what happens when a service leaves Meadow, is explained on How Meadow handles your childcare service's data.
7. How we protect your data
The security of your personal data is very important to us. Every service's data is isolated by row-level security enforced in the database, so a query from one service cannot return another service's rows. Photos and files live in private storage and are served through signed, expiring links after a permission check. Data is encrypted in transit (TLS) and at rest. Access inside a service is role-based (owner, manager, senior practitioner, practitioner, parent), each role with a fixed set of permissions. Multi-factor authentication is available to every user. Destructive actions, such as deleting a child record, require a typed confirmation and a recorded reason. Records carry audit fields showing who changed what. Attendance records are append-only; corrections are recorded as new entries.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your data, we will inform the affected childcare service, the Data Protection Commission where required, and you where the risk to you is high.
8. Use of third-party providers
Like other software businesses, we use third parties to host the Meadow services, communicate with you, take payments and support you. We choose them carefully, share data with them only when necessary, and they may not use it for their own purposes. We use the following third parties:
- Supabase Inc. for our database, authentication and file storage, hosted in Ireland (AWS eu-west-1);
- Vercel Inc. to host the web application and run scheduled jobs, in Dublin, Ireland;
- BunnyWay d.o.o. (bunny.net), Slovenia, for video hosting and transcoding where a childcare service enables video in its newsfeed;
- Stripe Payments Europe Ltd. and Stripe Inc. for subscription billing and card and SEPA payments. Stripe may collect personal data, including transactional data and device information, to operate and improve its payment services, including fraud prevention. See Stripe's Privacy Policy;
- Resend Inc. to send transactional email such as invitations, sign-in codes and notifications, from Ireland (eu-west-1), and, in future, our newsletter;
- Expo (650 Industries Inc.), together with Apple Push Notification service and Google Firebase Cloud Messaging, to deliver push notifications to the Meadow app;
- Functional Software Inc. (Sentry) for error and crash reporting, in the EU data region. Session replay is switched off;
- PostHog Inc., EU cloud, for product analytics, with session recording and screen capture switched off;
- Cloudflare Inc. (Turnstile) for bot protection on public forms, where enabled;
- Google Ireland Ltd. (Google Workspace) for our email, calendar and Google Meet calls with customers, including call recordings and transcripts; and for "Sign in with Google" if you choose it, where Google is an independent controller for your Google account;
- Google Ireland Ltd. (Google Ads) to advertise Meadow to childcare services and measure whether those advertisements work, on meadowapp.ie only and only if you accept advertising cookies;
- Usercentrics A/S (Cookiebot), Denmark, for the cookie banner on meadowapp.ie;
- Intercom R&D Unlimited Company, Dublin, for support chat and our support inbox, on EU hosting;
- Anthropic Ireland Ltd. (Claude) and OpenAI Ireland Ltd. (Codex, ChatGPT), generative AI tools used by our engineers and our team to draft, summarise and investigate problems, on business terms that bar the provider from training on our inputs.
We use strictly necessary cookies and local storage to sign you in and remember your settings. We also use analytics cookies, and on meadowapp.ie advertising cookies, but only if you accept them in the cookie banner. No advertising cookie is ever set inside the Meadow platform. Our Cookie Policy explains each one and how to change your mind.
9. Your rights and choices
It is important to us that you know your data protection rights. You are entitled to the following:
- The right to access. You may request copies of your personal data.
- The right to rectification. You may ask us to correct information you believe is inaccurate.
- The right to erasure. You may ask us to erase your personal data, in certain circumstances.
- The right to portability. You may receive your personal data in a structured, commonly used and machine-readable format.
- The right to restrict and to object. You may ask us to restrict processing, and object to processing, in certain circumstances.
- Opt out of marketing. If you have agreed to receive marketing, you can unsubscribe at any time using the link in the email.
- Withdraw your consent. Where processing is based on your consent, you may withdraw it at any time, without affecting what was done before.
We will answer your request as soon as possible and in any event within one month. For a complex request we may take up to two further months and will tell you why. We may need to verify your identity, and we may decline a request that is manifestly unfounded or excessive, giving our reasons.
To exercise your rights, email us at james@meadowapp.ie.
For records a childcare service holds about you or your child, contact the service: it is the controller and must answer you. How Meadow handles your childcare service's data explains how.
10. Data protection contact
Matters relating to privacy and data protection at Meadow are handled by the company's director. You can reach us at:
Meadow Labs Limited 7 Bearú Mhór, Cois Bhearú Athy, Co. Kildare, R14 D363 Ireland james@meadowapp.ie
11. Contact and complaints
If you have any questions or concerns about this Policy or the processing of your personal data, contact us at james@meadowapp.ie.
You also have the right to lodge a complaint with the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, www.dataprotection.ie.
12. Children and our services
Our services and website are not directed at children. You may not use Meadow if you are under 18. Children's data enters Meadow only because a childcare service records it, as described on How Meadow handles your childcare service's data. We apply the Data Protection Commission's "Fundamentals for a Child-Oriented Approach to Data Processing" to how we build Meadow.
13. Changes to our Privacy Policy
We may update this Policy from time to time. The effective date is shown at the top. For significant changes we will notify the owners and managers of every customer service by email, using the address on their Meadow account. By continuing to use our website and services after a change takes effect, you accept the revised Policy.