top of page
Logo.png

Privacy Policy

Effective date: 3 June 2026 · Last updated: 3 June 2026

My Funding Whizz (“we”, “our”, “us”) is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store and protect personal data when you use the My Funding Whizz mobile application (“App”) and website.

1. Who we are

My Funding Whizz is a United Kingdom childcare funding management platform that helps registered childminders and parents/guardians prepare, complete, and manage early-years funding declarations and related records.

The data controller responsible for your personal data under UK data protection law is:

My Funding Whizz (trading name)


Elmacneice Limited


Email: Support@myfundingwhizz,co,uk
Website: www.myfundingwhizz.co.uk

2. Scope

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the choices and rights available to you.

By creating an account, using the app, or otherwise using the Services, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Services.

Our Terms of Use govern your use of the Services and should be read together with this policy.

3. Information we collect

We collect only the information needed to operate the Services. The categories below reflect our current product behaviour.

3.1 Account and identity data

We may collect the following account and identity information:

• Email address and password (passwords are stored in hashed form on our servers)
• First and last name
• Date of birth and gender
• Mobile number
• Childminder registration/reference code, where applicable
• Your role, such as childminder or parent
• Postal addresses linked to your account
• Email verification status and secure verification information

3.2 Child and family records

Childminders and authorised users may enter information about children for whom funding declarations are prepared, including:

• Child’s first and last name, date of birth and gender
• The link between a child record and a parent/guardian account
• Operational information, such as who created or last updated a record and when

Sensitive personal data may appear within declaration forms, for example disability or access-related funding information, where you or the parent choose to provide it as part of a Local Authority funding process.

3.3 Declaration and document data

We collect and process information relating to funding declarations and documents, including:

• Funding declaration form responses, calculations, term dates and workflow status
• Electronic signatures captured in the app
• Generated PDF documents and related audit/history records
• Local draft data temporarily stored on your device until submitted or cleared

3.4 Payment and billing data (childminders)

We collect and process limited payment and billing information, including:

• Credit balance, purchase history and ledger entries within our platform
• Stripe customer identifier and checkout session references

We do not store full payment card numbers. Card payments are processed by Stripe. Stripe’s privacy notice applies to payment data you provide during checkout.

3.5 Communications and invitations

We collect and process information relating to communications and invitations, including:

• Parent invitation tokens, invitation status and related email/deep-link activity
• Transactional emails, such as verification codes, invitations and service messages, where email delivery is enabled

 

3.6 Device and technical data

We collect limited device and technical information needed to operate and secure the Services, including:

• Firebase Cloud Messaging (FCM) device tokens — to deliver push notifications you have agreed to receive
• Authentication tokens — to keep you signed in securely
• App preferences — non-sensitive settings stored locally on your device
• Server logs — including IP address, request timestamps, API paths and error diagnostics, for security and reliability

3.7 Information we do not collect

Unless you voluntarily include it in a form field, we do not collect:

• Precise GPS or continuous location tracking
• Photos, videos or microphone recordings from your device
• Contacts from your address book
• Health data from Apple Health or similar platforms
• Advertising identifiers for cross-app tracking
• Biometric data (beyond a drawn signature you provide in-app)

4. How we collect information

We collect information:

• Directly from you when you register, complete your profile, enter addresses, create child records, complete declarations, sign forms, purchase credits or contact support
• From other authorised users where their role allows, for example when a childminder creates a parent invitation or child record linked to your account
• Automatically when you use the app, for example API requests, session tokens, push token registration and server logs
• From Stripe when you complete a payment, such as payment status and customer references — not full card details

5. How we use information

We use personal data to:

• Provide, maintain and improve the Services
• Create and manage user accounts and authenticate users
• Enable childminders and parents to collaborate on funding declarations
• Generate, store and export declaration documents, including PDFs
• Process credit purchases and maintain billing records
• Send service-related emails and push notifications, where enabled
• Protect against fraud, abuse and security incidents
• Comply with legal obligations and respond to lawful requests
• Enforce our Terms of Use and protect our rights

We do not sell your personal data. We do not use your data for third-party behavioural advertising.

6. Legal bases (UK GDPR)

Where UK GDPR applies, we rely on the following legal bases:

• Providing the Services under your account — Performance of a contract (Article 6(1)(b))
• Security, fraud prevention and service logs — Legitimate interests (Article 6(1)(f)), balanced against your rights
• Legal and regulatory compliance — Legal obligation (Article 6(1)(c))
• Marketing communications (if ever offered) — Consent (Article 6(1)(a)), with the option to withdraw consent at any time
• Optional special-category data in declarations — Your explicit consent and/or substantial public interest or statutory purposes, as applicable to the funding process, and only where you provide such data

7. Sharing and processors

We share personal data only as described below. Our processors act on our instructions and must protect your data.

7.1 Service providers

• Stripe Payments Europe, Ltd. (and affiliates) — Payment processing for credit purchases. Stripe receives the information needed for checkout, payment status and billing. Card data is handled by Stripe.

• Google Firebase (Cloud Messaging) — Used to deliver push notifications. This may include your FCM device token and notification-related information.

• Google Cloud Platform (GCP) — Used for hosting, storage, encryption key management and infrastructure. Data you submit to the Services is stored and processed within our cloud environment.

• Email delivery providers — Where configured, these are used to send transactional emails and may process your email address and the content of service emails.

Firebase is used for push messaging only in our app — not for third-party advertising analytics.

7.2 Other disclosures

We may also disclose information:

• To Local Authorities or funding bodies only when you choose to submit or export declarations outside our platform, or as required by applicable funding rules you follow
• To professional advisers, such as lawyers and accountants, under confidentiality obligations
• To law enforcement or regulators when required by law or to protect rights, safety and security
• In connection with a merger, acquisition or asset sale, subject to appropriate safeguards

8. International transfers

Our primary systems are intended for users in the United Kingdom. Some processors, including Google and Stripe, may process data in the UK, EEA, United States or other countries.

Where personal data is transferred outside the UK, we implement appropriate safeguards such as the UK International Data Transfer Agreement, UK Addendum to EU Standard Contractual Clauses, or equivalent mechanisms recognised under UK law.

9. Data retention

We keep personal data only for as long as necessary for the purposes described in this policy, including:

• Active accounts: for the duration of your account and legitimate business needs
• Declarations and audit records: as needed for operational history, dispute resolution and legal obligations relating to funding records you create
• Billing records: as required for tax, accounting and financial regulations — typically up to six years in the UK unless a longer period is required
• Security logs: for a limited period appropriate to security monitoring
• Deleted or deactivated accounts: we apply soft-delete or erasure processes; residual backups may remain for a limited time before automatic purging

When data is no longer needed, we delete or anonymise it in accordance with our retention procedures.

10. Security

We implement technical and organisational measures designed to protect personal data, including:

• Encryption of sensitive personal data at rest, including names, dates of birth and similar fields, using industry-standard encryption
• Encryption in transit (HTTPS/TLS) for communications between the app and our servers
• Hashed storage of passwords and one-time verification codes
• Access controls, authentication and role-based permissions
• Infrastructure hosted on Google Cloud with managed key services where configured

No method of transmission or storage is completely secure. Please use a strong, unique password and keep your device secure.

11. Your rights

If you are in the UK, or where UK GDPR applies to our processing, you have the right to:

• Access — request a copy of personal data we hold about you
• Rectification — ask us to correct inaccurate or incomplete data
• Erasure — ask us to delete your data in certain circumstances
• Restriction — ask us to limit processing in certain circumstances
• Data portability — receive certain data in a structured, commonly used format
• Object — object to processing based on legitimate interests
• Withdraw consent — where processing is based on consent, without affecting prior lawful processing

To exercise these rights, email Support@myfundingwhizz.co.uk. We may need to verify your identity before responding. We aim to respond within one month, as required by law.

12. Account and data deletion

You may request deletion of your personal profile data through the app, where available, or by contacting us at Support@myfundingwhizz.co.uk.

Deletion options may include:

• Removing your extended profile details via in-app account settings or API features
• Requesting full account closure — we will guide you through any impact on active declarations, credits and linked parent/child records

Some information may be retained where we have a legal obligation or overriding legitimate interest, for example financial records, fraud prevention or dispute resolution. We will explain any retention that applies to your request.

Apple App Store users: You may also delete your account by contacting us at the email above if in-app deletion is not yet available. We will honour deletion requests in line with App Store requirements.

13. Children’s information

My Funding Whizz is not directed at children under 13 (or under 16 where applicable) to use as account holders. Accounts must be created by adults — childminders or parents/guardians aged 18 or over.

We process information about children only where an authorised adult enters it for legitimate childcare funding administration purposes, and only as necessary to provide the Services.

Parents/guardians should ensure information entered about a child is accurate and that they have authority to provide it.

If you believe we hold a child’s information without proper authority, contact Support@myfundingwhizz.co.uk and we will investigate promptly.

14. Push notifications

With your permission, we send push notifications about declaration status, invitations and other service updates. You can disable notifications at any time in your device settings.

Disabling notifications does not delete your account or other personal data.

15. Advertising and tracking

We do not use the App Tracking Transparency framework for cross-app advertising because we do not track you across third-party apps or websites for advertising purposes.

We do not sell personal data or share it for cross-context behavioural advertising.

16. Cookies and similar technologies

Our mobile app does not use browser cookies. Our website or payment flows, such as Stripe Checkout opened in a web view, may use cookies or similar technologies operated by those providers. See their respective privacy notices for details.

17. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. For material changes, we may provide additional notice in the app or by email where appropriate.

Continued use of the Services after changes take effect constitutes acceptance of the updated policy, except where further consent is required by law.

18. Contact us

For privacy questions, data subject requests or account deletion:

Email: Support@myfundingwhizz.co.uk
Website: www.myfundingwhizz.co.uk

19. Complaints to the ICO

You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you are unhappy with how we handle your personal data:

Information Commissioner’s Office
ICO website: ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113

We encourage you to contact us first so we can try to resolve your concern.

 

bottom of page