Comprehensive Privacy Notice
Table of contents
- 1. Who we are
- 2. Scope
- 3. Data we collect
- 4. Purposes and legal basis
- 5. Children's data
- 6. Health data
- 7. Sub-processors
- 8. International transfers
- 9. Retention
- 10. Security
- 11. Your rights
- 12. Cookies and similar technologies
- 13. Automated decisions
- 14. Breach notification
- 15. Minimum age
- 16. Changes to this policy
- 17. Complaints to supervisory authorities
- 18. Contact
1. Who we are
This Comprehensive Privacy Notice describes how NestRules collects, uses, retains and, where applicable, transfers personal data when you use our mobile and web applications. It is issued under Mexico's current Federal Law on Protection of Personal Data Held by Private Parties.
- Data controller
- Pedro Perafán Carrasco
- Postal address
- Guadalajara, Jalisco, México — domicilio completo disponible a solicitud en legal@nestrules.app
- Privacy email
- privacidad@nestrules.app
NestRules operates as a natural person in Mexico. If you are located in the European Union, the United Kingdom, or any other jurisdiction with applicable laws, this policy applies to you to the extent those laws are relevant.
2. Scope
This policy applies when:
- You create or use an account in our apps (iOS, Android, or web).
- You enter information about the minors in your care as a parent or legal guardian.
- Compartes una guía de cuidado o una carta de bienvenida mediante un enlace público privado.
- You contact us for support or to exercise your rights.
This policy applies alongside our Terms of Service.
3. Data we collect
3.1 Account data
- Name.
- Email address.
- Password (stored as a bcrypt hash only; we never see it in plaintext).
- Preferred language.
- Social-provider identifier (Google or Apple) if you sign in with them.
3.2 Children's profile data (entered by you)
- Child's name.
- Fecha de nacimiento o fecha estimada de nacimiento cuando registras a un bebé que aún no ha nacido.
- Avatar (optional emoji).
- Allergies and medical notes (optional; see section 6).
- Emergency phone (optional).
3.3 Family and care-rule data
- Caregiver roles (grandparent, babysitter, etc.) and trust levels.
- Rules and permissions you define for each caregiver.
- Family invitations (invitee email and invitation token).
3.4 Carta de bienvenida para un bebé
- Título, mensaje, acuerdos familiares, cierre y firma que redactas para la carta.
- Borrador privado y copia exacta de la última versión que decides publicar.
- Estado, caducidad, número de visualizaciones y último acceso del enlace compartible; el token se almacena únicamente como hash.
La carta pertenece al perfil del bebé y a su familia; no se asigna ni vincula a un cuidador. Las personas destinatarias pueden abrir el enlace sin crear una cuenta o tener un rol en NestRules.
3.5 Billing data
- Stripe customer id.
- Payment-method type and last four digits of the card.
- Contracted plan and trial end date.
We never store the full card number nor the CVV. Charges are processed directly by Stripe (web) or by Apple / Google (in-app purchases).
3.6 Technical and usage data
- IP address and user agent at sign-in.
- Push-notification device token (FCM, iOS/Android).
- Error and crash logs (see section 7 — sub-processors).
4. Purposes and legal basis
We process your data for the purposes listed below. For each purpose we indicate the legal basis under the General Data Protection Regulation (GDPR, art. 6) and the Mexican Federal Law on Protection of Personal Data Held by Private Parties.
- Providing the contracted service
- legal basis: performance of the contract (GDPR 6.1.b). Includes creating your account, saving your rules, generating shareable links and PDFs.
- Authentication and security
- legal basis: performance of the contract and legitimate interest (GDPR 6.1.b and 6.1.f). Includes sign-in, 2FA, abuse blocking, and detection of suspicious access.
- Payment processing
- legal basis: performance of the contract (GDPR 6.1.b) and legal obligation for tax purposes (GDPR 6.1.c).
- Service notifications
- legal basis: performance of the contract (GDPR 6.1.b) for transactional email (welcome, verification, password reset, someone viewed your guide).
- Storage of the child's health data
- legal basis: explicit consent (GDPR 9.2.a). If you withdraw consent or delete the information, we stop processing it.
- Service improvement and fraud prevention
- legal basis: legitimate interest (GDPR 6.1.f), kept to the minimum necessary and without profiling.
- Compliance with legal obligations
- legal basis: legal obligation (GDPR 6.1.c), for example to keep tax records or respond to requests from competent authorities.
5. Children's data
Minors do not create accounts in NestRules. The account is opened by an adult (parent or legal guardian) who voluntarily enters information about the children in their care.
As an adult account holder:
- You represent that you have parental authority or legal guardianship over the minors whose data you enter.
- You are responsible to us and to the minor for the stewardship of that information.
- You may delete the minor's profile at any time from the app; when you do, we delete that data from our systems within 30 days.
The minor's data is only visible to:
- You, as the account holder.
- Other members of your family whom you accept as co-parents.
- Las personas a quienes compartas un enlace de guía o carta, y solo mientras ese enlace siga activo.
6. Health data
We record the date, time and version of the statement through which you gave consent (health_data_consent_at and health_data_consent_version fields). The current version is 2026-07-17. If the purpose or this statement changes materially, we will request consent again.
You may withdraw consent without retroactive effect by deleting the health information in the app or emailing our privacy address. After withdrawal, we will stop processing that data except for blocking or retention required by law.
We never transmit health data to Sentry, Firebase, analytics services or similar. If an error occurs in the app while you are working with those fields, our error-capture layer strips the content before sending it to the diagnostic service.
7. Sub-processors
We use third-party providers to help operate the service. The contractual and international-transfer safeguards vary by provider. Our public sub-processor register records the currently documented DPA, terms or other transfer mechanism, including safeguards whose formalization is still pending; this notice does not state that every provider currently has a signed DPA.
- Stripe Payments Europe, Ltd.
- payment processing (web).
- Apple Inc.
- in-app purchases on iOS and "Sign in with Apple".
- Google LLC
- push notifications (Firebase Cloud Messaging), Sign in with Google, and Android in-app purchases (via RevenueCat).
- RevenueCat, Inc.
- mobile subscription orchestration.
- Resend, Inc.
- transactional email delivery.
- DigitalOcean, LLC and/or Amazon Web Services, Inc.
- almacenamiento de archivos (PDFs de guía y cartas de bienvenida).
- Laravel Nightwatch
- backend monitoring.
- Functional Software, Inc. (Sentry)
- crash reporting on the mobile app, with personal data stripped before sending.
- PostHog, Inc. (PostHog Cloud EU)
- product analytics with pseudonymized events (internal identifiers and counters only), hosted in the European Union; no names, no health data, and no permission or note content.
The full, up-to-date list, with links to each provider’s policy, is maintained in our registro público de sub-encargados.
8. International transfers
Some providers (Stripe, Google, Apple, Resend, AWS, DigitalOcean and Sentry) operate infrastructure outside Mexico or the European Economic Area. Our public sub-processor register identifies the mechanism applicable to each provider and any implementation step still pending. Depending on the provider, those mechanisms may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The EU-US Data Privacy Framework when the provider is certified.
- The DPA, provider terms or equivalent safeguard documented for that provider in our public sub-processor register; some formalization steps remain pending as identified there.
When a transfer requires your consent under the LFPDPPP, the applicable notice will identify the third party, purpose and way to accept or reject it. Transfers needed to operate the legal relationship rely on the applicable statutory exceptions.
9. Retention
- Active account
- as long as you keep it open.
- Deleted account
- personal data is wiped from our systems within 30 days. Shared links are invalidated immediately.
- Tax and payment records
- 5 years as required by law (Código Fiscal de la Federación, Mexico).
- Error and crash logs
- 90 days max.
- Cartas y enlaces compartibles
- mientras conserves el perfil del bebé o hasta que borres la carta. Los enlaces dejan de funcionar al revocarlos, al vencer o al eliminar el perfil o la cuenta.
- Encrypted backups
- up to 35 days, then overwritten.
10. Security
We apply technical and organizational measures proportionate to the risk, including:
- End-to-end encrypted traffic via HTTPS/TLS.
- Passwords stored with bcrypt (cost ≥ 12).
- Optional two-factor authentication (2FA) based on TOTP.
- Rotated and revocable session tokens; lockout after failed attempts.
- Mandatory email verification to access family data.
- Strict environment separation and least-privilege access for the technical team.
- Encrypted backups with periodic restore tests.
- Security code reviews before every deploy.
11. Your rights
In Mexico you may exercise ARCO rights: Access, Rectification, Cancellation and Objection. You may also withdraw consent and ask us to limit the use or disclosure of your data, without prejudice to other rights under applicable law.
- Access
- obtain a copy of the data we hold about you.
- Rectification
- correct inaccurate or incomplete information.
- Cancellation
- request that your data be blocked and later deleted, subject to applicable statutory exceptions.
- Portability
- receive your data in a structured format to move it to another service.
- Objection
- object to processing based on legitimate interest.
- Restriction
- ask us to temporarily suspend processing while a dispute is resolved.
- Withdraw consent
- for processing based on consent (e.g. health data).
To exercise ARCO rights, withdraw consent or limit use or disclosure, use the in-app features or write to privacidad@nestrules.app. State your name, a means to receive notices, the right you wish to exercise and a clear description of the data, and attach the documents needed to verify your identity or authority. Do not send identity documents through any channel other than the one we specify in our response.
See our account and data deletion instructions for the in-app steps, email alternative and retention periods.
We will communicate our determination within 20 business days and, if granted, implement it within the following 15 business days. These periods may be extended once for an equal period when justified by the circumstances.
13. Automated decisions
NestRules does not make automated decisions that produce legal effects on you, and does not perform profiling. All service logic is driven by the rules you configure yourself.
14. Breach notification
15. Minimum age
NestRules is intended exclusively for people aged 16 or older who act as parents or legal guardians. By registering you confirm that you meet that minimum age.
If we learn that an account was created by a person below the minimum age, we will delete it along with all associated information.
16. Changes to this policy
We may update this policy to reflect legal, technical or product changes. When changes are significant:
- We will notify you inside the app or by email before they take effect.
- We will update the version and date at the top of this document.
- If the change requires new consent (for example, a new purpose), we will ask you to accept it before you continue using the app.
17. Complaints to supervisory authorities
If you believe we have processed your personal data unlawfully, you can file a complaint with the competent authority in your country, including:
- Mexico
- Ministry of Anti-Corruption and Good Government, the competent authority under the LFPDPPP: gob.mx/buengobierno
- Spain
- Spanish Data Protection Agency (AEPD): www.aepd.es
- European Union
- Data-protection authority in the data subject's country (list at edpb.europa.eu).
- United States (California)
- California Privacy Protection Agency: cppa.ca.gov
We would like the chance to resolve your concern directly first, so please email us at privacidad@nestrules.app before escalating to a regulator.
18. Contact
- Privacy and data-subject requests
- privacidad@nestrules.app
- Legal matters
- legal@nestrules.app
- General support
- soporte@nestrules.app
- Postal address
- Guadalajara, Jalisco, México — domicilio completo disponible a solicitud en legal@nestrules.app