DayCape

Privacy Policy

For the DayCape mobile application

Last updated: [13 August 2026]  ·


Editor’s note: This version has been reorganised for GDPR completeness and updated to reflect that DayCape is distributed as a mobile app on the Apple App Store and Google Play, with a section covering Facebook Login. Bracketed placeholders [ ] mark items only Anton/DayCape can confirm (dates, retention periods, DPO contact, exact sub-processor list). This is not legal advice — have a lawyer give it a final read before publishing, especially the Facebook Login and children’s-data sections, which app store reviewers scrutinise closely.

1. Our Philosophy

Protecting the safety and well-being of children lies at the heart of everything we do at DayCape. Using DayCape’s planning app creates a trail of information that, when we need to look at it at all, is almost always reviewed without the names of account holders or children attached. We vigorously protect the privacy of the children and parents — including guardians, teachers, and anyone invited to view, edit, or otherwise engage with a child’s schedule — who use DayCape’s products and services. At the same time, accessing specific scheduling information in limited circumstances is sometimes essential to keeping our software running reliably and to generating the research insights behind new and improved features.

  • We will never sell your scheduling information. We charge usage fees so we don’t need to sell your data to stay financially viable.
  • We will sometimes access samples of anonymised scheduling statistics, to help maintain the app and for research purposes.
  • We handle your data in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and, where applicable, other data protection laws in the countries where DayCape is offered.

2. Who We Are — Data Controller

DayCape is the data controller responsible for your personal data.

Field Details
Company DayCape
Address Bänkåsvägen 72, 865 92 Alnö, Sweden
Organisation number 556972-0682
Contact info@daycape.com
Data protection contact anton@daycape.com

If you are under 16 years old, your guardian must agree to the processing of your personal data before you create an account. Where local law sets a lower age of digital consent (as low as 13 in some EU member states), that local threshold applies instead.

3. What We Collect

The table below sets out the personal data DayCape collects, why, and — where relevant — who inside DayCape can see it. Fields marked “non-obligatory” are never required to use the app’s core scheduling features.

Child

Data Why we collect it
Name of child Required. Displays a personalised, colourful list of children in the app.
Phone number Optional. Only used so users can contact each other within the app.
Date of birth Optional. Used to show anonymised statistics about our users’ ages.

Activities

Data Why we collect it
Activity feedback rate Optional. Communicates progress/success to parents and lets us build anonymised improvement statistics.

Parent / Guardian / Teacher

Data Why we collect it
E-mail address Used for account access, customer support, and (with consent) newsletters. Never handed to third parties for their own marketing.
Role (parent or teacher) Optional. Distinguishes account types so the right features are shown.
Date of birth Optional. Used to show anonymised statistics about our users’ ages.
Phone number Optional. Only used so users can contact each other within the app.
Name of activities, times, dates Collected to present the schedule; examined by staff only during debugging.
Pictures Collected to present the schedule; examined only in an encrypted, non-visual form during debugging.
Notes Collected to present the schedule; examined by staff only during debugging.

Account access (social login)

Data Why we collect it
Facebook account identifiers (see Section 5) Optional. Lets you create and sign in to your DayCape account using Facebook Login instead of an e-mail/password.
Apple ID identifiers (see Section 5) Optional. Lets you create and sign in to your DayCape account using Sign in with Apple.
Google account identifiers (see Section 5) Optional. Lets you create and sign in to your DayCape account using Google Sign-In.

Customer support

Data Why we collect it
Mail and chat conversations Handled via a third-party support tool. We can see which page/screen you were on. Conversation records are deleted once your issue is resolved, subject to any legal retention obligation.

Usage statistics & mobile/device data

Data Why we collect it
User rate (how often the app is used) Aggregated, anonymised statistical reporting.
In-depth usage (how you interact with the app) Aggregated, anonymised statistical reporting and to improve app stability.
Device & app identifiers (device type, OS version, app version, crash logs, advertising/analytics identifier where permitted, push-notification token) Needed to run a mobile app reliably: diagnosing crashes, sizing performance, and delivering optional push notifications. Collected via our analytics/crash-reporting provider [name provider, e.g. Firebase] and — for subscriptions — our subscription-management provider [name provider, e.g. RevenueCat].
Editor’s note: List every SDK actually bundled into the iOS/Android build (Firebase, RevenueCat, crash reporting, push notification service, Facebook SDK, etc.) here by name — app store privacy labels (Apple’s “Privacy Nutrition Label” and Google Play’s Data Safety form) must match this section exactly, or the app can be rejected or flagged.

4. Legal Basis for Processing (GDPR Article 6)

We only process personal data where we have a valid legal basis to do so:

  • Performance of a contract — creating your account, building your schedule, and delivering the core app functionality you signed up for.
  • Consent — optional fields (phone number, date of birth, photos), Facebook/Apple/Google sign-in, marketing newsletters, and any push notifications you opt into. You can withdraw consent at any time; see Section 15.
  • Legitimate interests — aggregated, anonymised research and product statistics, and keeping the app secure and running (e.g., crash diagnostics), balanced against your right to privacy.
  • Legal obligation — where we must retain or disclose data to comply with the law (for example, tax records for payments).

5. Signing In with Facebook, Apple, or Google

As an alternative to creating a DayCape account with an e-mail address and password, you may choose to sign up or sign in using Facebook Login, Sign in with Apple, or Google Sign-In. Each of these is entirely optional — you can always use e-mail/password instead, and you can switch later in Account Settings.

In every case: we use the information shared with us solely to create and authenticate your DayCape account and to pre-fill your profile; we do not post on your behalf on any of these platforms and do not request access beyond basic identity information. Each provider (Meta, Apple, or Google) processes your data as an independent controller under its own privacy policy once it is on that provider’s systems — DayCape has no control over, and is not responsible for, that separate processing. The legal basis for this processing is your consent, given when you tap the relevant “Continue with…” button.

Facebook Login

  • Facebook shares with us only the information you approve on Facebook’s permission screen before you connect your account — typically your name, the e-mail address linked to your Facebook profile, your public profile picture, and a unique Facebook user ID.
  • We do not request access to your Facebook friends list, timeline, or other Facebook content.
  • You can revoke DayCape’s access at any time from Facebook’s “Apps and Websites” settings.

Sign in with Apple

  • Apple shares with us your name and either your real e-mail address or an Apple-generated private relay e-mail address, depending on what you choose on Apple’s consent screen — plus a unique, app-specific Apple user identifier.
  • If you choose to hide your e-mail, Apple forwards messages we send to your private relay address without revealing your real address to us.
  • You can review or revoke DayCape’s access at any time in your Apple ID settings under Sign-In & Security → Apps Using Apple ID.

Google Sign-In

  • Google shares with us the basic profile information you approve — typically your name, e-mail address, profile picture, and a unique Google account identifier.
  • You can review or revoke DayCape’s access at any time in your Google Account settings under Security → Third-party apps with account access.

For any of the three, you can delete the DayCape account created this way from within the DayCape app (Account Settings → Delete Account) or by e-mailing info@daycape.com.

Editor’s note: Confirm in the App Store/Play Store listings and consent screens that each sign-in option is optional, and that the exact permissions/scopes requested (e.g. Facebook’s email/public_profile, Apple’s name/email, Google’s profile/email scopes) match what’s listed above — Apple’s App Review in particular checks this against the actual login flow. Note Apple also generally requires that if you offer any third-party or social login (Facebook, Google), you must also offer Sign in with Apple as an equivalent option.

6. How We Use Aggregated Statistics

To maintain and troubleshoot the app

If there are technical problems, we occasionally review account features (never your password) to diagnose and fix the issue. If a customer reports a problem, that individual account is reviewed within the narrowest scope necessary to resolve it.

For research

We sometimes study scheduling activity in non-personal, aggregate form. Your data may be bundled and analysed together with other users’ data, without your name or your children’s names attached, to answer questions such as which activities our features are used for most, where in the world we see the most activity, and how many parents are typically connected to a single child. Your name and your children’s names are never retrieved for, or attached to, this kind of research.

7. How Long We Keep Your Data

We keep personal data only for as long as it is needed for the purposes described in this policy, or as required by law:

  • Account and schedule data: for as long as your account is active, and for [X] after you delete your account, in case you wish to reactivate it or as required for legal/accounting purposes.
  • Customer support conversations: deleted once your issue is resolved, subject to a short retention period for quality assurance [X days/months].
  • Payment records: retained as required by Swedish accounting law (typically 7 years).
  • Aggregated/anonymised statistics: retained indefinitely, since they no longer identify you.
Editor’s note: Fill in the bracketed retention periods with DayCape’s actual policy — GDPR requires a defined retention schedule, not just “as long as needed.”

8. Who We Share Data With

We do not sell your personal data. We share it only with the following categories of recipients, each bound by a data processing agreement where they process data on our behalf:

  • Payment processing: Braintree, for handling credit card payments (see Section 9).
  • Sign-in: Meta (Facebook), Apple, or Google, only if and when you choose to sign in with that provider (see Section 5).
  • App infrastructure: our hosting, analytics, crash-reporting, and subscription-management providers [name each provider actually used, e.g. Firebase, RevenueCat] — used to keep the app running and to process subscriptions, not for their own marketing.
  • Customer support: our support/helpdesk tool provider (see Section 3).
  • Authorities: where required by law, court order, or to protect the rights, safety, or property of DayCape, our users, or the public.

9. Payment Information

Your credit card information is handled by our payment partner, Braintree, which follows industry-standard security practices. You can read how Braintree handles your data, including its EU model clauses for international transfers, at the links below.

https://www.braintreepayments.com/legal/payment-services-agreement-eu

https://www.braintreepayments.com/assets/Braintree-PSA-Model-Clauses.pdf

Editor’s note: If in-app purchases/subscriptions are sold through Apple’s App Store or Google Play billing rather than Braintree directly, add a line clarifying that Apple/Google handle that payment data under their own privacy policies.

10. International Data Transfers

Your personal data is mainly stored within the EU/EEA. We do not generally transfer personal data outside the EU/EEA. Where a subcontractor outside the EU/EEA is needed — for example, to operate and host IT systems, payment services, or app infrastructure such as Facebook/Meta — we enter into agreements (such as the EU Standard Contractual Clauses) that govern the transfer and the supplier’s handling of the data. DayCape remains responsible for your personal data, and our suppliers may only process it in line with our agreement and instructions.

11. Security

We only use your password for initial verification; most communication after that relies on secure, one-time tokens. Passwords are stored using industry-standard salting and hashing, so we cannot access them ourselves — this also protects your credentials against a typical adversary in the event of a security breach.

Things you can do to help protect your information:

  • Change your password on a regular basis.
  • Take care about who you share account access with.
  • If a device is lost or stolen, change your child’s name and/or your password.
  • If a device is lost or stolen, contact compliance@daycape.com.

12. Data Breach Notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (in Sweden, the Swedish Authority for Privacy Protection, IMY) without undue delay and, where required, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also notify you directly, describing the nature of the breach and the steps we are taking.

13. Children’s Data

DayCape is designed to be used by children under the direction of a parent, guardian, or teacher — a child does not create or manage their own account. Guardians must consent to the processing of a child’s personal data as described in Section 2. We collect the minimum data needed to run the scheduling features (see Section 3) and never use children’s data for third-party advertising.

14. Code of Conduct

Every DayCape employee and contractor signs our internal Code of Conduct, which sets out our company values and, in particular, our expectations for how each person handles privacy-sensitive information.

15. Your Rights Under GDPR

  • Right to information — to know how your personal data is processed, as set out in this policy. Questions go to info@daycape.com.
  • Right of access — to confirm whether we process your data and, if so, to receive a copy and additional details about that processing. You may request this once a year, free of charge, in writing, signed, and sent to our address above.
  • Right to data portability — to receive the personal data you provided to us in a structured, commonly used format, and to have it transferred to another controller, where technically feasible.
  • Right to rectification, erasure, or restriction — to correct inaccurate or incomplete data, request deletion, or restrict how we process it.
  • Right to object — to object to certain processing, including processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent (e.g., Facebook Login, optional fields, marketing), you can withdraw it at any time without giving a reason, without affecting processing carried out before withdrawal.
  • Right to lodge a complaint — with your national data protection authority; in Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se.

To exercise any of these rights, contact info@daycape.com or write to us at the address in Section 2.

16. Changes to This Policy

We may update this privacy policy from time to time, for example when we add a feature, a new sign-in method, or a new service provider. We will update the “Last updated” date at the top of this document, and where changes are material we will notify you in the app or by e-mail before they take effect.

17. Contact Us

Question about Contact
General privacy questions info@daycape.com
Lost or stolen device / security compliance@daycape.com
Postal address DayCape, Bänkåsvägen 72, 865 92 Alnö, Sweden