Back to home

Privacy policy

Last updated: 14 September 2026

This Privacy Policy specifies the purposes and conditions of personal-data processing in connection with the HomeNest website, applications and related services.

1. Data controller

Anna Bradshaw, trading as Anna Bradshaw Consulting Services, Kiepury 8A, 96-313 Budy-Grzybek, Poland, VAT/NIP PL5291813181 (the “Controller”), is the controller of personal data processed for account administration, billing, security, support and its own marketing. Contact: support@gethomenest.com.

Where a business determines the purposes of processing personal data within its workspace, HomeNest acts as a processor on that business’s behalf. The data-processing provisions of the Terms of Service apply to such processing.

2. Categories and sources of data

Personal data are obtained from the data subject or, in connection with shared workspaces and invitations, from project owners, business customers and authorised participants.

  • Account and business data: names, email addresses, profile and business information, authentication records, workspace membership and access permissions.
  • Project and community data: contact details, addresses and locations, tasks, expenses, payment records, decisions, messages, photographs, documents, invitations and other content supplied by participants.
  • Directory data: business descriptions, services, service areas, contact details, photographs and publication requests.
  • Billing data: business name, billing address, tax identification number, invoices, purchase references, subscription status and payment results. Card details are collected by the payment provider.
  • Correspondence and marketing data: enquiries, consultation requests, support correspondence, newsletter subscriptions and consent records.
  • Technical data: IP addresses, browser and device information, session identifiers, notification tokens, diagnostic records and usage data collected by enabled measurement tools.

3. Purposes and legal bases

Account administration, provision of services and steps requested before entering into a contract are based on Article 6(1)(b) of Regulation (EU) 2016/679 (“GDPR”) where the data subject is a party to that contract. Processing business representatives’ contact details and administering their access are based on the Controller’s legitimate interest in performing its business contracts, under Article 6(1)(f) GDPR.

Accounting, tax and other statutory obligations are based on Article 6(1)(c) GDPR. Service security, abuse prevention, necessary diagnostics and the establishment, exercise or defence of legal claims are based on the corresponding legitimate interests of the Controller under Article 6(1)(f) GDPR.

Optional analytics, advertising technologies and newsletter communications are based on consent where required, under Article 6(1)(a) GDPR. Submission of an enquiry does not constitute consent to marketing.

Provision of data required for an account, an order or a response to an enquiry is necessary for that purpose. Failure to provide those data may prevent performance of the requested service. Other fields and optional features are voluntary.

4. Access and disclosure

Authorised workspace participants have access to shared data within their assigned permissions. Published directory listings and public community content are accessible to their intended public audience and may be indexed by search engines.

Account deletion does not automatically require deletion of shared records which another controller is entitled or obliged to retain. Personal data may also be disclosed to competent public authorities where required by law.

5. Service providers

The Controller uses the following providers to the extent necessary for the relevant processing purposes:

  • Supabase and Netlify — hosting, authentication, database and file storage, and service delivery, including regional pricing.
  • Stripe — payments, subscriptions, invoices, tax verification and fraud prevention. Stripe also acts as an independent controller for its own payment and regulatory purposes.
  • Anthropic — receipt extraction and translations requested through AI features.
  • Resend and Slack — electronic communications, support and enquiries; Expo, Apple and Google — mobile notifications and platform services.
  • Mapbox and Cloudinary — address and location services, and delivery of website images.
  • PostHog, Google/Firebase, Sentry and Meta — applicable usage measurement, diagnostics, performance monitoring and advertising services. Session recording, where enabled, may include interactions with the service.

6. AI processing

Use of receipt extraction involves transmitting the submitted image to Anthropic. Use of listing translation involves transmitting the selected text. The provider processes those data to generate the requested result under its commercial service terms. Results retained by the User become part of the relevant project or listing.

7. Cookies and similar technologies

HomeNest uses cookies, local storage and similar technologies for authentication, security, preferences, usage analytics and advertising measurement. The relevant providers and purposes are identified in this Policy.

Browser settings may be used to restrict cookies and local storage. Blocking necessary storage may affect authentication and saved preferences. Mobile device permissions are managed in device settings. Newsletter consent may be withdrawn through the unsubscribe link. Other privacy requests may be submitted to the Controller.

8. Retention periods

Account and project data are retained for the duration necessary to provide the service and are subsequently deleted or anonymised, except where continued retention is required by law or necessary for the establishment, exercise or defence of legal claims. Shared records remain subject to the obligations of their respective controllers. Backup copies are removed through the applicable backup rotation.

Accounting and tax records are retained for statutory periods. Enquiry, support and consultation records are retained until the matter is resolved and, where necessary, until the relevant limitation period expires. Security and usage records are retained for the period necessary to investigate incidents or fulfil the stated measurement purpose. Newsletter data are retained until withdrawal of consent, subject to necessary consent evidence and suppression records.

9. Security and international transfers

The Controller applies technical and organisational measures appropriate to the risks of processing. Service providers may process personal data outside the European Economic Area, including in the United States.

Transfers requiring safeguards are based on an applicable adequacy decision or appropriate safeguards, including the European Commission’s standard contractual clauses. Information about the relevant safeguards, including a copy where applicable, may be obtained from the Controller.

10. Rights of data subjects

Subject to the conditions laid down in the GDPR, data subjects have the right of access, rectification, erasure, restriction of processing and data portability; the right to object to processing based on legitimate interests; and the right to withdraw consent. Requests may be submitted to support@gethomenest.com. Identity verification may be required. The Controller responds within one month; any lawful extension and its reasons are notified within that period.

Data subjects may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority, in particular in their place of habitual residence or work. Requests relating to data controlled by a business customer may be referred to that customer.

HomeNest does not use its AI features to make decisions based solely on automated processing which produce legal or similarly significant effects concerning a data subject.

11. Scope and amendments

The service is not intended for persons under 16 years of age. Suspected unauthorised processing of a child’s data may be reported to the Controller.

Amendments to this Policy are communicated where required by law. An amendment does not constitute consent to processing for a new optional purpose.