Privacy policy
Last updated 11 September 2026
This policy explains how AusBabysitters handles personal information, and is written to follow the Australian Privacy Principles in the Privacy Act 1988 (Cth). We handle information about people who are looking after children, so we collect as little as we can and delete it on a schedule rather than a promise — this page describes what the software actually does.
1. Who we are
AusBabysitters operates ausbabysitters.com and the AusBabysitters app, where families in Sydney and people offering babysitting or nannying work can find one another. AusBabysitters is a registered business name of Matthew Lewandowski, ABN 61 893 315 209 — the entity responsible for the personal information described below.
2. What we collect
Our app collects the same things as the website: everything in this section applies to both. Two things are the app’s own. One is the address notifications go to, described below. The other is a check for a newer version each time you open the app, which sends an identifier for that installation, the kind of phone, and the version it is running to the service that hosts our updates (section 4).
Account information
Your email address, your name, and the role you chose (parent or sitter). We do not store passwords: you sign in with a six-digit code we email you, with Google, or with Apple. Each sign-in creates a session that records the IP address and browser it came from, for security. Sessions expire after 30 days, and expired session records and used sign-in codes are deleted on a daily schedule. Your account also keeps the time you were last active. That is one date on the account rather than on a session, so it outlives them, and it tells us which accounts are still in use. We also keep which days you were signed in, and whether that was on the website, an iPhone or an Android phone, so we can count how many people use each. That is one record per day for each of those, not per visit, and it goes when your account does. Your account also keeps when you last opened the sitter search and the jobs feed, so your dashboard can tell you what is new since then. That is one time for each, and it goes when your account does too. While you set your account up we keep which setup screens you reached, and the page you were on your way to when you signed up, so we can see where setup loses people. Only we see either, and both go when your account does.
If you sign in with Google or Apple, they tell us the email address on that account and that they have confirmed you own it. One address is one account, whichever door you come through, and we keep the identifier that links your account to the provider. Google also offers us your name, which we keep to fill in your profile form so you do not type it twice, and a profile picture, which we copy into our own photo storage and use as your photo after the same automatic check every photo here gets (section 3) — you can replace or remove it any time. Apple sends a name on your first sign-in only, and we keep it the same way. Either way it becomes the name on your account until you change it, and other people only ever see your first name and last initial. If you chose Hide My Email, the relay address Apple made for you is the address on your account: it is where our email to you goes, it travels by way of Apple, and we record that it is a relay address. Because it is not the address on your Apple ID, an account made this way is separate from one you already have under your own address.
Creating an account also records your acceptance of our terms of use and this policy: which version, and when. Settings you change and things you dismiss for good inside the app are stored so they hold, and deleted with your account.
Profile information
What you choose to put on your profile. For sitters that is your name, date of birth, gender, suburb, headline, biography, photograph, rates, availability, languages, years of experience, the kind of work you are looking for, and self-declared claims such as holding a first aid certificate. Your profile shows your age, worked out from the date you gave us; the date itself is never shown to anyone but you. For parents it is your name, suburb, an optional photograph, and an optional note about your children. An open job ad shows a parent’s first name and last initial, their suburb and — when they have added one — their photograph, never a full name, never an email address and never a street address.
Public sitter profiles show a first name and last initial, a suburb, and — when the sitter has added them — an age and a gender, never a full name, never a date of birth and never an address. Public pages are indexed by search engines. Sitters can switch off search engine indexing of their own profile in settings. Profile photographs sit on our photo host at unlisted addresses; treat a profile photo as public, because the profile it belongs to is. One line on a sitter’s profile is ours rather than theirs: how quickly they usually reply, which is counted from message timing rather than typed (see Messages and reviews).
We sometimes feature public sitter profiles in posts on our own social media accounts — Facebook, Instagram and Reddit. A post shows what your public profile shows, plus a short line about you drawn from your bio, and any photograph on the post itself is our own brand imagery, never a photo of you. Switching off search engine indexing in settings also keeps your profile out of any post drafted after that, and deleting your account removes you from any unposted draft immediately.
Resumes, documents and references (sitters)
A sitter can keep one resume on their profile — a PDF they upload — and up to three documents: a police check, a first-aid certificate and a qualification, each one file, a PDF or a photo. They can also list up to five references: somebody a family can contact, with their name, how the sitter knows them, roughly when, a phone number or email address, and a short note. None of it is on the public profile, which says only which of these a sitter has and how many references. A family sees any of them only once the sitter sends it to them in a conversation, and from then on sees what is on the profile — a file you replace, or a reference you add later. We do not contact referees, we do not verify whether anything a resume claims is true, and we do not verify a police check, a certificate or a qualification: we keep the file you give us and show it to the family you send it to, and that is all.
A police check is information about your criminal history. Whether to give us one is your choice, and you make it by adding the file; we never ask for one, never read the result, and never record anything from it. If you remove it, the file is deleted.
A resume or a document sits on our file host at an unlisted address, like a profile photo: anyone who has the address can open it. We give that address to you, and to a family once you send it to them. A person at our end can also open it when moderating the site, the same way they can read a conversation. A family you send it to can download it and keep it: removing it from your profile deletes the file, so the address stops working, but it cannot take back a copy somebody already has.
A referee’s details are somebody else’s information. Only list a person who has agreed to be contacted about your work.
Verification information (sitters who opt in)
Your legal name as it appears on your Working With Children Check, your date of birth, your check number, the state or territory that issued it, and the expiry date.
- We never receive or store identity documents. The photograph of your ID and your selfie go directly to our identity verification provider (currently Didit), who holds them under their own privacy terms. What comes back to us is a pass or fail and whether the name and date of birth matched what you told us.
- Your check number, the date of birth on your check, and your legal name are encrypted before they are stored. They are readable only by us when running the check, and by you on your own verification page, where the check number stays partly masked even from you. They are never sent to any other user, never written to logs, and never used for anything except the check.
- We record which register we checked, the result, the date it was run, and the expiry date of the clearance.
- Your public profile says how far each check has got — checked, being checked, or not checked — and nothing more. A check that did not pass, and one that lapsed, both read as not checked, the same words as a check nobody ever started. We publish that a check has not been passed. We never publish that you failed one.
Identity checks (families who opt in)
A family can choose to have their identity checked, and a verified sitter they have been talking to can ask them to. We never receive or store identity documents here either.The photograph of your ID and your selfie go directly to the same identity verification provider, and what comes back to us is a pass or a fail. We ask you for no legal name and no date of birth, so there is nothing of that kind to keep. What we store is whether a check passed, the month it passed, and Didit’s reference for the session.
Sitters see “ID checked” beside your name, and so does anyone who opens one of your open job ads; nothing else about the check is shown. A check that did not pass, and one you started and left, both read as not checked — the same as a check nobody ever started — and nobody is told you skipped it. When a sitter asks you to confirm your identity, we store who asked, in which conversation, and when; the sitter is never told whether you read it, and deleting either account deletes the request.
Messages and reviews
The content of messages you send through the site, and reviews you write. Messages are never shown to other members. Each message is checked automatically before it is delivered, and each review before it is published (section 3); a person at our end can also read a conversation when moderating the site, most often because a report points at it, or where the law requires it. When a conversation is reported, a copy of its most recent messages is stored with the report, so the record cannot be erased by deleting an account. Reviews are public. We also count how quickly a sitter answers the families who message them, so their public profile can show how quickly they usually reply — timing only, never content, and nothing about the family. A conversation is also checked automatically to tell whether it led to a sit, so we can invite each of you to review the other. No person at our end reads a conversation for this.
Job ads
An open job ad is public, including to search engines: your first name and last initial, your profile photo if you have one, whether your ID check has passed, the suburb, the days, how many children and their ages, a rate guide, a start date and your notes. Your full name, email address and contact details are not part of it. When an ad is filled, closed or expires it stops being listed and your name, photo and ID-check tick come off it.
Shortlists
Parents can shortlist sitters while browsing. Deleting either account deletes the entry.
Nearby alerts
Setting up a family account with a suburb, or posting an ad, starts a watch on that suburb. We keep the suburb against your account and tell you when the number of sitters who travel to it has gone up, and nothing when it has not. You can turn these off in settings or from the link in any email, and deleting your account deletes them.
Draft profiles from public ads (sitters we invite)
If you advertise your babysitting publicly — for example a post in a local Facebook group with your email address on it — we may prepare a draft profile from that ad and email you once, personally, to offer it. The draft holds what your ad said and the email address it gave. It is not published and not in any search: the only way to open it is the private link in that email, and it becomes a profile only if you sign in with that address and publish it yourself. The same page lets you delete the draft on the spot; if you do nothing, the draft and your address are deleted after 30 days, and we don’t email you about it again either way.
Records of accounts we remove
If we ban an account, we keep a record of it: the email address, the name on the account, and the reason. We keep the address so the same person cannot make a new account with it, which means the record has to outlive the account itself — see section 5. We also keep the IP addresses that account last signed in from, for 90 days, to stop a new account being created from the same connection; they block nothing else.
Notification records
When we email you, or send a notification to your phone, we record the type and the time, never any of the content, so we can limit how often we contact you. These records are deleted within days. Separately, a few of those times are kept beside the thing they are about and go when it does, so that something meant to arrive once is not sent twice: which one-off reminders you have already had, when a suburb watch last wrote to you, and when your last job update went out.
Push notifications (our app)
If you use our app, we store the address the notification service gives that installation, which kind of phone it is, whether that phone allows our notifications, and the sign-in it was made under. The address belongs to the app on that device and is no use to anyone outside the notification service. Signing out of the app deletes it, so does signing that device out from another one, and so does deleting your account. We also keep a short record of each notification we hand over — which device it went to and what became of it, never what it said — deleted within days.
Usage information
Searches run on the site (the suburb and filters used, how many results came back, and a scrambled code derived from your network address and browser, so we can tell one person searching twenty times from twenty people), pages requested, and basic device information. We use this to work out which suburbs need more sitters. The code cannot be turned back into your address, though it can tell us two searches came from the same connection. Search records lose that code and their link to your account after 90 days and are deleted after two years. We do not sell any of it.
When you are signed in as a parent and open a sitter’s profile, or as a sitter and open a family’s ad, we record that your account opened it, and the day. We turn those records into counts — how many families looked at a profile in a week, how many sitters opened an ad — and never show anyone who looked. A record loses its link to your account after 90 days, and the daily count stays with the profile or ad it belongs to.
3. Why we collect it
- To let you create a profile and be found by, or find, other users.
- To let you message people and be messaged.
- To let a sitter keep a resume, documents and references, and send them to a family who asks.
- To show families how quickly a sitter usually replies, from the timing of messages already sent here.
- To show a sitter how many families opened their profile, and a family how many sitters opened their ads, from the signed-in opens described in section 2.
- To work out whether a conversation led to a sit, so we know whether to invite each of you to review the other.
- To run verification and give an accurate account of what has been checked, and to take a badge or a completed check off a profile when a clearance expires or a status changes.
- To check a family’s identity when they ask us to, so a sitter can see the account they are talking to belongs to a real person, and to carry a sitter’s request that they do it.
- To respond to reports, investigate misuse, enforce our terms, and remove people who put others at risk — including keeping a removed account from being made again, which is what the records in section 2 are for, and refusing a new account from places we don’t take sign-ups from, which we read from the connection at sign-up and don’t keep.
- To send the email the service runs on: sign-in codes, the result of a check, a short note from us when your account or profile is first set up, and a warning if an account you messaged is closed for putting people at risk.
- To tell you what has happened on your account: a message, a request from someone you have messaged, sitters joining or families posting near you, and reminders about your own ads or profile. These go to your phone if you use our app, or by email. A phone notification says what it is about and opens the app at the right screen; it never carries the text of a message, anything about a child, or an address. You control them in settings, or from the unsubscribe link in any email.
- To check ads, profiles, photos, resumes, documents, references, reviews, and messages before anyone else sees them, so spam, scams, unsafe requests, and images that have no place on a childcare site don’t reach families or sitters. We also check whether an account is being used by a business rather than a family or a carer, from the ads and messages we have already checked and from how the account is used. The checks are automated: what isn’t approved is not published or delivered, and you are told the reason. Section 5 says what we keep of it. Repeated refusals of an ad, a profile, a photo, a review or a message can suspend an account; a refused resume, document or reference is simply deleted. If you think a check got something wrong, email us and a person will look at it.
- To understand which suburbs need more supply, and to improve the service.
Those checks, the suspensions that follow repeated refusals, and the decision to remove an account and stop it being remade are usually made by software rather than a person; our staff can also suspend or remove an account. A person will review any of these on request — email hello@ausbabysitters.com and say what happened. We do not sell personal information to anyone.
4. Who we disclose it to
- Our identity verification provider (currently Didit), for sitters who opt in to verification and families who opt in to an identity check. They receive the identity document and selfie you submit and return an outcome to us. They may process and store that information outside Australia. Their own notice for people being verified is at Didit’s verification privacy notice.
- The NSW Office of the Children’s Guardian, when we verify a Working With Children Check issued in New South Wales. We submit your family name, date of birth and WWC number.
- The Working with Children Check Unit, through the Service Victoria status checker, when we verify a Working With Children Check issued in Victoria. We submit your family name and the first 8 characters of your card number.
We run the check once, when the sitter submits it, and the badge shows the month we did. The NSW Office of the Children’s Guardian also tells us if a status it confirmed for us later changes.
- Our email provider (Resend, United States), to deliver sign-in codes and notifications.
- Expo(Expo Application Services, United States), which delivers notifications to our app and hosts the app’s updates. It receives the line you see on your screen and the address of the device it is going to, and hands both to Apple (Apple Push Notification service) or Google (Firebase Cloud Messaging), which carry it the last step to your phone. They receive the same line and the same device address, and nothing else about you. For updates, each time you open the app it asks Expo whether there is a newer version, which tells Expo an identifier for that installation, the kind of phone, and the version it is running.
- Google (United States), only if you choose to sign in with Google. Signing in that way tells Google that you use this site or app, and when. We send nothing else about you, and if you never use that button we send them nothing at all.
- Apple(United States), only if you choose to sign in with Apple, on the website or in our app. Signing in that way tells Apple that you use this site or app, and when. We send nothing else about you, and if you never use that button we send them nothing at all. If you chose Hide My Email, our email to you also passes through Apple’s relay on its way to your inbox.
- Apple and Google (United States), the stores our app is distributed through. The store you got the app from knows you have it, and knows when you update it. If you let your phone share app data with developers, the store also shows us crashes and how much the app is used; none of that says who you are.
- Apple Maps(Apple, United States), which draws the map in our iPhone app. Your phone asks Apple for the map directly, so what Apple receives is the area of the map you are looking at and the connection your phone makes to fetch it, under Apple’s own privacy policy. We send Apple nothing about you: no name, no email address, no account identifier.
- Our content review providers(Groq, Inc. and OpenAI, Inc., both United States), which run the automated checks described in section 3. They receive the content being checked, including a parent’s note about their children, and little around it: a listing goes with the suburb and first name it is posted under; a review with the first name of the person it is about and the star rating; a message with the recent conversation around it, and with names, email addresses, and links replaced by placeholders; a photo on its own, with nothing about the person who uploaded it. A sitter’s resume or document goes to OpenAI as the file itself, with the sitter’s first name and nothing else about them; a photo of a document goes to Groq the same way, or to OpenAI if Groq is unavailable; a reference goes without the referee’s phone number or email address. OpenAI also drafts the short line under each sitter in the social media posts described in section 2, from the sitter’s first name, suburb, years of experience and biography; and when we write to someone who has advertised in a community group, it receives that post and the note we wrote about it, and we keep neither. A conversation also goes to OpenAI, so it can tell us whether the two people went ahead with a sit (section 3); names, email addresses, and links are replaced by placeholders there too, and the rest of a conversation goes as the two people wrote it. Apart from what a resume, a document, a reference, a post, or a message itself contains, they never receive last names or verification details, and neither keeps what we send nor uses it to train models.
- Our hosting and storage providers: the app runs on Vercel with its functions in Sydney, our database is DigitalOcean managed Postgres in Sydney, and photos, resumes and documents sit in Vercel’s file storage. Our primary database is hosted in Australia; some serving infrastructure sits outside it.
- Our error monitoring provider(Sentry, United States), which tells us when the site or the app breaks. It receives what went wrong: the error, the page or screen it happened on, and, from the app, the kind of device and the app version — not your name, email address, or account identifier.
- Our analytics provider (Vercel Web Analytics), which counts page views for us. It receives the page address with the query string removed, the site you came from, your browser, your device type, and the city your request came from — not your name, email address, or account identifier.
- Microsoft Clarity (United States), which shows us how the site is used — where people scroll, tap, and get stuck, including replays of individual visits. Anything personal is masked in your browser before anything is sent: sign-in, sign-up, and signed-in screens in full, and every field you can type into on a public page. It sets cookies to tell one visit apart from the next, and it never receives your name, email address, or account identifier.
- Google Ads (United States), which tells us which of our ads bring people here and lets us advertise to people who have been here before. Its tag runs as you browse and receives the address of the page you are on (cut back to the page itself plus the identifier Google stamps on an ad click), the site you came from, your browser, and the general area your request came from. It sets a cookie. If you arrive from a Google ad and create an account, we tell Google Ads the ad led to a sign-up; the report says a sign-up happened, and nothing about who. The sign-in and unsubscribe links we email you never load the tag. It never receives your name, email address, or account identifier.
- Meta (United States), whose pixel tells us which of our Facebook and Instagram ads bring people here and lets us advertise to people who have been here before. It runs as you browse and receives the address of the page you are on, your browser, and the general area your request came from, and it sets a cookie. The sign-in and unsubscribe links we email you never load it. It never receives your name, email address, or account identifier.
- Other users, but only what is on your public profile, what is in an open job ad (section 2), your first name and photo once you are in a conversation with them, and what you choose to send in a message — including a resume, a document or references a sitter sends into a conversation, which that family can keep.
- Law enforcement or a child protection authority, where we are required to disclose or where we reasonably believe it is necessary to prevent a serious threat to someone’s life, health, or safety.
Some of these providers store data outside Australia. Where that happens we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles.
5. How long we keep it
- Account and profile data:while your account is open. You can delete your account yourself, immediately and permanently: your profile, photos, your resume, documents and references, your job ads, conversations and their messages (on both sides), reviews you wrote and reviews about you, your shortlist, nearby alerts, the link to your Google or Apple account if you made one, any device registered for notifications, the record of which days you were signed in, when you last opened the sitter search and the jobs feed, which setup screens you reached and the page you were heading to when you signed up, and any verification or identity check record all go with it. A closed ad keeps its page until then. If we have banned your account you cannot sign in to do that yourself — email us and we will delete it for you. Deleting an account does not remove the record of a report, a moderation decision, or a ban; those are described below.
- Photos:a photo you upload but never attach to a profile is deleted within two days. An attached photo is kept while it is on your profile, and deleted when you replace or remove it, or delete your account. A photo the check refused is deleted straight away — or, if our file host is briefly unreachable, within two days by the same sweep — and we keep no copy of it.
- Resumes, documents and references:a resume or document you upload but never add to your profile is deleted within two days, and one the check refused is deleted straight away with no copy kept — or within two days by the same sweep, if our file host was briefly unreachable. A resume, a document and the references on your profile are kept while they are there, and deleted when you replace or remove them, or delete your account. The card you sent stays in the conversation and goes when the conversation does; removing what you shared stops that card opening.
- Verification data: kept while a clearance is current. A verification that has expired, was rejected, or was abandoned midway is deleted in full — encrypted details included — two years after it last changed. Deleting your account deletes it immediately. One exception: a check that returned a barred result is kept for up to seven years, because it is safety evidence.
- A family’s identity check:a check that passed is kept while your account is open, and deleted with it. A check that did not pass, and one you started and left, are deleted 30 days after they last changed — we keep no standing record that anybody failed a check. A sitter’s request that you confirm your identity is kept while both accounts are open.
- Reports and moderation records:up to seven years, because we may need to demonstrate we acted on a safety concern. A report survives the deletion of the account it is about, along with the reported person’s name and email and the copy of the reported conversation described in section 2; a reported review is kept with its report the same way, as it read when it was reported. The record of a listing we checked or declined to publish — the submitted text and the decision — is kept the same way, and so is a message we declined to deliver: the sender’s attempted text and the decision, nothing from the rest of the conversation. A photo we refused leaves a record of the decision and the reason — never the image itself. The record of why we judged an account to be a business rather than a family or a carer is kept the same way. A parent’s note about their children, a review, a sitter’s resume, a document and a reference are the exceptions: each is checked, and we keep no record of the check.
- Records of accounts we remove: a ban record is kept while the ban is in force, and for up to seven years after it is lifted. It survives the deletion of the account it is about, with the email address, name and reason described in section 2. The IP addresses expire after 90 days.
- Terms acceptance records: the version you accepted and when. If you delete your account, the record (your email, the version, the date) is kept for up to seven years, then deleted.
- Search and usage data: unlinked from your account after 90 days, deleted after two years.
- Profile and ad views: unlinked from your account after 90 days. The daily count stays with the profile or ad it is about, and is deleted with it.
- Nearby alerts: kept while your account is open, and deleted with it. Turning them off keeps your suburbs, so turning them back on picks up where it left off.
- Draft profiles prepared from public ads: deleted 30 days after we create them, whether or not they were used. Deleting one from its own page is immediate and takes the email address with it.
- Social media posts about public profiles: a draft that is never posted is deleted 14 days after we write it, and deleting your account removes you from any unposted draft straight away. A post we did publish is kept as our own record of what we published, holding nothing your public profile did not already show.
- Notification records: which notifications went to you and when, and what became of one we handed to the notification service — never any content — deleted within days.
- Devices registered for notifications: kept while the app is still being opened on that device, and deleted 180 days after the last time it was. They also go the moment that device signs out, when you sign it out from another device, when the notification service tells us the app is no longer installed, and when you delete your account.
- Which one-off reminders we have sent you: kept while your account is open, and deleted with it.
These schedules run as a daily job inside the product, not as a manual chore.
6. Security
Data is transmitted over TLS and stored on managed infrastructure with access limited to those who need it. Verification details are encrypted at the application layer with a key held separately from the database, so a copy of the database alone does not reveal them. No system is perfectly secure; if a data breach is likely to cause you serious harm we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
7. Access and correction
You can view and correct most of your information from your settings at any time. For anything you cannot reach yourself — including a copy of what we hold — email hello@ausbabysitters.com and we will respond within 30 days. We will not charge you to make a request, and if we refuse access we will tell you why in writing.
8. Cookies and analytics
Cookies here do five jobs: keeping you signed in, remembering the appearance you chose — system, light or dark — so the app opens in the right one, letting the advertising tools in section 4 measure our ads and show them to people who have been here before, letting Microsoft Clarity tell one visit from the next, and running the bot check on our sign-in and report forms — a check that runs from this site and never receives your name, email address, or account identifier. Our page-view analytics (Vercel Web Analytics) sets no cookies at all and does not follow you from one site to another.
If you arrive from a Google ad, your browser also keeps a short-lived note of that, so a sign-up can be counted once; it stays on your device. You can turn personalised advertising off at myadcenter.google.com for Google and facebook.com/adpreferences for Meta, and a browser that blocks third-party scripts stops Clarity, the ad tag, and the pixel loading at all. The site works the same either way.
9. Children
Accounts are for people aged 16 and over. We do not knowingly collect information about children, and profiles must not include children’s names, photographs, or any detail that identifies them. Parents describing their children should keep it general — “two kids, 3 and 6” is the level of detail the product is built for. A job ad is public, so the same rule applies to it: ages and a number, never a name, a school or a childcare centre.
10. Complaints
If you think we have mishandled your personal information, email hello@ausbabysitters.com and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
11. Changes
We will update this page when our practices change, and will email account holders before a material change takes effect. Continuing to use the service after that means you accept the updated policy; if you do not agree, you can delete your account first.
12. Contact
hello@ausbabysitters.com. See also our terms of use and what verification involves.