Privacy Policy

Effective 12 July 2026 · Morro Care Ltd (Company No. 17326603)

This Privacy Policy explains how Morro Care Ltd, a company registered in England and Wales (company number 17326603), whose registered office is at Hartford Marina, Banks End, Wyton, Huntingdon, PE28 2AA ("Morro", "we", "us", "our"), collects, uses, shares, and protects personal data when you use the Morro application and related services ("the Service").

Morro is the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner's Office (ICO) under registration reference 00014726889.

This policy should be read together with our Terms of Service.

1. Who this policy applies to

This policy applies to everyone who uses the Service, including account holders, members of a Morro Group (family and carers), and the people receiving care whose information is recorded in the Service ("patients").

Where you add information about another person (for example a patient or another carer), you are responsible for ensuring you have the authority or consent to do so, as set out in our Terms of Service.

2. The personal data we collect

We collect and process the following categories of personal data:

  • Account and identity data — your name, email address, password (stored only in a securely hashed form by our authentication provider), and language preference.
  • Health and care data (special category data) — information you enter to coordinate care, including medications, dose logs and adherence, medication side effects, wellbeing check-ins (such as mood, hydration, pain, and mobility), emergency events, care notes, and any documents you upload.
  • Care group and relationship data — Morro Group membership, roles and permissions, invitations, carer and patient links, and care contacts.
  • Communications data — messages, activity feed posts, and file attachments shared within a Morro Group, and any correspondence you send us (for example a support request, which is stored with a reference number).
  • Usage and technical data — device notification tokens, notification preferences, activity and audit records (including the care timeline), and system logs used to operate and secure the Service.
  • Billing data — your subscription plan, billing status, renewal date, and the identifiers used by our payment provider. We do not store your card or payment details — these are handled directly by Stripe (see section 6).

3. How we use your data, and our lawful bases

Under the UK GDPR we rely on the following lawful bases:

  • Performance of a contract — to create and manage your account, provide the Service, coordinate care within your Morro Group, and process your subscription.
  • Legitimate interests — to secure the Service, prevent misuse, maintain audit and system logs, and improve the Service. Where we rely on legitimate interests, we balance them against your rights.
  • Consent — for optional features and, in particular, for the processing of health and care data (see below). You may withdraw consent at any time.
  • Legal obligation — where we must process data to comply with the law.

Special category (health) data. Care information is special category data. We process it on the basis of your explicit consent, given when you use the Service to record and share care information, and/or where processing is necessary for the provision of care under applicable conditions in the Data Protection Act 2018. You may withdraw consent at any time, though this may limit your ability to use core features.

4. Notifications and reminders

If you enable notifications, we use device tokens to deliver reminders and alerts (for example medication reminders and check-in prompts) via push and web-push services. You can control notifications and quiet hours in the app, and disable them in your device settings.

5. How your data is shared within the Service

Care information is visible only to members of the relevant Morro Group, and only according to the permissions set by the group owner. It is not shared with other users outside that group. You control who is invited to a Morro Group and what they can access.

6. Service providers (data processors)

We use trusted third parties to operate the Service. They act as our processors under appropriate data protection agreements, or as independent controllers where noted:

  • Supabase — secure hosting, database, authentication, and storage of your data.
  • Stripe — subscription billing and payment processing. Stripe processes your payment details directly as an independent controller and is certified to the PCI DSS standard; Morro does not receive or store your card details.
  • Resend — delivery of transactional emails (for example account and support emails).
  • Firebase Cloud Messaging (Google) — delivery of push notifications to your device.
  • Base44 — the platform on which the application is built and delivered.
  • App stores (e.g. Google Play) — distribution of the mobile app, where applicable.

We only share the data each provider needs to perform its function.

7. International transfers

Some of our providers may process data outside the United Kingdom. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as an adequacy decision or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. Our primary hosting region is the United Kingdom. You can contact us for more information about the safeguards we use.

8. How long we keep your data

We keep personal data for as long as your account is active and for a reasonable period afterwards, so that we can meet legal, security, and operational requirements. When data is no longer needed, we delete or anonymise it. Specific retention periods for each category are set out in our Data Retention Schedule in the Appendix below, and are available on request from support@morro.health.

If you close your account, we will delete or anonymise your personal data in accordance with that schedule, except where we are required to retain certain records by law.

9. How we protect your data

We take appropriate technical and organisational measures to protect personal data, including encryption of data in transit and at rest, access controls that restrict data to permitted Morro Group members, and secured infrastructure. No system can be guaranteed completely secure, but we work to protect your data and to respond appropriately to any incident.

10. Your rights

Under the UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where we rely on it.

To exercise any of these rights, contact us at support@morro.health. We will respond within the timeframes required by law. Note that some data relates to a shared care record within a Morro Group, and we will handle requests in a way that respects the rights of all members and the patient.

11. Children

The Service is intended for users aged 16 or over. Carers under 16 may only participate under the consent and oversight of a responsible adult guardian who controls the account and data, as set out in our Terms of Service.

12. Changes to this policy

We may update this policy from time to time. Where changes are significant we will take reasonable steps to notify you. The "Last updated" date shows when this policy was last revised.

13. Contact and complaints

For any questions about this policy or your data, contact us at:
Email: support@morro.health
Company: Morro Care Ltd, company number 17326603

If you are not satisfied with how we have handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.


Appendix: Data Retention Schedule

Effective 13 July 2026 · Last reviewed 13 July 2026

This schedule sets out how long Morro keeps each category of personal data, and what happens to it when you close your account or leave a Morro Group. It supports section 8 above. Where we say "anonymised", the data can no longer be linked to you.

A note on shared records: Morro Groups hold a shared care record about the person receiving care. Information you contribute to a group (for example a wellbeing check-in or a medication log) forms part of that shared record. If you leave a group, your access ends, but the entries themselves remain part of the group's record, attributed to the group rather than to your account.

Data categoryWhat it includesKept while account activeAfter account closure / triggerWhy
Account & identityName, email, language preference, profile photoYesDeleted within 30 days of account closureOperational only; no reason to keep longer
Health & care records (shared group record)Medications, dose logs, side-effect reports, wellbeing check-ins, emergency events, care timelineYes — belongs to the Morro GroupDeleted within 30 days of the group being deleted, or of the last member's account closing. A member leaving does not delete group records (see note above)The record supports ongoing care of the patient; it is group-scoped, not individual-scoped
Group membership & rolesMembership records, roles, permissionsYesRemoved when you leave a group or close your account; deleted with the groupAccess control only
InvitationsInvite email, name, role, tokenUntil accepted, cancelled, or expired (7 days)Unaccepted invites deleted 90 days after expiryKept briefly for resend/troubleshooting, then no purpose
Messages, feed & attachmentsGroup chat, activity feed posts, files shared in a groupYes — part of the shared group recordDeleted with the group, within 30 daysSame basis as care records
DocumentsCare documents uploaded to a groupYes — part of the shared group recordDeleted with the group, within 30 daysSame basis as care records
Support ticketsReference, your email, correspondenceYes24 months from ticket closure, then deleted or anonymisedHandling follow-ups, complaints, and service-quality review
Billing & subscription recordsPlan, billing status, renewal dates, Stripe identifiers, invoices (held by Stripe)Yes6 years from the end of the relevant financial yearRequired for HMRC / Companies Act accounting records; also covers the limitation period for contract claims
Device & notification dataPush tokens, notification preferences, quiet hoursYesDeleted within 30 days of account closure; stale device tokens removed on rolling basisDelivery only
Technical & audit logsSystem logs, security and audit eventsRolling 12 monthsExpire on the rolling schedule regardless of account statusSecurity investigation and abuse prevention
BackupsEncrypted database backupsRolling window (typically 35 days)Deleted data leaves backups as the window rolls overDisaster recovery; deletion propagates automatically

When you close your account

Closing your account triggers deletion of your identity, device, and preference data within 30 days. Content you contributed to Morro Groups that continue to operate remains part of those groups' shared records. Billing records are retained for 6 years as required by law, and support correspondence per the schedule above. Data in encrypted backups is removed as the backup window rolls over (up to ~35 days after deletion).

Exceptions

We may retain specific data for longer where required by law, to establish or defend legal claims, or where a regulator requires it. Where we do, we retain only what is necessary, for only as long as necessary.

Review

This schedule is reviewed at least annually, and whenever we add a new category of data processing (any such addition is also assessed in our Data Protection Impact Assessment).