Privacy notice
Last updated: 25 August 2026
1. Our approach
Child, family and case information handled by ChildTrace is sensitive. We collect only what is needed for the purpose stated at the point of collection (minimum necessary data), and information about a child is private by default — publication requires an explicit, documented, human-approved safeguarding decision.
This notice describes our general practice. It is reviewed against applicable law, including Cameroon's Law No. 2024/017 on personal data protection, as part of our governance process; it does not itself constitute legal advice.
2. What we collect, and why
| Category | Examples | Purpose |
|---|---|---|
| Reporter information | Name, phone or email, relationship to the child (optional for anonymous sightings) | To follow up on a report and confirm status |
| Child information | Known name, approximate age or date of birth, sex, distinguishing features, photograph | To identify, search for, and safely reunite a child |
| Case and location information | Last-seen or found location, circumstances, sightings, case status history | To investigate and coordinate a response |
| Family and relationship information | Claimed and verified relationships, tracing attempts, safety assessments | To trace family and assess safe reunification |
| Evidence | Photographs, documents, statements uploaded by professionals | To support case review and investigation, with a recorded chain of custody |
| Device and location data (optional wearables) | Approximate location, battery/connectivity state, safe-zone entry/exit, SOS events | To support family safety features and, during an active case, authorized responders |
| Account and security data | Login timestamps, session and device information, audit and security events | To secure accounts and maintain an accountable, tamper-evident record of sensitive actions |
3. Data classification and who can see what
Every field is classified, and access follows the classification:
- Public — only the generalized fields on an approved, published profile: first name or known name, an age label, a general region, and a non-identifying summary. Never an exact address, coordinates, phone number, or reporter identity.
- Internal / professional — operational case information visible to the assigned team and organization handling a case.
- Restricted — family, identity and location detail visible only to professionals with a case-scoped, permission-checked reason to see it.
- Highly restricted — sensitive protection notes, certain evidence, and security investigations, visible only with an explicit elevated permission and a recorded reason.
Access to any of the above requires server-side authorization tied to your role, your organization, and — for case data — an active assignment to that case. Holding a technical administrator account does not by itself grant access to case content, and sensitive access is itself logged.
4. Publication and public search
A case is never published automatically. Publication follows a defined workflow: a request, a documented safeguarding review (covering whether identity fields are minimized, location is generalized, any photograph is appropriate, and risk of harm has been considered), and an authorized approval, before anything appears publicly. A published profile is withdrawn immediately when a child is located or a case is closed, and expires automatically after a limited period if not renewed. Public search never queries private case records directly — it reads only from the approved public projection.
5. Matching and automated processing
When comparing a missing-child case against found/separated-child cases, ChildTrace uses deterministic and structured-similarity comparison (name, age, sex, location, timing, descriptors) to produce a prioritized candidate list for human reviewers. This is decision support, not decision-making: no automated process establishes identity, parentage, guilt, or the safety of a reunification. Every match must be confirmed or rejected by an authorized professional, and every reunification requires a documented safety assessment and human approval.
6. Sharing and disclosure
We share information only:
- with the authorized professionals and organizations assigned to a case, scoped to what their role requires;
- with an approved partner institution (such as a child-protection authority, police unit, hospital, shelter or civil-registration office) under a defined referral or data-sharing arrangement, limited to the minimum necessary data;
- in the deliberately generalized form described above, where a case has completed the publication workflow;
- where required by law, or to protect the safety of a child or another person in an emergency.
We do not sell personal data, and we do not use case or child information for advertising or unrelated profiling.
7. Retention
Retention periods differ by data category — for example, temporary draft submissions, active case records, closed case records, evidence, and audit/security logs are each governed by their own retention rule rather than one blanket period. A public alert expiring or being withdrawn does not, by itself, delete the underlying case record; case and audit history is preserved for accountability and safeguarding purposes even after a case is closed, subject to applicable legal and safeguarding holds.
8. Security
Access is authorized server-side for every request; sensitive actions (verifying a case, approving publication, approving reunification, downloading evidence) are individually audited in a tamper-evident log. Evidence files are stored outside public web paths, downloaded only with an authorized reason, and never exposed through public or signed public links. We apply rate limiting and anti-scraping controls to public endpoints to prevent bulk collection of case information.
9. Your choices and rights
Depending on your role and applicable law, you may be able to request access to, correction of, or restriction of information ChildTrace holds about you, subject to child-safeguarding and legal exceptions (for example, information cannot be altered or removed where doing so would compromise an active safeguarding matter, a legal hold, or the integrity of an audit record). To make a request, use the contact option on the help page, or your organization's data protection point of contact if you hold a professional account.
A public sighting can be submitted anonymously. Providing contact details is optional but helps responders follow up.
10. Children's participation
Where a child interacts with age-appropriate ChildTrace workflows, we collect the minimum information needed, use accessible language, and provide clear paths to a trusted adult. Sensitive adult case notes are never exposed directly to a child.
11. Changes to this notice
We may update this notice as the platform, its governance, or applicable law changes. Material changes will be reflected here with an updated date.
Questions about this page? Contact your organization's data protection point of contact, or reach ChildTrace through the help & safety page.