Privacy Policy · YamoHQ
Legal

Privacy Policy

Effective 15 September 2026 · YamoHQ is a service of NestrCheck LLC

This statement explains what NestrCheck LLC, the parent company trading as YamoHQ, collects, why we collect it, who we pass it to in order to deliver the service, and how long we keep it. We collect little, we do not sell any of it, and we do not look inside your people’s devices. Where we act on your instruction as a service provider, you remain the controller of your employees’ data and we process it only to run the service you are paying for.

1. What we collect

From you directly: your name, work email, company, rough seat and device count, and whatever you write in the contact form or send us during setup.

Generated by running the service: order records and invoices, device serials and IMEI manifests, diagnostic and chain-of-custody documentation, asset assignment records, SaaS seat and licence state, device enrollment and policy status, and the support correspondence between us.

From your systems, with your authorisation: the directory and tenant data needed to provision and revoke access, such as names, work email addresses, roles, groups and employment status for the people you ask us to manage.

2. Why we collect it

To send the quote you asked for, to fulfil and document orders, to provision and revoke access, to author and verify device policy, to support your team, to invoice you, and to meet our own legal and tax obligations. That is the whole list. We do not build advertising profiles and we do not use your data to train anything.

3. What we never do

We do not sell, rent or trade your data. We do not read the contents of managed devices: management operates at the policy level, meaning enrollment, security settings, compliance state and remote lock or wipe, not your people’s messages, files, browsing or location beyond what a device policy check reports. If a support request needs us to see something on a device, we ask first and we say what we saw.

4. Who we share it with

Only what each party needs to deliver the service: our United States wholesale supply partner receives order and shipping details; the device management platform you use, such as Apple Business Manager, Microsoft Intune or a platform you already run, processes enrollment and policy data; identity providers such as Google Workspace, Microsoft Entra ID or Okta process the account changes we make on your behalf; carriers receive what is required to activate a line. Each operates under its own agreement with us or with you, and we share the minimum each one needs.

We may disclose information where the law requires it. If that ever happens in a way that affects you, we will tell you unless we are legally prohibited from doing so.

5. Employee privacy

The people whose accounts and devices we manage are your employees, not our customers, and we handle their data on your instruction only. We recommend telling them plainly what is managed, what a policy can see, and under what circumstances a device can be locked or wiped. We will help you write that notice if it is useful, and we will not action a request that appears designed to surveil an individual rather than secure a fleet.

6. Retention, security and your rights

We keep records for as long as the service and our legal obligations require, then delete them. Data is encrypted in transit and at rest with our providers, access inside YamoHQ is limited to the specialists who need it, and our own accounts are held to the same policies we write for you.

You can ask us to correct, export or delete your data, or the data of a person you manage, by emailing us. We will confirm what we hold, act on the request where we are able, and tell you plainly where a legal obligation requires us to keep something.

Questions about this statement go to hello@yamohq.com, and a person answers within one business day.