DRAFT — not legal advice, not yet reviewed by a lawyer.
Drafted 10 August 2026. Do not publish as final until a lawyer has reviewed it.
This is the working draft we hold ourselves to today. The highlighted gaps below are the parts still to be filled in, and we'd rather show you they're missing than make something up.
Last updated: 20 September 2026
1. Who we are, and what we are not
CareReady is Australian software for independent NDIS support workers. It helps you run your own business — your participants, your shifts, your notes, your invoicing, your records.
CareReady is not an NDIS provider. We are not registered with the NDIS Quality and Safeguards Commission, we are not endorsed or approved by the NDIA, and we do not deliver supports to anybody. You do. We are the software you use to keep track of it.
That distinction runs through this whole policy, because it decides who is responsible for what:
- You have the relationship with the participant. You have obligations under the NDIS Code of Conduct, including to respect their privacy. If you are a registered provider, you have more obligations again.
- We hold the information you put into the app, and we have our own obligations for keeping it safe, being honest about what we do with it, and telling you if something goes wrong.
One thing worth knowing, because most support workers don't. The Privacy Act has a small business exemption for businesses turning over $3 million or less — but that exemption does not apply to a business that provides a health service and holds health information. Care for a person with a disability counts as a health service, and your care notes are health information. That means you are very likely covered by the Privacy Act and the Australian Privacy Principles personally, no matter how small your business is. State health records laws may apply to you as well, and those have no small business exemption at all.
We are not giving you legal advice about your own position, and you should check it. But we would rather say it out loud than let you assume the app handles it for you. It doesn't. Using CareReady does not discharge your obligations — it helps you meet them.
CareReady itself complies with the Australian Privacy Principles as though we are fully covered, and we do not rely on the small business exemption.
Who we are, legally: CareReady is operated by AHTI Group Pty Ltd (ABN 65 702 401 634, ACN 702 401 634), an Australian proprietary company registered in Queensland, which holds CareReady as a registered business name.
Contact us about privacy: privacy@careready.com.au, monitored by the founding directors — or use our contact form, linked from every page of this site, which works right now even while that inbox is being set up. A postal address will be added here shortly.
2. What information we collect and hold
This section is the honest, complete list. It is longer than most privacy policies because we would rather name everything than write "and other information".
2.1 If you sign up as a support worker
Your account and business details. Your email address and password (stored as a cryptographic hash, never in readable form), your name or business name, ABN, phone, address, suburb, state and postcode, whether you are registered for GST, your invoice numbering settings, and a profile photo if you upload one.
Your bank details for getting paid. BSB, account number and account name. These are so your invoices show a participant, plan manager or plan nominee where to pay you. We do not move money, we do not debit anything, and these details are not used for your CareReady subscription.
Your business records. The services you offer and your rates, your bookings and rosters, your invoices and invoice lines, and your business expenses including receipt photos.
Your credentials. Compliance documents you record — NDIS worker screening, police check, first aid, insurance, driver licence, identity documents and similar — including the document type, the reference or certificate number you enter, issue and expiry dates, and the file itself if you upload one.
Policies you adopt. If you use the policy templates in the app, we hold the version you adopted and when.
Location, at check-in/check-out, and if you switch on "Track drive." When you tap check in or check out on a shift, the app asks your device for your location at that moment and stores the coordinates against that shift. Some bookings also let you switch on "Track drive," which works out how far you drove by asking your device for your location repeatedly while it runs — but it only ever stores the resulting kilometre total, never the individual coordinates it used to get there. Four things about this:
- In the browser, both only happen when you act: tapping check in or check out, or tapping Start on Track drive. Track drive stops the moment your screen locks or you leave the app — a limitation of how browsers work, not a choice we made — and it never runs silently or without you switching it on for that shift. The phone app, from version 1.1, can also record your travel through a whole shift with the screen off, but only if you turn that on yourself. Section 8 sets out exactly how it works; it stays off on your phone until you turn it on there, and a phone still running an earlier version of the app cannot do it at all, so the option does not appear on it.
- You can refuse the location permission, or leave it off entirely, and everything else in the app still works. You can use CareReady without ever checking in or using Track drive.
- The stored check-in/check-out coordinates are exact, not approximate, and the app shows them to you as a Google Maps link. Opening that link sends the coordinate to Google, in the same way any map link does.
- We also record whether a location was actually taken, and if not, why not. Against each check-in and check-out we store one of three words: that a location was recorded, that you declined the permission, or that your phone could not get a fix. This is about the app, not about you, and it exists so a shift can never appear to have a location it does not have — a record that stays silent about a refused permission reads as though nothing was ever asked. It is shown to you on the shift, and nothing about it changes what the app does if you say no: the shift is still recorded, and everything else works.
How your travel kilometres were arrived at. Where a shift has travel kilometres on it, we also store one word saying where the figure came from: measured by the phone app across the whole shift, measured by Track drive while the app was open, estimated from the straight line between your check-in and check-out, or entered by you. Travel is billed to a plan and can be claimed at the ATO's cents-per-kilometre rate, so a figure that can say where it came from is worth more to you than one that cannot. It is not a location and it is never shown to participants or their families.
Because a shift usually happens where the participant lives, a check-in coordinate can effectively record a participant's home address. We treat these coordinates as sensitive in practice even though the law does not classify location as sensitive information, and we say so again in section 8.
Technical information. Server logs recording that a request happened — timestamps, error details, and enough to keep the service running and diagnose faults. Section 4 explains where those logs sit.
If you use the CareReady phone app: a notification token for your device. The phone app (on the App Store for iPhone; Android to follow) lets you turn on booking reminders in Settings. Doing that registers your phone with Apple's or Google's notification service and stores the resulting device token against your account. The token is an opaque identifier for delivering notifications to that one phone — it is not your location, not your contacts, and not readable as anything about you. It only exists if you turn the feature on, and turning it off deletes it.
2.2 Information you enter about the participants you support
You control what goes in here. What the app can hold is:
Identity and contact. First and last name, date of birth, NDIS number, gender, pronouns, phone, email, preferred contact method, address, suburb, postcode, state, language, and a photo if you upload one.
Their plan. Plan type, plan start and end dates, plan budget, who pays your invoices, and plan manager name and email. Also, if you record it, a plan balance somebody has told you — the amount, the date it was true as at, and who told you — so the app can work out what is really left rather than counting only your own invoices.
Support and care information. Diagnoses, support needs, communication notes and whether an interpreter is required, dietary requirements, triggers, things they struggle with, support preferences, goals, interests, likes, dislikes, activity preferences, and any special notes you record.
Records of the work. Session and progress notes including your rating and what you worked on, incident records, complaints and feedback you log, messages in the participant message thread, and service agreements including who signed and when.
Voice memos you record about a session. When you write up a note you can record a voice memo instead of typing everything, and play it back while you check the written note over. The recording is held with the unconfirmed draft, in our Sydney storage like every other file you upload, reachable only through a short-lived private link. It is deleted the moment you confirm the note — the written note is the record, and we would rather not build up a library of recordings of your shifts. Deleting the draft instead deletes the recording with it. Nothing transcribes the audio and nobody outside CareReady's own storage receives it: it is not sent to any transcription service, any model, or any other company. If you are using the signed-out demo, a recording never leaves your own browser at all.
Their people. Names, relationships, phone numbers and email addresses of emergency contacts, family members, guardians and nominees you record. These are people who never signed up to CareReady, and their details are personal information too.
Whether they identify as Aboriginal or Torres Strait Islander, if you choose to record it.
Some of your messages are written by the app, not by you. When you check in or check out, the app posts a line into the participant message thread noting the time and that a location was recorded.
All of this is sensitive information under the Privacy Act. Health, disability and support-need information is sensitive. So, separately, is information about a person's racial or ethnic origin — which is exactly what Aboriginal and Torres Strait Islander status is, and why we name it rather than leaving it implied. An NDIS number and a date of birth are not "sensitive" by that legal definition, but they are identity-theft grade and in this context they reveal that someone has a disability.
Sensitive information needs the person's consent before it is collected. We never meet your participants, so we cannot get that consent — only you can. Before you enter a participant's information into CareReady, you should have their consent, or the consent of their guardian, nominee or other substitute decision-maker if they cannot give it themselves. The optional fields above are genuinely optional: a participant can agree to you recording their diagnoses and refuse to have their Aboriginal or Torres Strait Islander status recorded, and you should record only what you actually need for the support you provide.
2.3 If you work through an organisation
Your membership of that organisation, your role in it (owner, coordinator or worker), your membership status, and when you joined. If someone invited you, we hold the invitation — the email address it was sent to, who sent it, when it expires, whether it was accepted or revoked, and if it is a family or nominee invitation, which participant it relates to. Invitations are kept even after they are accepted, revoked or expired, so there is a record of who was given access to what.
2.4 If you publish a profile to CareReady Connect
CareReady Connect is an opt-in public directory of support workers. It is off unless you switch it on. If you do switch it on, the following becomes visible to anyone on the internet, signed in or not: your business name, suburb, state, profile photo, bio, qualifications, the names of the services you offer, your travel radius and general availability, your contact email address, your phone number if you choose to show it, and simple yes/no badges for whether you hold a current screening check, first aid certificate and insurance.
What is never published: your bank details, your ABN, your GST status, your rates, the reference numbers or files behind your credentials, and anything at all about your participants. Turning the listing off removes you from the directory.
Connect is a listing, not a booking or matching service. We do not broker work, take a fee for introductions, or run a matching algorithm.
2.5 If you contact us or put your name down for the trial
Contact form. Your name, email address, the topic you pick and the message you write.
Waitlist or free trial enquiry. Your name, email address, phone number, anything you write in the message box, and which campaign or page you came from.
Notes from talking to you. If we ring you about the trial, we keep a record of what stage you are at, notes of the conversation, and if it doesn't go ahead, why. These notes are about you and you can ask to see them (section 9).
These records are separate from the app. They contain no participant information, they are never linked to any participant record, and only CareReady team members can read them. They are also not deleted when you close a CareReady account — see section 7.
3. Why we collect it, and what we do with it
Your business and participant records exist so you can run your support work — keep track of shifts and notes, invoice correctly, hold the documents you are expected to hold, and have a record if something is ever questioned. We hold them for you. We do not read them, mine them, analyse them, or use them to train anything.
Your account details exist so you can log in, so we can bill you, and so we can contact you about the service.
Location at check-in and check-out exists to give you and the participant a record that the shift happened when and where you say it did.
Contact and waitlist details exist so we can reply to you or ring you about the trial you asked about.
Technical logs exist so we can keep the service running, find faults, and investigate security incidents.
We do not sell personal information. Ever. We do not share participant information with anyone for marketing, and we do not use participant information for our own marketing or research.
Automated decision-making. CareReady does not make any computer decision that significantly affects a person's rights or interests. It calculates figures — a total, a GST position, an estimate of tax — from what you enter, and a human, you, checks and acts on anything that matters. If that ever changes — the app auto-flags an incident, scores a risk, or produces a figure someone relies on without a person checking it first — we will describe the change here, in plain language, before it ships, not after.
4. Where your information is stored, and who else touches it
Your records are stored in a Supabase database in Sydney, Australia (Supabase runs its Sydney region on AWS infrastructure — the same fact our website states as "stored securely on AWS in Sydney"). The application servers that read and write that database run in Sydney too, and that is pinned in two separate places in our code. Uploaded files sit in private storage in the same place.
One small part of our app is not pinned, and we would rather tell you than have it be a surprise. There is a piece of code that runs on every request whose only job is to stop you being logged out while you are still working. We have no way to choose where it runs, and we tried. It handles your login session, not your records: it never reads a participant's notes, incidents, invoices or plan. All of that is read by the parts that are pinned to Sydney. So the honest summary is that a login token may pass through a server outside Australia, and participant health information does not.
How that pin is checked, and how far it has got. A configuration file saying "Sydney" and a server actually being in Sydney are two different claims, so two checks were written. The first reads our own settings and fails if the Sydney pin is ever removed; it works, and it is run by hand, because the automation that would run it on every change has never been installed. Since 16 August 2026 that check covers both places the region is declared, which is why there are two: one is a deployment setting and one is written into the application itself, so an edit that loses one does not quietly move where your records are processed. The second check is the one that matters — it runs inside the live service, reads the region the server actually ran in, and reports a failure if production is ever served from anywhere else. That check has not run yet, not once. It is built, it is scheduled for 7am daily, and it spent every day until now refusing its own scheduler because a required secret was unset. That secret was set on 10 August 2026, and the check will start running from the next deployment of the app.
So the honest position today: the region is pinned in configuration and reviewed by hand, and daily verification by the running service is built and waiting on that deployment rather than already happening. When it has run we will say so here. Section 5 of our security statement tracks it.
Your records don't leave Australia. By "your records" we mean the database — every participant record, note, incident, invoice, document and coordinate. If that ever changes we will update this policy and tell you before it happens.
Three things are honestly more complicated than that sentence, and we would rather name them than let you assume:
Server logs. Our hosting provider, Vercel, runs our application code in Sydney, but it is a United States company and the operational logs it keeps for us are part of its platform rather than something we host. Those logs record that requests happened and what went wrong. They are not a copy of your records. We are on a plan that gives us no way to choose where those logs are kept, so rather than claim something about them that is not in our control, we keep personal details out of them: as of 16 August 2026 our public contact form no longer writes the sender's name, email address or message into the log when the message has been saved to the database in Sydney. It writes those details only in the one case where the save failed and the log line is the only remaining copy of that person having written to us, because losing somebody's message would be the worse outcome.
Email. When you email an invoice, a reminder or a service agreement from the app, it goes out through an email provider, and that email contains what you would expect — the participant's name, the supports and dates you are billing for, and the amount. Email is not a private channel, from any system. If you would rather not send anything that way, every invoice downloads as a PDF you can send however you like. Outbound email is switched on as of 16 August 2026. It leaves through CareReady's own Google Workspace mailbox rather than a separate email delivery company, so the only additional company involved is Google, which is a United States company. Mail in transit and in the sending mailbox therefore leaves Australia, which is true of email generally and is why the PDF option exists.
Error reporting. When something breaks we use an error-reporting service, Sentry, so we find out and fix it. It receives technical detail about the failure: what went wrong, on which screen, and the kind of browser or phone. When an email fails to send it also receives the domain of the address we were writing to — the part after the @, for example gmail.com — so we can tell whether a whole mail provider is rejecting us. It does not receive the address itself, the subject line, or participant health or care notes. This is switched on, and the reports are stored in the European Union (Germany).
The full list of every company that touches data, what each one gets, and where it sits, is in our subprocessor list at docs/legal/SUBPROCESSORS.md. That document is kept current and is the one to ask for if you are assessing us.
5. Who can see your information
You see your own participants' records. Nobody else does.
Other support workers cannot see your participants' information. There is no shared pool of participant records. This is enforced by rules inside the database, so it does not depend on the app remembering to be careful.
How that is tested. There is a test that tries to break the separation: it signs in as two real accounts, writes a record as one, and then tries to read, change, delete or forge it using the other account's own session. One leaked row on one table fails the whole run. It covers 31 tables, including every table holding participant data — participants and their contacts, session notes, incidents, messages, agreements, invoices, compliance documents and expenses — plus the four narrowed views an organisation coordinator reads (section 5), where it additionally checks that each withheld field is genuinely not there rather than merely empty.
Two things about its standing, because a test's existence and a test's running are different facts:
- It runs automatically now — daily, and on any change to the database layer. It used to run only when a person typed the command, because the file that would run it in our build system could not be installed from where the code is developed. That was fixed on 14 August 2026.
- It has been run against the live database, and no leak was found — on any table, by reading, changing, deleting or forging. The last run, 17 August 2026, checked 155 separate questions and every one came back the way it should. An earlier version of this section had to record that one table (
contact_enquiries, the public contact form) came back as "couldn't check" rather than as a pass, which by this test's own rule fails the whole run — a check that did not happen must never be recorded as a check that passed. That probe was rewritten and has now been run: it passes, and nothing is left unproven. - Invitations are covered. An invitation record holds the email address it was sent to, who sent it, its status, and for a family or nominee invitation, which participant it relates to. It holds no health or care notes.
Section 4 of our security statement describes the test in full and section 8 lists what is not done yet.
If you work through an organisation that uses CareReady for its workforce, a coordinator or owner at that organisation can see a defined set of your information. The width of it is the point of this section, so here is the whole list:
- Your name, business name, photo, bio and qualifications. Not your bank details — not the BSB, not the account number, not the account name. Not your ABN, not your GST registration, not your home address, not your invoice numbering.
- Your credentials: which kind each one is, what it is called, and the issue and expiry dates. Not the reference or certificate number you typed in, and not the document you uploaded.
- Your shifts that are tagged to that organisation: when they were scheduled, when you actually clocked on and off, whether the shift went ahead, and which service it was. Not which participant the shift was for. Not anything you wrote about it. Not your check-in or check-out coordinates, and not the suburbs your travel claim runs between. Work that is not tagged to the organisation stays yours alone.
- Your invoices that are tagged to that organisation: the number, the dates, whether it has been paid, and the amounts. Not which participant it was for, not the address it was sent to, and not the individual lines.
- Your services that are tagged to that organisation — what you call each one, its NDIS item number and its fee. This is your price list for that organisation's work, not a participant record.
- Your membership record — your role, your status, and when you joined.
This list got shorter on 17 August 2026, and it is worth saying what it used to be. Until then a coordinator could read your whole profile record including your bank details, your whole credential records including certificate numbers and the uploaded files, and — on any shift tagged to the organisation — which participant it was for, whatever you had written about it, and the exact coordinates where you checked in and out. The database rule granting that access could only ever choose which *rows* a coordinator sees, never which *fields*, so it handed over the whole row; the app then displayed a small part of it. Every one of those fields is now genuinely unreachable, because a coordinator reads through a fixed list of columns in the database rather than through the record itself. Nothing suggests any of it was ever looked at — organisations are a preview feature with one test organisation on it — but "nobody used it" is not the same as "it was not available", and you were told the wider version, so you are being told the narrower one.
What is still wider than it should be, and we would rather write it here than have you discover it. The profile and credential access above is keyed to your *membership* of the organisation, not to the work you do for it: a coordinator sees the expiry dates of every credential you hold in CareReady, including ones that have nothing to do with that organisation. Narrowing that remains an open item in section 8 of our security statement.
What a coordinator cannot see is your participants. Not their names, not their notes, not their health information, not their incidents, not their messages, not their agreements, not their contacts. Those tables have no coordinator read path at all — the wall is the absence of any rule granting access, not a filter that could be got around.
If you are independent and not part of an organisation, none of this applies. Nobody else sees anything. That now rests on a specific rule in the database rather than on nobody trying: an account may only ever add itself to an organisation. One account putting another account into its organisation is not something the interface can do at all. Joining happens by invitation, which you accept yourself — so nobody can pull you into an organisation you never joined and then read the things listed above.
CareReady staff. As a matter of policy, our team does not read participant health and care records. We may look at account-level information — whether an account exists, its billing status, an error — to run the service and support you. We hold an administrative database key that technically bypasses the database rules described above, because somebody has to be able to run migrations, restore a backup and action a deletion request. Access to that key is restricted to the founding directors. Its use is not yet automatically logged — building that log is tracked as an open item on our public system map at /system — and until it is, use of the key is governed by the same commitment as the rest of this section: our team does not read participant health and care records, and the key exists to run the service, not to look at yours.
Everyone else. We disclose personal information outside CareReady only where the law requires or authorises it (for example a lawful request from a court, a regulator or police), where it is needed to investigate a security incident, or where you have asked us to look at a specific problem and given us permission.
We never sell personal information and we never share participant information for marketing.
6. Overseas disclosure
We do not store your records overseas. Some of the companies that help us run the service are based overseas or are subsidiaries of overseas companies, and to the extent they receive any personal information, the likely countries are:
| What | Who | Likely country |
|---|---|---|
| Database, authentication, file storage | Supabase | Australia (Sydney region). Supabase is a US company. |
| Application hosting and platform logs | Vercel | Code runs in Australia (Sydney). Vercel is a US company and platform logs are held on its infrastructure. |
| Outbound email (switched on 16 August 2026) | Google Workspace, CareReady's own mailbox | United States |
| Outbound email, alternative transport (not switched on) | Resend | United States |
| Error reporting (switched on) | Sentry | European Union (Germany). Sentry is a United States company; CareReady's project is in its EU region. |
docs/legal/SUBPROCESSORS.md carries the detail, including exactly what each one receives.
7. How long we keep information
Your retention obligations and ours are different things. Ours are in this section. Yours depend on who you are, and we set out what we understand below so you can check it — it is not advice about your situation.
What may apply to you:
- Registered NDIS providers must keep incident records for seven years from the day the record is made, reportable incident records for seven years from notification, and complaint records for seven years. These come from the NDIS incident management and complaints rules, and they apply because of registration.
- Every NDIS provider and worker, registered or not, is bound by the NDIS Code of Conduct. The Code sets no retention period at all.
- State health records laws may separately require you to keep participant health information for seven years from the last service, and for a participant who was under 18, until they turn 25. New South Wales and Victoria both have laws of this kind, and they apply regardless of how small your business is.
- Tax records are generally five years under ATO rules.
What CareReady does:
- We keep your records for as long as your account is open, and we do not delete anything automatically. There is no expiry, no archiving job, no pruning. The one exception is a voice memo (section 2.2): it is deleted when you confirm the note it belongs to, or when you delete the draft. That is the only thing in the product that removes itself, and it does so because keeping recordings of people's shifts around is a decision that should be made deliberately rather than by default.
- You can delete individual records yourself — a participant, a booking, an invoice — from inside the app, and that deletion is immediate and permanent. There is no undo and no recycle bin. Because you may be under a legal obligation to keep some of those records, think before you delete, and export first if you are unsure.
- Case notes work differently, and here is exactly how. A case note is evidence: a support coordinator may put it in front of a planner, and a plan manager can ask for it. So it can be freely changed for a short while and then only added to, never rewritten. - While it is less than 24 hours old and nothing has relied on it yet, you can edit every word of it, or delete it outright — immediately and permanently, like any other record. "Relied on" means something outside the note has come to depend on it: you have invoiced the shift it belongs to, or the note has gone out in a data export. Whichever happens first ends the free period, so a note you billed for an hour after writing it is settled straight away. - After that you can still correct it, by amendment. Your correction is added underneath the note with your name and the time on it, and the original stays exactly as you wrote it. This is deliberate and it protects you: a record that can be quietly rewritten after somebody has read it is worth nothing as evidence, and a correction that hides what it corrected looks worse than the mistake. - A note that should never have existed can be withdrawn. It is struck through, your reason is recorded against it, and it stays on the record rather than disappearing — because something was invoiced or handed over on the strength of it, and erasing it would erase that too. If a note genuinely has to be removed after that point, ask us (section 9) and a person will handle it, including telling you if a record-keeping obligation means we cannot. - We keep the original words you typed or dictated alongside the tidied-up note, and you can see them at any time under "View original" on the participant's timeline.
- Closing your account does not delete your data by itself. See section 9. From 27 August 2026, NDIS law specifically requires records relating to a claim — your invoices, and the bookings billed on them — to be kept for seven years from the date of the claim, even after your account is closed, so we retain exactly those records for that long and remove the rest.
- Contact enquiries, waitlist entries and our notes about talking to you are kept separately and are not removed when a CareReady account is deleted. If you want those removed too, say so, and we will handle it as part of the same request.
- Invitation records are kept after they are accepted, revoked or expired.
8. Location information, specifically
We are pulling this out of the other sections because it deserves its own paragraph.
Check-in and check-out coordinates are exact. Combined with a participant's identity, they can reveal where a person with a disability lives, and that makes them one of the more sensitive things in the app even though the law does not formally classify location as sensitive information. We treat them accordingly: they are covered by the same database isolation as participant records, they are included in any breach assessment as a high-harm category, and nobody but you can read them — including, since 17 August 2026, a coordinator at an organisation you work through. Section 5 sets out what changed and why we are telling you rather than quietly narrowing it.
You can avoid creating them entirely by not using check-in and check-out, or by declining the location permission on your device.
Background location — in the phone app, off until you turn it on. In a browser we do not track your location in the background and cannot: "Track drive," described above, only asks for your location while you have it switched on, the app is open, and your screen is on. A phone will not report your location to a website in any other state, which is a rule of how browsers work rather than a choice we made.
The phone app is different, because a proper phone app is the only kind that can read location with the screen off — which is the whole reason it exists, since a support worker drives with the phone in a pocket and a kilometre figure that stops when the screen locks is simply wrong. That feature is available from version 1.1 of the phone app. The first App Store release, 1.0, could not read location in the background at all — the capability was not in that build — and on a phone still running it the option does not appear, so nothing can be switched on there by mistake. Kilometres also still work three ways without it: typing them in, the one-tap estimate from your check-in and check-out, and "Track drive" while the app is open. Everything below is the standing promise of how it works — written before the feature, kept after it:
It will only ever run if you turn it on, on that phone. Turning it on means opening Settings, reading a consent screen that states these same terms line by line, and ticking every one of them. Until you do, nothing tracks. (On a version of the app that cannot do it, that consent screen does not appear at all.) It is per-phone, like the location permission itself, and you can turn it off again at any time from the same screen and go straight back to manual kilometre entry, with no effect on anything else in your account.
When it is on, this is the whole of it:
- It runs only between checking in and checking out of a shift you started yourself. Never all-day, never outside a shift, never on a shift you did not start.
- Your phone shows a visible, ongoing notification the entire time it is running, so you always know when it is on. On Android that notification is required by the operating system and we could not hide it if we wanted to.
- At check-out the app keeps only the kilometre total. The individual location points it used to work that total out live in the app's memory during the shift and are discarded the moment the total is calculated. They are never written to your phone's storage and they are never sent to us. Exactly as with "Track drive" above, there is no route, no trail, and no map of your day.
- If the app is shut down by your phone mid-shift, those points go with it and there are no kilometres to bring across. The app says so at check-out rather than showing you a zero.
One honest limitation on availability: the phone app is on the Apple App Store but not yet on Google Play, and background tracking needs version 1.1 of it or later. Nothing about your account changes either way, and nothing about the browser version changes at all.
9. Accessing, correcting and deleting your information
Access. Go to Settings → Your data in the app. It downloads your business profile, your participants and their contacts, services, bookings, invoices, compliance documents, agreements, session notes, messages, incidents, expenses and adopted policies — as spreadsheets (one CSV file per kind of record, zipped), as a complete data file, and as a plain-English summary you can actually read. All three are built from the same record, so they cannot disagree.
Being straight about what that download does not include: uploaded files themselves (photos and receipts come out as references, not the images), your organisation memberships, invitations you have sent, deletion requests you have made, and any contact, waitlist or call-note records we hold about you. If you want those, ask us and we will give them to you. We will give you everything we hold about you within a reasonable time, and we will tell you if there is anything we cannot give you and why.
Correction. Most things you can fix yourself in the app. Case notes have their own rules, set out in section 7 — briefly editable, then correctable by amendment, and withdrawable rather than deletable once something has relied on them. If you cannot fix something yourself, tell us and we will correct it. If we disagree that something is wrong, you can ask us to record a note of your view alongside it. If a participant or their family asks you to remove a case note that can no longer be deleted in the app, send that request to us at privacy@careready.com.au and a person will work through it with you.
Deletion. Settings → Delete my account files a request. It does not delete anything on the spot, and we would rather say that plainly than have you assume your data has gone. A person reviews the request and works through it. We aim to complete it within 30 days.
We may need to keep some information — for an open legal matter, or because a record-keeping obligation applies (section 7 names the seven-year rule for claim records). If that happens we will tell you what is being kept and why. Download your data first, so you have your own copy either way.
Closing your account also disconnects any Xero connection on our side, so nothing more can be pushed. Invoices already copied into your Xero organisation stay there, because they are your books; the grant itself is removed from your Xero under its Connected Apps screen, which only you can do.
Complaints. If you think we have mishandled personal information, tell us at privacy@careready.com.au, or through our contact form, and we will investigate. Here is what we will do: acknowledge you within 5 business days, look into it properly, and give you a written answer within 30 days telling you what we found and what we are doing about it. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992. You do not have to come to us first, but it is usually faster.
Anonymity. You can ask general questions without telling us who you are. You cannot use the app anonymously, because it holds records that have to be attributable to you.
10. If there is a data breach
If we become aware of a data breach likely to result in serious harm, we will contain it, assess it quickly, notify the OAIC and notify the people affected, telling them what happened, what information was involved and what to do about it.
One thing to understand about your position. If participant information held in your CareReady account is exposed, that is very likely a notifiable breach for you as well as for us, because you are the one who holds the relationship with those participants. Under the Notifiable Data Breaches scheme, where the same breach affects more than one organisation, notification by one can discharge the obligation for the others — but that only works if it is agreed in advance who does what. We will not leave you to work it out mid-incident: our plan is that we assess and notify the OAIC, and we support you to notify the participants affected, because you are the one who knows them and can reach them. Our full plan is in docs/DATA-BREACH-PLAN.md.
11. Security
Our security statement is at docs/legal/SECURITY-STATEMENT.md. In short: your data is separated from every other account by rules enforced inside the database rather than by application code; that separation is tested across every table holding participant data by a test that is run by hand rather than automatically (section 5 above); uploaded files are private and reachable only through short-lived signed links; and the hosting region is pinned to Sydney, with daily verification by the running service built and waiting on its first deployment rather than already running (section 4 above).
The security statement is deliberately explicit about which of those run today and which are built and not yet switched on, and its section 8 lists what is not done yet at all.
We rely on Supabase and Vercel for encryption of data in transit and at rest. Those are platform features we have not independently audited, and we say so rather than claiming a guarantee we have not checked.
We hold no security certification — no ISO 27001, no SOC 2, no NDIS-related accreditation of any kind. If that changes we will say so here.
No system is perfectly secure. We will keep improving this and the security statement records where we are.
12. Changes to this policy
We may update this policy. If we make a material change we will tell you inside the app or by email before it takes effect, and we will update the date at the top.
13. How to get this policy
This policy is on our website free of charge and is in the app. If you would like it in another form — a PDF, large print, or read to you over the phone — ask us and we will sort it out.
14. Contact us
Privacy queries, access requests, corrections and complaints:
privacy@careready.com.au — monitored by the founding directors, who are responsible for privacy at CareReady — or our contact form, linked from every page of this site, which always works. A postal address will be added here shortly (section 1).
Source of record: docs/PRIVACY-POLICY.md in the CareReady repository. Questions about anything on this page can go through our contact form.