Privacy policy

How Stoneglow Digital handles personal information in ClinicTrace Australia.

Version 1.0 · 21 September 2026

This describes how ClinicTrace works today. Where it and the product disagree, tell us: one of them is wrong and we would rather fix it than argue about it.

The short version

ClinicTrace holds a clinic's compliance paperwork. It holds no patient information at all, and there is nowhere in it to put any.

The personal information it does hold is about the people who work at the clinic: their names, their work email addresses, their professional registration details and the training and credential records the clinic keeps about them.

It is stored in Sydney. Email is the one part that leaves Australia, and that is set out below.

We handle all of it in line with the Australian Privacy Principles. Stoneglow Digital is a small business, and we commit to the Principles as a matter of contract with you rather than waiting to be told we have to.

What we collect, and why

About the people who use the product:

About the clinic's practitioners, whether or not they use the product:

About the clinic itself: its name, address, ABN, the registers it keeps, the logs it records, the documents it holds and the files it uploads.

We collect all of it because the clinic asked us to hold it. We do not collect it for any other purpose and we do not use it for any other purpose.

Most of it we collect from the clinic rather than from the person it is about. If you are a practitioner and your clinic has recorded you here, the clinic gave us that information, and this policy tells you what we do with it.

What we do not collect

No patient information. Not a name, not a date of birth, not a Medicare number, not a clinical detail. There is no field in the data model that could hold one and we will not add one. If a clinic uploads a document containing patient details it is a breach of the terms of service, and we will help remove it.

No payment card details. Invoices are paid outside the product and we never see a card number.

No government identifiers. We do not collect or use a tax file number, a Medicare number or a driver licence number, and we do not use any government identifier as our own reference for a person. A practitioner's AHPRA registration number is a professional registration and is recorded because the clinic tracks its renewal, not as an identifier for them.

No tracking of you across other websites. The product sets the cookies it needs to keep you signed in and nothing else. There is no advertising pixel and no third-party analytics in the application.

Dealing with us without giving a name

You can ask us a general question about the product without identifying yourself, and we will answer.

You cannot use the product anonymously or under a false name. The whole point of the activity log is that it says who did what, and a log of actions by unnamed people is not a record any assessor would accept. So an account carries a real name and a real work email address.

One thing worth knowing about staff records

Some of the records a clinic keeps about its own staff are health information about those people. A staff immunisation record is the usual example.

Health information is sensitive information and carries a higher standard of handling than an email address does. If your clinic uploads records of that kind, that standard applies to them, and the people they are about should know the records are held here.

We treat everything in the product to the same standard regardless, but the decision to upload a record like that is your clinic's and so is the obligation to be open with the person about it.

Who else touches it

Running the product needs a small number of suppliers. Each one is here because the product cannot work without it, and none of them may use what they hold for their own purposes.

We do not sell personal information, we do not disclose it for marketing, and we do not use it to train any model.

We would disclose information if the law required it, for example under a warrant or a court order. If that happened and we were allowed to tell you, we would.

If we change a supplier we will keep the storage of clinic records in Australia and tell clinics before it happens.

Marketing

The emails the product sends are the ones it has to send: a sign-in link when someone asks for one, and a reminder when a record is falling due. They are not marketing and there is no way to opt out of them while holding an account, because an account you cannot sign in to is not useful to anybody.

We may email the clinic about the product itself: a change to these terms, a change to how it works, an incident, or an invoice. Those are service messages.

If we ever want to send you something that is marketing, we will ask first, and every one will carry a way to stop it. We do not sell or rent contact details to anyone.

What leaves Australia, and what does not

Your records, your uploaded files and the backups of both are stored in Sydney and stay there.

Email does not. Sign-in links and expiry reminders are sent through Resend, which has no Australian region and sends from Tokyo. What passes through it is the email: the clinic name, the recipient's address and the names and dates of the records that are falling due. It is not your documents and it is not your files.

The nightly backup job runs on GitHub's infrastructure, which is outside Australia, on the way to a bucket in Sydney. The records pass through it and are not stored there.

We have told you this because Australian Privacy Principle 8 says an overseas disclosure has to be disclosed, and because a clinic asked about data residency deserves the whole answer rather than the flattering half of it.

How it is protected

Every clinic's records are separated at the database rather than in the application. A query from one clinic cannot return another clinic's rows even if the application asks it to, because the database refuses rather than the code remembering to filter. That rule is tested on every table on every test run.

Uploaded files are held in a private store and are never public. They are reached through a link that is signed for the person asking and expires.

There are no passwords. Sign-in is a one-time link to the email address on the account, and owners and administrators must also have a second factor.

The activity log is append-only, enforced by the database. Nobody can edit or delete an entry, including us.

Backups run nightly to a separate account, and restoring from one is tested rather than assumed. What each test established is written down in words.

Access on our side is limited to what is needed to run the service, and every change made inside a clinic's account appears in that clinic's own activity log.

No system is perfect and we would rather say that than imply otherwise.

Keeping it accurate

Most of what we hold is entered by your clinic, so your clinic is best placed to keep it right, and can change nearly all of it directly in the product.

We do not verify what a clinic enters against any register. A registration number recorded here is the number the clinic typed, and a renewal date is the date the clinic recorded. The product tracks them; it does not confirm them.

If something we hold about you is wrong and you cannot change it yourself, tell us and we will correct it.

How long we keep it

For as long as the clinic's subscription runs, and for 30 days after it ends so that nothing is lost while someone is away.

After that the clinic is erased. The erasure is permanent and takes the records, the files and the activity log together. What was erased and when is recorded outside the data it destroys, so we can show it happened.

Copies of it exist in the nightly backups until those backups are rotated out, which is within 35 days. The backup will not run at all against a store that does not delete on that schedule, so this is enforced rather than promised.

One person can be removed at any time without erasing the clinic. Their entries in the activity log remain, because a log that can be edited to remove a person is not a log.

Seeing it and correcting it

Anyone in the clinic can produce a complete export of the clinic's records from inside the product at any time. It needs no request to us.

If you want to know what personal information we hold about you specifically, ask and we will tell you. If it is wrong, tell us and we will correct it. We will answer within 30 days and normally much sooner.

We do not charge for either. If we ever refuse a request, we will tell you why in writing and how to complain about it.

If something goes wrong with it

We have a written plan for a data breach and we wrote it before we needed it. If we become aware of one, we contain it, work out what was reached, and tell the clinics affected.

Where a breach is likely to cause serious harm to the people whose information it was, we will notify them and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme.

We will tell you what happened, what it means for you and what we have changed, and we will not wait until we know everything before telling you something.

Complaining

Tell us first. Write to Stoneglow Digital, Brisbane, Queensland, or use the address on your invoice. We will acknowledge within five business days and answer within 30 days.

If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.

Changes to this policy

We will tell clinics before a change that matters takes effect. Every version carries a version number and a date and we keep the old ones. Ask and we will send you the version that applied on any date.

ClinicTrace Australia is supplied by Stoneglow Digital, ABN 98 279 841 620, Brisbane, Queensland.
Terms of service · Service status