Skip to content
Clinical intelligence for the nursing floor Built for every career stageAustralia · 2026
Healthcare NotesClinical intelligence for the nursing floor
Log inOpen Floor Notes ↗
HEALTHCARE NOTES POLICY

Privacy Policy

This policy explains how Healthcare Notes collects, uses, discloses, secures and gives access to personal information connected with healthcarenotes.org.

Effective 14 August 2026Version 2.3.1Applies to healthcarenotes.org

Scope and privacy approach

Healthcare Notes is operated by the Australian business operating Healthcare Notes. This policy applies to visitors, members, group administrators, contributors and people who contact us.

Healthcare Notes is designed as a professional education and workflow-support platform. It is not intended to collect patient records. Users must not enter patient names, dates of birth, addresses, record numbers, photographs or other identifying clinical information.

Information we collect

We collect only information reasonably needed to provide and administer the service.

  • Account information, including name, email address, role and login credentials protected by WordPress.
  • Membership and entitlement information, including Stripe customer and subscription identifiers, plan, status and paid-period dates.
  • Profile preferences such as state, hospital name, ward, role and experience level.
  • Support, complaint, accessibility and contributor correspondence that you choose to send.
  • Security and technical records such as IP address, browser information, timestamps, error records and rate-limit events produced by hosting or security systems.
  • Learning records you intentionally save, including the activity, time claimed and reflective notes.

Payment information

Payments are completed through Stripe Checkout. Healthcare Notes does not receive or store full card numbers, card security codes or digital-wallet credentials. Stripe may provide limited transaction information such as payment status, card brand, last four digits, billing country and invoice identifiers.

Stripe handles payment information under its own privacy and security terms. Payment methods displayed at checkout depend on Stripe configuration, customer location and device eligibility.

Clinical workspace boundary

The Floor Notes Dashboard and Shift Lead Toolkit are designed to keep working text in the active browser session. This package does not intentionally save clinical drafts to WordPress, browser local storage, analytics or an external clinical system.

Temporary display can still involve handling information. Users must therefore use minimum necessary information, avoid identifiers, follow employer directions and close the workspace when finished.

Why we use information

  • Create and secure accounts; confirm entitlement; provide paid modules and group seats.
  • Process checkout, invoices, renewals, plan changes, failed-payment recovery and cancellation.
  • Personalise ward and learning navigation without inferring patient facts.
  • Respond to support, accessibility, privacy, billing and content-correction requests.
  • Maintain service security, prevent fraud and investigate misuse.
  • Meet legal, accounting, tax, dispute and recordkeeping obligations.
  • Improve aggregate product usability where analytics have been lawfully enabled.

Disclosure and service providers

Information may be disclosed to service providers only as reasonably required to operate Healthcare Notes, including WordPress hosting, Stripe, transactional email, security, backup and professional advisers. Providers may process data outside Australia. Their locations and contractual protections depend on the services configured by the operator.

We do not sell personal information. Group owners can see seat identity and membership assignment; they cannot see another nurse’s password, personal CPD reflection, Dashboard draft or Shift Lead session.

Retention and security

We retain account, subscription, transaction and correspondence records only for operational, security, legal and accounting needs. Retention periods vary by record type and applicable law. Expired records should be securely deleted or de-identified where lawful and practical.

Reasonable safeguards include HTTPS, role-based administration, signed Stripe webhooks, server-side secrets, secure password handling, restricted access, backups and logging. No internet service can guarantee absolute security.

Access, correction and choices

You may request access to or correction of personal information held about you, subject to lawful exceptions. You may update certain account and billing information directly. Marketing consent can be withdrawn using the unsubscribe method in the message; essential service messages may still be sent.

Send a privacy request to maxillarvundi@gmail.com. We may need to verify identity before acting.

Privacy complaints and changes

Privacy concerns are handled under the Complaints and Feedback Policy. If unresolved, eligible individuals may contact the Office of the Australian Information Commissioner.

This policy may be updated when the service, law or data practices change. Material changes will be identified by a new effective date and, where appropriate, communicated to members.

Authoritative references

Contact

Questions about this policy can be sent to maxillarvundi@gmail.com. Do not include patient information.