Privacy Policy

Last updated: June 2026

SimplyRefer ("we", "us") is committed to protecting your privacy and handling personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what we collect, why, and how we protect it.

1. Information we collect

  • Account information: name, email, clinic name, suburb, and role (GP, clinician, or clinic manager).
  • Clinician details: profession, specialty, location, AHPRA registration number, and availability.
  • Referral tokens: the anonymous referral references you generate or receive — the referring GP clinic name and reference only. No patient health information is collected.
  • Billing information: handled securely by our payment processor (Stripe); we do not store full card details.

2. How we use information

  • To operate the directory, verify AHPRA registration, and facilitate referrals.
  • To manage subscriptions, free trials, and billing.
  • To send service notifications (e.g. referral updates) and respond to support requests.
  • To maintain security and improve the Service.

3. Disclosure

Referral and clinician directory information is shared with the relevant participating professionals to deliver the Service. We use trusted third-party providers (such as Supabase for hosting/database, Stripe for payments, and an email provider for notifications). We do not sell your personal information.

4. Data security

We use access controls, row-level security, and encryption in transit (HTTPS) to protect your data. Access to administrative functions is restricted to authorised SimplyRefer staff. No method of transmission or storage is completely secure, but we take reasonable steps to safeguard your information.

5. Patient information

SimplyRefer is designed so that no patient health information is required or stored. Referrals use anonymous referral tokens — we record only the referring GP clinic name and a referral reference, never patient details. Any clinical information you share directly with another practitioner outside SimplyRefer must be handled in accordance with applicable health records and privacy laws, with appropriate patient consent.

6. Access, correction & retention

You may access or correct your account information at any time. We retain information for as long as needed to provide the Service and meet legal obligations. You can request deletion by contacting us.

7. Contact

For privacy enquiries or to make a complaint, contact our team at hello@simplyrefer.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

Questions about this policy? Contact hello@simplyrefer.com.au.