Privacy Policy
Effective date: 29 March 2026 · Last reviewed: 1 April 2026
1. Overview
Aged Care Circle (“we”, “us”, “our”) operates the website at agedcarecircle.com.au and is committed to protecting your privacy. This policy explains what information we collect when you use this website, how we use it, who we share it with, and your rights under the Privacy Act 1988 (Cth).
The short version: Our cost calculators process all inputs in your browser — nothing you enter into the calculator is sent to our servers. If you create an account, we collect and store additional personal information to provide account features such as saved providers, saved locations, Care Circles, and Premium subscription access.
2. Information We Collect
2a. Calculator inputs
When you use any of our cost calculators (Residential Aged Care, Home Care Package, Support at Home, RAD vs DAP), your inputs — including care type, region, income range, asset range, and accommodation preference — are processed entirely in your browser. Results are encoded into the page URL so you can share or bookmark your estimate. We do not transmit, store, or have access to your calculator inputs.
2b. Account registration and profile
If you create an account, we collect and store:
- Your email address — used to send a magic link for passwordless login (no password is created or stored)
- A display name — automatically generated from your email address when you first log in; you may update this
- Your account creation date, subscription tier (Free or Premium), and subscription expiry date
- A Stripe customer ID — created if you upgrade to Premium, used to manage your subscription and avoid duplicate billing records
2c. Provider enquiries
When you submit an enquiry to a provider through the site, we collect and store your name, email address, phone number (optional), message, and the page from which the enquiry was submitted. This information is stored in our database and forwarded to the provider if they have a claimed listing. It is used for enquiry routing and moderation purposes.
2d. Provider reviews
When you submit a review of a provider, we collect your display name, your relationship to the facility (e.g. resident, family member, visitor), star ratings across up to six categories, and a written comment. We also collect your email address for verification purposes. Your email address is not stored in readable form — it is converted to a one-way cryptographic hash (SHA-256) before storage, which allows us to detect and prevent duplicate reviews from the same address but cannot be reversed to recover your email.
All reviews are held as pending until you verify your email address via a link we send you, and until a manual moderation check is completed. Unverified reviews are not published and are periodically deleted.
2e. Saved data (registered users)
When you use account features, we store:
- Saved locations — suburb name, postcode, and geographic coordinates (latitude/longitude) for locations you save to your account
- Shortlisted providers — the aged care facilities you save or add to your comparison list
- Care Circle data — your circle name, the email addresses of people you invite to your Care Circle, and their membership role (owner, editor, or viewer)
- Notes — any notes you add to providers or your journey
This data is associated with your account and is not used for any purpose other than delivering account features to you.
2f. Anonymous browser data (pre-login)
Before you log in or create an account, the site stores shortlists and saved locations in your browser's local storage (not a cookie). This data never leaves your device. If you subsequently create an account, this anonymous data is automatically merged into your account and removed from local storage.
The site also uses session storage to track enquiry submission counts per provider within a single browsing session to prevent spam. This data is cleared when you close the browser tab.
2g. Analytics data
We use Google Analytics 4 to understand how visitors use this site. This collects anonymised usage data including:
- Pages visited and time spent on each page
- General geographic region (country and state — not precise location)
- Device type (mobile, tablet, desktop)
- Browser and operating system type
- How you arrived at the site (search engine, direct, referral)
IP addresses are anonymised. This data is aggregated and cannot be used to identify you personally. Google Analytics data is subject to Google's Privacy Policy.
2h. Contact form
The contact form on this site is processed by Formspree. When you submit the form, your name, email address, and message are sent to Formspree's servers and forwarded to us. This information is used solely to respond to your enquiry and is not used for marketing or shared with any other party. Please review Formspree's Privacy Policy for details of how they handle submitted data.
3. Cookies and Local Storage
Cookies we set
When you log in to your account, our authentication provider sets a session cookie (auth-token) in your browser. This cookie is required for authenticated features and contains an encrypted session token. It is cleared when you log out.
Third-party cookies
The following third-party services may set cookies in your browser:
- Google Analytics 4 — analytics cookies used to measure usage patterns
- Google AdSense — advertising cookies used to serve and personalise advertisements
Browser local storage
As described in section 2f, the site uses local storage to temporarily hold anonymous shortlists and saved locations before account creation. This data is not transmitted to our servers unless you log in.
You can control or delete cookies and local storage through your browser settings. Disabling cookies will not affect your ability to use the cost calculators. Disabling local storage may affect the anonymous shortlist and saved location features before you log in.
4. How We Use Your Information
| Information | How we use it |
|---|---|
| Email address (account) | To send magic link login emails. Not used for marketing. |
| Display name | To personalise your account experience |
| Subscription tier / Stripe customer ID | To manage your Premium subscription and billing |
| Provider enquiry details | To forward your enquiry to the relevant provider |
| Review data | To display verified, moderated community reviews on provider profiles |
| Saved locations and shortlists | To provide personalised search results and account features |
| Care Circle data | To enable family collaboration features |
| Invited email addresses | To send Care Circle invitations; stored to track membership status |
| Payment details | Processed by Stripe to charge your Premium subscription; we do not store card numbers |
| Analytics data | To understand site usage and improve content and usability |
| Contact form data | To respond to your support enquiry |
We do not use your personal information for direct marketing. We do not sell, rent, or trade your personal information to any third party.
5. Transactional Emails
We send the following transactional emails using Resend (our email delivery provider):
- Review verification — a link to verify your email address when you submit a provider review
- Care Circle invitation — an invitation email when you are added to someone's Care Circle
- Enquiry confirmation — a notification to the relevant provider when you submit an enquiry
- Premium upgrade confirmation — a summary of features unlocked when you subscribe to Premium
These emails are sent in response to specific actions you take. We do not send newsletters, promotional emails, or any unsolicited communications.
6. Third-Party Service Providers
We share personal information with the following third-party service providers only to the extent necessary to deliver the service:
| Service | Purpose | Information shared | Privacy policy |
|---|---|---|---|
| Supabase | User authentication, account data, provider data | Email, profile, saved data, enquiries, review data | supabase.com/privacy |
| Stripe | Payment processing for Premium subscriptions | Email address, user ID | stripe.com/privacy |
| Resend | Transactional email delivery | Recipient email address, email content | resend.com/legal/privacy-policy |
| Google Analytics 4 | Anonymous site usage analytics | Anonymised usage data | policies.google.com/privacy |
| Google AdSense | Advertising | IP address, browsing behaviour, device information | policies.google.com/technologies/ads |
| Google Maps Platform | Address autocomplete and location distance calculations | Address search inputs | policies.google.com/privacy |
| Formspree | Contact form processing | Name, email address, message | formspree.io/legal/privacy-policy |
These providers are bound by their own privacy policies and applicable data protection laws. We do not authorise them to use your information for their own marketing purposes.
7. Data Storage and Location
User account data, provider enquiries, reviews, saved locations, and shortlists are stored in Supabase, hosted in the ap-southeast-2 region (Sydney, Australia). Payment records are held by Stripe on their infrastructure. Analytics data is held by Google.
Some third-party providers listed above may process or store data outside Australia. Where this occurs, we rely on those providers' own data handling commitments and applicable cross-border transfer mechanisms.
8. Data Retention
| Data type | Retention period |
|---|---|
| Account profile and saved data | Retained while your account is active; deleted within 30 days of an account deletion request |
| Provider enquiries | Retained for 12 months from submission |
| Published reviews | Retained indefinitely while published; deleted if a review is removed or rejected |
| Pending / unverified reviews | Deleted within 30 days if not verified |
| Google Analytics data | Subject to Google Analytics retention settings (14 months by default) |
| Payment records | Retained for 7 years as required for Australian taxation and accounting obligations |
| Contact form data | Retained by Formspree subject to their retention policy; we retain forwarded emails for up to 12 months |
9. Your Rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate, out of date, or incomplete
- Request deletion of your account and associated personal information (subject to retention obligations noted in section 8)
- Complain if you believe we have handled your personal information in a way that does not comply with the APPs
To exercise any of these rights, email us at support@agedcarecircle.com.au with the subject line “Privacy Request”. We will acknowledge your request within 5 business days and respond substantively within 30 days.
10. Data Breach Notification
We take reasonable steps to protect your personal information from unauthorised access, misuse, or disclosure. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with our obligations under the Notifiable Data Breaches scheme.
11. Complaints
If you are not satisfied with how we have handled your privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
12. Children's Privacy
This site is intended for adults and is not directed at children under the age of 13. We do not knowingly collect personal information from children.
13. External Links
This site contains links to external websites including servicesaustralia.gov.au, myagedcare.gov.au, and agedcare.health.gov.au. We are not responsible for the privacy practices of those sites and encourage you to read their respective privacy policies.
14. Advertising
This site displays advertisements through Google AdSense. Google may use cookies and similar tracking technologies to serve relevant advertisements based on your browsing behaviour. You can opt out of personalised advertising at Google's Ad Settings. For more information, see Google's Advertising Policy.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page indicates when it was last revised. Continued use of this site after any changes constitutes acceptance of the updated policy.
16. Contact
For privacy-related enquiries, requests, or complaints, contact us at:
Email: support@agedcarecircle.com.au
Subject line: Privacy Request