Privacy Policy
Last updated: 15 July 2026
CareFlow Pro ("CareFlow", "we", "us") provides rostering, client records, and NDIS claiming tools for Australian disability and care providers. This policy explains how we handle personal information in line with the Privacy Act 1988 (Australian Privacy Principles) and our obligations as a Xero developer partner.
Information we collect
- Account details (name, email, organisation) for staff and administrators
- Client and care records entered by your organisation (names, NDIS details, shifts, notes)
- Usage and audit logs for security and support
- Xero connection data when you connect Xero: OAuth tokens, tenant name, and accounting data accessed via the Xero API (contacts, invoices) as needed for sync
How we use information
We use data only to operate the service you request: rostering, compliance, finance workflows, and optional Xero invoice or payroll sync. We do not sell personal information. Each organisation's data is isolated by organizationId (multi-tenant row-level security).
Xero integration & sensitive data
- Xero OAuth access and refresh tokens are stored encrypted at rest (AES-256-GCM) in our database — never in the web root or client-side code
- Xero client ID and secret live only in server environment variables, not in source control or public URLs
- Only organisation administrators can connect or disconnect Xero
- API routes return connection status only — tokens are never exposed to the browser
- You can disconnect Xero at any time from Settings → Integrations; tokens are deleted from our systems
Security measures
- HTTPS (TLS) for all production traffic, including sign-in and authenticated pages
- Encrypted sessions (JWT), role-based access control, and rate limiting on writes
- Platform operator actions are audit-logged
- Hosting on a dedicated VPS (not shared web hosting) with database access restricted to the application server
Access control
Operational access to production systems is limited to authorised personnel. Tenant data is accessed only for support when necessary (e.g. audited impersonation with your consent) or as required by law.
Data retention & deletion
Your organisation controls its care records. Account deletion and data erasure requests can be submitted via your administrator or our support channel. We process erasure in line with APP 11 and document irreversible deletion where applicable.
Security incidents
If we become aware of a breach or potential breach affecting Xero customer data, API tokens, keys, or other sensitive information, we will:
- Notify Xero promptly at api@xero.com
- Notify affected customers without undue delay where required by law
- Take steps to contain, investigate, and remediate the incident
Contact
Privacy questions or erasure requests: contact us via the demo / support form or email your account administrator.