Privacy Policy
DispenseCPD (ABN 31 139 837 360) ("we", "our", or "us") is committed to protecting your privacy. We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained within it, which regulate how we collect, store, use, and disclose personal information. This policy explains how we handle your personal information when you use our CPD tracking service at dispensecpd.com.au.
1. Information We Collect
We collect the following information when you use DispenseCPD:
- Account information: your email address and encrypted password, or Google account details if you sign in via Google.
- CPD activity data: titles, dates, hours, activity types, providers, and notes you enter into the recorder.
- CPD plan data: your selected development standards, practice context, and goals.
- Consent record: date and time you accepted these Terms & Conditions and Privacy Policy.
- Device information: browser type, operating system, and IP address, collected automatically for security purposes and for the advertising measurement described in section 7.
- Campaign information: if you reach us by clicking an advertisement, a referral link, or a link in one of our emails, we record which campaign that link belonged to. See section 7.
Sensitive information: We do not intentionally collect sensitive information as defined by the Privacy Act (such as health information, racial or ethnic origin, or religious beliefs), and we do not collect or store patient data or clinical records. All data stored is your own professional development records. If your CPD activity descriptions contain sensitive content — for example, references to clinical cases — you should ensure such content is appropriately de-identified before entry. Any sensitive information incidentally contained in your records will only be used for the purpose of providing the Service and will not be disclosed to third parties.
If personal information is not provided: Certain information, such as your email address, is required to create an account and use the Service. If you choose not to provide required information, we may be unable to create your account or deliver certain features of the Service. We will advise you if this is the case.
Consent: By creating an account and using DispenseCPD, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. You may withdraw consent at any time by deleting your account via Account settings → Delete account within the app, or by contacting us at support@dispensecpd.com.au.
2. How We Use Your Information
Your information is used solely to provide and improve the DispenseCPD service:
- To store and sync your CPD records across devices.
- To generate PDF CPD reports on your request.
- To manage your subscription and account access.
- To send transactional emails (e.g. email verification, password resets).
- To send product and marketing emails, such as the welcome email. You can unsubscribe from these at any time using the link in any such email.
- To understand how the Service is used, so that we can improve it.
- To meet our legal and regulatory obligations.
- To measure the effectiveness of our advertising, as described in section 7.
We do not sell or rent your personal information. We do not share your CPD records, activity descriptions, CPD plans, or any other content you enter into the Service with advertising or marketing partners. The limited information we do share is described in section 6 (the third-party services we rely on) and section 7 (advertising measurement).
3. Data Storage and Security
Your data is stored securely using Google Firebase, which provides encryption in transit using TLS and encryption at rest. Firebase infrastructure is hosted in the Asia Southeast 1 region (Singapore) and meets internationally recognised security standards including ISO 27001 and SOC 2 Type II certification. Access to your data is restricted exclusively to your authenticated account — no other user or third party can access your records through our platform.
We take reasonable technical and organisational measures to protect your data; however, no system is completely secure. You are responsible for keeping your password confidential.
4. Data Retention
Your account and CPD data are retained for as long as your account exists, regardless of whether your subscription is active. A lapsed subscription does not result in data deletion — your records remain securely stored and will be accessible if you resubscribe.
You may permanently delete your account and all associated data at any time directly within the app via Account settings → Delete account. Deletion is immediate and irreversible — all CPD activity records, CPD plans, and account credentials are permanently removed from our systems at the time of deletion. No recovery is possible once the deletion is confirmed.
If you are unable to access the in-app deletion option, you may alternatively contact us at support@dispensecpd.com.au and we will process your deletion request within 30 days.
5. Overseas Data Storage
As required under the Australian Privacy Principles, we disclose that your data is stored on Google Cloud servers located in Singapore (Asia Southeast 1). As the operator of DispenseCPD, we remain bound by the Australian Privacy Act 1988 regardless of storage location, and we take reasonable steps to ensure your data is handled in accordance with Australian privacy standards. Google Cloud's data processing terms require Google to handle your data in accordance with applicable privacy laws.
6. Third-Party Services
DispenseCPD uses the following third-party services:
- Google Firebase — authentication, database, and hosting. Data stored in the Asia Southeast 1 region (Singapore).
- Stripe — payment processing. Stripe handles all payment data; we do not store card details.
- Resend — delivery of CPD record PDFs emailed on request. Email content and your address are transmitted through Resend's servers.
- Google reCAPTCHA — used via Firebase App Check to verify that requests originate from the legitimate app. reCAPTCHA may collect device and browser signals for this purpose.
- Google Fonts — font delivery.
- Loops — delivery of product and marketing emails, such as the welcome email. We provide Loops with your email address, your first name, and your subscription status (for example, whether you are on a free or paid plan) so that we can send relevant messages and stop sending them when you unsubscribe. Unlike the advertising measurement described in section 7, your email address is provided to Loops in ordinary readable form, because it is the address the email is sent to.
- Google Analytics — measurement of how the Service is used, such as which pages are visited and which features are opened. This helps us understand where people encounter difficulty. We do not send Google Analytics your CPD records or activity descriptions.
- Meta (Facebook) — advertising measurement, as described in section 7.
Each of these services has its own privacy policy governing their use of data.
7. Advertising and Measurement
We advertise DispenseCPD on Meta's platforms (Facebook and Instagram). To understand which advertisements lead people to sign up, we share limited information with Meta. We want to be specific about what this involves.
What we share. When you create an account or purchase a subscription, we send Meta a record of that event. It includes a hashed version of your email address — irreversibly transformed using SHA-256 so that Meta receives a scrambled value rather than your actual address — together with Meta's own advertising identifiers (the _fbp and _fbc cookies described below), your IP address, and your browser's user-agent string. Meta uses these to match the event to an advertisement you may have seen.
What we never share. We do not send Meta your name, your CPD records, your activity descriptions, your CPD plans, or any other content you enter into the Service. We do not send your email address in unhashed form.
How this is sent. Some of this information is sent from your browser by Meta's advertising pixel, and some is sent directly from our servers using Meta's Conversions API. Both methods transmit the same categories of information described above. Sending from our servers means this measurement still occurs even if your browser blocks the advertising pixel.
Campaign information. If you arrive at our site by clicking an advertisement, a referral link, or a link in one of our emails, the campaign details contained in that link are stored in your browser and recorded against your account when you sign up. This tells us which campaign introduced you. It is recorded once and is not updated afterwards.
Your choices. You can limit this by using your browser's tracking protection or an ad blocker, by adjusting your advertising preferences in your Meta account settings, or by deleting your DispenseCPD account. Blocking advertising cookies does not affect your ability to use any part of the Service.
8. Cookies and Local Storage
DispenseCPD uses browser local storage to cache your CPD data for offline access, to remember your display preferences (e.g. light/dark mode), and to store the campaign information described in section 7. This storage is essential to the Service or, in the case of campaign information, used only for the advertising measurement described above.
Meta's advertising pixel sets its own cookies on your device, principally _fbp and _fbc, which Meta uses to identify your browser for advertising measurement. These are advertising cookies set by Meta, not by us, and are governed by Meta's privacy policy. We also use Google Analytics, which sets analytics cookies to help us understand how the Service is used.
9. Your Rights and Complaints
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or out-of-date information.
- Request deletion of your data (subject to any legal retention obligations).
- Know how your personal information is being used and disclosed.
To exercise any of these rights, contact us at support@dispensecpd.com.au.
Making a complaint: If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, you may lodge a privacy complaint by emailing support@dispensecpd.com.au. Please describe your concern in as much detail as possible. We will acknowledge your complaint within 5 working days and endeavour to resolve it within 30 days. If we require additional time to investigate, we will notify you of the expected timeframe.
If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Phone: 1300 363 992
Website: oaic.gov.au
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or an in-app notice. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact
Questions about this policy? Contact us at support@dispensecpd.com.au.