Privacy Policy
1. Who we are
FamilyChart is a product of WheelieLabs (ABN 55 846 950 339), operated by Benjamin Horder. We provide family medication and health tracking software as a managed hosting service and as open-source self-hosted software.
This policy applies to the managed hosting service accessible at familychart.app and to this website. It does not apply to self-hosted deployments operated by third parties.
Contact: [email protected]
2. Our commitment to your privacy
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). FamilyChart processes health information, which is sensitive information under the Privacy Act and attracts additional protections.
3. What information we collect
We collect the following categories of information:
- Health and medication data — information you enter about family members, including medications, dosages, schedules, health observations, and related notes. This is sensitive information under s 6 of the Privacy Act.
- Account information — your name and email address provided when subscribing.
- Billing information — payment details are collected and processed by Stripe on our behalf. We do not store card numbers or full payment credentials.
- Technical and usage data — server logs (IP address, browser type, pages accessed, timestamps) used to operate and secure the service.
FamilyChart is intended to be used by adults to manage health information for members of their household, including children. We do not knowingly collect information directly from children interacting with us as data subjects in their own right — all accounts are held by an adult, who is responsible for any data entered about dependants, including minors.
4. How and why we collect it (APP 3 & 5)
We collect personal information only when you provide it to us — there is no passive collection beyond technical logs. Health data is collected for the sole primary purpose of providing the FamilyChart service to you.
We will tell you at or before the time of collection (or as soon as practicable afterwards) why we are collecting your information, what we will do with it, and whether any third party will receive it.
5. Health information — sensitive information (APP 3.3)
We will not use or disclose your health information for any secondary purpose without your explicit consent, unless we are required or authorised to do so by law (for example, in an emergency or by a court order).
6. Unsolicited personal information (APP 4)
If we receive personal information we did not solicit — for example, sensitive details included in a support email — we will assess within a reasonable period whether we could have lawfully collected it. If we could not, and the information is not required to be kept as part of a Commonwealth record, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
7. Use and disclosure (APP 6)
We use your personal information only to:
- Provide and maintain the FamilyChart managed hosting service;
- Process your subscription payment via Stripe;
- Communicate with you about your account or this service;
- Comply with legal obligations.
We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use your health data for advertising, analytics, or any purpose other than operating the service.
Two third parties receive your personal information in the ordinary course of business: Stripe, our payment processor, which receives your name and email address to process subscription payments; and Microsoft, whose Microsoft 365 infrastructure we use — through our own WheelieLabs tenancy, hosted in Microsoft's Australian region — to send account and service emails, such as onboarding notifications, and which receives your email address for that purpose.
8. Direct marketing (APP 7)
From time to time we may email subscribers about new features, product updates, or other promotional content. These emails always include a working unsubscribe link, and you may opt out at any time — including the account holder (admin), who is never required to receive marketing content.
This is separate from operational service communications — such as planned maintenance windows, security notices, or billing/account-critical notices — which the account holder (admin) will always receive, as these are necessary to operate the service and are not marketing.
Other household members with access to a FamilyChart instance may opt in or out of any email communications independently.
9. Cross-border disclosure (APP 8)
Stripe is headquartered in the United States. When you subscribe, your billing name and email address are transmitted to Stripe's servers in the US. We have taken reasonable steps to ensure Stripe protects your information in a manner consistent with the APPs, including reviewing their privacy policy and data processing terms.
FamilyChart's own hosting infrastructure is located in Australia (Sydney and Adelaide) — your health and account data is not stored offshore by us. Account and service emails are sent through our own Microsoft 365 tenancy, hosted in Microsoft's Australian region — so this is not an offshore transfer either. The only offshore transfer is the billing information sent to Stripe, described above.
10. Security (APP 11)
We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include:
- Encryption of data in transit (TLS/HTTPS);
- Encryption of data at rest on our hosting infrastructure;
- Mandatory multi-factor authentication (MFA) and a minimum password length of 10 characters for all managed hosting accounts, enforced by the platform and unable to be disabled;
- Access controls limiting who can access stored data;
- Regular review of our security practices.
If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
11. Data retention
We retain your personal information for as long as your account is active and as reasonably necessary to provide the service. If you close your account, we will delete your personal data within 30 days of receiving a written request to do so, subject to any legal obligations requiring us to retain it for longer.
12. Your rights — access and correction (APP 12 & 13)
You have the right to:
- Request access to the personal information we hold about you (APP 12);
- Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
To make an access or correction request, email us at [email protected]. We will respond within 30 days. We may need to verify your identity before fulfilling your request.
In most cases FamilyChart is designed so you can access and correct your own data directly within the application.
13. Data quality (APP 10)
We take reasonable steps to ensure the personal information we collect, use, and disclose is accurate, up to date, complete, and relevant. Because most data in FamilyChart (medications, observations, schedules) is entered directly by you, you are able to review and correct it yourself at any time within the application — see clause 12 above.
14. Anonymity and pseudonymity (APP 2)
Where it is lawful and practicable, you may interact with us anonymously or using a pseudonym. However, to provide the managed hosting service we must be able to identify your account (your email address), so full anonymity is not possible for subscribers.
15. Government-related identifiers (APP 9)
FamilyChart does not require or request government-related identifiers (such as Medicare numbers or driver’s licence numbers) as part of the service, and we do not adopt, use, or disclose any such identifier as your own identifier with us.
16. Complaints (APP 1.4)
If you have a complaint about how we have handled your personal information, please contact us first:
Email: [email protected]
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
17. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days before the change takes effect. The current version is always available at /privacy.html.
18. Contact us
For any privacy-related questions or requests:
Email: [email protected]