Privacy Policy
Last updated: 2 October 2026
1. Overview
This privacy policy explains how Wani Meridian Pty Ltd (ABN 97 701 307 020), which operates ProviderQMS at providerqms.com.au, collects, uses, and protects personal information through providerqms.com.au. We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. Information We Collect
We may collect the following types of personal information:
- Purchase information: your name, email address, and payment details. Payment is processed by Stripe — we do not store your credit card numbers.
- Usage data: anonymised page views and funnel events (such as which tool features you use) collected to improve the product. These tools set cookies and can identify a returning browser. See section 4 for exactly which ones and what each does.
- Contact information: your email address and any details you provide when you contact us at hq@providerqms.com.au (our mailbox during the name change).
3. How We Use Your Information
We use personal information for the following purposes:
- To deliver purchased products, including download links and confirmation emails
- To process refund requests
- To respond to enquiries sent to hq@providerqms.com.au (our mailbox during the name change)
- To improve our website and products through anonymised usage analytics
- To send occasional product updates to email addresses given to us for that purpose. Each such message includes a one-click unsubscribe link, and we honour unsubscribe requests immediately.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Third-Party Services
We use the following third-party services to operate ProviderQMS:
- Stripe (payment processing) — see Stripe's privacy policy
- Cloudflare (website security and content delivery) — see Cloudflare's privacy policy
- Anthropic (AI processing for Ethan — the ProviderQMS Assurance & Quality Agent) — questions you submit are processed via API and are subject to Anthropic's usage policy
Microsoft Advertising Universal Event Tracking (UET) measures visits and confirmed kit purchases to help attribute and improve our advertising. Microsoft collects or receives browser/device information, page URLs, Microsoft click identifiers and purchase value/currency and product identifiers, and may use cookies for advertising measurement. We send an opaque transaction identifier, not checkout access codes or participant care records. This integration does not enable Microsoft Clarity session recordings or enhanced email/phone matching. We respect browser Do Not Track, Global Privacy Control and our usage-analytics opt-out for this tag. See the Microsoft Privacy Statement.
Meta (Facebook) Pixel and Conversions API — measures which advertisements lead to a purchase. Sets cookies. We send Meta your email address in a hashed, pseudonymised form, together with an identifier we generate ourselves (nc_xid, described in section 7), so that Meta can match a purchase to its own advertising records. We do not send the readable address. See Meta's privacy policy. Google Analytics 4 — measures how pages are used. Sets cookies. See Google's privacy policy. Microsoft Clarity — records anonymised session replays and heatmaps so we can see where the site is confusing or broken. Text you type is masked before it leaves your browser, so form fields, email addresses and payment details are never recorded. Sets cookies. See Microsoft's privacy statement.
5. Data Storage and Security
- The application and its database run on a server in Sydney, Australia, operated by Vultr. Your account, your sign-in sessions, the entitlement your receipt carries, any ticket you raise with us and any document you upload for the document check are stored on that server
- Until 28 August 2026 that server was in Kuala Lumpur, Malaysia, and that machine is still in place as our fallback while the move settles, so a copy of these records is in Malaysia as well until we shut it down. Hostinger, the provider of that machine, may hold its own snapshots for a period afterwards
- Purchase records — your receipt, the email address you paid with and what it entitles — are held in a separate database in Sydney, Australia, run by Supabase on Amazon Web Services (ap-southeast-2); both are United States companies
- Workspace records in the existing dashboard may remain in the browser on the device you use. Saved records in the invited new portal are held on its Sydney server and are available across devices to authorised organisation members. See the portal privacy and collection notice for its access, support, processors and retention.
- We use HTTPS encryption for all data transmission
- Payment processing is handled entirely by Stripe, which is PCI-DSS compliant
- We retain purchase records for 7 years as required by Australian tax law
- We are an Australian company and the Australian Privacy Principles apply to how we handle your information, including where it is stored or processed overseas — see Your data
6. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate or out-of-date information
- Request deletion of your personal information, subject to legal retention requirements
To exercise any of these rights, email hq@providerqms.com.au (our mailbox during the name change).
PostHog helps us understand page use, checkout progress and use of purchased kits. We use pseudonymous browser and account identifiers, campaign parameters, selected product identifiers and confirmed payment amounts. On selected public pages, masked recordings and heatmaps help us improve the layout. We do not record checkout, sign-in or dashboard screens, document contents, email addresses, sign-in codes or card details in PostHog. Data is processed in PostHog’s European region. See PostHog’s privacy policy. Do Not Track and Global Privacy Control signals disable this tracking.
7. Cookies
We use essential cookies for site functionality, and advertising cookies set by the Meta pixel described in section 4 — including _fbp, and _fbc when you arrive from an advertisement. These let us measure which advertisements lead to a purchase.
We also store our own advertising measurement identifier, nc_xid, in your browser. It is a randomly generated string that we create; it contains no information about you, is not derived from anything you have told us, and is not used to identify you to anyone other than Meta for advertising measurement. It lasts up to 13 months, and is shared with Meta so that a purchase can be recognised as coming from the same browser that saw an advertisement. Clearing your browser storage removes it, and a new one is generated on your next visit.
We send Meta a record of completed purchases from our own server, using these identifiers together with your email address in a hashed, pseudonymised form, so that Meta can match your purchase to its own advertising records. We do not send Meta the readable address.
We do not sell your information, and we do not use these cookies to build a profile of you for anyone else. You can block them in your browser settings or with the advertising controls in your Meta account, and the site will still work.
8. Children's Privacy
Our products are designed for authorised staff of NDIS service providers. We do not market the portal to children. A provider’s service records may contain information about children only where the provider has a permitted purpose and appropriate authority, notices and consent. Initial portal acceptance tests use fictional information.
9. Changes to This Policy
We may update this privacy policy from time to time. The current version is always available at providerqms.com.au/privacy.
Overseas disclosure
Our server is in Australia, but the company that operates it and several of the services we rely on are based overseas, so some personal information you give us is stored or processed overseas. Specifically:
- Stripe processes payments and is headquartered in the United States. Your card details go directly to Stripe and never reach our servers.
- Our transactional email provider is United States based, and handles the address we send your receipt, your sign-in code and your download links to.
- Our application server and its database are in Sydney, Australia, operated by Vultr, a United States company. Your account, your sign-in sessions, the entitlement your receipt carries, any ticket you raise with us and any document you upload for the document check are stored there. Until 28 August 2026 that server was in Kuala Lumpur, Malaysia, and that machine is still in place as our fallback while the move settles, so a copy of these records is in Malaysia as well until we shut it down. Hostinger, the provider of that machine, may hold its own snapshots for a period afterwards.
- Questions you put to Ethan are processed in the United States by the provider named in section 4.
- Your purchase records are held in a separate database in Sydney, Australia, run by Supabase on Amazon Web Services (ap-southeast-2) — United States companies operating Australian infrastructure.
- Workspace records in the existing dashboard may remain in your browser. The invited new portal stores saved organisation records on its Sydney server. Its privacy and collection notice describes overseas email/support processing and recovery storage.
We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, but we cannot control their operations and they may be subject to the laws of the country they operate in.
Accessing and correcting your information
You may ask us what personal information we hold about you, and ask us to correct it if it is wrong. Email hq@providerqms.com.au (our mailbox during the name change) from the address your account uses and we will respond within 30 days. There is no charge.
You can also ask us to delete your account and the personal information attached to it. Some records — a receipt, for example — we may need to keep to meet our own legal obligations, and we will tell you plainly if that applies.
10. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us at hq@providerqms.com.au (our mailbox during the name change). We will investigate your complaint and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Contact
For privacy-related enquiries, email hq@providerqms.com.au (our mailbox during the name change).