Legal
In The Waiting Room Privacy Policy
Effective date: 29 July 2026
1. About this Policy
In The Waiting Room is a patient-education platform that helps healthcare practices share clear, credible health information with the people in their care.
The platform is operated by Moss Pty Ltd ABN 72 107 905 475 trading as In The Waiting Room (ITWR, we, us or our).
This Policy explains, in plain English, what personal information we collect, why we collect it, who we share it with, how we store and protect it, and how you can access, correct or delete it. It applies to our website, the practice portal, the staff-assisted enrolment process, patient-facing reading pages, and the emails we send.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. The kinds of information we collect
We collect only what we need to run the platform. We do not collect patient medical records, clinical notes, diagnoses, test results or Medicare information, and the platform must not be used to send them to us.
3. Practice account and profile information
When a practice registers or is enrolled, we collect and store:
- practice name, practice type and public profile slug
- contact email address, phone number, website address and booking link
- practice address and opening hours
- logo, hero image, brand colours and theme preference
- practice description, philosophy, mission, services and practitioner listings
- billing, appointment, communication and accessibility notes the practice chooses to publish
- practice announcements the practice chooses to display
- onboarding progress and account status
Most of this information is business information that the practice chooses to publish to patients. Some of it, such as a named practitioner or a personal work email address, may also be personal information.
4. Staff-assisted enrolment and recorded consent
An ITWR team member may create a pending practice record and prepare an invitation after speaking with an authorised representative of a practice. When that happens we record:
- the practice the invitation relates to
- the name, role and email address of the contact person
- that consent to be invited was given, and the method it was given by (for example a phone call, an in-person visit or an email)
- the name and role of the person who gave that consent
- any notes made by our team member about the conversation
- the date and time consent was recorded, and which ITWR team member recorded it
We keep these records so that we can demonstrate an invitation was requested rather than unsolicited, and so we can answer questions about how a practice came to be contacted.
5. Invitation, authentication and account-claim information
For invitations and account activation we collect and store:
- the contact name, email address and role the invitation was sent to
- the invitation status (draft, sent, accepted, expired or revoked), send and resend history, and expiry date
- a securely stored, single-use activation token that can only be used once
- the date and time the account was claimed
- the version of our Terms of Use accepted, and when it was accepted
Sign-in accounts are managed by our authentication provider, which stores the account email address, an encrypted password credential, sign-in and session records, and password-reset and email-confirmation activity. We never see or store your password in readable form.
6. Patient subscriptions and consent
A patient or reader can choose to subscribe from a practice's public reading page. When someone subscribes we store only:
- the email address they enter
- the practice page they subscribed from
- the channel the visit came from, where a practice used a labelled link or QR code
- a record that consent was given, and the date and time it was given
- whether the record was created during internal testing
Subscribing is always the reader's own choice. We do not ask patients for health information, and practices must not upload patient lists or patient contact details to the platform.
Every subscription email includes a way to unsubscribe, and a reader can ask us to delete their subscription at any time by emailing us.
7. Activity events and engagement analytics
We record product-usage events so practices can see how their sharing is performing and so we can improve the platform. These events record what happened and which practice it relates to — for example that a feature was shared, a link was copied or an invitation was sent — together with the date and time.
When someone reads a feature on a practice page, we also record a reading session:
- which feature was read, the version of the document, and how many pages it has
- the practice and, where relevant, the campaign or labelled link the reader arrived through
- an anonymous, randomly generated reader identifier that is not linked to a name
- broad device category, browser family and operating system family (for example mobile, Safari, iOS)
- the domain a reader arrived from, where a referrer is present — not the full URL
- whether the session was internal testing activity
These records are engagement statistics, not clinical records. We do not build reader profiles, we do not sell reader data, and practices see aggregate engagement rather than the identity of individual readers.
8. Email delivery logs, bounces and suppression
We send transactional emails such as invitations, activation links, password resets, confirmations and subscriber welcome emails. Our email provider processes the recipient address and message content in order to deliver it, and returns delivery information to us, including whether a message was delivered, bounced, failed or was marked as spam.
Where an address bounces repeatedly or a recipient opts out, that address may be added to a suppression list so we do not keep emailing it. We keep suppression records for as long as needed to honour that request.
9. Cookies and website analytics
We do not use advertising cookies, tracking pixels, or third-party advertising or analytics networks such as Google Analytics, Meta Pixel or similar tools on this site.
The only browser storage we use is functional:
- a sign-in session stored by your browser so you stay logged in to the practice portal
- a small local record that a reading page has already been unlocked on that device, so a reader is not asked twice
- a preference cookie that remembers whether the portal navigation panel is open or collapsed
Our hosting and infrastructure providers also keep standard server and security logs, which can include IP addresses, request times and browser user-agent strings, for the purpose of delivering the service securely and detecting abuse.
10. Service providers we use
We use a small number of trusted providers to run the platform. Each is given only the information it needs to perform its function:
- Supabase — database, authentication and file storage for practice profiles, invitations, activity events and documents
- Lovable — application hosting, deployment and delivery of the website and portal
- Resend — delivery of transactional and subscriber emails
- Stripe — payment and subscription processing, where a practice chooses a paid product. Card details are entered directly with Stripe and are never stored by us
These providers act as our service providers, not as independent owners of your information. We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.
We may also disclose information where the law requires it, where it is necessary to protect someone's safety, or to our professional advisers under confidentiality obligations.
11. Overseas storage and processing
Some of our providers operate global infrastructure, so information may be stored or processed outside Australia, including in the United States and other countries where those providers or their subprocessors maintain facilities.
Where information is handled overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including by using reputable providers with contractual privacy and security commitments.
If you would like current details about where a particular category of information is hosted, email us and we will tell you.
12. How we use information
We use personal information to:
- create, activate and support practice accounts
- verify that an invitation was consented to and is being claimed by the right person
- publish the practice profile and features the practice chooses to share with patients
- deliver the reading experience and the emails you have asked for
- show practices honest engagement statistics about their own sharing
- keep the platform secure, prevent misuse, and diagnose faults
- improve content, design and usability
- meet our legal, record-keeping and tax obligations
We only send marketing or product-update emails to practice contacts where they would reasonably expect it or have opted in, and every such email includes an unsubscribe option.
13. How we store and protect information
Information is stored in managed cloud services with access controls, encryption in transit, and encryption at rest provided by our infrastructure providers.
- database access is restricted by row-level security so a practice can only reach its own records
- administrative keys are held as server-side secrets and are never exposed in the browser
- activation tokens are single-use and time-limited
- passwords are stored only as salted, hashed credentials by our authentication provider
- access by our team is limited to those who need it to provide support or operate the service
No online service can promise perfect security. If a data breach occurs that is likely to cause serious harm, we will respond in accordance with the Notifiable Data Breaches scheme and notify affected people and the Office of the Australian Information Commissioner as required.
14. Retention and de-identification
We keep personal information only for as long as we need it for the purposes described in this Policy, or for as long as the law requires.
- practice account and profile information is kept while the account is active, and for a reasonable period afterwards to handle reactivation, disputes and record-keeping obligations
- invitation and consent records are kept as evidence that contact was authorised, and are deleted when they are no longer needed for that purpose
- reading sessions and activity events are retained as long-term engagement statistics; they carry only anonymous identifiers and broad device information rather than names
- email delivery logs are retained for a limited period by our email provider, and suppression records are kept for as long as needed to honour an opt-out
- internal test activity is flagged as test data and excluded from reporting
When information is no longer needed, we delete it or de-identify it so it can no longer reasonably be linked to an individual, and retain only aggregate statistics.
15. Access, correction and deletion
You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong or out of date, or ask us to delete it.
Practices can view and update most of their own profile information directly in the practice portal. Readers can unsubscribe from any subscription email, or email us to have their subscription record deleted.
To make a request, email info@bnourishd.com.au. We may need to verify your identity first. We aim to respond within 30 days. Access is free, except that we may charge a reasonable cost for unusually large or repeated requests, and we will tell you before any cost applies.
In limited cases we may need to refuse a request, for example where the law requires us to keep a record or where deleting it would affect another person's rights. If we refuse, we will explain why in writing.
16. Anonymity and pseudonymity
You can browse the public website and read a practice's shared features without giving us your name. An account is required to manage a practice profile, and an email address is required if you choose to subscribe.
17. Children
The platform is designed for practices and adult readers. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
18. Privacy complaints
If you think we have mishandled your personal information or breached the Australian Privacy Principles, please tell us first. Email info@bnourishd.com.au with the words "Privacy complaint" in the subject line and describe what happened.
We will acknowledge your complaint promptly, investigate it, and give you a written response, usually within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.
19. Changes to this Policy
We may update this Policy as the platform changes. The current version is always available at this Privacy Policy page, and the effective date at the top shows when it last changed. If we make a significant change, we will take reasonable steps to notify account holders.
Our Terms of Use should be read together with this Policy.
20. Contact details
Moss Pty Ltd trading as In The Waiting Room
ABN: 72 107 905 475
Email: info@bnourishd.com.au
Website: https://inthewaitingroom.co
Postal address: 3 Feathertop Avenue, Lower Templestowe, Victoria, Australia 3107