Legal
Privacy Policy
Last updated: 18 July 2026
About this policy
This policy is maintained by Medibyte Telehealth Pty Ltd (ABN 50 700 913 613) ("Medibyte", "we", "us") and explains how we handle personal and health information when you use medibyte.com.au to request an online medical certificate. We are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
This is owner-maintained content describing our current practices. It is not an independent certification.
What we collect
- Identity & contact: full name, date of birth, email, mobile phone.
- Health information (sensitive information under the APPs): symptoms, symptom start date, past medical history, current medications, leave type and certificate dates.
- Consent records: the safety and truthfulness confirmations you tick.
- Doctor account data: for AHPRA-registered doctors using the dashboard — name, AHPRA number, signature name, email and login credentials.
- Payment metadata: a Stripe session ID, amount, and status. We never see or store your full card number, CVC or expiry — that goes directly to Stripe.
- Technical logs: standard request logs (IP address, user agent, timestamps) used for security and abuse prevention.
How we use your information
- To allow an AHPRA-registered doctor to assess your request and decide whether to issue a certificate.
- To generate, sign and deliver the certificate PDF to you by email.
- To let employers, schools or institutions verify a certificate via the verification code.
- To process payment and issue refunds where applicable.
- To detect fraud, abuse, or misuse of the service.
- To meet our legal, regulatory and medical-record obligations.
We do not sell your personal or health information, and we do not use it for advertising.
How we store and protect your information
- Data is transmitted over HTTPS/TLS and stored encrypted at rest by our cloud providers.
- Patient records are only accessible to authenticated, AHPRA-registered doctors on the Medibyte platform, enforced by database row-level security policies.
- Signed certificate PDFs are kept in private object storage and only delivered via time-limited signed URLs.
- Access is logged, and staff access is limited to those who need it.
Third parties we share information with
We use the following processors to operate the service. Each only receives the data needed to perform its function, and is contractually bound to protect it.
Supabase
Database, authentication and file storage
All patient intake records, certificate records, doctor accounts, and issued certificate PDFs.
Stripe
Payment processing
Your name, email and payment card details (entered directly into Stripe's hosted checkout). Medibyte receives only a session ID, amount and payment status — never your card number.
Resend
Transactional email delivery
Recipient email, patient first name, certificate dates, verification code and a time-limited download link, used to send approval and outcome emails.
Microsoft Advertising
Conversion measurement
Anonymised or pseudonymised ad click data, IP address, browser information, and a conversion event when a payment is completed. UET is blocked in EU/EEA/UK/CH and other consent-required regions until a consent choice is implemented.
Google Ads
Conversion measurement
Anonymised or pseudonymised ad click data, IP address, browser information, and a conversion event when a payment is completed. The Google tag is blocked in EU/EEA/UK/CH and other consent-required regions until a consent choice is implemented.
Some of these providers may process data on servers located outside Australia. By using Medibyte you consent to this cross-border handling, which remains subject to contractual protections.
How long we keep it
Issued medical certificates and the underlying patient records are retained indefinitely. This is necessary so that employers, schools and other institutions can verify the authenticity of a certificate at any point in the future, and so we can meet medical-record-keeping obligations.
Doctor account data is kept for as long as the account is active, and for a reasonable period after closure to meet legal and audit requirements.
Your rights under the Australian Privacy Principles
You have the right to:
- Request access to the personal and health information we hold about you.
- Request correction of information that is inaccurate, out of date or incomplete.
- Make a privacy complaint and have it investigated.
To exercise any of these rights, email pc.medibyte@gmail.com. If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Security incidents
If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC in accordance with Australia's Notifiable Data Breaches scheme.
Children
Medibyte is not intended for people under 16. We do not knowingly issue certificates to, or collect information from, anyone under that age.
Changes to this policy
We may update this policy from time to time. When we do, we'll change the "Last updated" date at the top, and for material changes we'll take reasonable steps to notify you.
Contact us
For any privacy question, access or correction request, or complaint, please email pc.medibyte@gmail.com.
Medibyte Telehealth Pty Ltd · ABN 50 700 913 613 · Australia · In an emergency call 000.