Do you store our clients' health information or NDIS numbers?
No. This is the part of Careforms we've engineered hardest. When a client submits,
their answers exist only for the length of that one request: we render the PDF,
email it to you and to them, and discard the payload. Nothing about the person —
name, contact details, NDIS number, health information, answers — is written to
our database or our file storage. The completed record lives in your inbox, which
is where your record-keeping obligations already sit.
Then what do you keep?
One row per submission, with none of the answers in it: internal IDs, the timestamp, the country and
Cloudflare ray ID of the request, the funding type and services the link was
issued for, email delivery status, and SHA-256 hashes of the submitted content.
The hashes let you prove the JSON in your inbox hasn't been altered. Contact
details are reduced to a one-way fingerprint, keyed per account, so repeat
submitters are recognisable to you without being identifiable to us.
What if the email never arrives?
Delivery is attempted, with retries, before the submission is accepted. If we
can't reach either recipient, the client is told immediately and their link stays
usable so they can resubmit — we'd rather ask once more than quietly lose the
form. Because we hold no copy, there is no after-the-fact resend; that's the
trade-off for not being a second database of your clients' data.
Does this cover Support at Home, or only NDIS?
Both, and privately funded clients too, on every plan. You choose the funding type
when you issue the link and the form is assembled for it: a Support at Home intake
asks about the aged care assessment, contributions and supporters; an NDIS intake
asks about the plan and how it's managed. The terminology follows the program —
participant or client, care worker or support worker, My Aged Care client number
or NDIS number — so neither client is reading the other one's paperwork.
What counts as an intake link?
Every link you issue counts against the monthly cap, whether or not the client
completes it, and an expired link still counts for the cycle it was issued in.
One exception, for the mistyped address: revoke a link before anyone has opened
it and its slot goes back into that month's allowance. Once it has been opened,
revoking stops the link but keeps the slot spent. The cap resets at the start of
each billing period.
Can I change plans later?
Yes — upgrade or downgrade at any time from the billing portal inside the app.
An upgrade lifts your cap straight away, in the billing period you're already in:
the links you've sent this month stay counted, and the rest of the new allowance
is there immediately. A downgrade lowers it the same way, so if you've already
issued more than the smaller plan allows, links you've sent keep working and you
won't be able to issue another until the period resets.
Can my team have their own logins? Do you support SSO?
Not yet — an account is one business with one sign-in address, and everyone who
works on intake shares it. There are no per-user logins, no roles and no SSO, and
a branch or a second trading name needs a second account and a second
subscription. Worth knowing before you sign up if your intake team is more than
one or two people, or if procurement needs named users. Sign-in is a link emailed
to that address rather than a password, and you can add two-factor to it under
Profile.
Can I use my own intake form?
No — and this is the honest limit of the product. Careforms carries one
professionally maintained intake form per funding type, kept current against the
NDIS Practice Standards and the Aged Care Act, and what you control is how much
of it you ask. You choose the depth, switch individual questions off, and reword
a good number of them. You can't add your own questions, and you can't reword the
ones a standard fixes the words of — roughly four in ten on a typical NDIS form,
each of which tells you on screen which instrument holds it. If you need your
own questionnaire reproduced exactly, this is the wrong tool and we'd rather you
knew now.
Where does the service run?
On Cloudflare's network, with the account database in the Oceania region and file
storage in APAC. That storage holds your logo — not client submissions. Email is
sent through Resend. Card details are held by Stripe; we never see a card number.
Details in Privacy.
What about refunds?
Cancel from the billing portal at any time and access continues to the end of the
period you've paid for. We don't issue prorated refunds.