Privacy Policy
Last updated: 5 August 2026 · WeCare Health Limited, Christchurch, New Zealand
1. Who we are
WeCare Health Limited ("WeCare", "we", "us") is a telehealth provider based in Christchurch, New Zealand. We operate Quindlee to connect patients with registered clinicians, including General Practitioners and Nurse Practitioners, for non-urgent consultations.
This Privacy Policy explains how we collect, use, share, and protect your personal information in accordance with the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020 (HIPC).
2. Information we collect
| Category | Examples | How collected |
|---|---|---|
| Identity | Full name, date of birth, sex | Your profile |
| Contact | Email address, phone number, home address | Your profile |
| Health information | Symptoms, current medications, allergies, medical history, usual-practice enrolment | Consultation chat, your profile |
| Care search text | Words you type to find the closest option in our care catalogue | Care options search |
| Consultation records | Chat transcript, AI-assisted draft clinical summary for clinician review, clinician notes, prescription details | Generated during consultation |
| Payment information | Payment method type, last 4 digits (Stripe tokenised — full card number never stored by WeCare) | Payment step |
| Membership information | Trial activation and end dates, membership declaration, WeCare enrolment check, membership source, benefit dates, usual-practice routing and provisional-price audit | Your request and authorised WeCare staff |
| Technical | Browser type, IP address, device type, push notification token | Automatically on use |
3. How we use your information
We use your personal information to:
- Provide the telehealth service — including sharing your consultation details with the reviewing clinician;
- Process payments — via Stripe's secure payment infrastructure;
- Verify and administer WeCare membership — including recording a patient declaration, activating provisional benefits, checking it against WeCare's clinic system, retaining the pricing source needed to review any unmatched discount, and routing an enrolled account holder's approved summary to the WeCare team;
- Notify you of clinician decisions — via email (Resend) and push notifications;
- Improve the service — using aggregated, de-identified analytics;
- Comply with legal obligations — including health records retention requirements.
We do not use your health information for marketing. We do not sell your data to third parties.
4. Who we share your information with
| Recipient | Purpose | Location |
|---|---|---|
| WeCare clinicians | Review your consultation and decide the next clinical steps | New Zealand |
| Your preferred pharmacy | Receive electronic prescription when approved | New Zealand |
| Supabase | Secure database hosting and authentication | AWS ap-southeast-2 (Sydney) |
| Google Cloud (DLP) | Removes likely identifying details before AI processing. This reduces, but cannot eliminate, the risk that identifying information remains. | Australia (australia-southeast1) |
| Anthropic | AI-assisted history-taking and draft clinical summarisation (Quinn) — receives consultation text after automated de-identification processing | United States |
| Voyage AI | Matches your search phrase to our public care-catalogue wording. Receives no account or profile details and cannot diagnose or start care | United States |
| Stripe | Payment processing; Stripe Identity processes your ID photo for the one-time identity check (WeCare never stores your documents) | United States |
| Twilio | SMS notifications and sign-in codes | United States |
| Resend | Transactional email notifications | United States |
We use contractual and technical safeguards appropriate to each provider. Overseas disclosures are assessed under the Privacy Act 2020 and rule 12 of the Health Information Privacy Code 2020 so the information remains adequately protected.
5. Data security
We take the security of your health information seriously. Our measures include:
- All data in transit is encrypted using TLS 1.2 or higher;
- Database access requires authentication and is restricted by role-based policies;
- Payment data is tokenised by Stripe — we never handle or store raw card numbers;
- Clinician access to the dashboard is protected by a server-side authentication check;
- Regular review of access logs and security configurations.
Despite these measures, no internet transmission is 100% secure. Please contact us immediately at hello@wecarehealth.co.nz if you suspect a security issue.
If a privacy breach happens and it is likely to cause you serious harm, we will notify you and the Office of the Privacy Commissioner as soon as practicable, as required by the Privacy Act 2020. We will tell you what happened, what information was involved, and what you can do.
6. Retention
Health records are retained for at least 10 years, as required by the Health (Retention of Health Information) Regulations 1996. Account data is kept while your account is active and for a reasonable period afterwards. You may ask us to delete non-health data where we are not required to keep it.
7. Your rights
Under the Privacy Act 2020 and Health Information Privacy Code 2020, you have the right to:
- Access the personal information we hold about you;
- Correct any inaccurate information;
- Ask us to delete non-health personal data where no legal retention obligation applies;
- Withdraw consent to non-essential data use at any time;
- Complain to the Office of the Privacy Commissioner if you believe your rights have been breached.
To exercise any of these rights, email us at privacy@wecarehealth.co.nz. We will respond as soon as reasonably practicable and usually within 20 working days. If the law permits an extension, we will explain it to you.
8. Children and dependants
You may add a child profile so you can seek care for a child you are responsible for. When you do, you confirm you are that child's parent or legal guardian and are authorised to share their health information and act on their behalf. We hold a child's health information under the same protections set out in this policy. Quindlee accounts are held by adults aged 18 and over; anyone under 18 is cared for through their parent or legal guardian's account.
9. Cookies and local storage
- No advertising cookies, trackers or third-party analytics.
- Session storage holds consultation data during booking; local storage keeps you signed in and remembers your profile. Both stay on your device and clear when you sign out.
- Some pages load fonts and address/pharmacy search from Google, so Google receives your IP address for those requests.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email. The current version is always available on this page.
11. Contact and our Privacy Officer
Our Privacy Officer is Dr John Ko, Clinical Director, responsible for handling your privacy enquiries, access and correction requests, and any concerns about how we handle your information.
Privacy Officer / privacy enquiries: privacy@wecarehealth.co.nz
General support: hello@wecarehealth.co.nz
You can also complain to the Office of the Privacy Commissioner at privacy.org.nz.
WeCare Health Limited, Christchurch, New Zealand