Privacy Policy
Last updated: 17 August 2026
Who we are
Practice Pulse is operated by Live Learn Thrive Pty Ltd ("we", "us"). Contact: [email protected].
What we collect
- Account data: name, email, password (hashed), practice name, time zone, profession, country.
- Practice management data: with your authorisation, we read patient demographics, appointments, invoices, and payments from Cliniko via their API.
- Accounting data: with your authorisation, we read profit and loss statements from Xero via their API.
- Advertising data: with your authorisation, we read advertising spend and campaign performance from Meta Marketing API and Google Ads API. We do not modify or create ads, campaigns, or budgets on your behalf. From the Google Ads API we additionally read your conversion actions (ID and label) so we can install matching conversion tracking tags into your Google Tag Manager container. Once conversion tracking is on, we also send conversion events back to Meta and Google Ads — that a booking happened, its value, the click identifier, and hashed contact details for match-back — so your campaign reporting is accurate.
- Google Tag Manager: with your authorisation, we read your GTM container, then create and publish container versions to install conversion tracking tags, triggers, and variables for the conversion actions you select. We do not modify or delete tags we did not create.
- Billing data: Stripe handles subscription payments. We store your Stripe customer and subscription identifiers; we do not store your card details.
- Usage data: standard server logs, IP addresses, and timestamps used to operate and secure the service.
How we use it
- To present your practice's data back to you in dashboards and reports.
- To compute aggregate insights and benchmarks across your tenant.
- To send you operational emails (subscription notices, weekly digests if enabled, beta-trial reminders).
- To detect and prevent fraud or abuse of the service.
What we don't do
- We do not sell your data to anyone.
- We do not share patient identifiable information with other Practice Pulse tenants. Cohort benchmark features (when enabled) only ever publish anonymous aggregate statistics across n >= 25 tenants in the same discipline + country.
- We do not advertise to your patients on your behalf.
- We do not write to Cliniko or Xero. Those two connections are read-only. Where we do write, it is only into the advertising tools you connect: Google Tag Manager (we install conversion tracking by creating and publishing a container version) and the conversion events we send back to Meta and Google Ads once that tracking is on. We never create or change your ads, campaigns, budgets, or bids.
Google API Services User Data Policy
Practice Pulse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google Ads and Google Tag Manager data only to provide the conversion-tracking-install feature visible to you inside the app; we do not transfer this data except as necessary to provide the feature, comply with applicable law, or as part of a merger or acquisition; we do not use this data for serving advertisements; and we do not allow humans to read this data unless we have your affirmative consent, it is necessary for security or to comply with law, or the data is aggregated and used for internal operations in line with this policy.
Storage and security
Data is stored in MySQL hosted in Australia. Tokens for connected services (Cliniko, Xero, Meta, Google, Stripe) are stored server-side. They are never sent to the browser or to third parties.
What is and is not encrypted. Traffic between you and Practice Pulse is encrypted in transit (HTTPS), and database backups are encrypted. Your practice data and the connection tokens themselves are not encrypted at rest ... they sit in plain columns in the database, protected by server and database access controls rather than by encryption. Passwords are the exception: they are stored hashed, never in plain text. We would rather tell you this than imply protection we do not have.
Your rights
You may export, correct, or delete your account data at any time. Email [email protected] with the request and we'll action within 30 days. Disconnecting Cliniko, Xero, Meta, or Google revokes our access to that source immediately and stops further data pulls.
Changes
We will update this page when material changes are made and notify active users by email. Continued use after notification is acceptance of the updated policy.