Privacy Policy
Last updated: 4 September 2026
Who we are
Ready Set Rove is operated by Brooke Richards, trading as Ready Set Rove, in Australia. Contact for anything in this policy: contact@readysetrove.com.
The short version
There are no accounts and no marketing list. Browsing and checking an itinerary sends us nothing that identifies you. We collect your email address only when you ask us to email you something or buy a pack, and your trip selections only to build what you asked for. Your medication selections are health information, and we treat them that way. Certificate requests sent to a clinic hold more, and are deleted on the schedule set out below. We never sell personal information and never use it for advertising.
Does the Privacy Act apply to us
Small businesses with turnover under A$3 million are often exempt from the Privacy Act 1988 (Cth). We do not rely on that exemption. Medication selections and certificate requests are health information, which the Act treats as sensitive information, and the clinics we work with are bound by the Act in full. So we handle all personal information in line with the Australian Privacy Principles (APPs) whether or not the law strictly requires it, and this policy is written to APP 1.
What we collect, and why
Nothing, if you browse or run the checker. The itinerary checker builds its answer from your selections in your browser. Choosing medications and destinations does not send us your name, your email, or anything that identifies you.
Your email address, when you ask for a summary. We use it to send that one email and do not store it afterwards. The email lists your destinations and their status, and carries a link that reopens your itinerary. That link contains your medication and destination selections, because that is how the page rebuilds itself. The email does not name your medications in its text.
Your trip and email, when you buy a trip pack. Stripe collects your email and payment details at checkout. Your card details never touch our systems. The trip you built (your medication selections, destinations, transit stops, travel date, nights per stop and days of supply, where you entered them) is attached to your Stripe checkout record, together with the rules it was priced against. That is how your pack is generated and how the link in your email finds it again. We use your email to send the pack link, to send you a notice if a published rule for one of your stops changes before your travel date, and, if you ask on the recovery page, to send your links again.
Your email, when you ask for your links again. On the recovery page we use the address you enter to look up purchases made with it at Stripe and to email the links to that same address. The page never says whether anything was found, and nothing is sent if nothing was.
Your details, when you send a certificate request to a clinic. This is optional and you do it yourself from inside your pack. You see the full list of what will be shared before you send, and you tick a box to consent. We collect your name, date of birth and email (required), and passport number, nationality, country of residence, address, a note, and your pharmacy's name and email (each optional), together with your medications and the countries and dates on your trip. The purpose is to let the clinic you name issue the medical certificate you asked for, and, if the clinic chooses, to write to your pharmacy about early dispensing. The certificate records a diagnosis of ADHD alongside your medications; that is what the document is for.
Clinic and clinician details, for practices that sign up. Practice name, address, phone, email and ABN; each clinician's name, qualifications, AHPRA registration number, prescriber number and email; and, if uploaded, a signature image and a letterhead. These print on certificates and letters the practice issues.
Technical data. Our hosting provider keeps standard server logs for a limited time. Our code is written not to put names, email addresses, medications or destinations into those logs. Client IP addresses are used briefly in memory to limit abuse of the email and clinic-request forms and are not stored.
Health information and your consent
Your medication selections, and everything in a certificate request, are health information. We collect it only when you choose to give it to us for the specific thing you asked for. At checkout, the sentence above the payment button says what is attached to your purchase and what your email will be used for; continuing to Stripe is your consent to that. For a certificate request, you tick an explicit consent box after reading what the clinic will see, and the time you gave consent is recorded. We do not use health information for any other purpose, and we do not disclose it to anyone except the recipients listed next.
Who receives your information
| Recipient | What they receive | Why |
|---|---|---|
| Stripe (payments) | Your payment details, your checkout email, and your encoded trip and the rules it was priced against | To take payment and bind your pack to your purchase |
| Vercel (hosting, file storage, analytics) | Everything the site processes; stored files include per-purchase rule snapshots, clinic and clinician records, certificate requests and filed PDFs; analytics receives anonymous events only | To run the site and store what the clinic flow needs |
| SMTP2GO (email delivery) | The address and content of every email we send: pack links with your stops, medications and dates; rule-change notices; summary emails; clinic sign-in links; certificate-request notices naming the patient; issued-certificate links; pharmacy letters as PDF attachments | To deliver the email you or your clinic asked for |
| The clinic you name | Your whole certificate request, including your pack | To issue your certificate. The clinic is itself bound by the Privacy Act and its own record-keeping duties |
| Your pharmacy, if the clinic sends an early-supply letter | Your name, date of birth, medications, days of supply and travel dates, on the clinic's letterhead, with you copied in | Only if you gave a pharmacy and the clinic chooses to write |
We do not give a clinic any information about a patient who redeems its code but does not send a request. We do not share personal information with advertisers, and we do not send marketing email.
Overseas disclosure
Stripe and Vercel are United States companies and process data in the United States among other regions. SMTP2GO is a New Zealand company operating infrastructure in several regions. Your information is therefore likely to be handled outside Australia, and overseas recipients are not bound by the Australian Privacy Principles in the same way we are. We rely on each provider's published privacy and security commitments and use only the services described above. By using the features that involve them, you consent to that handling.
How we hold it, and what to keep secret
Stored files sit at addresses that cannot be guessed and are never listed publicly. Certificate requests and filed PDFs are stored at addresses derived from a secret salt; clinic records are the same. Two things in this system are links that work for anyone who holds them, like a piece of mail: your pack link, and the link to a signed certificate (which also stops working after 30 days, and immediately if the clinic withdraws the certificate). Keep both to yourself. Clinic sign-in links work once and expire in fifteen minutes; clinic sessions last 30 days and can be ended from the profile page on every device at once.
How long we keep it
| Information | Kept until |
|---|---|
| Summary or recovery email address | Not stored. Used to send the email and discarded. |
| Your purchase and trip, at Stripe | As long as your pack link needs to work, and as a transaction record for the period tax law requires (seven years). Ask us and we will remove the trip details from the record sooner. |
| Our copy of the rules your pack was priced against | Deleted 30 days after your travel date. It holds no name or email. |
| A certificate request the clinic did not act on | Deleted 90 days after you sent it, with everything in it. |
| A certificate request the clinic issued or declined, including the filed PDF and any pharmacy letter | Deleted 12 months after you sent it. The clinic keeps its own copy in your medical record under its own obligations; ours exists so you can retrieve the document for the trip. |
| Clinic and clinician profiles, signature and letterhead images | Until the practice removes the clinician or asks us to close the account. |
| Copies of sent email at SMTP2GO; anonymous analytics at Vercel | Under each provider's own retention policy. |
Analytics
We use Vercel Analytics, which is cookieless and does not identify you. The events we record carry counts only: that a check was completed and how many stops it had, that a checkout started, that a purchase happened. They never carry medication names, destinations, email addresses or pack links, and the pack and checker page addresses are stripped of their query strings before they are recorded.
Automated processing
The status of each medication at each border, the apply-by dates and the rule-change notices are computed automatically from published government rules and the selections you enter. That computation is information, not a decision about you: it does not grant or refuse you anything, and no person or system here makes a decision with legal or similarly significant effect on you. Whether to issue a certificate is decided by a clinician at the clinic you named, not by this site. We state this so that it is on record before the automated decision-making transparency rules in the Privacy Act commence on 10 December 2026.
Your rights
You can ask what personal information we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. Email contact@readysetrove.com from the address you used with us and we will respond within 30 days. For a certificate request, we can delete what we hold; anything the clinic has already filed in your medical record is theirs to manage under their own obligations, and we will tell you that is where to ask. For a purchase, we can remove the trip details from the Stripe record and delete our rule snapshot, and must keep the bare transaction record for tax purposes.
If you think we have mishandled your personal information, email contact@readysetrove.com. We will acknowledge it within seven days and respond within 30. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
If something goes wrong
We keep a written data breach response plan. If we become aware of a breach involving your information that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme, and we aim to do so within 72 hours of confirming it.
If you are outside Australia
This service is designed for travellers departing Australia: prices are in Australian dollars, the departure guidance is Australian, and the clinic flow is built around Australian prescribers. We do not target residents of any other country. The site can still be reached from anywhere, and if you use it from elsewhere the following applies in addition to everything above.
European Union and United Kingdom. Where the GDPR or UK GDPR applies to you, our lawful basis for handling your information is your consent, and for health information your explicit consent, which you give at checkout or on the clinic request form as described above. You can withdraw it at any time by asking us to delete what we hold. You have the rights of access, rectification, erasure, restriction, portability and objection; email contact@readysetrove.com and we will respond within one month. Your information is transferred to the United States and New Zealand through the providers named above. We have not appointed a representative in the EU or UK because we do not offer services there. You can complain to the supervisory authority in your country.
United States. We are not a HIPAA covered entity or business associate. Some states, including Washington, Nevada and Connecticut, regulate consumer health data without a size threshold. If one of those laws applies to you: the categories of health data we collect, where it comes from, why we collect it, who it is shared with and how long it is kept are set out above; we do not sell health data and do not use it for advertising; you can withdraw consent and ask us to delete it by email, and we will confirm within 45 days; and you may appeal a refusal by replying to our response.
New Zealand and elsewhere.If the Privacy Act 2020 (NZ) or another country's law gives you rights over your information, the same email route applies and we will honour access, correction and deletion requests on the same terms as for Australians.
Children
A trip pack or certificate request may concern a child travelling with a parent or guardian. In that case the adult enters the details and gives consent on the child's behalf, and the information is handled exactly as described above. The site is not directed at children and we do not knowingly collect information from a child directly.
Changes
This policy describes what the product actually does, so it changes when the product does, and the date at the top moves with it. The terms of service incorporate it.