Policy

Security Policy

Care2All Australia Pty Ltd, trading as ShiftLink · Last updated 21 July 2026

Payment security

When you subscribe to ShiftLink, your card details are transmitted through a secure, PCI-compliant payment gateway. ShiftLink does not store your full card number, expiry date or CVV on our own servers at any point after your payment is processed.

Row-Level Security
Every organisation's data is isolated at the database level — no provider can see another's records.
Sydney data hosting
All customer data is hosted within Australia, keeping your data under Australian jurisdiction.
Full audit logging
Every authentication event and data change is logged and tamper-evident for compliance review.

How we protect your data

ShiftLink is built for organisations handling sensitive NDIS participant, provider and worker information, so security is treated as a foundation rather than an add-on:

  • Encryption in transit — all traffic between your browser or mobile app and ShiftLink is encrypted over HTTPS.
  • Authentication — access is controlled through JWT-based authentication, with permissions scoped to each user's role.
  • Multi-tenant isolation — Row-Level Security ensures one provider organisation's data is never visible to another.
  • Audit trail — every login, data change and administrative action is logged for accountability and NDIS Commission readiness.

Card payment processing

Subscription payments on ShiftLink are handled by an accredited third-party payment processor. Card details you enter are sent directly and securely to that processor — they are transmitted through an encrypted connection and are not held on ShiftLink's own infrastructure after the transaction is processed.

Only approved card scheme logos are displayed on our payment pages, and all transactions are processed and settled in Australian Dollars (AUD).

Card testing & fraud prevention

To protect our customers and cardholders from misuse, ShiftLink applies safeguards against automated card-testing and fraud attempts on our payment pages, including transaction monitoring and restrictions on abnormal request patterns.

Reporting a security concern

If you believe you've found a security vulnerability or have a concern about how your data is handled, please contact us directly at support@shiftlink.au. We take all reports seriously and will respond promptly.

This Security Policy should be read alongside our Privacy Policy and Terms & Conditions. It may be updated from time to time to reflect changes to our systems or practices. © Care2All Australia Pty Ltd. All rights reserved.

Scroll to Top