Cookie Policy

Effective Date: November 20, 2025

Last Updated: November 20, 2025

1. Introduction

This Cookie Policy explains how Lionheart Clinic Pty Ltd (ABN 43 675 012 601) ("Lionheart," "we," "us," or "our") uses cookies and similar tracking technologies on our website and platform (collectively, the "Platform").

By using the Platform, you consent to the use of cookies as described in this Cookie Policy. This Cookie Policy should be read in conjunction with our Privacy Policy and Terms of Service.

2. What Are Cookies?

Cookies are small text files stored on your device (computer, tablet, or mobile phone) when you visit a website. They help the website remember information about your visit, such as your preferences, login status, and browsing behavior.

Similar technologies include:

  • Web beacons (pixels): Small invisible images embedded in web pages or emails to track user behavior
  • Local storage: Data stored in your browser to save information across sessions
  • Session storage: Temporary data storage that expires when you close your browser

3. Types of Cookies We Use

3.1 Essential Cookies (Always Active)

These cookies are necessary for the Platform to function and cannot be disabled. They enable core functionality such as user authentication, security, and session management.

Cookie NamePurposeDuration
sb-access-tokenUser authentication (Supabase)1 hour
sb-refresh-tokenSession refresh (Supabase)30 days
Session cookiesAssessment progress auto-saveSession (expires when browser closes)

Why essential cookies cannot be disabled: Without these cookies, you would not be able to log in, complete assessments, or book appointments. They are strictly necessary for the Platform to operate.

3.2 Analytics Cookies (Planned)

We plan to use analytics cookies to understand how visitors interact with our Platform, which helps us improve user experience and optimize our services.

ServicePurposeDuration
Google Analytics 4 (GA4)Track page views, user flow, traffic sourcesUp to 2 years
_gaDistinguish unique users2 years
_ga_*Persist session state2 years

Data collected: Pages visited, time spent on pages, browser type, device type, geographic location (city/region level), referral source

Privacy note: Google Analytics does NOT collect personally identifiable information (PII) such as your name, email, or medical data.

3.3 Marketing Cookies (Planned)

We plan to use marketing cookies to track the effectiveness of our advertising campaigns and understand which channels bring visitors to our Platform.

ServicePurposeDuration
Facebook PixelTrack conversions, build retargeting audiences90 days
_fbpStore and track visits across websites90 days
Google AdsTrack ad performance and conversionsUp to 540 days
_gcl_*Google Click Identifier for ad attribution90 days

How marketing cookies work: When you visit our Platform from an advertisement (e.g., Facebook ad, Google search ad), a cookie is placed to track whether you complete a desired action (e.g., booking submission, assessment completion). This helps us understand which marketing campaigns are effective.

Privacy note: We do NOT share Protected Health Information (PHI) or medical data with advertising platforms. Marketing cookies only track general website activity, not your medical information.

4. How We Use Cookies

We use cookies for the following purposes:

4.1 Authentication and Security

  • Log you in and keep you logged in across pages
  • Verify your identity when accessing protected areas
  • Prevent fraud and unauthorized access
  • Enforce security policies (e.g., password requirements, session timeouts)

4.2 User Experience

  • Save assessment progress so you can return later
  • Remember your preferences and settings
  • Enable features like form auto-fill
  • Provide personalized content based on your role (patient, clinician, admin)

4.3 Analytics and Performance (Planned)

  • Understand which pages are most visited
  • Identify technical issues (e.g., pages that load slowly)
  • Measure user engagement (time spent, bounce rate)
  • Improve website design and navigation

4.4 Marketing and Advertising (Planned)

  • Measure the effectiveness of advertising campaigns
  • Understand which marketing channels bring visitors to our Platform
  • Build retargeting audiences for relevant advertisements
  • Optimize ad spending and campaign performance

5. Third-Party Cookies

Some cookies are set by third-party services we use to provide functionality or analytics. We do not control these third-party cookies.

Third PartyPurposePrivacy Policy
SupabaseAuthentication, database, file storageView Policy
Google AnalyticsWebsite analytics (planned)View Policy
Meta (Facebook)Advertising and retargeting (planned)View Policy
StripePayment processing (no tracking cookies)View Policy

6. Managing Your Cookie Preferences

6.1 Australian Privacy Context

Unlike the European Union (GDPR), Australian law does not require explicit cookie consent banners for most cookie types. However, we believe in transparency and want you to understand and control your cookie preferences.

6.2 Browser Cookie Settings

You can control and delete cookies through your browser settings. Here's how:

  • Google Chrome: Settings → Privacy and security → Cookies and other site data
  • Safari (Mac/iOS): Preferences → Privacy → Manage Website Data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data

Note: Blocking or deleting essential cookies will prevent you from using certain features of the Platform, such as logging in or completing assessments.

6.3 Opt-Out of Analytics Cookies

Google Analytics: You can opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on.

6.4 Opt-Out of Marketing Cookies

Facebook Ads: Adjust your ad preferences at Facebook Ad Preferences.

Google Ads: Adjust your ad personalization settings at Google Ads Settings.

6.5 Do Not Track (DNT)

Some browsers support a "Do Not Track" (DNT) signal. Currently, there is no industry standard for how websites should respond to DNT signals. We do not currently respond to DNT signals, but we will review this as standards develop.

7. Cookie Data Security

We take the security of cookie data seriously:

  • Encryption: All cookies are transmitted over HTTPS/TLS 1.3 encrypted connections
  • Secure flag: Authentication cookies are marked as "Secure" (only transmitted over HTTPS)
  • HttpOnly flag: Authentication cookies are marked as "HttpOnly" (cannot be accessed by JavaScript, preventing XSS attacks)
  • SameSite attribute: Cookies use SameSite=Lax or SameSite=Strict to prevent cross-site request forgery (CSRF) attacks

8. Protected Health Information (PHI) and Cookies

Important Privacy Protection:

We NEVER store Protected Health Information (PHI) or medical data in cookies. This includes:

  • Assessment responses or scores
  • Medical diagnoses or conditions
  • GP referral details
  • Booking reasons or medical history
  • Clinician notes or treatment information

All medical data is stored securely in our database in Sydney, Australia, with AES-256 encryption at rest. Cookies only store:

  • Session identifiers (random tokens, no personal information)
  • Authentication tokens (for login verification)
  • Anonymous analytics data (page views, device type)

9. Cookie Data Retention

Cookie TypeRetention Period
Session cookiesDeleted when browser closes
Authentication cookies30 days (or until logout)
Analytics cookiesUp to 2 years
Marketing cookiesUp to 540 days

10. Updates to This Cookie Policy

We may update this Cookie Policy from time to time to reflect:

  • New cookie technologies or tracking methods
  • Changes to third-party services we use
  • Implementation of planned analytics or marketing cookies
  • Changes to Australian privacy law or regulations

When we make material changes, we will update the "Last Updated" date at the top of this page and notify you via email (if you have an account).

Current status: Analytics and marketing cookies are PLANNED but not yet implemented. We currently only use essential cookies for authentication and session management.

11. Contact Us About Cookies

If you have questions or concerns about our use of cookies, please contact our Privacy Officer:

Privacy Officer: Kenneth Cheung

Email: privacy@lionheartclinic.com.au

Phone: (02) 8552 7393

Address: 112 May Street, St Peters, NSW 2044, Australia

Business Hours: Monday-Friday, 9:00 AM - 5:00 PM AEDT/AEST

12. Related Policies

For more information about how we protect your privacy and data:

13. Australian Privacy Principles (APPs)

Our cookie practices comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988, including:

  • APP 1: Open and transparent management of personal information
  • APP 3: Collection of solicited personal information (cookies collect data with your knowledge)
  • APP 5: Notification of collection (this Cookie Policy serves as notice)
  • APP 11: Security of personal information (encryption, secure flags)

For more information about your privacy rights, visit the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au