NDIS Ally
Privacy Policy
Last updated: 16 September 2026.
Sumit Dahal trading as NDIS Ally (ABN 22 320 747 179) operates NDIS Ally, software used by Australian NDIS support providers. This policy explains how NDIS Ally handles information across the public website, Provider Portal and mobile app.
Who this policy applies to
This policy applies to people who visit ndisally.com.au, start or administer a provider workspace, or use an account or access code supplied by a provider, including owners, office users, support workers and participant/family users.
NDIS Ally is software for providers. It is not the National Disability Insurance Agency and it is not an NDIS registration or quality-and-safeguards authority.
The Android app is intended for account holders aged 18 or over for the first release. A provider may still lawfully store participant records about a person under 18 where the provider is authorised to do so; that does not mean the child is an NDIS Ally app account holder.
Information we handle
Account and identity information can include business name, owner name, names, email addresses, mobile numbers, password hashes, account role, provider/workspace membership and verification state. Support-worker and participant profiles can also contain provider-entered contact and service information.
Provider operational records can include participants, staff, rosters, shifts, timesheets, progress or shift notes, tasks, goals, events, incidents, leave and availability, participant requests, messages, compliance records, documents and internal finance or invoice records. Access to these records is controlled by the provider workspace and the user's role or assignment.
The mobile app may temporarily store authenticated session information in secure device storage and limited offline/retry data needed for supported mobile workflows. Documents selected for upload, downloaded documents and temporary cache files may pass through device storage as part of the action the user chooses.
If a worker chooses to allow location permission, the mobile app may collect foreground location coordinates when the worker clocks in or out. Location is optional for clocking: if permission is denied or location is unavailable, the attendance action can proceed without coordinates. NDIS Ally does not use background location for worker tracking.
If a user enables push notifications, the app registers a device push token so notifications can be delivered. Notification preferences are controlled in the product. Push notifications are designed to use generic lock-screen wording rather than participant or clinical detail.
Billing for provider subscriptions is processed by Stripe. NDIS Ally stores subscription, invoice and billable-person state needed to operate billing, but it does not store full payment-card numbers. The Android app itself does not sell subscriptions or take card payments.
Support or security correspondence may include the information a person sends to the published support or security contact. Do not send passwords, one-time codes or unnecessary participant extracts in an initial support message.
Why we use this information
We use information to create and secure accounts, verify sign-up, provide provider workspaces and mobile access, show authorised rosters and participant information, support clocking and timesheets, store notes and documents, deliver notifications, support provider billing, respond to support requests, maintain audit and security records, and operate the service.
Provider-entered participant and workforce records are used to provide the provider's NDIS-related operational workflows. NDIS Ally does not use those records as a public marketing list.
Service providers and disclosures
NDIS Ally uses third-party technology providers to operate parts of the service. Current product integrations include Stripe for provider subscription billing, email and SMS providers for account communications and verification, Expo/Firebase services for mobile push delivery, and hosting or storage services used to run the application and store authorised records.
We disclose information to those providers only as needed to provide the relevant service. A provider workspace may also connect external services such as Xero; those actions are initiated and controlled within that provider's account.
NDIS Ally does not sell personal information and the Android app does not contain advertising functionality.
Provider responsibilities and access
For information entered into a provider workspace, the provider decides which workers, office users and participant/family users should have access and is responsible for ensuring it has authority to collect and use that information.
Provider owners and authorised office users can view and update operational records according to their permissions. Support workers and participant/family users receive only the product access allowed for their account, role, assignment or access code.
Retention
Operational records are retained while needed to provide the workspace and as reasonably required for security, audit, billing, dispute handling and applicable legal or regulatory obligations. Different record types may need different retention periods, including records the provider is required to keep.
Closing an account or cancelling a subscription does not automatically erase operational records. A deletion or offboarding request is reviewed against the provider's responsibilities and any applicable retention, audit and billing requirements.
Security
NDIS Ally uses account authentication, role and tenant access controls, private storage patterns, audit records and encrypted HTTPS connections as part of its security controls. No online service can guarantee absolute security.
Users must keep login details confidential and should report suspected unauthorised access promptly through the security contact.
Access and correction
Where the product allows it, authorised users can review or update their account details and provider records in-product. Participant or workforce records controlled by a provider may need to be corrected by that provider.
Use hello@ndisally.com.au for support, billing questions, and account help. Ask for a privacy access or correction request if you cannot complete the change in-product.
Data and account deletion requests
NDIS Ally provides a deletion-request process rather than automatic hard deletion of regulated provider records. A user can request removal of their login or ask for account/workspace deletion or offboarding, but some information may need to be retained for legitimate audit, billing, security, legal or provider record-keeping reasons.
Use the in-product support/deletion route where available, or email the support contact with the subject “Data deletion request”, the workspace name and the account email. See also /support#data-deletion. We will review the request and explain the outcome; a request is not a promise of automatic or same-day erasure.
Important product boundaries
NDIS Ally can produce local NDIA claim-file or finance exports for a provider to use in its own process. That export is not a submission to NDIA, PRODA or PACE.
A local or Xero-ready export does not by itself mean an invoice was sent, paid or accepted by Xero or another external system.
NDIS Ally does not currently offer a native participant invoice PDF/email send. Internal invoices in the Provider Portal are not the same as a sent participant invoice.
Privacy and security contact
Use hello@ndisally.com.au for security or privacy reports.
Describe the issue and a safe way to continue the conversation. Do not include passwords, one-time codes or bulk participant extracts in the first message.