Privacy Policy
How MediShifa collects, uses, and protects your personal and health information across our website and mobile apps.
What we collect
Account details, profile and medical information you provide, appointment and payment records, pharmacy and lab orders, device notifications, and usage data needed to run the service.
How we use it
To book and deliver consultations, prescriptions, pharmacy orders, lab tests, payments, notifications, support, fraud prevention, and service improvement.
Who sees it
We do not sell your data. Relevant information is shared only with doctors, hospitals, pharmacies, payment partners, and support staff as needed to fulfil your request.
Your controls
You may update profile details, manage notification preferences, and request access, correction, or account closure subject to legal and medical record retention rules.
1. Who we are
MediShifa (“we”, “us”, “our”) operates a telemedicine platform that connects patients with doctors, hospitals, pharmacies, and diagnostic partners through our website and mobile applications (patient and doctor apps).
This Privacy Policy explains how we handle personal information when you create an account, book care, place pharmacy or lab orders, or otherwise use MediShifa.
2. Information we collect
Depending on how you use MediShifa, we may collect:
- Identity and contact data: name, phone number, email, country, and profile photo.
- Account and authentication data: login credentials, OTP verification, Google sign-in identifiers, and session/security logs.
- Health and care data you choose to provide: date of birth, gender, address, emergency contact, allergies, medications, conditions, symptoms, prescriptions, reports, and family member details.
- Service data: appointments, consultation mode, follow-ups, hospital test bookings, pharmacy carts/orders, invoices, and delivery addresses.
- Payment data: payment status, amounts, currency, and gateway transaction references. Full card or bank credentials are handled by our payment partners—not stored by MediShifa.
- Device and technical data: app/browser type, IP address, language, crash logs, and push notification tokens.
- Communications: support messages, reviews, and in-app notifications.
3. How we use your information
We use personal information to:
- Create and manage your account and role (patient, doctor, hospital, pharmacy, or admin).
- Schedule consultations, process payments, send reminders, and enable video/voice visits.
- Share necessary clinical details with your chosen doctor, hospital, or pharmacy.
- Fulfil medicine orders and lab bookings, including delivery updates, prescription checks, and report access where available.
- Verify doctor credentials, hospital profiles, and pharmacy partner accounts.
- Detect fraud, secure accounts, enforce our Terms, and comply with law.
- Improve product quality using aggregated or de-identified analytics where possible.
4. Pharmacy (medicine) data
When you browse medicines, add items to cart, upload or link a prescription, choose delivery, or place an order, we process product selections, quantities, prescription files, shipping address, delivery preference, order status, invoices, and payment details needed by partner pharmacies.
Partner pharmacies receive only what is required to verify, dispense, and deliver. Couriers may receive name, phone, and address for shipment.
5. Hospital / lab test booking data
When you book diagnostic tests, we process selected tests, hospital or lab partner, preferred schedule, patient or family-member details, payment information, booking status, and digital reports when shared through MediShifa.
Partner hospitals and labs use this information to schedule collection or visits and to release results to you where supported on the platform.
6. Sharing and disclosure
We share information only when reasonably necessary to provide the service you requested, including with:
- Doctors, hospitals, and pharmacies involved in your booking or order.
- Payment gateways and banks for checkout and settlement.
- Cloud hosting, storage, SMS/email, and notification providers acting on our instructions.
- Regulators, courts, or law enforcement when legally required.
7. Security and retention
We use industry-standard safeguards such as encrypted connections (HTTPS/TLS), access controls, and secure cloud storage for documents like prescriptions and test reports.
No method of transmission or storage is 100% secure. Please protect your device, PIN/password, and OTP codes, and sign out on shared devices.
We retain records for as long as needed to provide services, resolve disputes, meet medical and financial record-keeping obligations, and comply with applicable law.
8. Your rights and choices
Subject to applicable law, you may request access to or correction of your information, update profile settings in the app or website, manage notification preferences, and ask us to delete or deactivate your account where legally permitted.
Some records (for example completed consultations, prescriptions, pharmacy invoices, lab bookings, or audit logs) may need to be retained even after account closure.
9. Children
MediShifa is intended for adults who can enter into a binding agreement. Guardians may create family-member profiles for dependents and remain responsible for the accuracy of that information and for booking care, medicines, or tests on their behalf.
10. International use
MediShifa may display multi-country doctors, fees, and currencies. Your information may be processed in countries where we or our service providers operate, with contractual and technical safeguards appropriate to the sensitivity of health data.
11. Changes and contact
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of MediShifa after an update means you accept the revised policy.
For privacy questions or data requests, contact us through the in-app Help & Support option or the Contact page on medishifa.com.