Offline — Enable network to continue
Privacy Center

Privacy across every HealthHepta service

This policy explains how HealthHepta handles personal and business data across medicine commerce, the sales hierarchy, stores, deliveries, hospital networks, ambulance providers, drivers, and patient bookings.

Effective: August 20, 2026Version: 2.0Applies to web, PWA and mobile apps

HealthHepta Pvt. Ltd. ("HealthHepta", "we", "our", or "us") respects your privacy. This policy should be read before using a HealthHepta account, role dashboard, website, PWA, Android app, API, delivery service, or ambulance service.

Section 01

Who and what this policy covers

This policy applies when you use HealthHepta as an Admin; CMO; Field Sales Head (FSH); Regional Marketing Manager (RMM); District Sales Manager (DSM); Field Sales Person (FSP); Store; Delivery Partner; Retailer/User; Organization; Hospital; Ambulance Provider; Ambulance Driver; or B2C User/Patient. It also covers a person who books an ambulance for somebody else, a responsible contact, and visitors who browse without signing in.

HealthHepta generally acts as the data fiduciary for processing it determines. A hospital, organization, ambulance provider, store, employer, or other participating entity may separately determine how it handles information in its own operations. In that case, its own notices and legal duties may also apply.

Emergency and medical notice: HealthHepta helps users request and coordinate services. It is not a substitute for government emergency numbers, clinical judgment, medical advice, diagnosis, or treatment. If there is immediate danger, contact the appropriate emergency service without waiting for the app.

Section 02

Information we collect

The exact fields depend on your role, permissions, and the feature you use.

Identity and authentication

Name, phone number, email, OTP events, password hash, account ID, role, approval status, profile image, language, and session or device identifiers. We do not store a readable copy of your password.

Address and business profile

Home, shop, office, hospital, provider, or organization address; pincode; service area; reporting entity; contact person; GST, PAN, registration, licence, and other business records.

Documents and workforce records

Identity and verification documents, Aadhaar details where lawfully required, driver licence, vehicle and insurance records, employment profile, attendance, visits, leads, tasks, targets, sales, collections, and performance.

Commerce and finance

Searches, cart, wishlist, orders, products, free-lot or bonus quantities, invoices, delivery records, payment status, collections, refunds, returns, wallet or part-payment information, and support disputes.

Ambulance and patient service

Patient name, age or gender if provided, condition or service category, responsible person, pickup, destination, preferred hospital, bed request, assigned ambulance and driver, booking events, OTP verification, fare, payment, rating, and incident reports.

Location, device and diagnostics

GPS coordinates, route and milestone locations, IP address, browser or app version, operating system, push token, permission state, network status, logs, timestamps, crash details, and security events.

We receive information directly from you, from another person acting for you, from your employer or reporting entity, from a hospital, store, or provider that creates or manages your account, from an assigned service partner, from your device with permission, and from your use of our services. Please provide only information you are authorized to share.

Section 03

Role-specific processing and visibility

Access depends on both the signed-in role and the actual reporting, ownership, booking, or assignment relationship.

Admin

Platform administration

Authorized administrators may access platform-wide records when needed for user management, approvals, finance and refunds, support, analytics, security, compliance, and incident investigation. Administrative access is permission-controlled and should be auditable.

CMO, FSH, RMM, DSM and FSP

Sales and marketing employees

We process profiles, reporting relationships, attendance, assigned regions, visits, leads, targets, tasks, sales, collections, and performance. A manager may view and manage their own records and the records within their authorized lower reporting tree, but not unrelated branches or higher-role private data.

Store

Fulfilment and inventory

Stores use business, licence, inventory, transfer, order, invoice, payment, delivery assignment, and delivery-partner information to fulfil orders and operate their assigned service area.

Delivery Partner

Last-mile delivery

We process identity, verification documents, assigned store and orders, availability, collections, delivery milestones, and location used for routing and proximity checks. Assigned delivery partners receive only the customer and order details needed to complete a delivery.

Retailer or User

B2B commerce customer

We process account and pharmacy details, pincode, addresses, verification records, cart and wishlist, orders, invoices, payments, returns, support requests, and preferences to provide medicine and healthcare-product services.

Organization

Hospital network owner

Organizations may manage hospitals in their own network and view scoped fleet, booking, bed, operational, financial, and performance information belonging to those hospitals. They cannot access an unrelated organization or provider.

Hospital and Ambulance Provider

Ambulance operations

We process entity registration, licences, staff, ambulances, vehicle documents, drivers, assignments, availability, beds, bookings, patients, fares, payments, alerts, and scoped live or historical trip locations. Hospitals and providers are separate entities and see only their own authorized operations.

Ambulance Driver

Trip execution

We process driver identity and documents, assigned vehicle, availability, booking responses, trip milestones, OTP verification events, earnings, ratings, safety events, and location while online or completing an active assignment.

B2C User, Patient or Booker

Ambulance customer

We process identity and contact details, pickup and destination, patient or responsible-person details, ambulance and bed requests, condition and service category, booking status, OTP events, trip tracking, fare, payment, support, and ratings.

Hierarchy rule: an upper sales role may access authorized data in its own subordinate tree to assign and track work. A lower role should not see upper-role records, and one branch should not see an unrelated sibling branch. Role names alone do not create access; the reporting or entity relationship must also match.

Section 04

How and why we use information

  • Create and secure accounts; verify phone numbers, email addresses, roles, documents, approvals, and login attempts.
  • Display products available for a pincode; operate carts, orders, inventory, transfers, bonus quantities, invoices, fulfilment, delivery, payments, refunds, and customer support.
  • Operate the sales hierarchy, territory allocation, leads, attendance, visits, targets, tasks, performance tracking, reporting, and authorized analytics.
  • Search for hospitals and locations; estimate routes, distance, arrival time, ambulance availability and fares; create bookings; assign drivers and vehicles; reserve a bed when requested; and complete pickup and drop-off verification.
  • Send OTPs, transactional messages, assignment alerts, push notifications, safety notices, and service updates.
  • Maintain security, prevent duplicate or fraudulent activity, investigate incidents, enforce policies, recover services, and meet accounting, tax, regulatory, legal, and audit obligations.
  • Measure reliability, improve accessibility and performance, debug errors, plan service coverage, and develop new features using aggregated or de-identified data where practical.

Depending on the context and applicable law, we process information with your consent, to provide a service you requested, for employment or business administration, to comply with law, to protect life or health in an emergency, and for other uses permitted by law. Where consent is required, you may withdraw it, but features that depend on that information may stop working.

Section 05

Location, routes and live tracking

Location is used only when relevant to the feature and permission you selected. Depending on the role, it may include the following:

  • Retailers and B2C users: foreground location to identify a pickup or delivery address, find services, search nearby places, estimate distance and fare, and follow an active trip.
  • Ambulance drivers: location when going online and periodic foreground or background location during an accepted active trip so dispatchers and the authorized patient, hospital, provider, or organization can see progress.
  • Delivery partners: current location for routing, delivery milestones, and a proximity check before an OTP can be sent at the registered shop or delivery address.
  • Field employees: location connected to attendance, planned or completed visits, territory activity, and role-authorized operational maps where that feature is enabled.
  • Hospitals, providers and organizations: the latest and historical positions of their own assigned vehicles and bookings, including route and stoppage information where recorded.

Active ambulance tracking can continue when the Driver app is in the background if the driver grants background-location permission. A visible system notification may be shown while tracking is active. Tracking is intended to stop when the trip is rejected, cancelled, completed, the driver logs out or goes offline, or no active assignment remains. A device, network, operating system, or permission failure can delay or interrupt updates.

You can change location permissions in device or browser settings. Disabling location may prevent live tracking, current-location pickup, attendance, routing, or proximity-verified delivery. Map searches and routes may be processed by Google Maps or another configured mapping service under that provider's privacy terms.

Section 06

When and with whom information is shared

We do not sell or rent personal information. We disclose only what is reasonably needed for a service, authorized oversight, safety, security, or legal obligation.

  • Within an authorized sales reporting tree, upper roles receive subordinate work and performance data needed for targets, tasks, supervision, and reports.
  • A fulfilling store receives order, retailer, invoice, payment, and address details; its assigned delivery partner receives the minimum order, contact, and location information needed for delivery.
  • For an ambulance booking, the assigned driver and responsible patient or booker may receive each other's relevant name, phone number, pickup or destination, and live status after assignment.
  • A hospital, ambulance provider, or organization receives bookings, fleet, driver, patient, bed, trip, payment, and tracking data only within its authorized operational scope.
  • Service providers may process data for cloud hosting, databases, authentication, maps, routing, storage, analytics, messaging, email, push notifications, payment processing, app distribution, security, and support.
  • Authorities, courts, advisers, insurers, or affected persons may receive information where required by law, necessary to protect rights or safety, or needed to investigate fraud, abuse, accidents, or security incidents.
  • If the business is reorganized, financed, acquired, or transferred, relevant data may be transferred subject to confidentiality and applicable law.

Technology and communication providers

Current services may include Google Firebase and Google Cloud for authentication, databases, storage, live data and push notifications; Google Maps for places, geocoding and maps; Fast2SMS, WhatsApp-compatible messaging services, mobile networks and email providers for OTPs or alerts; payment providers when online payment is enabled; and hosting, monitoring, app-store, and document-processing providers. Their own privacy notices may also apply when they independently collect data.

Some providers may process or store information outside your state or outside India. Where applicable, we use contractual, technical, access-control, and legal safeguards and follow government restrictions on cross-border transfers.

Section 07

Automated matching, assignment and risk signals

HealthHepta uses rules and calculations to support fast operations. These processes can affect which option appears first, but they do not provide a medical diagnosis.

  • Ambulance suggestions may consider whether the destination is a registered hospital, emergency category, required ambulance type, ownership or service scope, bed information, driver and vehicle availability, pickup or destination distance, route direction, return route, recent workload, and operational flags.
  • Delivery assignment may consider the store's available delivery partners, current and previous workload, existing assigned orders, route compatibility, and delivery status. Stores can review or reassign where the product allows it.
  • Fare and ETA estimates may use service category, route distance and duration, base charge, per-kilometre or per-minute rates, minimums, fees, taxes, waiting or other configured charges. The confirmed record may differ if the route or service changes.
  • Late arrival, repeated rejection, location inconsistency, user reports, failed verification, suspicious access, or policy violations may create a flag for review, restriction, or blocking.

Authorized staff may review assignments, flags, support disputes, and corrections. Contact us if you believe an automated recommendation or operational flag was based on incorrect personal data.

Section 08

Data retention, account closure and deletion

We keep information only for as long as reasonably required for the purposes in this policy, an active account or assignment, safety and dispute handling, legitimate business records, or a legal obligation. Different records have different retention needs:

  • Account and role records are generally retained while the account or business relationship is active and for a reasonable period afterward.
  • Orders, invoices, payments, refunds, tax records, contracts, bookings, trips, patient transport records, OTP audits, incidents, and related logs may be retained for statutory, accounting, safety, fraud-prevention, legal-claim, and audit periods.
  • Live-location records are used for current operations; selected route samples and trip milestones may remain with booking history for safety, support, performance, and dispute review.
  • Push tokens, expired sessions, temporary search state, cached content, and diagnostic logs are deleted, rotated, or anonymized when no longer useful, subject to operational backup cycles.
  • Aggregated or irreversibly de-identified information may be retained because it no longer identifies an individual.
Retailer account deletion: a signed-in Retailer/User can request deletion at /delete-me. The active retailer profile and wishlist are removed and the session is ended. The current deletion process keeps a restricted archive containing the deletion event, prior profile snapshot, order history, and related business records for audit, accounting, fraud prevention, disputes, and legal obligations. These retained records are not treated as an active storefront account.

Other roles can request account closure, access, or deletion through the privacy contact below. We may need to verify identity and authority, preserve records that cannot lawfully be erased, or retain a minimal suppression record so a deleted account is not recreated improperly. Deletion from encrypted backups may occur on the normal backup-rotation schedule.

Section 09

How we protect information

  • Role-based and hierarchy-based authorization, entity and booking scope checks, and least-privilege access controls.
  • Encrypted network transport, HTTP-only session cookies for web access, protected native tokens, OTP verification, and hashed passwords where email/password login is enabled.
  • Database security rules, restricted service credentials, audit and security logs, rate limits, input validation, and monitoring of suspicious or unauthorized behavior.
  • Operational controls for document access, staff or partner access, account approval, session termination, and incident response.

No system can guarantee absolute security. Keep your OTP, password, phone, and unlocked device private; use official HealthHepta applications; and report an unexpected login, message, or disclosure promptly. HealthHepta will never ask you to disclose an OTP for an unrelated transaction.

Section 10

Your choices, rights and responsibilities

Subject to applicable law and any valid exception, you may ask us to:

  • Confirm whether we process your personal data and provide a summary of that processing and relevant sharing.
  • Correct, complete, or update inaccurate account, contact, address, profile, document, booking, or role information.
  • Erase personal data that is no longer required or withdraw consent where processing depends on consent.
  • Stop optional promotional communications while continuing to receive essential OTP, safety, booking, order, payment, and account messages.
  • Review a grievance, incorrect assignment, operational flag, privacy concern, or suspected unauthorized access.
  • Nominate another person to exercise applicable rights in the event of death or incapacity where the law provides that right.

You can update many fields from the relevant profile or dashboard and control browser, location, camera, document, and notification permissions through your device. We may verify your identity, role, booking relationship, or authority before acting on a request. We may decline or limit a request where retention or disclosure is required by law, necessary for another person's rights or safety, or covered by another lawful exception, and will explain where appropriate.

India privacy requirements may include the Digital Personal Data Protection Act, 2023 and rules or commencement notifications issued under it as their provisions take effect. Official materials are available from India Code and the Ministry of Electronics and Information Technology.

Section 11

Patients, children and booking for another person

Business dashboards and independent account management are intended for adults who have authority to act for themselves or their entity. Ambulance services may involve a child, dependent, unconscious patient, or another person who cannot complete the booking.

  • When booking for somebody else, provide the responsible person's correct contact details and only the patient information needed to arrange safe transport.
  • You confirm that you are authorized to provide that information and, where practical, that you have informed the patient or their lawful guardian about the booking and this policy.
  • For a child, the parent or lawful guardian should create or authorize the request and OTP verification, except where emergency law permits otherwise.
  • Do not enter detailed diagnoses, documents, or sensitive facts that the service does not request. Hospitals and care professionals remain responsible for their own clinical records and consent obligations.

Section 12

Cookies, local storage, notifications and communications

We use essential cookies or similar storage for login sessions, role isolation, security, pincode and preference selection, cart continuity, offline app assets, notification routing, and service reliability. You can clear browser or app storage, but doing so may sign you out, remove local preferences, or interrupt queued actions.

We may send OTPs and transactional notices by SMS, WhatsApp-compatible service, email, phone, or push notification. Transactional and safety messages are part of the requested service. Marketing messages, if any, will provide an opt-out where required. Push permissions can be disabled in device settings, although this can delay booking or assignment alerts.

Section 13

Third-party sites and app stores

HealthHepta may link to maps, payment services, telephone diallers, app stores, support channels, hospitals, stores, or other third-party services. A third party's own terms and privacy policy govern information it collects independently. Review those notices before providing information outside HealthHepta.

Section 14

Changes to this policy

We may update this policy when services, roles, technology, vendors, laws, or data practices change. The current version and effective date will remain available at /privacy. If a change materially affects how we use personal data, we may also provide an in-app, website, email, SMS, or push notice and request fresh consent where required.

Section 15

Privacy requests and grievances

Contact HealthHepta's Privacy and Grievance team with a privacy request, correction, deletion request, consent concern, safety issue, or complaint. Include your name, phone or account identifier, role, and enough detail to locate the relevant record. Do not email an OTP, password, full Aadhaar number, or unnecessary medical document.

Postal address

HealthHepta Pvt. Ltd.
Gokarna, Murshidabad, West Bengal 742136, India

We will acknowledge and investigate a grievance within a reasonable period and in accordance with applicable law. If a statutory regulator or Data Protection Board has jurisdiction and the applicable process is in force, you may also use that authority's complaint process after giving us an opportunity to resolve the issue.