Privacy Policy
Last Updated: March 2026
This Privacy Policy describes how DoctorStatus™ ("we", "us", or "our") collects, uses, and discloses your information. We are committed to protecting your privacy and ensuring a transparent experience.
Operational information only
DoctorStatus™ is built around operational and directory information that clinics choose to publish (for example clinic and doctor names, locations, specializations, and status updates). We do not operate as a patient health record system and do not ask the public to submit private medical data or patient health information to use the directory.
1. No third-party ads; security and integrity
DoctorStatus™ does not use third-party advertising networks and does not sell your personal information to marketers. We may process technical and account-related information—including server logs, IP addresses, browser or device signals, bot-protection results, and activity tied to registered accounts—for security, abuse prevention, spam detection, rate limiting, fraud prevention, and platform integrity. If we detect abuse, spam, or a serious discrepancy with our policies, we may investigate, restrict, suspend, or block access or accounts as appropriate.
2. Information we collect
- Visitors and public users: You can browse much of the site without creating an account. We may still collect limited technical data needed to run the service (for example network requests, cookies or similar technologies required for sessions or security, and interactions such as search queries where needed for functionality or abuse protection). We do not treat the public directory as a place to collect patient medical records or patient personal health information.
- Registered clinic operators: Creating and managing a clinic on DoctorStatus™ requires an account. Sign-in may use email and password, one-time codes (OTP), and/or Google OAuth, as offered on our login flows. For those accounts we process identifiers such as email address and, where applicable, profile name from the provider, for authentication, account management, and communication about the service. Only users who register in this way share account contact details with us; casual visitors are not asked to register simply to view operational listings.
- Clinic and directory content: Listings (clinic names, addresses, doctor names, specializations, operational status, and similar fields) are provided voluntarily by verified clinic operators and displayed according to our terms and product rules.
- Clinic team roles, invitations, and ownership changes: When a clinic owner invites a manager or initiates an ownership transfer, we process data needed to run those flows—for example invitee email addresses, invitation and acceptance timestamps, role assignments (owner vs manager), and records that show which account ultimately controls the clinic after a transfer. That information is used to operate access control, audit sensitive actions, secure the service, and meet legal or safety obligations where applicable.
3. Data ownership and responsibility
Clinic listing content is entered and managed by the respective clinic operators (and by managers they authorize, where the product allows). DoctorStatus™ hosts and displays that information and runs onboarding checks; operators remain responsible for what they and their delegates publish. Privacy practices for patient-facing care at a clinic are separate from this platform.
4. Sensitive clinic account actions
Adding or removing managers and completing an ownership transfer are high-impact actions. We may show confirmations and warnings in the product; you should read them carefully. We do not use these features to collect patient health data—they concern who may administer the clinic account. If you accept an invitation or a transfer, you acknowledge that we will record the resulting roles and account linkage as part of normal service operation. We are generally not able to reverse a completed ownership transfer at your request; resolving disagreements between parties is between those users except where we must intervene for security, fraud, or legal reasons.
5. Data Storage & Security
Your data is securely stored using enterprise-grade database solutions. We employ strict security policies so that only authorized clinic owners and designated managerscan perform permitted changes to a clinic's operational data, according to their roles.
6. Jurisdiction
This policy is governed by the laws of India. Any disputes arising in connection with this policy shall be subject to the exclusive jurisdiction of the courts located in New Delhi.
7. Bot protection
To protect the platform and limit automated abuse (including alongside rate limiting and other safeguards described above), we use Cloudflare Turnstile. Turnstile may process technical signals to distinguish human use from bots. Your use of DoctorStatus™ is subject to the Cloudflare Turnstile Privacy Addendum.
8. Contact Us
For privacy-related concerns, please contact our Data Protection Officer at support@doctorstatus.in.