DigCare Privacy Policy
This Privacy Policy explains how DigCare collects, uses, stores, and protects your personal and health data. It covers all data collected across every platform feature, including health cards, consultations, prescriptions, lab services, payments, insurance, messaging, and push notifications.
1. Data We Collect
1.1 Personal Information
- Name, email address, phone number, username
- Role (Student, Adult, Visitor, Doctor, Pharmacist, Lab Technician)
- Profile photo (optional)
- Location data (latitude/longitude — provided at registration, optional)
1.2 Health Information (Patients)
- Health Card data (card number, allergies, blood type, emergency contacts, medical history)
- Prescriptions and medication records
- Lab test orders and test results
- Appointment and consultation history
- Encrypted chat messages with healthcare providers
1.3 Provider Information
- Professional credentials and verification documents (uploaded for identity verification)
- Facility affiliations, specialisations, and shift schedules
1.4 Insurance & NHIS Information
- Insurance provider name, policy / membership number
- Coverage start and end dates, plan type, and coverage tier
1.5 Payment Information
- Transaction amounts, payer email, and phone number
- Payment method type (Card, MoMo, Bank Transfer)
- Payment tokens and references handled by Paystack (Card numbers and MoMo PINs are never stored by DigCare)
1.6 Notification & Device Data
Device tokens (registered via Firebase Cloud Messaging and Expo Push Notifications) and notification preferences.
1.7 Technical Data
IP addresses (logged for security and consent audit trails) and User-Agent strings (device/browser information).
2. How We Use Your Data
Service Delivery
Facilitating appointments, video consultations, prescriptions, lab orders, billing, and digital health card access.
Identity Verification
Verifying provider credentials (doctors, pharmacists, lab techs) through identity document review.
Health Card Access Control
Processing remote access requests, OTP verification, PIN scan authorisations, and access revocations.
Communication
Sending push notifications for appointments, prescriptions, lab results, access requests, and system updates.
Insurance & Billing
Verifying coverage eligibility, submitting claims, and managing provider split payments via Paystack.
Security & Compliance
Maintaining permanent audit logs, enforcing access controls, and complying with legal duties under Ghanaian law.
3. Third-Party Services
We share data with the following infrastructure providers strictly as needed to deliver platform functionality:
| Service | Purpose | Data Shared |
|---|---|---|
| Paystack | Payment processing (Card, Mobile Money, Bank Transfer) | Transaction amounts, payer email, phone number, payment tokens |
| Cloudinary | Secure media storage (profile photos, verification docs, lab result uploads) | Uploaded encrypted files |
| Firebase / Expo Push | Push notification delivery | Device push tokens, notification alert payloads |
| Twilio | Video & audio consultations (WebRTC) | Encrypted audio/video streams, room identifiers |
4. Health Card & Consultation Data
- Health Card data is protected by your user-set 6-digit PIN. Remote access requires both your explicit approval and OTP verification entered by the doctor.
- Consultation metadata (date, time, duration, participating provider) is logged for billing and audit purposes.
- All access events (requests, approvals, denials, scans, revocations) are permanently logged in your immutable Data Access Log.
- Chat messages are stored securely and are accessible only to the participants of the conversation.
5. Verification Document Data
Verification documents (government IDs, professional licences, facility affiliation proofs) are stored securely via Cloudinary with encryption at rest and in transit.
- Documents are accessible strictly to DigCare's credential verification team and platform administrators.
- Documents are never shared with other users, healthcare providers, or commercial third parties.
- Documents are used solely for identity and credential verification — never for marketing, profiling, or analytics.
6. Payment Data Security
PCI-DSS Compliant Payment Handling via Paystack
DigCare does not store card numbers or Mobile Money PINs. All payment credential collection and processing are handled directly by Paystack.
- Billing records (transaction amounts, references, split details) are retained as required by Ghanaian financial regulations.
- If a payment is debited but fails to verify, related transaction data is retained to assist in prompt dispute resolution.
7. Notification Data
- Device tokens are used solely for delivering push notifications and are stored securely on DigCare's servers.
- Tokens are not shared with third parties beyond the notification delivery services (Firebase Cloud Messaging / Expo Push).
- You may opt out of push notifications at any time via app settings. Essential security alerts may still be delivered in-app.
8. Data Retention & Deletion Schedule
| Data Type | Retention Period |
|---|---|
| Active Account Data | Duration of active account |
| Personal Data (Deleted Accounts) | Deleted within 30 days |
| Chat Messages (Deleted Accounts) | Removed within 30 days |
| Completed Prescriptions & Audit Logs | Retained as required by healthcare regulations |
| Billing & Payment Records | Retained as required by financial regulations |
| Verification Documents | Duration of verified account; deleted within 30 days of account closure |
9. Your Rights Under Ghana Data Protection Act 2012 (Act 843)
Under the Ghana Data Protection Act 2012 (Act 843), you have the following statutory rights regarding your personal and health information:
Right to Access
Request a complete copy of the personal and health data DigCare holds about you.
Right to Rectification
Correct or update any inaccurate or incomplete personal information.
Right to Erasure
Request account deletion and data removal (subject to statutory health retention rules).
Data Portability
Request a structured export of your medical history, prescriptions, and health card records.
Right to Withdraw Consent
Revoke consent for optional data processing features at any time without impacting prior lawful processing.
10. Security Measures
11. Children's Privacy
Student users under 18 must have parental/guardian consent. We do not knowingly collect personal data from children under 13 without verifiable parental consent, in full compliance with relevant child protection regulations.
13. Changes to This Policy
We will notify you of material changes to this Privacy Policy via in-app notification and require re-acceptance of the updated policy before continuing to use DigCare.
Data Protection Officer
Have questions about how your health data is handled, stored, or processed? Reach out directly to our privacy compliance team.
