4. Information We Collect
We collect only what we need to arrange and run a safe companion visit. We group it so a reviewer can map app behavior to this policy without guessing.
— Information You Provide
• Account details: full name, email (from Google/Apple sign-in or you type it), primary mobile number, address, and emergency contact you enter.
• Patient & family details: patient full name, age, gender, language preferences, mobility needs (e.g., wheelchair), cognitive/language needs, and any health context you choose to share (symptoms, conditions, past reports you describe in text).
• Service details: hospital name/branch, doctor name, department, ward/room, diagnostic appointments, pharmacy pick-ups, and time slots.
• Health-related uploads (voluntary): photos of prescriptions, discharge summaries, reports, or other documents you choose to attach to a booking — including text visible inside those images.
• Support messages: what you send to support via WhatsApp, call, email, or in-app chat, and any attachments.
• Payment context: UPI handle or card reference passed to our PCI-DSS compliant processor — we do not store full card numbers or UPI PINs.
— Automatically Collected Information
• Device & log: IP address, browser type, device type, OS and app version, language, timestamps, pages/screens viewed, booking actions, error and crash reports.
• Performance & analytics: anonymized performance data via Vercel Speed Insights (see §8) to improve load speed — not cross-app tracking.
• Approximate & precise location: only if you select “At home” as the meeting point (we store latitude/longitude you confirm), and — during an active visit only — live trip coordinates shared on channel trip:<id> to your booking circle. We never collect ACCESS_BACKGROUND_LOCATION.
• Cookies identifiers (§9): only on the website, to keep sessions and remember form progress.
— Information from Third Parties
• Authentication providers: profile name and verified email from Google or Apple when you sign in with them.
• Verification partners: for companions, verification result (not raw document images in our long-term store) from UIDAI (Aadhaar) and AuthBridge (police clearance) — used once to approve activation.
• Communications providers: delivery status for SMS/WhatsApp (via MSG91 and WhatsApp gateway) and push (via Firebase Cloud Messaging) — not your message content.
• Hosting & platform: infrastructure logs from Supabase (database/auth/storage) and Vercel (hosting/edge) — see §7–8.