Privacy Policy
This page was last updated on August 30, 2026.
1. Information We Collect
We collect information you provide directly (name, email, phone, medical-topic search queries, appointment details, doctor-registration details including credentials and Google Business Profile links), and information collected automatically (IP address, browser type, device information, pages visited, via cookies and similar technologies).
2. How We Use Information
- To operate the directory, process bookings, and facilitate instant consultations
- To verify doctor listings against submitted Google Business Profiles
- To process payments via our third-party payment processors
- To respond to support requests
- To improve the Service and understand usage patterns (aggregated/anonymized where possible)
- To comply with legal obligations
3. How We Share Information
We share information with: (a) the practitioner you choose to book with, to facilitate your consultation; (b) payment processors (Stripe, Razorpay, or PayPal) to process transactions; (c) scheduling providers (e.g. Calendly) if you use our booking calendar; (d) service providers who help us operate the Service (hosting, analytics, email); and (e) authorities where required by law. We do not sell your personal information to third parties for their own marketing purposes.
4. Cookies & Tracking
We use cookies and similar technologies for essential site functionality (e.g. remembering that you've seen the instant-consultation popup this session), analytics, and, where applicable, advertising. See our full Cookie Policy for details and how to manage preferences.
5. Payment Data
We do not store full payment card numbers on our own servers. Payment processing is handled by PCI-DSS compliant third-party processors (Stripe, Razorpay, or PayPal); please also review their respective privacy policies.
6. Data Retention
We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Doctor listing data is retained while the listing is active plus a reasonable period for record-keeping after removal.
7. Security
We use reasonable technical and organizational measures (encryption in transit, access controls) to protect personal information. No system is 100% secure, and we cannot guarantee absolute security.
8. Your Rights by Region
| Region | Applicable framework | What it means for you here |
|---|---|---|
| European Union, UK, Switzerland, Norway, Iceland | GDPR / UK GDPR | You have rights to access, correct, delete, and export your data, and to object to certain processing. Our legal basis for most processing is consent or contract performance. |
| California, USA | CCPA / CPRA | California residents have the right to know what personal information is collected, to request deletion, and to opt out of the "sale" or "sharing" of personal information (we do not sell personal information). |
| Rest of USA | State-level privacy laws (varies) | Several states (Virginia, Colorado, Connecticut, and others) have their own consumer privacy laws with similar access/deletion rights; we apply CCPA-equivalent protections platform-wide as a baseline. |
| Canada | PIPEDA | You have the right to access your personal information and challenge its accuracy. |
| Australia, New Zealand | Privacy Act 1988 (AU) / Privacy Act 2020 (NZ) | You have rights to access and correct personal information we hold about you. |
| UAE, Saudi Arabia, Qatar, Bahrain, Kuwait, Oman | UAE PDPL / regional data protection laws | We apply reasonable technical and organizational safeguards consistent with regional data protection requirements. |
| Singapore | PDPA | You have rights to access and correct your personal data, and we obtain consent before most collection and use. |
| India | Digital Personal Data Protection Act, 2023 | We process personal data with consent and provide mechanisms to access, correct, and withdraw consent. |
This table is a general summary, not legal advice. If your jurisdiction isn't listed, contact us and we will confirm the applicable protections for your region.
To exercise any of these rights, contact us via our Contact page. We will respond within the timeframe required by applicable law (commonly 30 days).
9. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
10. International Data Transfers
Because we serve patients and doctors across many countries, your information may be transferred to and processed in a country other than your own. Where required (e.g. transfers from the EU/UK), we rely on appropriate safeguards such as Standard Contractual Clauses.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be reflected in the "last updated" date above, and where required by law, we will provide additional notice.
12. Contact
Privacy questions or data requests: privacy@drayurvedas.com, or via our Contact page.