Privacy Policy
Last updated: Pending final review
Who we are
Orbitcare (“we,” “us,” or “Orbitcare”) operates a mobile platform connecting patients in Nigeria with MDCN-verified doctors for chat consultations, appointment booking, and personal health tracking. This policy explains what information we collect, why we collect it, and the real controls you have over it — including how our consent system works, since that’s central to how your medical data is actually shared.
We process personal data in line with the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act.
What we collect
Account information
- Name, email address, phone number, date of birth, and gender, collected at registration.
- A profile photo, if you choose to add one.
- For doctors specifically: MDCN license number, a government-issued ID, and a selfie used to verify your identity against that ID.
Health information
If you choose to use them, our health tracking features collect information you enter directly — medical conditions, allergies, medications, surgeries, family history, lifestyle details, weight, menstrual cycle data, pregnancy and vaccination records, and lab results you upload. None of this is required to use the core app; it exists for your own record-keeping and to share with a doctor when you decide to.
Communications
Messages you send to doctors through the app, and content you post to the public feed (health tips, comments, reviews).
Payment information
Subscription and boost payments are processed by Paystack. We do not store your card details — Paystack handles that directly, and we only receive confirmation that a payment succeeded or failed.
Device and usage information
Basic device information and a push notification token, so we can send you appointment and message alerts. We do not sell this information to advertisers, and Orbitcare does not run third-party ads.
How we use it
- To create and secure your account, and verify doctors’ medical licenses.
- To connect you with doctors — search, chat, and appointment booking.
- To let you track your own health information privately, for your own reference.
- To process subscription and boost payments.
- To send you notifications about messages, appointments, and account activity.
- To investigate reports of abuse, harassment, or platform misuse.
- To meet legal and regulatory obligations.
Consent-based sharing with doctors
This is the part of our privacy model we want to be most specific about, because it’s genuinely different from how most apps handle health data: a doctor cannot see your medical records, lab results, or health tracker data by default— not even a doctor you’re actively chatting with.
You choose exactly what to share and with whom, by granting a specific doctor access to specific categories of information (for example, just your allergies and medications, not your full history). You can revoke that access at any time, and revoking it takes effect immediately.
Lab results work the same way — uploading a result doesn’t share it with anyone until you explicitly choose a doctor to share it with.
Third-party services
We work with a small number of third-party services, each for a specific purpose:
- Paystack — processes subscription and boost payments.
- Cloudinary — stores uploaded images and documents (profile photos, lab results, chat attachments).
- Firebase Cloud Messaging — delivers push notifications to your device.
Each of these providers only receives the specific data needed to perform its function, and none of them are permitted to use your data for their own marketing purposes.
How we protect your data
Sensitive free-text fields — including chat messages, medical history notes, and license numbers — are encrypted before they’re stored, so the raw content isn’t readable even from the database itself. Access to production data is restricted to the systems that need it to operate the app.
No system is perfectly secure, and we can’t guarantee absolute security — but health data gets the highest level of protection we apply anywhere in the platform.
How long we keep data
When you delete data — a medical record entry, a lab result, your account — we don’t immediately erase it from our systems. Health-related records are marked as removed rather than permanently deleted right away, which protects the integrity of your medical history and supports audit and regulatory requirements. Deleted content is no longer visible to you or to any doctor, regardless of retention.
Your rights
Under the NDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate information.
- Request deletion of your account and associated data.
- Withdraw consent you’ve previously given a doctor to view specific health data, at any time.
- Object to certain uses of your data.
Most of these — editing your profile, revoking a doctor’s access, deleting your account — are available directly in the app. For anything else, contact us using the details below.
Children’s privacy
Orbitcare is not directed at children under 18, and we don’t knowingly collect personal data from anyone under that age. If you believe a minor has created an account, contact us and we’ll take appropriate action.
Changes to this policy
If we make material changes to this policy, we’ll notify you in the app before they take effect.
Contact us
Questions about this policy or your data can be sent to support@orbitcare.ng.