Last updated: June 2026
Effective for: ZoeCare (zoecare.in)
ZoeCare is committed to protecting your privacy and complying with India's Digital Personal Data Protection Act (DPDP Act, 2023).
1. What Data We Collect
We collect the following personal data when you use ZoeCare: - Account information: name, email address, phone number - Family member details: names, dates of birth, blood group, gender, allergies - Health information: medications, prescriptions, health records, doctor visits - Usage data: dose tracking events, adherence logs - Device data: push notification tokens for medicine reminders We collect only what is necessary to provide the service.
2. Why We Collect Your Data
Your data is used solely to: - Provide family health coordination features - Send medicine dose reminders via push notifications - Generate QR Health Passports for doctor visits - Create Emergency Health Cards - Allow co-caregivers to collaborate on family health We do not sell, rent, or share your data with third parties for marketing purposes.
3. How We Store Your Data
• All data is stored on Supabase (PostgreSQL) with encryption at rest - Prescription images and health documents are stored in encrypted Supabase Storage - All data transmission uses HTTPS/TLS encryption - We use Singapore-based servers (Asia-Pacific region) - We are working towards Mumbai (ap-south-1) data residency for full DPDP compliance
4. Data Sharing
We share your data only with: - Supabase — our database and storage provider (data processor) - OneSignal — push notification service (device tokens only, no health data) - Vercel — hosting provider (processes requests, no persistent data storage) The QR Health Passport shares selected health information publicly when a QR code is scanned. You control what is visible through your profile settings.
5. Your Rights (DPDP Act 2023)
Under India's Digital Personal Data Protection Act, you have the right to: - Access your personal data - Correct inaccurate data - Delete your data (right to erasure) — available in Account Settings - Withdraw consent at any time - Nominate a person to exercise your rights To exercise any of these rights, contact us at privacy@zoecare.in
6. Data Retention
• Active account data: retained while your account is active - Deleted members: soft-deleted (anonymised) immediately, hard-deleted after 30 days - Account deletion: all personal data deleted within 30 days of request - Health records: never retained after account deletion We do not retain prescription images longer than necessary.
7. Children's Data
ZoeCare may store health information about minors (under 18) as family members. We require explicit parental/guardian consent before adding a minor's health data. The account holder (caregiver) is responsible for ensuring appropriate consent has been obtained.
8. Push Notifications
With your consent, we send push notifications for medicine reminders. You can withdraw this consent at any time through your browser or device notification settings. Withdrawing consent will disable automated dose reminders.
9. Contact Us
For privacy concerns, data requests, or complaints: Email: privacy@zoecare.in Website: www.zoecare.in We will respond to all privacy requests within 72 hours.
This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the jurisdiction of courts in India.