Corelatin

Privacy Policy — Corelatin

Version 3.3  |  Last Updated: September 2026  |  Effective upon use of the Platform

Read this before you book. This policy describes what Corelatin actually collects and does — verified against how the platform works, not a template. It is part of our Terms of Service, and is read together with our Cancellation & Refund Policy and Cookie Policy.

Who is responsible for your data


1. What this policy covers

This policy applies to the Corelatin website, mobile app, and companion portal. It covers two kinds of people: Clients (who book companion services, including NRIs booking for family in India) and Companions (who apply and work through us). Where a rule applies to only one group, we say so.

Corelatin is an independent logistics service. We have no affiliation with any hospital — the hospital names on our site are locations where our companions work. Patient information you give us is used only to run your booking. For Document Collection bookings, a hospital may require us to present your authorization letter and ID at its counter before releasing records — that disclosure happens only because the facility requires it for the service you requested; we share nothing beyond it.

The law we work under: the Information Technology Act, 2000 and the IT (SPDI) Rules, 2011 are the operative framework today. The Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 are being phased in (core obligations effective 13 May 2027) — the rights in Section 6 are things we extend to you voluntarily from today.


2. What we actually collect

This list is complete — if it isn't here, we don't collect it.

2.1 Your account (all users)

  • Name, email address, phone number
  • Password (stored as a one-way hash — we never see or store your actual password)
  • If you sign in with Google: your Google-verified name and email (we do not get your Google password)

2.2 Booking details

  • Patient name, age, and your relation to the patient
  • Hospital name, appointment date and time, service duration
  • Notes you type in "additional details" — which may include mobility needs or other patient-relevant information you choose to share
  • Coupon codes applied
  • For Document Collection bookings only: the delivery address, hospital department, document details, and your authorization confirmation

2.3 Payment data

  • Online advance payments go through PayU's hosted checkout — your card, UPI, net-banking, or wallet details are entered on PayU's systems and never reach ours
  • We store: the PayU transaction ID, amount paid, gateway charge, and refund status against your booking
  • Balance payments after a visit are cash/UPI to your companion; we record only that the bill was settled
  • We do not store card numbers — not even partial digits

2.4 Files linked to your service

  • Reports and documents uploaded during a booking (prescriptions, test results, discharge papers, care reports) — stored against the booking and visible to you, the assigned companion, and our support team
  • Arrival photo — the companion may take a photo on arrival at the hospital to confirm they reached the right place; this is stored against your booking
  • Cancellation proof — if you request an emergency refund, the medical document you submit (admission slip, discharge note) is stored for audit

2.5 Companion applicants (not clients)

  • Full name, email, phone, alternate phone, residential address, city, state, pincode, gender, date of birth
  • Aadhaar and PAN numbers with front/back document scans — collected and stored for identity verification before they can work
  • Experience, languages, skills, and a self-written profile
  • Live location during urgent bookings — companions on urgent assignments may share their GPS position so the visit can be coordinated

2.6 App and device data

  • Push-notification token (Expo), device platform, and device name — only if you install the app and allow notifications
  • IP address and browser type — recorded automatically when you sign in, accept a policy, set cookie preferences, or perform a security-sensitive action (part of our audit trail)

2.7 Communications

  • Emails you send us and our replies
  • WhatsApp messages — only if you message us first or coordinate with a companion directly; we have no automated WhatsApp feed of your chats
  • Contact-form submissions (name, email, subject, message)
  • Feedback survey answers, ratings, and reviews you submit

What we do NOT collect

No call logs or call recording · no SMS content (we don't run an SMS service) · no contact-list access · no card or bank details · no background location tracking of clients · no browsing history outside our site · no data purchased from brokers.


3. Why we use it
  • To run your booking — match a companion, coordinate the visit, record OTP-verified completion, generate the itemized bill
  • To collect payment — advance via PayU, balance settlement after the visit, refunds where owed
  • To keep you informed — booking confirmations, status updates, and refund emails; push notifications if you use the app
  • To keep people safe — companion identity verification, audit logs for disputes and fraud prevention
  • To improve the service — anonymized usage analytics (only with cookie consent), feedback surveys
  • Marketing, only with consent — testimonials and anonymized chat screenshots appear on the site only after we have recorded customer permission and confirmed sensitive details are redacted

We do not use your medical notes or patient information for advertising. We do not sell personal data to anyone, ever.


4. Extra care with patient information

Health-related details you volunteer in booking notes or uploaded documents are sensitive. In practice that means:

  • Minimum-necessary sharing: the assigned companion sees only what they need for the visit — patient name, hospital, appointment, and relevant notes — not your account history or payment details
  • Documents stay sealed: companions who collect physical medical records are contractually prohibited from opening, reading, or photographing the contents of sealed files
  • No clinical use: we never interpret medical information, never give medical advice, and share patient details with a hospital only to the extent its own rules require for the service you booked
  • No profiling: patient information is not used to build advertising profiles or sold to data brokers

5. Who actually sees your data
  • Your assigned companion — minimum necessary for the visit (see Section 4)
  • PayU — processes your online payment on their secure checkout
  • Google — if you use "Sign in with Google"; Google Analytics if you consent to analytics cookies
  • Expo — delivers push notifications to the app
  • Our hosting and email providers — store and transmit data under contract
  • Our staff — support and admin access, logged in an internal audit trail
  • Law enforcement or regulators — only when legally required by court order or Indian law

Never shared: we do not share patient details with hospitals beyond what a facility requires for an authorized document release, do not share companion ID scans with third parties, and do not give your contact details to marketers.


5b. Testimonials and published stories

5b.1 Voluntary. Reviews, testimonials, photographs, and feedback are always voluntary (see Terms §18).

5b.2 What we may publish. Name (or initials/pseudonym), your review text, service context (hospital, city, date range), and — only with recorded consent — screenshots of chat conversations with identifying details redacted.

5b.3 Consent before publishing. Chat screenshots and any identifiable patient information are published only after we record both your permission and confirmation that sensitive details were removed. You may ask us to take anything down.

5b.4 Licence. By submitting a testimonial you grant us a non-exclusive, royalty-free licence to display it on our site, app, and marketing materials — not to sell it as data.

5b.5 Withdrawal. Write to the Grievance Officer (below) and we will remove active use within 30 days. Material already distributed in print or by third parties cannot be recalled.

5b.6 Minors. We never publish identifiable information about a minor patient.


6. Your rights

Under the DPDPA (extended to you voluntarily ahead of its full commencement) you can:

  • Access — ask what personal data we hold about you
  • Correct — ask us to fix inaccurate information; you can edit most account details yourself
  • Erase — delete your account from the app/website or ask us to erase data; account deletion removes your bookings, reviews, and uploaded reports, subject to Section 7 legal retention
  • Withdraw consent — cookie categories, testimonials, marketing emails — without affecting what was already done
  • Grievance — complain to our Grievance Officer; if unresolved you may approach the Data Protection Board of India once the Board is operational
  • Nominate — name someone to exercise these rights if you die or are incapacitated

Email support@corelatin.in — acknowledgement within 24 hours, resolution target within 15 days.


7. How long we keep it
  • Booking records: up to 5 years — for disputes, service records, and contractual enforcement
  • Payment and refund records: up to 8 years — Income Tax Act record-keeping
  • Support and communication history: up to 2 years
  • Companion verification documents: kept for as long as the companion works with us, plus a post-engagement period for dispute and safety purposes
  • Account: until you delete it (see Section 6), subject to the retention above
  • Cookie-consent and policy-acceptance logs: kept as compliance evidence
  • Analytics: only aggregated/anonymized statistics long-term

When a retention period ends, data is deleted or anonymized. We may keep specific records longer where a law, dispute, or investigation requires it.


8. Cookies

We use a small, audited set of cookies and browser storage — the full inventory is in our Cookie Policy. In short: strictly-necessary cookies run the site; functional and analytics cookies (Google Analytics 4) load only if you opt in via the consent banner. We use no advertising or marketing trackers. You can change your choice anytime from "Cookie Preferences" in the footer.


9. Links to other websites

Our pages link to third-party sites — hospital websites, maps, social media, PayU's checkout, and WhatsApp (wa.me links). Once you leave our site or app, their privacy policies apply, not ours. We encourage you to read them.


10. How we protect it
  • Encryption in transit — all traffic runs over HTTPS/TLS
  • Hashed passwords — stored as one-way hashes; support staff can never see your password
  • Access control — role-based admin access; companions see only their assigned booking's minimum details
  • Audit logging — admin actions, consent records, and policy acceptances are logged with timestamps
  • Companion confidentiality — companions sign confidentiality obligations covering patient information
  • Incident response — if a confirmed breach affects your data, we will notify you and the relevant authorities as required by law

Honest note: no internet service can guarantee absolute security. We maintain reasonable, documented practices and review them periodically — and we will tell you if something goes wrong.


11. Children

11.1 Accounts. You must be 18 or older to create an account. If a minor registered by mistake, contact the Grievance Officer and we will remove the account.

11.2 Minor patients. An adult client can book for a minor patient. We process the minor's details only for that service, on the adult's booking consent, consistent with DPDPA Section 9. We never run behavioural tracking or advertising on a minor's data, and never publish identifiable information about them.


12. Where your data lives

Your data is stored on our hosting provider's servers and processed in India. We do not intentionally transfer personal data outside India except where a service you choose to use requires it (for example, Google's systems when you use Sign in with Google or consent to analytics). The DPDPA permits such transfers to countries not restricted by government notification.


13. Changes to this policy

When we change this policy we update the version number and "Last Updated" date above, post the new version here, and — for material changes — notify registered users by email or a notice on the site. Using the platform after a change means you accept the updated policy. We recommend checking this page occasionally.


14. Grievance Officer & Contact

For questions, data-rights requests, or complaints (acknowledgement within 24 hours; resolution target within 15 days):

Grievance Officer & Contact

For complaints, data rights requests, refund disputes, and policy grievances under the Consumer Protection (E-Commerce) Rules, 2020 and DPDPA 2023.

Shubham
Grievance Officer
Monday to Saturday, 9:00 AM to 6:00 PM IST
Ghaziabad, Uttar Pradesh, India

Response timeline: acknowledgement within 24 hours; resolution target within 15 days. General support (non-grievance): support@corelatin.in / +91-9870550407

You also retain the right to approach the Data Protection Board of India once it is operational, and the consumer commissions under the Consumer Protection Act, 2019.