Draft — pending legal review
This document has not been reviewed by a lawyer and is published here as a working draft. It is not yet a binding statement. Ask us if you need the current position on anything it covers.
Privacy policy
Last updated: Draft
Shifora is a platform used by private medical practices in Bangladesh to manage patient records, appointments, video consultations and payments. This policy describes what information the platform handles and how.
Who holds your information
If you are a patient, your medical record belongs to the practice you booked with. That practice decides what is recorded and who at the practice can see it. Shifora operates the platform on their behalf.
If you are a doctor or a member of practice staff, your practice's data is scoped to your practice and is not visible to any other practice on the platform.
What is collected
- Account information — your name and the email address of the Google account you sign in with. Shifora uses Google sign-in only and never receives or stores a password.
- Patient information — the details entered when booking or during a consultation: contact details, medical history, complaints, allergies, vitals, diagnoses, prescriptions and any documents uploaded.
- Appointment information — bookings, their status over time, and timestamps for when a consultation was joined and left.
- Consultation transcripts — where live transcription is used, the text of a video consultation is stored with the appointment. Consultations are not recorded as audio or video.
- Payment information — the amount, status and reference of a payment. Card and mobile wallet details are handled by the payment provider and are never stored by Shifora.
- Delivery records — a log of each notification sent, on which channel, and whether it was delivered.
- Device tokens — where you use the Android app, an identifier used to deliver push notifications to your device.
How it is used
To operate the service: to show a practice its patients and appointments, to generate and deliver prescriptions, to run video consultations, to take payments and pay them out, and to send the notifications a booking depends on.
Shifora does not sell personal information, and does not use medical information for advertising.
Who it is shared with
- The practice you booked with, and its staff, to the extent their role allows.
- Service providers used to operate the platform: cloud hosting and database, video infrastructure, the payment gateway, and email, WhatsApp, SMS and push delivery providers.
- Shifora staff, where access is needed to operate or support the platform.
- Where required by law.
How it is protected
Access is restricted at the database level so that each practice can reach only its own records, and privileged operations re-check the caller's identity independently. Patient reports and prescriptions are held in private storage and reached only through short-lived signed links — they are never available at a public address. Administrative actions are recorded in an audit log.
Our security page describes these mechanisms, and their limits, in more detail.
Your choices
- You can see your own record, appointments, prescriptions and files in the patient portal.
- Some parts of a patient profile are locked after they are set, to keep the clinical record reliable. Corrections are made by the practice.
- To ask for a copy of your information, or for it to be corrected or deleted, contact the practice you booked with. If you cannot reach them, contact us and we will help.
Children
A patient account is created with a Google account. Where a child is treated, the record is managed by the practice.
Changes
When this policy changes materially, the updated date above changes and the current version replaces this one on this page.
Contact
Questions about this policy can be sent through our contact page.