MediCare+ / Privacy Policy
Privacy Policy
Controller: SquareML Inc., #2983 John F Kennedy Blvd., Jersey City, New Jersey 07306, USA
Contact: sales@squareml.ai (subject: MediCare+ Privacy)
Draft pending counsel review. Applies to the MediCare+ mobile and web applications.
This policy describes how SquareML Inc. (“SquareML”, “we”) collects, uses, shares, and retains information when you use MediCare+. The company named on the App Store and Google Play listings for MediCare+ is SquareML Inc..
If a clinic deploys MediCare+ for its staff and patients, that clinic also handles personal data as a healthcare provider. Some records may be retained by the clinic under applicable law even after you ask us to delete your app account.
1. Who this app is for
MediCare+ is clinic software. Accounts are created by a clinic administrator. It is not intended for children under 13. Health ID can include an emergency contact. Checkup and health suggestions in the app are for you to review with your doctor.
2. Information we collect
Account and profile
Name, username, password (stored hashed), email, phone, date of birth, gender, address, country, language preference, clinic / campus / team assignment, and role (patient, doctor, consultant, or admin).
Health information you or the clinic enter
Health ID details (for example blood group, emergency contact, height, weight, blood pressure, glucose or diabetes notes, oxygen saturation, allergies, history), uploaded files (reports, prescriptions, scans), visit notes, summaries, and prescriptions written by the treating doctor. These values are entered by people. MediCare+ does not measure them from device sensors.
Appointments and communication
Visit date and time, clinic or online type, booking reason, chat messages and attachments on a visit, video-session signaling (to connect the call), and documents attached to a visit.
Campaigns
Campaign name and status, form questions the clinic publishes, and answers and contact details people submit on a campaign form (in the app or on a public link). The clinic can use a response to book a visit.
Payments
Patient and doctor identifiers, amount, currency, order and payment reference from the payment processor, invoice number, and refund references. We do not store full card numbers.
Device and technical
IP address and basic logs, app version, and, only when you join a video visit, camera and microphone access on your device. We use camera and microphone solely to provide that visit.
Support
Email and any information you send to support.
3. How we use information
- Create and authenticate clinic-provisioned accounts
- Book, remind, reschedule, and cancel visits
- Collect and refund consult fees and issue invoices
- Connect a scheduled one-to-one video visit and in-visit chat
- Show Health ID and records to you and to authorized clinicians
- Let clinic admins manage users, campuses, and access
- Publish clinic campaigns and turn registrations into visits
- Send transactional email (booking, reminder, cancellation, notices)
- Secure the service, prevent abuse, and comply with law
We do not sell personal information. We do not use health information for advertising or data-mining unrelated to running the clinic service.
4. How we share information
We share only as needed to operate MediCare+:
| Recipient | Why |
|---|---|
| Your clinic (admin, treating doctor, booking staff) | To provide care coordination and the visit you booked |
| Payment processor | To create, verify, and refund consult fees |
| Email delivery provider | To send booking and reminder messages |
| Infrastructure / hosting | To store and run the application |
| Authorities | When required by law |
Third parties that process personal data for us are required to protect it at least to the level described in this policy. Video media is sent between the two participants' devices. Signaling metadata is processed on our servers to connect the call.
5. Permissions
- Camera and microphone, only for a video visit you start or join.
- Photos / files, only when you attach a document or health record.
- Network, to reach the MediCare+ service.
6. Retention
We keep account and visit data while the account is active and as long as the clinic or law requires (for example clinical record-keeping). Payment records are kept as needed for accounting and refunds. Support emails are kept as needed to resolve the request.
7. Your choices
- Access or update profile information in the app where the clinic has enabled it
- Ask your clinic or SquareML for a copy of data we hold
- Withdraw optional consents where they apply
- Request deletion of your account and associated personal data we are not legally required to keep, in the app, or at Delete account
Healthcare and bookkeeping laws may require the clinic or SquareML to retain some records after account deletion. We will tell you if that applies. We aim to complete deletion requests within 30 days, unless a shorter period is required by law.
8. Security
Passwords are hashed. Access to the service uses authenticated sessions. Data is transmitted over HTTPS. Video visits use encrypted transport typical of WebRTC. Clinic roles limit who can see whose visits. No method of transmission or storage is 100% secure.
9. International processing
SquareML Inc. is based in the United States. Data may be processed in the country of the clinic, in the United States, or in infrastructure regions used to host the service.
10. Children
MediCare+ is not directed at children under 13. A clinic that creates an account for a minor is responsible for obtaining any required parent or guardian consent.
11. Changes
We will post the new “Last updated” date on this page. Material changes will be communicated in the app or by email where appropriate.
12. Contact
Privacy questions and deletion requests: sales@squareml.ai
SquareML Inc., #2983 John F Kennedy Blvd., Jersey City, New Jersey 07306, USA
SquareML Ltd., 5 Walden St, London E1 2EF, UK
SquareML Inc., #2983 John F Kennedy Blvd., Jersey City, New Jersey 07306, USA