Privacy Policy
How we handle your personal and health information.
Last updated: 23 September 2026
1. Who we are
DoctorGiri ("we", "us") operates doctorgiri.com, a telemedicine platform that connects patients in Bangladesh with licensed doctors for online video consultations. This policy explains what information we collect, why we collect it, and what control you have over it.
It applies to our website, our patient and doctor dashboards, and the Google account integration described in section 4.
2. Information we collect
From patients. When you book a consultation we collect your name, email address, phone number, the reason for your consultation and any notes you choose to add, along with the appointment date, time and the doctor you selected.
From doctors. We hold professional profile information including name, designation, qualifications, hospital affiliation, BMDC registration number, chamber address, consultation fees, availability and, where provided, a signature image used on prescriptions.
Account credentials. Email addresses and passwords for portal accounts. Passwords are stored only as bcrypt hashes and are never retrievable in readable form.
Payment information. Payments are processed by bKash. We receive and store the transaction reference, amount and payment status. We never receive or store your full payment credentials.
Technical data. Standard server logs, and cookies required to keep you signed in.
3. How we use your information
- To schedule, confirm, remind you about and deliver your consultation.
- To create the video meeting for your appointment and share the joining link with you and your doctor.
- To process payments, issue receipts and calculate doctor payouts.
- To produce and deliver prescriptions issued by your doctor.
- To send transactional email about your bookings. We do not sell your data or use health information for advertising.
4. Google account data
Doctors may connect a Google account so that each confirmed consultation automatically gets a Google Meet link. This is optional, and is used only by doctors — patients never connect a Google account.
What we request. With the doctor's explicit consent we request permission to create calendar events on their Google Calendar, and to read the email address of the connected account so we can show which account is linked.
What we do with it. We create one calendar event per confirmed appointment, with a Google Meet conference attached, on the doctor's own calendar. We store the resulting meeting link and event identifier against that appointment. We do not read, export, analyse or store the rest of the doctor's calendar.
How access is stored. Google access and refresh tokens are encrypted at rest using AES-256-GCM and are never exposed through our interface or API.
Revoking access. A doctor can disconnect Google at any time from their dashboard, which deletes the stored tokens. Access can also be revoked directly at myaccount.google.com/permissions. Meeting links already created will continue to work.
Limited Use disclosure. DoctorGiri's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising, do not sell it, and do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
5. When we share information
We share your information only where it is necessary to deliver the service:
- With your doctor — the clinical details you submit are shared with the doctor you booked.
- bKash — to take payment and confirm it.
- Google — appointment time, title and attendee email, in order to create the calendar event and Meet link.
- Email and hosting providers — to send booking email and to run the platform.
- Where legally required — to comply with a valid legal obligation.
We do not sell or rent your personal information to anyone.
6. How long we keep it
Appointment and prescription records are retained for as long as needed to provide continuity of care and to meet medical record-keeping and tax obligations. Payment records are retained as required by financial regulation. OAuth tokens are deleted as soon as the integration is disconnected.
7. Security
Traffic is served over HTTPS. Passwords are bcrypt-hashed and third-party access tokens are encrypted at rest. Access to production data is limited to authorised administrators. No system is perfectly secure, but we work to protect your information and will notify you of a breach affecting your data where the law requires it.
8. Your rights
You may request a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Patients can also request deletion of their account. Some records must be retained where a legal or medical record-keeping obligation applies; we will tell you if that is the case. Write to info@doctorgiri.com and we will respond within 30 days.
9. Children
Accounts are intended for adults. A consultation for a child should be booked and attended by a parent or legal guardian.
10. Changes to this policy
We may update this policy as the service changes. The revision date at the top of this page always reflects the current version, and material changes will be communicated by email or a notice on the site.
11. Contact us
Questions about this policy or about your data:
- Email: info@doctorgiri.com
- Phone: +880 1968-885555
- Address: UTC Building, Suite 03, Level 11, 08 Panthapath, Dhaka 1215, Bangladesh