Privacy Policy
Last updated: 4 September 2026
1. Who we are
Hospital Hunter (“we”, “us”) is operated by Tensor Foundry & Labs at https://www.hospitalhunter.com, a hospital discovery and practice-management platform for patients, hospital owners, and staff in India.
Contact: privacy@hospitalhunter.com
2. What this policy covers
This policy describes how we collect, use, store, and share personal information when you:
- Search for hospitals on our public site
- Create a patient account or book appointments
- Use hospital owner or staff (ERP) tools
- Use Hospital Hunter SCM (hospital buyer or supplier seller desks)
- Contact us or receive notifications (email, WhatsApp where enabled)
3. Information we collect
- Account: email, password (stored hashed), name
- Patient profile: mobile, pincode, blood group, insurer (optional)
- Clinical / hospital operations: appointment details, queue tokens, consultation records, uploaded images
- Search & usage: search queries, pages visited
- Technical: IP address, browser type, device
Hospital SCM
Hospital Hunter SCM is a separate product from Clinic ERP. When a hospital or supplier uses SCM Login, we store organisation contacts, purchase and sales orders, and proof-of-delivery photos or files uploaded with a shipment.
4. How we use information
- Provide search, booking, and ERP services
- Authenticate users and prevent abuse (rate limits, CAPTCHA)
- Send OTP codes, appointment confirmations, and WhatsApp messages (where configured)
- Improve the product (aggregated analytics)
- Comply with law and protect security
5. Where data is stored
Personal data is hosted on Google Cloud Platform in India (asia-south1) — primarily PostgreSQL (Cloud SQL) and Google Cloud Storage for clinical file uploads.
6. Sharing with third parties
We use the service providers below to run Hospital Hunter. They process data only for the purpose listed. Clinic onboarding contracts may point to this page as the subprocessors list.
| Provider | What they do | Where |
|---|---|---|
| Google Cloud (GCP) | Hosting, database, file storage, and application logs | India (asia-south1) |
| Cloudflare Turnstile | Bot protection on public booking and search | Cloudflare global network |
| Google Analytics 4 | Aggregated website usage statistics | Google Analytics |
| Email (Resend / SMTP) | OTP, reminders, and other transactional email | Email provider |
| Meta WhatsApp | Appointment and billing utility messages, where a clinic enables WhatsApp | Meta WhatsApp Business Platform |
| Google Gemini / Vertex AI | Search intent and lab-report extraction, only where that feature is used | Google (Vertex in asia-south1 when configured) |
We do not sell personal information.
7. Cookies and similar technologies
We use essential HttpOnly session cookies for logged-in features, Google Analytics in production, and Cloudflare Turnstile on appointment booking.
8. Security
We use HTTPS, access controls, hospital-scoped permissions, and industry-standard password hashing.
9. Retention
How long we keep each class of data is on our data retention schedule. In short: we keep clinic ERP records while the clinic is a customer; ICT logs for 180 days in India; GST/ledger rows for eight years; and we process verified deletion requests as described in data deletion instructions.
10. Your rights
Depending on applicable law, you may request access, correction, or deletion of your personal data. See our data deletion instructions for step-by-step guidance, or contact privacy@hospitalhunter.com.
11. Children's privacy
Our services are not directed at children under 18 without parental or guardian involvement.
12. Changes
We may update this policy and will post the new version on this page with an updated date.