CareFlow
Back to home

Legal

Privacy Policy

Last updated 10 July 2026

This document is a plain-language template provided as a starting point. It is not legal advice. Review and adapt it with qualified counsel, and replace the bracketed placeholders (company name, contact details, governing law) before relying on it.

CareFlow is a hospital operations platform, operated by [Legal Entity Name] (“CareFlow”, “we”, “us”), that healthcare facilities use to track patients from registration through treatment and follow-up. This policy explains what personal data we handle when you use CareFlow: both the account data of the staff who sign in, and the patient information hospitals record on the platform.

01Two kinds of data, two roles

CareFlow handles two distinct categories of information, and our role differs for each:

  • Account & usage data: information about the hospital staff and owners who sign in to CareFlow (for example a name, email, and role). For this data we act as the controller, and this policy governs it.
  • Patient / clinical data: the health records a hospital enters (demographics, notes, vitals, prescriptions, and so on). Here the hospital is the controller and CareFlow is a processoracting on the hospital's instructions. How that data may be used is governed by our agreement with the hospital and the hospital's own privacy notice, not this page.

02Information we collect

Account & authentication data. When a hospital owner creates an account, they verify their identity with Google sign-in or a one-time email code. When you sign in with Google, we receive your name, email address, and basic profile information from your Google account, used only to authenticate you and create your CareFlow account. Staff members sign in with a username and password; passwords are stored only as salted hashes by our authentication provider and are never visible to us.

Patient & clinical data (entered by the hospital). On the hospital's instruction, CareFlow stores the records staff create, such as patient identifiers, dates of birth, contact details, visit and consultation notes, diagnoses, orders and results, vital signs, allergies, prescriptions and medication administration, care plans, and billing entries.

Technical & device data.Basic log data (such as IP address, browser type, and timestamps) needed to run and secure the service. Because CareFlow works offline, a copy of your hospital's working data is also cached locally in your browser on the device you use, and synchronised back to our database when you are online.

Notification data. If you enable push notifications, your browser provides a push subscription (an endpoint and keys) that we store so we can deliver alerts to that device. You can turn this off at any time in your browser or device settings.

03How we use information

  • Provide, operate, and maintain the CareFlow platform for your hospital.
  • Authenticate you and keep each hospital's data isolated from every other tenant.
  • Send transactional messages: sign-in codes and in-app or push notifications you have enabled.
  • Keep the service secure, diagnose problems, and improve reliability.

We do not sell personal data, and we do not use patient data or data received from Google for advertising or any purpose beyond operating the service.

04Use of Google user data

CareFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only your basic profile and email, and we use them solely to sign you in and provision your account.

05Service providers we rely on

We share data only with the infrastructure providers needed to run CareFlow, under agreements that require them to protect it:

  • Supabase: hosts our database, authentication, and file storage, with per-hospital row-level security.
  • Resend: delivers transactional email such as sign-in codes.
  • Google: provides optional sign-in for hospital owners.
  • Our hosting provider: serves the application.

We may also disclose information where required by law, or to protect the rights, safety, and security of CareFlow, our customers, and their patients.

06Storage & security

Data is stored in our hosted database and protected by row-level security so that one hospital can never read or write another hospital's records. Traffic is encrypted in transit. Access to production systems is limited to authorised personnel. Remember that a working copy of data is also cached on the device you use for offline access, so keep your devices secured and sign out on shared computers.

07Retention

We keep account data for as long as your hospital's account is active. Patient records are retained on behalf of the hospital in line with its instructions and any applicable medical-records laws. When a hospital closes its account, we delete or return its data as described in our agreement and this policy, unless we are required to keep it by law.

08Your choices & rights

Depending on where you live, you may have rights to access, correct, export, or delete personal data we hold about you as an account holder. Contact us at [privacy@your-domain.com] and we will respond as required by applicable law. Requests that concern patient records should be directed to the hospital that controls those records; we will support the hospital in responding.

09Children

CareFlow is a professional tool for healthcare staff and is not directed to children as account users. Patient records may include minors; those are entered and managed by the hospital under its own lawful basis and consent processes.

10International processing

Your data may be processed and stored in the regions where our service providers operate, which may be outside your country. Where required, we rely on appropriate safeguards for such transfers.

11Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify hospital account owners.

12Contact us

Questions about this policy or your data? Contact [Legal Entity Name] at [privacy@your-domain.com].

Read the Terms of Service

The hospital's own operational record.