This Privacy Policy explains what personal data MedTrackPro collects, why we collect it, and how it is used and shared, both for personal accounts and company accounts.
| Category | Examples |
|---|---|
| Account information | Name, email address, phone number, password (hashed) |
| Company information | Company name, registration key, subscription plan, seat usage |
| Field activity data | Doctors, hospitals, territories, scheduled and completed visits, visit notes |
| Location data | GPS coordinates captured at check-in and check-out of a visit |
| Visit proof | Photos and signatures captured during visit checkout |
| Sales & inventory data | Product sales, quantities, prices, discounts, sample and brochure distribution |
| Device information | Push notification token, device type, app version |
| Usage data | App activity logs, feature usage, timestamps of actions |
Company accounts: if you belong to a company, your field activity, visit records, and sales/performance data are visible to administrators of that company. This is a core function of the Service and cannot be disabled while you remain part of a company account.
Personal accounts: your data is not shared with any other user or company.
Service providers: we may share data with infrastructure and notification providers (such as push notification delivery services) strictly to operate the Service. We do not sell your personal data to third parties.
Location data is captured only at the moment of check-in and check-out for a scheduled visit, and is used to verify proximity to the doctor or hospital's registered address. We do not continuously track your location in the background. For company accounts, check-in/check-out location data is visible to your company's administrators as part of the visit record.
We retain account and field activity data for as long as your account remains active, and for a reasonable period afterward as needed for record-keeping, dispute resolution, or legal compliance. You may request deletion of your personal account data by contacting us, subject to any records a company administrator is entitled to retain for their organization's business records.
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), hashed password storage, and access controls that scope data to the correct company or individual account. No system is completely secure, and we cannot guarantee absolute security.
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal data. To exercise these rights, contact us using the details below. Note that for company accounts, some requests may need to be coordinated with your company administrator, since certain data is part of your employer's business records.
The Service is intended for business use by adult professionals and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18.
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by other reasonable means.
Questions about this Privacy Policy can be directed to support@medrepapp.com.