How HEALTO collects, uses, shares and protects your information.
Last updated: 13 August 2026
This Privacy Policy explains how HEALTO ("HEALTO", "we", "us") handles your personal information when you use the HEALTO website at healto.in, the HEALTO Patient mobile app, the HEALTO Doctor mobile app, and the hospital admin panel (together, the "Services").
HEALTO is a booking platform. We connect you to hospitals, clinics and doctors so you can find them, book an appointment and track your token. We are not a healthcare provider and we do not give medical advice or diagnosis.
By using the Services you agree to this policy. If you do not agree, please do not use the Services.
With your permission, the Patient app collects your device location (latitude and longitude) to show hospitals near you and sort them by distance. We store your most recent location and the time it was updated. You can refuse or withdraw this permission at any time in your device settings and still browse hospitals — only the "near me" ordering stops working.
Payments are processed by Razorpay. Your card, UPI, netbanking and wallet details are entered on Razorpay's systems and are never stored on HEALTO's servers. We keep the transaction reference, amount, payment method type, and payment status so we can show your booking and settle with the hospital.
Patients sign in with a mobile number and a one-time password sent by SMS. The OTP is stored only until it is used or expires.
We do not sell your personal information, and we do not use your health or appointment information for advertising.
We keep your account information for as long as your account exists. Appointment records are kept while your account is active so you can see your history.
When you delete your account, your profile, appointment history, reviews and (for doctors) your availability schedule are permanently removed. Certain payment and transaction records may be retained for a limited period where required for accounting, tax or legal compliance. Retained records are not linked to your deleted profile and are not used for any other purpose.
Data is transmitted over encrypted HTTPS connections. Access to personal information is restricted to the accounts that need it — a hospital sees only its own patients and appointments. Passwords are stored hashed, and OTPs and session tokens are never exposed in our APIs. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your information and to address issues promptly if they arise.
The Services are not intended for children under 18. We do not knowingly collect information from a child directly. A parent or guardian may book an appointment on a child's behalf using their own account, and is responsible for the information they provide. If you believe a child has created an account, contact us and we will remove it.
HEALTO does not provide medical advice, diagnosis or treatment, and does not verify the clinical decisions of any doctor or hospital listed on the platform. HEALTO is not for medical emergencies. In an emergency, contact your local emergency services or go to the nearest hospital immediately.
We may update this policy as the Services change or as the law requires. The revised policy will be posted on this page with a new "Last updated" date. If the change is significant, we will also notify you in the app. Continuing to use the Services after a change means you accept the updated policy.
For any question, request or complaint about this policy or your personal information, email us at support@spidermart.in. Please write from the email address linked to your account so we can verify your identity.