Healthstack

Privacy Policy

Last updated: 24th July 2025

Overview

This Privacy Policy explains how Healthstack collects, uses, shares, and protects data of users interacting with our APIs, infrastructure, dashboard, and Medicard services.

How we collect data

  • When businesses sign up or verify via KYC
  • When developers or patients interact with the platform via APIs
  • When consent tokens are generated or used
  • From device logs, requests, or usage metrics

Data we collect & how we use it

    Business KYC details, developer credentials, logsPatient data: NIN, demographics, medical records, Medicard flagsUsed to authenticate users, process consent, store records, enable payments

How we share data

    With authorized businesses that own or created the dataWith consent or in emergencies via MedicardWith service providers (e.g., OTP, cloud storage, verification)With regulators if required by law

Your choices

    Withdraw consent (except in emergencies)Request deletion or correctionContact: privacy@healthstackhq.com

How we protect data

  • Encryption in transit and at rest
  • Role-based access, token headers
  • Audit logs, database row-level security

How long we keep data

As long as necessary to provide services or meet legal obligations. Consent and access logs are retained for compliance.

Other information

We use logs, devices, IPs, and metrics to monitor and protect infrastructure and enhance performance.

Medicard data

Tier 3 businesses may access data without real-time consent. All access is logged. Medicard funds may be used for patient care.

Children's data

We do not knowingly collect data of minors unless authorized by a guardian and through verified medical entities.

International transfers

Where data leaves Nigeria, we apply safeguards such as standard contractual clauses in line with NDPR and GDPR-like frameworks.

Changes to this policy

We will update this page if our policy changes. Check the "Last updated" date. Important changes will be emailed.

Contact us

  • Email: privacy@healthstackhq.com
  • Phone: +234 9011 684 646
  • Address: Elzazi complex, Opposite Westharm petrol station along gbalajam/Akpajo road, woji ( Odili Road, Port-Harcourt )

Terms & Conditions

Includes platform usage rules, data access obligations, Medicard controls, KYC terms, fees, suspension clauses, and developer responsibilities.

Developer Disclaimer

Healthstack provides APIs, SDKs, and developer tools intended for use by registered businesses and verified developers building compliant digital health applications. By using these tools, you agree to implement data security best practices and ensure lawful use of patient data.

Developers are responsible for:

  • Securing API keys and tokens
  • Following proper consent workflows
  • Handling data in compliance with local and international health privacy laws (e.g., NDPR, HIPAA)

Healthstack shall not be liable for breaches, data leaks, or legal violations caused by improper API implementation, insecure integrations, or misuse of sensitive health data.

Patient Disclaimer

Healthstack is a backend health infrastructure provider and not a healthcare provider. We do not offer medical advice, treatment, or diagnosis. Your medical data is processed only by licensed healthcare providers who are registered on our platform.

Patients should:

  • Verify the identity of businesses accessing their data
  • Understand and review consent prompts before authorizing access
  • Contact their provider directly for clinical questions or treatment

Healthstack does not make healthcare decisions and is not responsible for the quality of medical services rendered by businesses using our platform.

Medicard Disclaimer

The Medicard feature is a virtual medical card issued by verified Tier 3 businesses on the Healthstack platform. It is used to:

  • Access patient medical records without real-time consent
  • Manage healthcare wallet balances and billing history

Medicard is not a debit or credit card. Its usage is limited to healthcare-related services within the Healthstack ecosystem. Only authorized businesses can activate or manage a Medicard for patients. Misuse, overreach, or unauthorized access will result in revocation and possible legal action.

Patients retain the right to request logs, revoke Medicard permissions, or delete their profile in accordance with data privacy laws.

Emergency Access Disclaimer

Healthstack allows emergency access to patient records without consent through Tier 3 Medicard accounts—but only in clearly justifiable, auditable, and life-threatening situations.

By using emergency access features, you confirm that:

  • The situation qualifies as an emergency under medical ethics and regulatory standards
  • All actions will be logged and reviewed
  • Abuse of emergency access can lead to suspension, regulatory reports, and legal consequences

This feature is intended to protect patient life—not bypass consent norms or privacy protocols.