Privacy Policy

This Privacy Policy sets out the basis on which TravelPatient.com Co., Ltd (TP) and our related companies (“TravelPatient.com”, “we”, “us”, or “our”)may collect, use, disclose, or otherwise process personal data of our customers when you use our website at https://www.travelpatient.com  (“Website”) and/or the Travel Patient mobile application (“Application”) (collectively, “Platforms”) under the Law Protecting the Privacy and Security of Citizens (Union Parliament Law 5/2017) 8 March 2017. This Privacy Policy applies to personal data in our possession or under our control, including personal data in the possession of organizations which we have engaged to collect, use, disclose or process personal data for our purposes. If you do not agree to this Privacy Policy and our Terms and Conditions, please do not use any of the Platforms.

PERSONAL DATA

1. As used in this Privacy Policy

“Customer” means an individual who (a) has contacted us through any means (such as through any of the Platforms) in relation to the goods or services available on the Platforms, or (b) may, or has, entered into a contract with us for the supply of any goods or services by us; and “personal data” means data, whether true or not, about a customer who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access.

WHAT INFORMATIONS ARE COLLECTED FROM YOU

2. Depending on the nature of your interaction with us, some examples of personal data that we may collect from you include
(a) Your name, identification numbers such as residential address, email address, telephone number;
(b) Appointments, bookings, referral and history;
(c) Information about the computer or mobile device you are using; or
(d) Other information which you may input into the platforms or related services.

3. We may also seek permission to use the minimal requirements of related services.

4. We may also collect information other than Personal Information from you through the Website and Application when You enter and /or use the Website and Application. Such information may not personally assist us to identify you and will be stored in server logs. Such Non-Personal Information may include
(a) Your usage details such as time, frequency, duration and pattern of use, features used, and the amount of storage used,
(b) Master and transaction data and other data stored in Your user account,
(c) Internet Protocol address, browser type, browser language, referring URL, files accessed, errors generated, time zone, operating system and other visitor details collected in our log files.

5. Health and Medical Information: In connection with the services provided through the Website and Mobile Application, we may collect, store, process, and display health-related and medical information provided by users or healthcare professionals, including:

(a) Referral information and referral records;

(b) Appointment information and appointment history;

(c) Medical reports, case papers, diagnostic records, prescriptions, laboratory results, and related healthcare documents;

(d) Documents and images uploaded through the Mobile Application, including documents or images selected from your device’s photo library or captured using your device’s camera, where you have granted the applicable permission.

 (e) Electronic health records made available through the Mobile Application;

(f) Treatment information and healthcare service records;

(g) Patient profile information; and

(h) Healthcare professional information, including doctor profiles, qualifications, specialties, practice details, and related professional information where applicable. Such information is collected solely for providing healthcare-related services, facilitating referrals and appointments, managing healthcare records, improving service delivery, and other purposes described in this Privacy Policy.

(i) We request access to your camera or photo library only when needed for a feature you choose to use, such as uploading medical documents or profile images. We access such content only with your permission.

6. Device and Technical Information: When you access or use the Website or Mobile Application, we may collect certain technical and device-related information, including:

(a)Device type and device model;

(b)Operating system type and version;

(c)Mobile application version;

(d)Internet Protocol (IP) address and server log information where collected through our systems;

(e)Language and regional preferences;

(f)Notification permission status;

(g)Firebase Cloud Messaging (FCM) device token and related identifiers used for push notifications; and

(h)Other technical information necessary for the operation, security, maintenance, and improvement of the Website and Mobile Application. We may also collect information relating to application performance, error reports, and diagnostic information where such features are enabled to help us improve the reliability, security, and functionality of our services.

HOW WE COLLECT YOUR INFORMATION

7. We may collect your information by the following means but are not limited to those.
(a) When You register on Our Website and Application,
(b) When You create a profile on Our Website and Application or as part of Services and also on mobile application,
(c) When You provide Your Information to us,
(d) When You use the features on Our Website and Application and/or when You use Services,
(e) When You access Website and Application or Services:

We shall seek your consent before collecting any additional personal data and before using your personal data for a purpose that has not been notified to you, except where permitted or authorized by law.

To create or access a TravelPatient account, users may choose to sign in using Google Sign-In or Sign in with Apple. When you use these authentication services, we may receive certain personal information from the provider, such as your name and email address, for account creation, authentication, and account management purposes. If you choose Sign in with Apple, Apple may provide a private relay email address instead of your actual email address, depending on your privacy settings. TravelPatient does not use Facebook, Twitter, or other social media accounts for account registration or login

8. As you use the Platforms, services, or purchase or arrange for the delivery of products, certain information may be passively collected:
(a) Site Activity Information: We may keep track of some of the actions you take on the Platforms, such as the content of searches you perform on the Platforms;
(b) Access Device and Browser Information: When you access the Website and Application from a mobile or other device, we may collect anonymous information from that device, such as your Internet protocol address, device type, connection speed and access times;
(c) Cookies and Similar Technologies: We may use both session Cookies (which expire once you close your web browser) and persistent Cookies on the Website to make the Website and services easier to use, to improve functionality and performance, to enhance user experience, and to help protect both you and TravelPatient. You can instruct your browser, by changing its settings, to stop accepting Cookies or to prompt you before accepting a Cookie from websites you visit. If you do not accept Cookies, certain Website features, including login functionality, may not operate properly. We presently do not honor “Do Not Track” requests across all parts of our Website.

For the Mobile Application, we do not typically use browser Cookies. Instead, we may use authentication tokens, secure local storage, and similar technologies to maintain user sessions, keep users signed in, protect account security, and support the operation of the Mobile Application. These technologies are used solely for providing and improving the services and functionality of the Mobile Application.
(d) Real-Time Location: The current versions of the TravelPatient Website and Mobile Application do not collect or use GPS-based real-time location information. If we introduce location-based features in the future, we will update this Privacy Policy and provide any required notices before collecting such information.

(e) Device information: We may also collect non-personal information from your mobile device or computer. This information is generally used to help us deliver the most relevant information to you. Examples of information that may be collected and used include how you use the Website and Application(s) and information about the type of device or computer you use. Besides, in the event, our Website and Application(s) crashes on your mobile device we will receive information about your mobile device model software version and device carrier, which allows us to identify and fix bugs and otherwise improve the performance of our Website and Application(s).

(f) Web and Mobile Analytics: We may use Google Analytics and Firebase Analytics to help us understand how users interact with our Website and Mobile Application and to improve our services.

For our Website, Google Analytics may use cookies and similar technologies to collect information about how users use the Website, including how often users visit the Website, which pages they view, and other websites visited before accessing our Website. Google Analytics may collect information such as your IP address, browser type, device information, and usage data. We use this information solely to analyze and improve the performance, functionality, and user experience of our Website and services.

For our Mobile Application, Firebase Analytics may collect and process information related to app usage and user interactions, including but not limited to screen views, login and sign-up activities, search activities, referral events, appointment-related events, application language preferences, user roles (such as doctor or patient), and Firebase-generated user identifiers. This information helps us understand how our Mobile Application is used, measure the effectiveness of features and services, identify areas for improvement, and enhance the overall user experience.

We do not use analytics information collected through Google Analytics or Firebase Analytics to directly identify you by name. Analytics data is used in an aggregated or pseudonymized form where appropriate and is used solely for business, operational, and service improvement purposes.

The collection and processing of information by Google Analytics and Firebase Analytics are subject to Google’s applicable terms and privacy policies. For more information about how Google collects and processes data, please refer to:

Google Privacy Policy: https://policies.google.com/privacy

Google Analytics Terms of Use: https://marketingplatform.google.com/about/analytics/terms/

Firebase Privacy and Security Information: https://firebase.google.com/support/privacy


HOW THE INFORMATION COLLECTED IS USED

9. We may collect and use your personal data for any or all of the following purposes:
(a) To enable you to use the Website and utilize the Services. For instance, you may provide your health-related information on the website in order to consult privately with a doctor.
(b) verifying your identity;
(c) responding your inquiries;
(d) managing your relationship with us;
(e) for proper administration of website and our services;
(f) marketing and promoting the Platforms, and the services and products offered on the Platforms to you;
(g) complying with any applicable laws, regulations, codes of practice, guidelines, or rules, or to assist in law enforcement and investigations conducted by any governmental and/or regulatory authority;
(h) for analysis of our products and services for better presentation or outcome;
(i) any other purposes for which you have provided the information;
(j) transmitting to any unaffiliated third parties including our third party service providers and agents, and relevant governmental and/or regulatory authorities, whether in Myanmar or abroad, for the aforementioned purposes; and
(k) any other incidental business purposes related to or in connection with the above.

10. Push Notifications: The Platform may use Firebase Cloud Messaging (FCM) or similar notification services to send push notifications to your mobile device. To enable and deliver these notifications, we may collect and store an FCM device token and other technical information related to your device.

Push notifications may be used to deliver referral notifications, appointment reminders and updates, account-related alerts, service announcements, security notifications, and other important system messages relating to your use of the Platform.

You may choose whether to receive push notifications by granting or denying notification permissions on your device. You may also disable push notifications at any time through your device’s operating system settings and, where available, through the Platform’s notification settings. Disabling push notifications may affect your ability to receive timely updates and important information regarding the Platform and its services.

11. We may disclose your personal data where such disclosure is required for performing obligations in the course of or in connection with our provision of the goods and services requested by you:
(a) To our subsidiaries, related companies, affiliates, or partners;
(b) To the relevant parties who may process your claims for your medical care. For the avoidance of doubt, we will not disclose any confidential medical diagnoses to such parties unless your consent is provided to us separately in writing;
(c) To contractors, service providers and other third parties we use to support our business and who are bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them (including logistics service providers, data service providers);
(d) As required by law, which can include providing information as required by a court order;
(e) When we believe in good faith that disclosure is necessary to protect your safety or the safety of others, to protect our rights, to investigate fraud, or to respond to a government request;
(f) To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of TravelPatient’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal data maintained on the Platforms is among the assets transferred;
(g) Upon receiving user data, the buyer or successor (Buyer/Successor) shall not use or process such data at their own discretion. They are legally obligated to continue safeguarding and protecting the data strictly within the scope and boundaries of the original Privacy Policy.

(h)To any other person or organization disclosed by us when you provide the information.

12. The purposes listed in the above clauses may continue to apply even in situations where your relationship with us (for example, pursuant to your employment contract should you be hired) has been terminated or altered in any way, for a reasonable period thereafter (including, where applicable, a period to enable us to enforce our rights under a contract with you).

13. This Privacy Policy applies only to information we collect through the Platforms and in email, text, and other electronic communications set through or in connection with the Platforms. This policy does not apply to information collected by any third party. When you click on links on the Platform, you may leave our site. We are not responsible for the privacy practices of other sites, and we encourage you to read their privacy statements.

WITHDRAWING YOUR CONSENT

14. The consent that you provide for the collection, use, and disclosure of your personal data will remain valid until such time it is being withdrawn by you in writing or via email to our office whose contact is provided below.

15. Upon receipt of your written request to withdraw your consent, we may require a reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within ten (10) business days of receiving it.

16. Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our goods or services to you and we shall, in such circumstances, notify you before completing the processing of your request.

17. Please note that withdrawing consent does not affect our right to continue to collect, use, and disclose personal data where such collection, use, and disclosure without consent is permitted or required under applicable laws. For the avoidance of doubt, such withdrawal of consent shall not require us to delete any personal data that has already been collected by us from our records.

ACCESS TO AND CORRECTION OF PERSONAL DATA

18. If you wish to make (a) an access request for access to a copy of the personal data which we hold about you or information about the ways in which we use or disclose your personal data, or (b) a correction request to correct or update any of your personal data which we hold about you, you may submit your request in writing or via email to our Data Protection Officer at the contact details provided below. Such a request shall include the details of the requestor, description of the personal data being requested, and the date and time range the personal data was believed to be collected.

PROTECTION OF PERSONAL DATA

19. To safeguard your personal data from unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks, we have introduced appropriate administrative, physical, and technical measures such as up-to-date antivirus protection, encryption, and disclosing personal data both internally and to our authorized third-party service providers and agents only on a need-to-know basis.

20. You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.

RETENTION OF PERSONAL DATA

21. Account Deletion Requests

You may request the deletion of your TravelPatient account through the Mobile Application by navigating to My Account → Account Delete Request (or any equivalent account deletion feature made available by us from time to time).

After you submit a request, you will be signed out of the Mobile Application.

Our staff may review the request (including via our admin tools). Staff may approve or reject the request earlier than the timeline below. If there is no admin response within two (2) weeks of your request, we will completely remove your account and associated personal data from our systems, except where retention is required or permitted by applicable law, regulatory requirements, dispute resolution obligations, fraud prevention purposes, security requirements, medical record retention requirements, or other legitimate business purposes.

Upon completion of the account deletion process, your account will no longer be accessible. Certain information may remain retained where required by law, for record-keeping obligations, fraud prevention, security investigations, dispute resolution, or the establishment, exercise, or defense of legal claims. Some non-personal or aggregated data that cannot identify you may also remain.

22. We may retain your personal data for as long as it is necessary to fulfill the purpose for which it was collected, or as required or permitted by applicable laws.

23. We will cease to retain your personal data, anonymize it, or remove the means by which the data can be associated with you as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected and is no longer necessary for legal, regulatory, security, or legitimate business purposes.

TRANSFERS OF PERSONAL DATA OUTSIDE OF MYANMAR

24. We generally do not transfer your personal data to countries outside of Myanmar. However, if we do so, we will obtain your consent for the transfer to be made and we will take steps to ensure that your personal data continues to receive a standard of protection that is at least comparable to that provided under the LAW PROTECTING THE PRIVACY AND SECURITY OF CITIZENS.

25. We may transfer, store, or process your personal data outside Myanmar through third-party service providers, including cloud infrastructure and technology providers such as Amazon Web Services (AWS). These transfers may be necessary to provide, operate, secure, and maintain the Website and Mobile Application.

26. We take reasonable steps to ensure that personal data transferred outside Myanmar receives appropriate protection and is handled in accordance with applicable privacy and data protection requirements. Personal data may remain subject to the laws of the country where it is processed.

ADVERTISING AND THIRD-PARTY DATA DISCLOSURES

27. We may display internal and third-party advertisements, promotional content, or links on the Website. Third-party advertisers or service providers associated with such content may collect information in accordance with their own privacy policies when you interact with their websites or services.

28. The TravelPatient Mobile Application does not currently display third-party advertisements and does not use third-party advertising SDKs. The Mobile Application also does not currently use advertising identifiers, such as the Android Advertising ID or Apple’s Identifier for Advertisers (IDFA), for advertising purposes.

29. We do not share your private medical documents, health information, or account credentials with advertisers. If third-party advertising is introduced to the Mobile Application in the future, we will update this Privacy Policy and any applicable app store privacy disclosures before collecting or processing data for advertising purposes.

ACCEPTANCE OF TERMS AND PRIVACY POLICY

30. By creating an account, accessing, or using the TravelPatient Website or Mobile Application, you acknowledge that you have read and understood the applicable Terms of Use and this Privacy Policy and agree to the collection, use, disclosure, processing, and retention of your personal data in accordance with this Privacy Policy.

During the account registration process, users are required to accept the applicable Terms of Use and Privacy Policy.

CONTACT

31. You may contact our office, if you have any inquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request, in the following manner:

Email Address: dev@travelpatient.com

EFFECT OF PRIVACY POLICY AND CHANGES TO PRIVACY POLICY

32. This Privacy Policy applies in conjunction with any other notices, contractual clauses, and consent clauses that apply in relation to the collection, use, and disclosure of your personal data by us.

We may revise this Privacy Policy from time to time without any prior notice. You may determine if any such revision has taken place by referring to the date on which this Privacy Policy was last updated. Your continued use of our services constitutes your acknowledgment and acceptance of such changes.

Updated on August 12, 2026