Sanpha
§ Privacy notice

How we handle your data.

Last updated

2026-04-01

This notice describes what data Sanpha collects, why we collect it, how we use it, and the choices you have. We follow Moroccan data protection law (Loi 09-08 and the CNDP framework). We do not sell your data. We do not show ads.

01

What we collect

  • Account data — name, mobile number, email, hashed password, city.
  • Health profile data — blood type, conditions, allergies, current medications, emergency contact. Optional, but useful.
  • Activity data — bookings, consultations, prescriptions, orders, ambulance requests, messages.
  • Device and network data — IP address, device model, app version, operating system. Used for security and performance.
  • Payment data — handled by our payment processors (CMI, PayPal). We don't store card numbers ourselves.
02

Why we collect it

To provide the service: signing you in, connecting you with a doctor or pharmacist, dispatching an ambulance, tracking a delivery. For security: detecting brute-force attempts, abuse, suspicious sign-ins. For improvement: aggregated usage patterns help us decide what to fix or build next.

04

Who we share with

  • Doctors, pharmacists, ambulance and delivery providers — only the data needed to deliver the service you requested.
  • Payment processors — to process payments.
  • Infrastructure providers — AWS (storage), ZegoCloud (video), FCM (push), under contracts that respect the same protections.
  • We do not share data with advertisers. We do not sell data.
05

How long we keep it

Account data — for as long as your account exists, plus a short retention period required by Moroccan law. Medical records — retained per Moroccan medical regulations. You can request deletion of your account at any time; some records may be retained for legal compliance, with everything else fully erased.

06

Security

We use TLS 1.3 in transit, bcrypt for passwords, short-lived access tokens with refresh, and rate-limited authentication endpoints. Read the Security note for the full set of choices.

07

Your rights

  • Access — request a copy of your data.
  • Correction — fix anything inaccurate.
  • Deletion — close your account and erase data, subject to legal retention requirements.
  • Portability — export your medical records in a portable format.
  • Withdrawal of consent — for the AI-parsing feature, or marketing emails.
08

Contact and complaints

Write to privacy@sanpha.ma. If you're not satisfied with our response, you can complain to the CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel).