Legal

Privacy Policy

Effective date: 24 March 2026

This Privacy Policy describes how HealthApp Services Private Limited ("HealthApp Services", "we", "us", or "our") collects, uses, and protects information when you visit healthapp.co.in (the "Website").

1. Information We Collect

1.1 Information you provide voluntarily

When you submit our contact form, we collect:

  • Full name
  • Work email address
  • Company name
  • Role or title (optional)
  • Company type (Bank, Insurer, Wealth Platform, or Other)
  • Message (optional)

You may also contact us directly via email at partners@healthapp.co.in, in which case we receive whatever information you choose to include.

1.2 Information collected automatically

When you visit the Website, we and our service providers may automatically collect certain information, including:

  • IP address (anonymised where supported)
  • Browser type and version
  • Operating system
  • Pages visited, time spent on pages, and navigation paths
  • Referring URL
  • Device type and screen resolution

1.3 Analytics and tag management

We use the following services to understand how visitors use our Website:

Google Tag Manager (GTM), provided by Google LLC, is a tag management system that loads and manages third-party scripts on the Website, including Google Analytics. GTM itself does not collect personal data, but the tags it deploys may do so as described below.

Google Analytics (loaded via GTM) uses cookies and similar technologies to collect and analyse information about Website usage. This data is processed in aggregate to help us improve our Website and services. Google may transfer and store this data on servers outside India. Google's use of this data is governed by Google's Privacy Policy. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

Cloudflare Web Analytics (provided by Cloudflare, Inc.) collects aggregate, privacy-focused metrics such as page views, visits, referrers, and country of origin. It does not use cookies, does not track individual users, and does not collect personal data. All data is processed on Cloudflare's edge network. See Cloudflare Web Analytics for details.

1.4 Bot protection

Our contact form uses Cloudflare Turnstile, a privacy-focused challenge service, to prevent automated abuse. Turnstile may process your IP address and browser signals to verify you are a real visitor. It does not use cookies for tracking and does not collect personal data beyond what is necessary for the challenge. See Cloudflare's Privacy Policy for details.

2. How We Use Your Information

We use the information you provide through the contact form solely to:

  • Respond to your inquiry
  • Communicate with you about our services
  • Evaluate potential business partnerships

We do not use your information for automated decision-making, profiling, or direct marketing unless you have separately consented.

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We may share it with the following categories of recipients:

3.1 Service providers

Service Provider Purpose
Cloudflare, Inc. Website hosting, content delivery, bot protection (Turnstile), and privacy-focused web analytics
Twilio Inc. (SendGrid) Delivering contact form submissions to our team via email
Adobe Inc. Serving web fonts (Adobe Typekit) — no personal data is shared
Google LLC Tag management (Google Tag Manager) and website analytics (Google Analytics) — collects anonymised usage data via cookies

3.2 Partners

From time to time, we may share your information with trusted partners — such as licensed insurance brokers and distribution partners — for the purpose of fulfilling service inquiries and connecting you with relevant insurance products. We only share information that is necessary to address your inquiry and require our partners to handle it in accordance with applicable data protection law.

We may also disclose information if required by law, regulation, or legal process, or to protect our rights, safety, or the rights of others.

4. Data Storage and Security

This Website is fully static and does not store your personal data in any database. When you submit the contact form, your information is transmitted directly to our team via email through SendGrid's servers. We retain your information only in our email systems and only for as long as necessary to fulfil the purpose for which it was collected.

We implement reasonable security practices and procedures consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to protect your information from unauthorised access, disclosure, alteration, or destruction.

5. Your Rights

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian law, you have the right to:

  • Access — request confirmation of whether we hold your personal data and obtain a summary of it
  • Correction and erasure — request correction of inaccurate data or erasure of data that is no longer necessary
  • Grievance redressal — raise concerns about how your data is handled
  • Nominate — nominate another person to exercise your rights in the event of your death or incapacity

To exercise any of these rights, please email us at partners@healthapp.co.in. We will respond within a reasonable timeframe and in accordance with applicable law.

6. Cookies

The Website uses a limited number of cookies. We do not use cookies for advertising or cross-site tracking.

Cookie Provider Purpose Duration
_ga Google Analytics Distinguishes unique visitors 2 years
_ga_* Google Analytics Maintains session state 2 years
__cf_bm Cloudflare Bot management (strictly necessary) 30 minutes

You can control or delete cookies through your browser settings. You can also opt out of Google Analytics specifically by installing the Google Analytics Opt-out Browser Add-on. Disabling cookies will not affect your ability to browse the Website, but the contact form may require the Cloudflare bot management cookie to function.

7. Third-Party Links

Our Website may contain links to third-party websites (such as LinkedIn). We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policies of any third-party site you visit.

8. Children's Privacy

This Website is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date. We encourage you to review this page periodically.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: