Skip to content
Yashfeeni

Privacy policy

Last updated:

This page is translated from Arabic. If the translation differs from the Arabic text, the Arabic text applies. Read the Arabic text

This policy explains how the Yashfeeni platform (“Yashfeeni”, “we”) handles data when you use the website or the patient, doctor and pharmacy apps. This page is not consent to share health data beyond the functions the user requests inside the service.

1. Data we may process

The scope of data depends on the app and feature used, and may include:

  • Account data: name, phone number, email address and verification data.
  • Health service data: appointments and the information the user or care provider adds within the permissions granted to them.
  • Transaction data: booking history and payment or refund status when these functions are enabled.
  • Approximate location (optional): only when you choose “Nearest to me” or “My location” on the map in the patient app, an approximate location (to about 100 metres) is sent to sort clinics by distance, and we do not store it on our servers. You can withdraw the permission at any time in the device settings.
  • Pharmacy location (pharmacy app): the device’s precise location is read only when the pharmacist taps “Use my current location”, and it is stored as the pharmacy’s business address only when they tap Save, so patients can find the pharmacy on the map. It is the location of the shop, not of a person, and the pharmacist can change it in the pharmacy profile at any time.
  • Visit reviews: when you rate a completed visit, the review is published after moderation without the patient’s name, unless they chose to show their first name and father’s initial.
  • Technical and security data: device type, app version, network address, notification tokens, and the crash and security logs needed to run and protect the service. The API access log records only the request path, never the query string.
  • Interface language: the language you choose (Arabic, Kurdish or English) is saved on your device, and on your account when you are signed in, so messages and notifications reach you in the same language.

We never ask users to send passwords, verification codes, ID photos or medical details by email or through the support page.

2. Purposes of use

  • Creating, verifying and managing the account.
  • Performing functions the user requests, such as booking and contacting the service provider.
  • Sending operational and security alerts related to the account.
  • Preventing misuse, investigating faults, and improving service reliability.
  • Meeting legal, accounting and regulatory obligations where applicable.

We don't sell health data or use it for targeted ads.

3. Protection and security

We use access controls, permissions, security logs and encrypted connections when data is in transit. Hosting, encryption and monitoring settings are reviewed for every release before it goes live; this policy does not mean every optional feature or integration is enabled in every environment.

No electronic system is entirely free of risk, so we keep controls up to date, limit access to what each role needs, and respond to incidents when they are found.

4. Sharing with third parties

We share data only as far as needed to provide a function the user asked for, with an approved technical service provider acting on our instructions, or when the law requires it. The actual parties differ by country, environment and release, and we do not treat any provider as enabled just because it is mentioned in planning documents.

When the service involves sharing with a doctor, pharmacy or laboratory, sharing is limited to that role’s permissions and the purpose the user started.

When dispensing a prescription, the pharmacy sees the prescription (medications and doses) and drug-safety alerts only: the name of a recorded drug allergy or of another current medicine when it conflicts with a medicine on the prescription, so it can check before dispensing. The pharmacy does not see the full medical file, medical history, or lab and imaging results.

5. Retention and deletion

We keep data for as long as needed to run the service, protect the account and meet legal, accounting and professional requirements. When an account deletion request is accepted, we delete or de-identify data that does not have to be kept; limited records may remain where the law, professional duty or fraud prevention requires it. Timing depends on the type of data and the outcome of verifying the request.

6. User rights and privacy requests

  • Requesting access to or correction of account data within legally available limits.
  • Requesting account deletion or restriction of some processing where possible.
  • Withdrawing optional permissions from device or app settings.

To send a privacy request, use the support and contact page or email privacy@yashfeeni.com. We may ask you to confirm you own the account before acting on the request — never by asking for your password.

7. Children and dependent accounts

A minor does not open an independent account where the law does not allow it. Where dependent accounts are available, they are managed by the parent or legal guardian within the permissions described in the service.

8. Changes and contact

We publish material changes on this page and update its date. For privacy questions email privacy@yashfeeni.com; for general help use the support page.

Privacy policy · Yashfeeni