Legal

Privacy Policy

Last updated 4 October 2026

This policy explains what personal data Medical Tourism CRM ("we", "us") collects, why, who it is shared with, how long it is kept, and the choices you have. It applies to our website at medicaltourismcrm.com and to the Medical Tourism CRM application.

1. Two different roles

We handle personal data in two capacities, and the difference matters.

  • As a controller, for the data about our own customers: the agencies that subscribe, the people who use their accounts, and visitors to our website. We decide why and how that data is used.
  • As a processor, for the data our customers put into the CRM: their patients, leads, notes, files, finance records and conversations. The agency is the controller of that data. We store and process it only to provide the service, on the agency's instructions, and for no purpose of our own.

If you are a patient or lead of an agency that uses our CRM, that agency decides what is collected about you and why. Please contact the agency directly to exercise your rights; we will help them respond.

2. What we collect

Account data: your name, email address, phone number, role, password (stored only as a bcrypt hash), two-factor settings, profile photo and language preference.

Agency data: the agency's name, logo, address, currency, time zone, team members and the settings you configure.

Billing data: plan, invoices and payment status. Card payments are handled by Stripe; we never receive or store your full card number.

Security and usage data: IP address, browser user agent, sign-in times and failed attempts, and an audit log of create, update and delete actions in your account, including actions by our own support staff.

Customer content: everything your agency enters into or receives through the CRM — leads and patient records, medical intake answers, travel details, documents and photos, finance records, notes, and conversations.

Connected-account data: when you connect a mailbox or a messaging account (see section 4), the messages, contact names, addresses and phone numbers of those conversations, and the credentials needed to keep the connection working.

Website data: what you send through our contact form, and the messages you exchange with us through our website chat.

We do not use advertising trackers or third-party analytics on our website or in the application.

3. How we use it

  • To provide the CRM: storing your data, showing it to the people in your agency who are allowed to see it, sending the emails and messages you ask it to send, and running the automations you configure.
  • To keep the service secure: authentication, rate limiting, abuse prevention and investigating incidents.
  • To bill you and manage your subscription.
  • To support you: answering requests and, when you ask us to investigate a problem, viewing your account. Support access is restricted to named administrators and is recorded in your audit log.
  • To tell you about changes to the service, your account or this policy. We send marketing email only if you have agreed to receive it, and you can opt out at any time.
  • To meet legal obligations, such as tax and accounting records.

We do not sell personal data. We do not use customer content for advertising. We do not use customer content, or any data received from connected accounts, to train artificial-intelligence models — ours or anyone else's.

4. Connected mailboxes and messaging accounts

The CRM's inbox can connect to a user's or an agency's own accounts: Gmail and Google Workspace, Microsoft Outlook and Microsoft 365, other mailboxes over IMAP, WhatsApp (as a linked device), Instagram, Telegram and Facebook Page Messenger. Connecting is always a deliberate action by a user, and each connected account is either personal (visible only to the user who connected it) or shared with the agency's team, as chosen when connecting.

When an account is connected, the CRM:

  • reads recent conversations (for email, the last 14 days of the Inbox and Sent folders, up to 200 messages per folder) and new messages as they arrive;
  • stores those messages — including the photos, voice notes, videos and documents in them — with sender and recipient names, addresses and phone numbers, so your team can read and answer them in one place;
  • matches a conversation to an existing lead when the email address or phone number is the same;
  • sends only the replies a person in your agency writes and chooses to send. It does not send messages on its own, in bulk, or to people who are not already part of the conversation.

Credentials for connected accounts — sign-in tokens, passwords, app passwords and session cookies — are encrypted with AES-256-GCM before they are stored, are decrypted only by the service that holds the connection, and are never shown again, including to the person who entered them.

A photo or document from a conversation can be filed under the patient's record by an agent; it then stays with that record like any other upload. Disconnecting an account stops all syncing and sending. Removing it also deletes the conversations and messages it brought into the CRM. Messages in the original mailbox or app are never deleted or changed by us.

WhatsApp and Instagram connections use the same web sessions as the official apps rather than the providers' business APIs. The providers may restrict accounts used this way; see our Terms of Service.

5. Google user data

This section applies when a user connects a Gmail or Google Workspace account with "Sign in with Google".

Scope requestedWhy
https://mail.google.com/To read the mailbox over IMAP and send the user's replies over SMTP. It is the only Google scope that allows IMAP and SMTP access.
openid, email, profileTo identify which Google account was connected and show its address in the CRM.

What we access: the messages in the account's Inbox and Sent folders, as described in section 4, and the account's email address and name. We do not access contacts, calendars, Drive or any other Google service.

How we use it: only to provide the inbox features the user can see — displaying conversations, matching them to the agency's leads, and sending replies the user writes. We do not use Google user data for advertising, for building user profiles, for credit or lending decisions, or to train artificial-intelligence or machine-learning models, and we do not send it to any AI service.

Who sees it: the user who connected the account, and — only if they chose to share it — the people in their agency who are allowed to see shared conversations. Our staff do not read it, except when the user asks us to investigate a problem with their account, when it is needed for security or to comply with the law, or when the data has been aggregated and anonymised for internal operations.

Sharing: we do not sell or transfer Google user data to anyone, except to the sub-processors in section 7 that host and operate the service on our behalf, as needed to provide it, or when required by law.

Storage and deletion: access and refresh tokens are encrypted at rest. Synced messages are kept until the user or agency removes the mailbox from the CRM, deletes the conversations, or closes their account, and are then deleted. A user can also revoke access at any time at myaccount.google.com/permissions, which stops all access immediately.

Medical Tourism CRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The same commitments apply to data received from Microsoft when a user connects an Outlook or Microsoft 365 mailbox; access can be revoked at myaccount.microsoft.com.

6. Legal bases (EU and UK)

  • Contract — to provide the service you subscribed to and to manage your account.
  • Legitimate interests — to keep the service secure, prevent abuse, and improve it, balanced against your rights.
  • Legal obligation — to keep financial records and respond to lawful requests.
  • Consent — for optional marketing email, which you can withdraw at any time.

For customer content, including health data about patients, the agency as controller is responsible for having a lawful basis and, where required, the patient's explicit consent.

7. Sub-processors

We use a small number of companies to run the service. Each receives only what it needs to do its job.

CompanyWhat it doesLocation
RailwayApplication hosting, database and file storageUnited States (US West)
StripeSubscription billing and, if an agency enables it, card payments from its patientsUnited States / global
ResendDelivery of transactional email such as invitations, password resets and notificationsUnited States
AnthropicAI drafting features, only when a user invokes them; content is not used to train modelsUnited States
Web push servicesDelivering browser notifications to users who turn them on (operated by the user's browser vendor)Varies

When an agency connects its own Google, Microsoft, Meta (WhatsApp, Instagram, Facebook), Telegram or email accounts, or uses its own Resend or Stripe account, those providers process data under the agency's own agreement with them.

8. International transfers

Our database is hosted in the United States. If you or your patients are in the European Economic Area, the United Kingdom or Switzerland, personal data is transferred to the United States. Where required, we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard with our sub-processors. If EU-only data residency is a requirement for your agency, please tell us before you subscribe.

9. How long we keep it

  • Customer content stays in your account for as long as your subscription is active and until you delete it. After cancellation it remains available for export until the end of the period you have paid for. On request we permanently delete an agency and everything in it.
  • Messages from connected accounts are kept until the account is removed from the CRM or the conversation is deleted.
  • Audit logs and security records are kept for as long as the agency's account exists.
  • Billing and tax records are kept for as long as the law requires.
  • Contact-form messages are kept for as long as needed to answer them and follow up.

10. Security

Every connection is encrypted with TLS. Each record is scoped to the agency that owns it, and every query is filtered by the agency of the person making the request. Passwords are hashed, two-factor authentication is available, sign-in is rate limited, and connected-account credentials are encrypted. Our trust page at /trust describes these controls in detail, including what we do not yet have.

If we become aware of a personal data breach affecting your data, we will notify you without undue delay with what we know.

11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent. You also have the right to complain to your data protection authority.

To exercise these rights for your own account data, email support@medicaltourismcrm.com. If your data was entered into the CRM by an agency — for example, as a patient — please contact that agency; we will support them in responding.

12. Cookies and local storage

We use only cookies that the service needs to work. There are no advertising or analytics cookies.

NamePurposeDuration
next-auth session and CSRF cookiesKeep you signed in and protect forms against cross-site requestsSession, or up to 30 days
Language and currency preferenceRemember the language and display currency you chose1 year
ib_oauthProtect the "connect your mailbox" sign-in against forgery10 minutes

The chat widget that agencies place on their own websites stores an anonymous visitor identifier in the visitor's browser so the conversation continues across pages. That data belongs to the agency running the website.

13. Children

Our service is for businesses and is not directed at children. Agencies may hold records about patients who are minors; doing so lawfully, including obtaining a guardian's consent, is the agency's responsibility as controller.

14. Changes to this policy

When we change this policy, we update the date at the top of the page. If a change materially affects how we use personal data, we will tell account owners by email before it takes effect.

15. Contact

Questions or requests about privacy: support@medicaltourismcrm.com.