Blue Rhino Services ("we", "us", "our") operates a diagnostic-imaging scan-booking platform (the "Service") that connects referring doctors, patients, and diagnostic centres so a patient can book an imaging scan (such as MRI, CT or ultrasound) ordered by their doctor. This policy explains what personal data we collect, why, how we use and protect it, and the choices and rights you have. We are committed to handling data in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
From doctors (account): name, mobile number, email, medical specialty, clinic name and address, and clinic location (latitude/longitude) if you choose to set it.
From diagnostic centres (account): centre name, area/city, phone number, address and location, the scans offered and their prices.
From/about patients: name and mobile number (entered by the referring doctor), the scan(s) requested, the doctor's clinical note (if provided), the centre selected, and — only if the patient chooses to share it on the booking page — their approximate device location, used solely to sort nearby centres.
Health information: the type of scan requested and the diagnostic report(s) uploaded by the centre. We treat this as sensitive information and restrict access to the doctor who created the request and the centre fulfilling it.
Technical data: device push-notification tokens (to alert doctors/centres), and standard app diagnostics needed to operate the Service.
We process personal data on the basis of consent and to provide the service you requested. A patient explicitly agrees, on the booking page, to share their name and mobile number with the diagnostic centre they select before any booking is made. You may withdraw consent at any time by deleting your account (see Section 9); withdrawal does not affect processing already carried out.
Your data is stored on Google Firebase infrastructure located in India (Mumbai region). Some processing by our service providers may occur on their global systems consistent with applicable law.
Data is transmitted over encrypted connections (HTTPS/TLS) and access is restricted by authentication and server-side security rules so that a doctor sees only their own requests and a centre only requests booked to it. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.
We keep account and request data for as long as your account is active and as needed to provide the Service and meet legal or accounting obligations. When you delete your account, we delete or de-identify your personal data as described below, subject to any retention the law requires.
You may access, correct, or delete your personal data. You can delete your account and associated personal data from within the app (Profile → Delete account), or request deletion via our web page: /delete-account. You may also contact our Grievance Officer below to exercise any right under the DPDP Act.
The doctor and centre apps are intended for professional adults. A scan may be for a patient who is a minor; in such cases the patient's guardian provides consent when choosing a centre.
For any question, request, or complaint about your data, contact our Grievance Officer:
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.