Privacy Policy
Last updated: 21 July 2026
This Privacy Policy explains what personal data PhysioDirect collects, why, how it is used and protected, who processes it on our behalf, and the rights you have over it under the PDPA.
1. Who this applies to
- Patients who create an account, search for a physiotherapist, or make a booking.
- Physiotherapists who register directly, or whose publicly available professional details are seeded into the directory before they claim their profile (see Section 4).
- Visitors who browse the Platform without an account.
2. What we collect, and why
We collect different categories of personal data for different purposes. We do not use data collected for one purpose (e.g. verifying a registration) for an unrelated purpose (e.g. marketing) without a separate legal basis.
Account and contact data
Name, email address, phone number, and locale — collected when you create an account or make a booking, to identify you and communicate with you about bookings (including by email and SMS).
Health-related information you provide
The symptoms, conditions, and other health-related information you choose to provide in booking and intake forms, or when using the optional AI-assisted matching tool. This is sensitive personal data, and we collect it only with your explicit consent, given when you submit the form, for the purposes of matching you with a suitable physiotherapist, running a deterministic safety check for red-flag symptoms, and facilitating the booking you request. It is not used to train models on your identity, and it is not shared with a physiotherapist beyond what you include in a booking request.
Home-visit address
For home-visit bookings, your home address and postal code — collected so the physiotherapist can travel to you and so any applicable transport fee can be disclosed at booking. It is shared only with the physiotherapist who accepts your booking.
Physiotherapist professional data
Registration number and authority, specialties, languages, clinic address, fees, availability, headshot, and free-text bio/credentials — collected at signup or profile editing, to build your public listing. Free-text fields are screened by an automated content-safety check before publishing.
Booking and payment data
Proposed/confirmed appointment times, visit mode, deposits, invoices, and payment status — collected to facilitate and account for the booking. Payment card data is collected and processed directly by Stripe, our payment processor — your card details never touch our servers.
Usage data and cookies
Standard technical data (such as device, browser, and pages visited) and cookies used to keep you signed in and understand how the Platform is used. See our Cookie Policy for details.
3. Disclosure to your physiotherapist
When you book, the physiotherapist you book with receives your booking details, contact details, home address (for home visits), and any reason for visit or health information you include in the request — so that they can decide whether to accept, prepare for, and deliver your session. From that point, the physiotherapist is independently responsible under the PDPA for the personal data they hold about you, including their own clinical records, which they must keep in accordance with the PDPA and their professional record-retention obligations. Requests concerning a physiotherapist's clinical records should be directed to that physiotherapist.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
4. Physiotherapist directory listings sourced before claiming
To help patients find physiotherapists who have not yet joined the Platform directly, we may list factual, publicly available professional information — such as a name, registration number and status, listed specialties, and public clinic contact details — sourced from the AHPC register or other publicly available professional listings.
- We only seed factual, professional information — never reviews, ratings, testimonials, or sensitive personal data.
- Unclaimed listings never display reviews.
- The legal basis for this pre-claim listing is a legitimate-interest assessment (helping patients find registered practitioners, and helping practitioners be discoverable) balanced against the individual's interests; once a physiotherapist claims their profile, further processing of their data is based on their consent and the contract they enter into with us.
- Any physiotherapist can request their listing be removed at any time, free of charge and without needing to give a reason, via the opt-out option on their profile page or by contacting us (Section 9). We aim to action opt-out requests within 72 hours, and we keep a minimal record (a one-way hash, not your personal data) to prevent the same listing being re-added later.
5. Processors we use, and overseas transfers
We use a small number of service providers who process personal data on our behalf, under contract, and only for the purposes described in this policy:
- Stripe — payment processing (deposits and invoices). Card details go directly to Stripe and never touch our servers.
- AWS (Amazon Web Services) — application hosting.
- Neon — database hosting.
- Upstash — background job queues and caching.
- Typesense — search over physiotherapist listings.
- Resend — transactional email delivery.
- Twilio — SMS and voice notifications.
- Anthropic — AI-assisted matching. Used for navigation only (helping route you to a suitable physiotherapist), never for diagnosis.
Overseas processing. Some of these providers store or process data outside Singapore. Where personal data is transferred outside Singapore, we only do so where the recipient is bound by legally enforceable obligations to provide the transferred data a standard of protection comparable to that under the PDPA, in accordance with section 26 of the PDPA.
6. Data security
- Data is encrypted in transit (TLS 1.2+) and at rest.
- Payment card data is handled entirely by Stripe; we never store full card numbers on our servers.
- Access to personal data is limited by role, and sensitive actions are logged.
- We do not include personal data in general application logs.
No method of transmission or storage is 100% secure, and we cannot promise absolute security. This is a statement of fact, not a disclaimer: we remain responsible for making reasonable security arrangements to protect personal data in our possession or under our control, as the PDPA requires.
7. How long we keep data
- Booking and payment records (bookings, deposits, invoices) are kept for up to 7 years, aligned to tax record-keeping and limitation periods, and are then deleted or anonymised.
- Account data is kept for as long as your account is active. If you delete your account, we anonymise or delete your personal data within our deletion SLA, retaining only what the bullet above requires and the minimal anti-relisting record described in Section 4.
- Unclaimed directory listings (Section 4) contain factual professional information only, with an easy free opt-out at any time. Raw data from professional-listing sourcing is retained only as long as needed to build and verify a listing, then pruned.
- Clinical records are held by the treating physiotherapist, not by us, and are subject to the physiotherapist's own professional retention obligations (Section 3).
8. Your rights
Subject to the PDPA, you have the right to:
- Access the personal data we hold about you and information about how it has been used or disclosed in the past year.
- Correct inaccurate or outdated data.
- Withdraw consent for processing based on consent (this may limit what the Platform can do for you, e.g. we can't facilitate a booking without your contact details).
- Request deletion or opt-out of a directory listing, as described in Section 4.
To exercise any of these rights, contact our Data Protection Officer (Section 9). If you are not satisfied with our response, you may also complain to the Personal Data Protection Commission (PDPC).
9. Data Protection Officer and breach notification
Our Data Protection Officer can be reached at gininnovate@gmail.com. Privacy queries, data-subject requests, and directory opt-out requests can all be directed there.
If a data breach occurs that is likely to result in significant harm, we will notify the PDPC and affected individuals in line with the PDPA's data breach notification obligations.
10. Changes to this policy
We may update this Privacy Policy as the Platform evolves. Material changes will be reflected by an updated date on this page and, where the change significantly affects how we handle your personal data, notified to you by email.