Privacy Policy
Last updated: June 12, 2026
On this page
App Riders LLP ("App Riders," "we," "us," or "our") is committed to protecting the privacy and personal data of individuals who use our products, services, and websites, including the Dant Upchaar™ suite of applications (collectively, the "Services"). This Privacy Policy ("Policy") describes the types of information we may collect from you or that you may provide ("Personal Information") and our practices for collecting, using, maintaining, protecting, and disclosing that information.
This Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
Which policy applies to you. App Riders LLP operates products under distinct brands. If you use the Dant Upchaar™ platform — the Patient Care App, Doctor App, Clinic Management App, or dantupchaar.com — the Dant Upchaar Privacy Policy applies to that platform and prevails over this Policy to the extent of any inconsistency. This Policy governs www.appriders.com and any App Riders service for which no product-specific policy has been published. App Riders LLP remains the Data Fiduciary in every case.
By accessing and using the Services, you acknowledge that you have read this Policy and agree to all its terms and conditions. If you do not agree, please do not use the Services. This Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.
1. Data Fiduciary Information
App Riders LLP acts as the Data Fiduciary under the DPDP Act 2023.
Registered Office: APP RIDERS LLP, 848/2, First Floor, Arna Barna Chowk, Patiala, Punjab, India — 147001
Email: support@appriders.com
Grievance Officer: Gaurav Singla, support@appriders.com
2. Personal Data We Collect
2.1 Data You Provide
You can access and use the Services without revealing any information by which someone could identify you. If, however, you wish to use certain features, you may be asked to provide certain Personal Information. We receive and store any information you knowingly provide when you create an account, make a purchase, or fill any forms. This may include:
- Identity data: Name, date of birth, gender, photograph
- Contact data: Email address, phone number, postal address
- Account data: Username, password (stored in hashed form)
- Health data: Dental health records, treatment history, prescriptions, medical images (only within Dant Upchaar applications)
- Professional data: For doctors and clinic owners — registration number, qualifications, clinic details
- Financial data: Payment information processed via secure third-party payment gateways; we do not store full card numbers
- Family member data: Name, age, gender, and relationship of family members you add to your account for booking appointments on their behalf
You can choose not to provide us with your Personal Information, but then you may not be able to take advantage of some features. Users who are uncertain about what information is mandatory are welcome to contact us.
2.2 Data Collected Automatically
When you use the Services, our servers automatically record information that your device sends. This data is used only to identify potential cases of abuse and establish statistical information regarding usage. This statistical information is not aggregated in such a way that would identify any particular user. This may include:
- Device data: Device model, operating system, unique device identifiers, language preferences
- Usage data: App usage patterns, feature interactions, search queries, booking interactions, session duration
- Location data: Approximate location (city-level) for clinic search; precise location only with explicit consent
- Log data: IP address, access times, error logs
- Device permissions: Camera and storage access (for document and image uploads), location services (for clinic search)
- Mobile identifiers: Push notification tokens, app installation identifiers, and diagnostic session identifiers used for service delivery and crash reporting
2.3 Professional Content
Healthcare professionals and clinic administrators may upload content that constitutes professional work product or commercial intellectual property — such as clinic branding, facility photographs, and clinical images (“Professional Content”). Professional Content is governed by the intellectual property and User Content provisions of our Terms of Service.
3. Use and Processing of Collected Information
We act as a Data Fiduciary (data controller) when we ask you to submit Personal Information necessary to ensure your access and use of the Services. We act as a data processor in situations when you submit Personal Information through the Services and we process it only in accordance with your instructions.
Any of the information we collect from you may be used for the following purposes:
- To provide, maintain, and improve the Services
- To create and manage user accounts
- To enable appointment booking, treatment tracking, and patient-doctor communication
- To verify the credentials of healthcare professionals
- To process payments and generate invoices
- To send important service notifications and administrative information
- To respond to inquiries and offer support
- To ensure the security and integrity of the platform
- To comply with legal obligations, including regulatory reporting
- To conduct anonymized analytics to improve product experience
- To protect from abuse and malicious users
Processing your Personal Information depends on how you interact with the Services and applies when: (a) you have given your consent for one or more specific purposes; (b) provision of information is necessary for the performance of an agreement with you; (c) processing is necessary for compliance with a legal obligation; (d) processing is necessary for the purposes of the legitimate interests pursued by us.
For healthcare professionals: we process Professional Content to display your credentials to patients, verify your registration status, and facilitate treatment record management within the platform.
Marketing communications and targeted advertising, if any, are carried out only with your explicit consent.
4. Payment Processing
For Services requiring payment, your payment information is used solely for processing payments. We use third-party payment processors ("Payment Processors") to assist us in processing your payment information securely. Payment Processors adhere to applicable security standards administered by the PCI Security Standards Council. Sensitive and private data exchange happens over a TLS secured communication channel and is encrypted.
We share payment data with Payment Processors only to the extent necessary for processing your payments, refunding such payments, and dealing with complaints related to such payments. The Payment Processors’ use of your Personal Information is governed by their respective privacy policies.
5. Consent
In accordance with the DPDP Act 2023, we obtain your free, specific, informed, unconditional, and unambiguous consent before processing your personal data. Where in-person patient registration occurs (such as walk-in appointments), consent may be obtained verbally at the point of care with a recorded timestamp. You may withdraw your consent at any time by contacting support@appriders.com or through in-app privacy settings. Withdrawal will not affect the lawfulness of processing before the withdrawal.
6. Privacy of Children
We do not knowingly collect any Personal Information from children under the age of 18. If you are under 18, your parent or legal guardian must provide verifiable consent before you use the Services. If you have reason to believe that a child under 18 has provided Personal Information to us without appropriate consent, please contact us to request deletion of that information.
Where a registered user books appointments or submits information for a family member under the age of 18, the user represents that they have parental or legal guardian authority to consent on that minor’s behalf, in accordance with the DPDP Act 2023.
We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide Personal Information through the Services without their permission.
7. Data Sharing and Disclosure
We do not sell, disclose, or transfer your Personal Information to any third party for monetary or other valuable consideration. We may share data only in these circumstances:
- With healthcare providers: To facilitate treatment within the Dant Upchaar platform
- With service providers: Trusted third parties assisting in operating the Services under strict contractual obligations. Service Providers are not authorised to use or disclose your information except as necessary to perform services on our behalf
- Legal requirements: When required by law, court order, or government directive, and when we believe in good faith that disclosure is necessary to protect our rights, your safety, or investigate fraud
- Business transfers: In the event of a merger, acquisition, or sale of assets, your account and Personal Information will likely be among the assets transferred, with advance notice. Any successor entity shall be bound by the same terms regarding User Content as set forth in these policies
8. Data Storage and Retention
Data is stored on secure servers in India. We will retain and use your Personal Information for the period necessary to enforce this Policy, resolve disputes, and comply with legal obligations. Retention periods:
- Account data: While active, plus a reasonable period after deletion request to complete processing
- Health data: Minimum 3 years from last treatment (per medical record requirements)
- Transaction data: 8 years (per tax/financial regulations)
- Analytics data: Anonymized and retained indefinitely
We may use aggregated, anonymized statistical data — such as usage patterns, feature adoption rates, and appointment volume trends — derived from your use of the Services after you update or delete your account, in a manner that does not identify you personally. Once the retention period expires, Personal Information shall be deleted.
9. Account Deletion
You have the right, at any time, to request deletion of your account and associated data. You can use the “Delete Account” option available within the application settings, or contact support@appriders.com. Deletion will result in removal of your account and the inability to access associated features. Health and transaction data may be retained as required by law (see Section 8).
10. Data Security
We secure information you provide on servers in a controlled, secure environment, protected from unauthorised access, use, or disclosure. We maintain reasonable administrative, technical, and physical safeguards including:
- Encryption in transit (TLS) and at rest (AES)
- Access controls and role-based permissions
- Security reviews and vulnerability assessments as part of our development lifecycle
- Secure development practices and code reviews
However, no data transmission over the Internet or wireless network can be guaranteed. While we strive to protect your Personal Information, you acknowledge that there are security and privacy limitations of the Internet which are beyond our control, and any information and data may be viewed or tampered with in transit by a third party despite best efforts.
11. Your Rights as a Data Principal
You may exercise certain rights regarding your information processed by us:
- Right to Access: Request a summary of your personal data and processing activities
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion, subject to legal retention requirements
- Right to Grievance Redressal: Lodge a complaint with our Grievance Officer
- Right to Nominate: Nominate an individual to exercise your rights in your absence
Any requests to exercise your rights can be directed to us at support@appriders.com. We may ask you to verify your identity before responding.
12. Cross-Border Data Transfers
We primarily store and process data within India. We use service providers located outside India to deliver the Services, including Google LLC (United States) for authentication, database, storage, push notifications, and crash diagnostics. By using the Services, you consent to this transfer. Any cross-border transfer complies with the DPDP Act 2023 and includes appropriate contractual safeguards, such as Data Processing Addenda, to protect your information.
13. Cookies
Our website uses essential cookies for functionality and anonymized analytics. No third-party advertising cookies. Control preferences through your browser settings.
14. Links to Other Resources
The Services contain links to other resources that are not owned or controlled by us. Please be aware that we are not responsible for the privacy practices of such other resources or third parties. We encourage you to read the privacy statements of each and every resource that may collect Personal Information.
15. Data Breach Notification
In the event we become aware that the security of the Services has been compromised or users’ Personal Information has been disclosed to unrelated third parties as a result of external activity, including security attacks or fraud, we reserve the right to take reasonably appropriate measures, including investigation, reporting, and cooperation with law enforcement authorities. We will notify the Data Protection Board of India and affected individuals as required under the DPDP Act 2023, without undue delay.
16. Changes to This Policy
We reserve the right to modify this Policy at any time. Material changes will be communicated via email or prominent notice at least 15 days before taking effect. Your continued use of the Services after the effective date of the revised Policy will constitute your consent to those changes.
17. Acceptance of This Policy
You acknowledge that you have read this Policy and agree to all its terms and conditions. By accessing and using the Services and submitting your information, you agree to be bound by this Policy. If you do not agree to abide by the terms of this Policy, you are not authorised to access or use the Services.
18. Grievance Officer
Name: Gaurav Singla
App Riders LLP
Email: support@appriders.com
19. Contact Us
If you have any questions regarding the information we may hold about you or wish to exercise your rights, you may contact us:
Email: support@appriders.com
Website: www.appriders.com
This document was last updated on June 12, 2026.