গোপনীয়তা নীতি

Privacy Policy

Last updated: [date] · Draft — pending legal review

This is a starting draft written to match the platform's actual data model — it is not legal advice. Have it reviewed by a lawyer familiar with Bangladeshi data protection law before publishing it live.

1. What We Collect

To operate a verified blood donor/recipient community, we collect: full name, gender, blood group, date of birth, approximate weight, phone number, optional email, location (division/district/upazila/village), address, emergency contact details, optional health conditions you choose to share, profile photo, and records of posts, comments, messages, and donation history you create or that are verified about you.

2. Why We Collect It

This information exists to verify your identity as a genuine member, match donors and recipients by blood group and location, maintain an accurate donation history, and keep the community safe from fake accounts and spam. We do not sell this data.

3. Who Can See Your Information

  • Your phone number is visible only to administrators, not to other members.
  • Your name, blood group, and general location appear on your approved posts and public profile.
  • Your health conditions field, if filled, is visible only to administrators verifying donation eligibility.
  • Private messages are visible only to you and the other participant, and to administrators when investigating a report.

4. Data Retention

We retain membership, post, and donation records indefinitely for community trust and historical accuracy, using soft-deletion (hidden, not erased) rather than permanent deletion for health-related records, consistent with standard practice for donation registries. You may request account deactivation at any time.

5. Your Rights

You may request a copy of your data, request corrections, or request account deactivation by contacting support. Certain donation history records verified by an administrator may be retained for community integrity even after deactivation, with personal identifiers removed where possible.

6. Security

Passwords are stored using industry-standard hashing (never in plain text). Access to administrative functions is role-restricted, and all administrative actions are logged in an audit trail.

7. Changes to This Policy

We may update this policy as the platform evolves. Material changes will be communicated through the notification system before taking effect.