Privacy Policy
Last updated:
This policy explains what personal data MacroSora (“we”, “us”) collects, why, and what rights you have. We aim to comply with the EU General Data Protection Regulation (GDPR) and China’s Personal Information Protection Law (PIPL).
What we collect
- Contact and request details you send through our form, email, WhatsApp or Instagram: name, email, phone or WhatsApp number, preferred language, location, the city and dates you’re interested in, and a short description of what you need.
- Health-related information only when you choose to share it so we can arrange your care (for example, which department you need or reports you want translated). Our website form asks for a brief description only — please don’t paste detailed medical records into it. When we need records, we send you an encrypted channel.
- Payment information is collected and processed by Stripe. We see the payment amount, your name and email and the payment status — never your full card number.
- Website usage: if analytics are enabled, we use a privacy-friendly, cookie-free service that records aggregated page views and button clicks without identifying you.
How we use it
- To answer your questions and prepare a plan and quote.
- To book appointments, accompany you, interpret and pay hospitals on your behalf.
- To send receipts and keep the accounting records the law requires.
- To follow up after your visit, if you want us to.
We do not sell your data and do not use it for advertising.
Legal bases
We process your data to take steps you request before a contract and to perform our contract with you; based on your explicit consent for health-related information; and to meet legal obligations such as tax and accounting rules.
Who we share it with
- Hospitals and doctors you are visiting — only what is needed for your appointment, with your agreement.
- Service providers that help us run the service: Stripe (payments), Resend (sending emails from our website form), Cloudflare (website hosting and spam protection) and our email and messaging providers.
- Authorities, only when the law requires it.
International transfers
Our service involves China, and our providers may process data in the United States, the European Union and other countries. When we transfer data, we use the safeguards the law requires, and we only share with hospitals in China what is necessary for your care.
How long we keep it
- Enquiries that do not lead to a booking: deleted within 12 months.
- Booking, invoice and payment records: kept for as long as tax and accounting law requires.
- Medical documents you share for a visit: deleted after the service is complete, unless you ask us to keep them for follow-up.
Your rights
You can ask to access, correct, delete or receive a copy of your data, object to or restrict its use, and withdraw your consent at any time. Email hello@macrosora.com. You also have the right to complain to a data protection authority.
Cookies
We don’t use advertising or tracking cookies. Our spam protection on the contact form (Cloudflare Turnstile) may use strictly necessary technical data to tell people from bots.
Contact
MacroSora · hello@macrosora.com