Your information and privacy.
This policy explains what personal information Goa Blood Network handles, why it is used, who may see it, and the choices available to you.
Effective: 16 August 2026
Information we collect
We collect information you submit, which may include name, email, phone and WhatsApp number, password hash, account role, blood group, gender, date of birth, location, availability, last donation date, hospital or NGO details, licence or registration details, blood-request information, donor-contact requests, and blood-camp registrations.
We also process technical and security information such as session identifiers, IP address-derived rate-limit keys, OTP issue and attempt records, timestamps, account status, and administrator audit activity. We do not store your plain-text password or OTP.
How information is used
We use information to create and secure accounts, verify email ownership, reset passwords, review organizations and donors, display donor search results, coordinate blood requests, prevent duplicates and abuse, send matching alerts, process donor-contact approvals, administer camps and participants, maintain audit records, and communicate account or submission decisions.
Public and restricted visibility
Public visitors may see limited donor information such as first name, blood group, district, taluka, area, and availability. Phone, email, date of birth, and full address are not intended for public display. A verified requester may receive a donor's permitted phone or WhatsApp details only after the donor accepts the contact request. Donors can see the identity and contact details of people requesting contact.
Camp organizers and authorized administrators can view participant names, phones, emails, blood groups, and registration times, and organizers may export that information to administer the camp. Administrators can access account and submission information for review, support, safety, and platform operation.
Emails and notifications
We use the email address associated with your account for OTP verification, password recovery, approval decisions, matching blood-request alerts, donor-contact updates, and camp-related status messages. These are operational communications connected to the service rather than marketing messages.
Cookies and external services
We use an essential session cookie to keep you signed in and protect forms. The website also loads some fonts, styles, scripts, and images from external content-delivery providers; those providers may receive technical information such as your IP address and browser details. Database hosting and email-delivery providers process information only as needed to provide their services.
Retention
We retain account and coordination information while it is needed to provide the service, handle active requests or camps, resolve disputes, prevent abuse, and maintain security records. Blood requests and availability may expire automatically, but expiry does not immediately erase the underlying record. OTPs expire quickly, while consumed OTP and audit records may be retained for security and troubleshooting. Camp organizers must securely delete exported participant files when no longer needed.
Your choices and requests
Donors can change availability, hide their profile, control contact consent, and update profile information. Users can manage supported blood requests and camp registrations. You may contact us to request access, correction, or deletion of personal information. We may need to verify your identity and may retain limited information where reasonably necessary for security, legal obligations, dispute handling, or prevention of repeated abuse.
Security
We use access controls, password hashing, OTP expiry, CSRF protection, session safeguards, rate limiting, restricted contact workflows, and audit logging. No internet service is completely secure, so users should protect their credentials and notify us if they suspect misuse.
No medical responsibility
Goa Blood Network does not verify medical eligibility, donor health, blood safety, hospital requirements, request authenticity, transport, testing, storage, transfusion, or emergency outcomes. Users must independently verify all information with qualified medical professionals, hospitals, blood banks, and lawful authorities.
No accountability for outcomes
The platform is provided only as a network and information-sharing tool. Goa Blood Network, its owners, admins, volunteers, developers, and associated persons are not accountable or liable for any loss, delay, mismatch, fraud, misinformation, medical complication, injury, death, dispute, or damage arising from use of the platform or reliance on information shared through it.
Data accuracy and user responsibility
Users are responsible for submitting accurate information and updating their own availability and details. We may edit, suspend, reject, or delete accounts or requests that appear false, unsafe, abusive, or inappropriate.
Contact
For privacy questions or access, correction, and deletion requests, use the contact page. Include the email associated with your account so the request can be verified.
Policy changes
We may update this policy as the service or applicable requirements change. The effective date above identifies the current version.