Nombara Privacy Policy
Last updated: 29 September 2026 · Policy version: 2026-09-29
This policy explains what information the Nombara mobile app collects, why, and what choices you have. It is written to be read alongside the summary shown in the app when you first sign in.
Who we are
Nombara (“Nombara”, “we”, “us”) is operated by Naaz Global Corporation (Pvt) Ltd, a company registered in Sri Lanka (Akurana, Kandy). Contact: nombara@naazglobalcorp.com.
What Nombara is
Nombara is a booking and queue-management platform for local dispensaries (clinics). It shows live queue numbers and lets you get a token online instead of waiting in person. Nombara is not a medical provider: it does not give medical advice, diagnoses, or interpret prescriptions — that stays between you and the doctor.
What we collect, and why
| Data | Why we collect it | Basis (Sri Lanka PDPA) |
|---|---|---|
| Phone number | To create your account and sign you in with an SMS one-time code | Contract / consent |
| Patient profiles: name, age, relationship (self, mother, father…) | Shown to the doctor and reception when your token is called | Contract; consent for health-adjacent data |
| Booking activity: doctor, dispensary, session time, token number and status (waiting / channeled / absent / cancelled) | Runs the live queue and the dispensary’s billing record | Contract / legitimate interest |
| Approximate or precise device location — only if you allow it | Sorts the doctor list by distance; lets a field agent pin a clinic during onboarding | Consent — you can decline and pick a town instead |
| Photos you take in the app (Collector / Owner roles only): signed onboarding agreement, cash receipts | Proof of the clinic agreement and of cash collected | Contract |
| Device push token | To send “your turn is coming up” notifications | Consent |
| Crash and diagnostic data (via Sentry) | To find and fix app crashes | Legitimate interest |
We do not collect your address, payment card details, or medical history. We do not currently collect your National Identity Card (NIC) number; if a future version adds it as an optional field it will be stored encrypted and readable only by a server-side check that it belongs to your account — never as plain text, and never visible to dispensary staff.
Payments, cancellations & refunds
Nombara never takes a card payment from a patient. The booking fee and the doctor’s fee are both paid in cash at the dispensary counter. Because no online payment is ever taken, there is nothing to refund: if you cancel, don’t attend, or a session is cancelled by the doctor, you are simply not charged.
Who can see your data
The reception and doctor at the dispensary you booked can see an active token’s name, age, and queue status — the same information they would write on a paper token. We do not sell, rent, or share your data with advertisers or data brokers.
Processors we use
- Supabase — database, authentication, hosting (Singapore region)
- Google Firebase Cloud Messaging — push notification delivery
- Sentry — crash and diagnostic reporting
- Dialog Axiata / eSMS — SMS delivery in Sri Lanka
Each processes data only on our instructions.
International transfer
Our database and backend are hosted in Singapore. Crash and push infrastructure may process data in other countries under the providers’ own safeguards.
How long we keep it
Account and profile data: until you delete your account. Booking and billing records: retained as long as needed for the dispensary’s financial records, then deleted or anonymised.
This website
The public website (nombara.naazglobalcorp.com) has no accounts, no advertising and no tracking or analytics cookies. The doctor directory shows only practitioners who have been verified, and only the professional details they publish on Nombara. If you tap Sort by nearest, your browser asks for your location. It is rounded to about 1 km in your browser, sent with the search only to sort the list by distance, and not saved to any account or database. The “List your practice” form opens your own email app — nothing you type into it is stored by the website. The site remembers the directory results for a few minutes in your browser’s session storage so pages load faster; closing the tab clears it.
How your data is protected
Data is encrypted in transit (HTTPS / TLS) and at rest. Fields that identify you outside the app are additionally encrypted at the database column level.
Your rights (PDPA)
You can access, correct, or delete your data, and withdraw consent. Edit or remove a patient profile any time from the Profiles tab. To delete your whole account and data, use Menu → Delete my account in the app, or follow the instructions on our account deletion page, or email nombara@naazglobalcorp.com. We respond within 30 days.
If a Doctor or Dispensary Owner account is linked to the same phone number, contact us by email instead of using the in-app button, so deleting your patient data doesn’t affect that business account.
Children
Nombara is for adults. An adult account holder may create a profile for a child they are responsible for; that child does not have their own account.
Changes
Material changes bump the policy version and you will be asked to agree again in the app.
Contact / complaints
nombara@naazglobalcorp.com. You may also complain to Sri Lanka’s Data Protection Authority.