Medical Information Disclaimer
Information is for general purposes only, not medical advice.
🌐 www.marham.pk
Collects personal data (name, email, phone, address) and uses tracking technologies, but lacks detailed explanation of sensitive data handling and user control over data sharing.
References COPPA but not GDPR or CCPA; user rights are vaguely described and no clear mechanism for data access or deletion is provided.
Contains one-sided clauses (e.g., Marham not liable for third-party actions, unilateral policy changes) and limited user recourse beyond cancellation/refund.
Uses some plain language but is lengthy and repetitive; key risks (e.g., data theft, third-party sharing) are mentioned but not clearly explained.
- The Privacy Policy grants itself broad rights to change the terms at any time without advance notice and demands continued acceptance of use, which is legally problematic as it fundamentally lacks prior notification for material changes.
- There is a contradictory and misleading statement that says "We do not sell, trade, share or otherwise transfer...your personally identifiable information unless we provide users with the advance written notice" but then immediately allows sharing with "website hosting partners and other parties who assist us" without defining limits or requiring consent, which undermines the initial promise and leaves the definition of "third parties" dangerously vague.
- The policy states "non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses and purposes," yet the list of collected data includes name, email, phone, and mailing address, which are personally identifiable, so this distinction is confusing and could allow misuse of personal data under a broad interpretation.
- The security section claims data is "encrypted via Secure Socket Layer (SSL) technology" and behind secured networks, but it does not specify the standards for encryption, access control protocols, or how long data is retained, leaving security claims unsubstantiated and potentially insufficient.
- The policy acknowledges it uses Google Maps APIs and cookies, but it does not specify what data these third-party services collect, how they process it, or what control users have over that data, which creates a gap in transparency.
- The email section says users can "opt-in to receive newsletters and emails" but later states that to unsubscribe, users "can email us and we will promptly remove you from ALL correspondence," which is an overly burdensome process and provides no guarantee of timely removal, violating best practices for consent and easy opt-out.
- The "Data Theft" clause claims "All data contained by the website and application is collected by Team Marham. We own complete rights of this data and legal action would be taken if we found any instance of theft of data" - this is highly problematic because it asserts ownership over user-generated data (like personal health information), which should belong to the user, and threatens legal action against users who might try to access or export their own data, effectively locking users in and violating data portability rights.
- The "Cancellation Policy" for online payments allows cancellation with refund "subject to bank charges and other deductions by third parties," which is unclear as it does not define what these charges are or who bears the cost, potentially shifting financial burden to the consumer without transparency.
- The "Refunds & Exchange Policy" states refunds are processed within 24 working hours but adds that "we shall not be responsible for any delays in credit to the Cardholder's credit card account" due to third-party issues, which effectively absolves the company of responsibility for the full refund cycle.
- The "Dispute Resolution" clause mandates arbitration in Lahore under Pakistan's Arbitration Act 1940, which forces users into a specific legal venue and process that may be inaccessible or expensive, limiting users' ability to seek redress.
- The policy says "We may also release information when its release is appropriate to comply with the law, enforce our site policies, or protect our or others' rights, property, or safety" - this is overly broad and could be used to justify sharing data for purposes not strictly required by law, without a clear definition of "appropriate."
- The use of "non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses and purposes" contradicts the earlier claim that "We do not sell, trade, share or otherwise transfer...your personally identifiable information," as IP addresses, device IDs, and browsing patterns can often be re-identified, making this separation misleading.
- The policy states "When you register on our site we may collect information including Name, Email Address (for international patients only), Phone Number, Mailing Address in case of medicine delivery and lab test home sample collection" - the
Information is for general purposes only, not medical advice.
Use of site does not establish a doctor-patient relationship.
Personal data is encrypted and access is restricted.
Cookies are used to personalize experience and analyze traffic.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free