Your full card details are not held by GetClinic. Card and bank credentials are collected and handled by a regulated payment service provider under its own privacy terms and financial-services regulation. GetClinic receives transaction information about the payment, not the card itself.
Who collects your card details
When you make a clinic-related payment, it is processed through a third-party payment service provider or other approved payment infrastructure identified in the collection route shown at checkout. That provider may collect card, bank, billing, identity, device and fraud information (Patient Privacy Policy §10).
Stripe is the named payment service provider in the Booking Terms definitions, and the Subprocessor List records the position plainly: card data is handled by Stripe and does not reach GetClinic systems.
The Cookie Policy lists Stripe as a strictly necessary technology, used for payment integrity and fraud prevention when you make a payment (Cookie Policy §6). More on that in cookies, analytics and your tracking choices.
What GetClinic does hold
GetClinic receives the transaction metadata it needs to run the booking, confirm what the payment satisfied, process or facilitate refunds, reconcile payment status, prevent fraud, respond to disputes and keep records. Under Patient Privacy Policy §10 that may include:
- payer name;
- payment method type;
- a token;
- the last four digits;
- amount and currency;
- authorisation status;
- the payment provider's reference;
- refund or chargeback status.
That is enough to show you a payment confirmation and to send a refund back down the same route. It is not enough to charge a card on its own.
The security code
GetClinic does not need to store a card security code to operate the marketplace (Patient Privacy Policy §10). The same commitment appears in the policy's key commitments, which state that payment card and bank details are generally handled by regulated payment providers.
What GetClinic does not ask you to send
GetClinic does not intentionally ask patients to send full card credentials through ordinary messages or document uploads (Patient Privacy Policy §10). If a message asks you to type a full card number, expiry and security code into a chat, a form or an email, treat it as suspicious and do not reply to it.
Deposits are also not collected off-platform. A clinic booking deposit may only be paid through the approved refundable route shown at checkout, and if a clinic asks you to pay one another way you should contact GetClinic before paying (Terms of Service §28; Booking Terms §20). Paying safely covers what to check before sending money, and what to do if instructions look wrong.
Where the money sits
GetClinic does not operate a wallet, a stored-value account, a peer-to-peer payment service or a remittance service (Terms of Service §31; Booking Terms §23). Your money is not held in a GetClinic balance between payment and treatment. It moves through the collection route identified at checkout to the payment beneficiary named there, and when you pay, and who you pay explains those roles.
You can ask for a copy of the personal information GetClinic holds about you, including payment records, through the privacy request routes described in your privacy rights, or by contacting [email protected].
GetClinic is a technology marketplace. The clinic you choose provides your healthcare and is responsible for it. This is general information about how GetClinic works, not medical advice. Only the clinic's qualified healthcare professionals can decide what treatment is right for you.