Legal
Privacy Policy
How PharmacyOS handles your data — what we collect, why, who else sees it, how long we keep it, and how to get it out or get it deleted. Written to satisfy the Bangladesh Personal Data Protection Act 2023, Apple App Store Review Guideline 5.1, and Google Play's User Data policy.
Last updated: 19 August 2026 · Effective: 19 August 2026 · Supersedes the version of 25 May 2026
Who is responsible for your data
PharmacyOS is operated from Dhaka, Bangladesh, and is the data controller for your account and staff data. For the business records you enter — your pharmacy's own customers, sales and documents — you are the controller and we are your processor: we act on your instructions and never use those records for our own purposes.
- Data Protection Officer — privacy@pharmacyos.work
- Security reports — security@pharmacyos.work
- We answer privacy requests within 30 days (PDP Act 2023 §16).
What we collect
We collect only what the product needs to work. Grouped by category, with the reason it exists:
- Account and staff data
- Your name, email address, a hashed password, an optional two-factor secret, your role, and the sign-in and paired-device history that lets you see and revoke your own sessions. Staff accounts hold the same fields, created by you.
- Pharmacy records
- Your products, batches and expiry dates, stock levels, suppliers, purchase orders, sales, invoices, and the settings that make your counter behave the way you want. This is your data — we hold it so your staff and your devices can share one copy of it.
- Customer records
- Only what the counter needs to serve a returning customer: name, phone number, purchase history, and — where you record one — the prescription and the medicines dispensed. You collect this from your own customers with their consent (PDP Act 2023 §5); we store it on your behalf, and we never contact them ourselves.
- Files you upload
- Prescription photos, product and pack photos, and the receipts or reports you export. Each file goes to your own storage area, is readable only by your own staff, and is deleted with your account.
- Device and technical data
- When the app or site talks to our server we receive your IP address, the app or browser version, and — for the app — a device identifier we generate at first launch, plus the device model and operating-system version. The device identifier lets you see and revoke your own paired devices; it is not an advertising identifier and it is not shared.
- Diagnostics (crash reports)
- When the app hits an error it records the error message, a stack trace, the screen you were on, the app version, and a short trail of the last actions taken — scrubbed of personal data before it is stored — and uploads it so we can fix the fault. These reports go to our own database on our own infrastructure. There is no third-party crash-reporting SDK in any of our apps.
- Usage counts
- Our server counts page views, searches and orders on your public storefront so you can see your own traffic. These events carry no name, phone number or account id; the visitor IP address is never stored — only a per-day salted hash of it, used to count unique visitors and then discarded. Search terms are normalised and stripped of anything that looks personal.
Why we use it, and on what legal basis
Each purpose below is tied to the lawful basis it relies on under the PDP Act 2023. We do not repurpose data for anything not listed here without asking you first.
- To provide the service you signed up for — running your counter, storing your records, syncing your devices (performance of our contract with you).
- To authenticate you and keep the account secure — sign-in, two-factor codes, device pairing, abuse and bot protection (contract, and our legitimate interest in preventing fraud).
- To send you the transactional messages your account has switched on — one-time codes, receipts, and the alerts you chose (contract; consent where the recipient is your customer, PDP Act 2023 §5).
- To keep records the law requires us to keep — invoice and tax records, and the audit trail (compliance with a legal obligation).
- To fix faults and keep the product working — crash diagnostics and error logs (legitimate interest in a functioning service).
- To answer your support requests (contract).
- We do not use your data for advertising, we do not profile you, and we do not train any model on your business records or your customers.
Device permissions the app asks for
The app asks for a permission only at the moment a feature needs it, and every feature still works if you decline — you can type a barcode instead of scanning it, or print over USB or the network instead of Bluetooth. What each one is for:
- Camera
- Scanning barcodes at the counter, and taking the photos described above. Nothing is captured unless you open the scanner or the camera yourself.
- Photo library
- Attaching a photo you pick, and saving a receipt or document you asked to export. We read only the file you select.
- Bluetooth (and, on Android 11 and older, location)
- Discovering and connecting to your thermal receipt printer. Older Android versions gate Bluetooth scanning behind the location permission, which is why the app asks for it there. We do not collect, store or transmit your location — not for that feature, not for any other. On Android 12 and newer, the scan permission is declared with the "never for location" flag.
- Local network
- Finding a network receipt printer on the same Wi-Fi. Used only to reach printers.
- Microphone
- Only the used-device buyback flow uses it, to record a short consent video with audio when a seller hands over a device. No other feature touches the microphone, and nothing is recorded unless you start that capture yourself.
Health data, and how it is treated
A prescription, a dispensing record, and a customer's medicine history are health data — the most sensitive information this product holds. They exist for one purpose: so your pharmacy can dispense correctly and keep the registers the law requires.
- Health data stays inside your own pharmacy's records. It is never pooled with another pharmacy's, and no cross-pharmacy view of it exists.
- We never use it to improve, market, or price any other product, and no model of ours is trained on it.
- Prescriptions and prescription photos are never sent to any of the optional third-party features listed below. None of them can read a file you upload, and none is given the prescription itself.
- One optional feature reaches further than the rest, and only if you switch it on yourself: connect the ChatGPT or Claude assistant and it signs in as you to read whatever an answer needs — stock and sales figures, an invoice line by line, or a customer you name, with their contact details, what they owe and the items they usually buy. At a pharmacy counter those are not ordinary sales figures: the lines of a dispensing invoice are a dispensing record, and the items a customer usually buys are their medicine history — health data, as defined above. Treat connecting the assistant as a decision about health data, not about convenience. The answer arrives inside your own ChatGPT or Claude account, so whether that conversation may be used to improve OpenAI's models or Anthropic's is settled by that provider's terms and your own ChatGPT or Claude data controls — not by this policy, and that is the one limit on the promise above. Disconnect it in Settings → Connected apps whenever it is not right for you; the OpenAI and Anthropic rows below state exactly what each receives and how quickly access ends.
- It is never used for advertising, marketing, or any use-based data mining — by us or by anyone else.
- It is never sold, rented, or shared with a data broker, and it is never used to build a profile of an individual.
- Staff access is limited by role, and every access is written to the audit trail.
Where it lives
Your data lives on Cloudflare infrastructure, encrypted in transit and at rest. Every record carries your own pharmacy identifier and access is enforced on every single query, so one pharmacy can never read another's — that check is in the server, not in the interface. Passwords are stored only as PBKDF2-SHA256 hashes (100,000 iterations); we cannot read your password, and neither can anyone who obtains the database.
Whether your data leaves Bangladesh
Some of it does, and you should know which. Your records are served from Cloudflare's global network, so they may be processed on servers outside Bangladesh. Email is delivered from the United States, and the optional sign-in, help-video, assistant and messaging providers listed below operate globally. SMS and payment processing stay with providers in Bangladesh. Where data is processed abroad it remains covered by this policy and by our contract with that provider; if you need processing confined to Bangladesh, write to privacy@pharmacyos.work before you enable the optional features.
How long we keep it
When a period ends, the data is deleted — not archived indefinitely, except where a row below says so and gives the legal reason.
- Sales and invoice records — 6 years, then deleted. Bangladesh tax law requires the retention (NBR Mushak rules), so this survives account deletion.
- Audit trail — moved to cold storage after 90 days and kept as legal-compliance evidence, isolated from any live system. Audit rows are never edited or deleted.
- Business and customer records — kept while your account is open, and deleted with it. A customer may ask you, or ask us, to erase their record sooner (PDP Act §16); we act within 30 days.
- Account and authentication data — until you delete the account, then removed within 30 days.
- Crash diagnostics — 90 days, then deleted automatically.
- Usage counts — retained in aggregate; the per-day IP hash that counts unique visitors is not reversible and is not kept beyond the day it was computed.
Your rights, and how to use them
The PDP Act 2023 gives you these rights. Each one has a route you can actually take today — a right with no button behind it is not a right.
- Access (§14) — export everything as CSV and SQLite from Settings, or ask us and we will send it.
- Correction (§15) — edit any record in the app at any time; ask us if a record is not editable.
- Deletion (§16) — delete the account in the app, or email us. See the section below.
- Portability (§17) — the same export, in open formats you can load elsewhere.
- Objection (§18) — turn off any optional processing.
Withdrawing consent
Everything optional can be switched off where it was switched on: alerts and their channel in Settings → Notifications, Telegram by unlinking the chat, a payment method by disabling it, a linked Google or Apple sign-in by removing it and using a password instead, and a device by revoking it in Settings → Devices. Withdrawing consent stops that processing from then on; it does not undo what was lawfully done before, and it cannot shorten the tax-record period above. If a switch is missing or does not work, email privacy@pharmacyos.work and we will act on it within 30 days.
Deleting your account and your data
You can delete the account from inside the app — Settings → Data & privacy → Delete account — or by emailing privacy@pharmacyos.work from the owner address on the account. Deletion takes the account offline immediately and erases the data permanently after 30 days; inside that window you can still ask us to restore it. The only things that survive are the tax records and the audit trail described above, and the legal reason is stated there.
Full deletion instructions and what is erased
A staff member who wants only their own profile removed should ask the account owner, or email us — deleting the account removes the whole business.
How we protect it
- Encrypted in transit (TLS) and at rest.
- Passwords hashed with PBKDF2-SHA256 (100,000 iterations) and never logged.
- Optional two-factor authentication, and a manager PIN on sensitive counter actions.
- Role-based access, enforced on the server for every request.
- An append-only audit trail of every sign-in, export, override and settings change.
- Per-device sessions you can revoke yourself.
If something goes wrong
If we confirm a breach affecting your data we will notify you within 72 hours of becoming aware of it (PDP Act 2023 §22), tell the authority where the law requires it, and publish a summary at pharmacyos.work/security. The notice will say what happened, which categories of data were affected, roughly how many records, what the likely consequences are, and what we have done. If you think you have found a vulnerability, email security@pharmacyos.work.
Children
PharmacyOS is business software for pharmacies and their staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. An account holder must be an adult who can enter a contract. If you believe a child's data has reached us — including through a record entered by a pharmacy — email privacy@pharmacyos.work and we will delete it.
What this means on the App Store and Google Play
So that this policy and the store labels say the same thing:
- We do not track you across apps or websites, and we do not ask for App Tracking Transparency permission, because there is nothing to track you with.
- There is no advertising identifier, no ad SDK, and no advertising network in any of our apps.
- Data is collected only to run the service, keep it secure, meet a legal obligation, or fix a fault — the purposes declared in our Apple privacy labels and our Google Play Data safety form.
- Account deletion is available inside the app and on the web, as both stores require.
- Our Google Play Data safety declaration is kept consistent with this page; if you spot a difference, that is a bug — tell us and we will fix it.
Changes to this policy
If we change how we handle data we will update this page, move the "last updated" date, and — for any change that reduces your protections or adds a purpose — tell account owners by email at least 14 days before it takes effect, so you can export your data or close the account first. Superseded versions are available from privacy@pharmacyos.work on request.
Contact
Questions, requests, and complaints all go to the same place, and a real person answers.
- Data Protection Officer — privacy@pharmacyos.work
- Security — security@pharmacyos.work
- We reply within 30 days, and usually much sooner. If you are not satisfied with our answer you may complain to the supervisory authority established under the PDP Act 2023.