Privacy Policy — Clear & Protected
We collect only what is necessary to fulfill orders, verify prescriptions, and provide licensed pharmaceutical services. We never sell your data, and we safeguard your health records with enterprise-grade encryption.
Last Updated: 15 December 2024
DPO: privacy@pharmogram.in
100% HEALTHCARE COMPLIANT
Security Architecture
Zero-trust infrastructure & patient privacy
256-bit AES Encryption
End-to-end security for prescriptions & orders
DPDP Act 2023 Aligned
Built in compliance with Indian digital privacy laws
Zero Data Monetization
We never sell your medical or personal information
Granular Access Control
Full user authority to export or delete your profile
Simple, transparent privacy principles
Core commitments we adhere to across our web portal and mobile application. For specific statutory disclosures, consult the comprehensive sections below.
We collect minimal data
Only what is needed to verify accounts, process prescription orders, and provide dedicated support.
Transparent data usage
We state explicitly why information is collected and how it enhances your medical logistics experience.
Strictly limited sharing
Data is shared exclusively with essential licensed partners such as payments and courier delivery handlers.
Security by architecture
Role-based access controls, continuous monitoring, and 256-bit encryption protect patient records.
Comprehensive user rights
You maintain authority to inspect, update, correct, and download your personal and clinical account records.
Right to erasure
Request complete account deletion at any time, subject only to statutory pharmacy retention laws.
What information may be collected
Collection is purpose-bound and context-specific. Clinical information like prescriptions is processed exclusively when you initiate an Rx order.
Digital prescription scans and doctor verification records
Prescribed medication names, dosages, and fulfillment orders
Optional clinical delivery notes and patient temperature requirements
Restricted access: Processed solely by licensed pharmacists to verify regulatory compliance and dispense scheduled medicines.
Delivery address, postal pincode, and recipient contact person
Real-time order dispatch, tracking milestones, and batch receipts
Courier handoff metadata (limited strictly to delivery execution)
Used exclusively to ensure accurate dispatch, temperature-controlled transit, and door-to-door delivery tracking.
Payment mode selected (UPI, Credit/Debit Card, Net Banking, COD)
Encrypted payment gateway reference and settlement transaction IDs
Tax invoices, credit notes, and reimbursement claim receipts
PCI-DSS Compliant: We never store complete debit or credit card details on Pharmogram servers.
In-app live chat conversations and inquiry ticket logs
Resolution metadata, response times, and quality assurance notes
User-uploaded screenshots or dispute documentation
Maintained to resolve logistics or medication queries promptly and uphold pharmaceutical service excellence.
Operating system version, device model, and unique installation ID
System crash diagnostics and performance monitoring metrics
Approximate location derived from IP / delivery pincode (no passive GPS tracking)
Deployed to identify fraudulent activity, secure sensitive endpoints, and guarantee application stability.
Why we collect data (purpose-bound)
We process personal data strictly to deliver pharmacy services, protect user safety, and satisfy healthcare regulations. We never monetize clinical data for third-party advertising.
Process orders
Verify medicine availability, validate digital prescriptions, and record authenticated batch invoices.
Key Uses: Order confirmation, prescription review by licensed pharmacists, invoice generation.
Deliver medicines safely
Coordinate with verified logistics handlers using delivery pincodes and address instructions.
Key Uses: Dispatch coordination, temperature-controlled transit tracking, OTP-based delivery receipt.
Dedicated care & support
Resolve fulfillment questions, address pharmacist clarifications, and process returns or refunds.
Key Uses: Live chat context, phone callbacks, prescription re-upload assistance.
Security & fraud mitigation
Continuously detect malicious login attempts, verify authentic payment tokens, and protect accounts.
Key Uses: Session anomaly alerts, device binding checks, regulatory fraud reporting.
App stability & telemetry
Aggregated analytics used to enhance navigation speed, eliminate app crashes, and streamline search.
Key Uses: Page load speed monitoring, search relevancy benchmarks, network fault detection.
Transactional notifications
Transmit critical transactional updates regarding medicine transit, delivery arrival, and regulatory policies.
Key Uses: Order dispatched alerts, out-for-delivery SMS, scheduled refill reminders.
Statutory compliance
Adhere to Drugs and Cosmetics Act, pharmacy dispensing logs, and DPDP Act 2023 mandate records.
Key Uses: Prescription audit trails, tax compliance documentation, statutory inspector records.
Data Minimization Principle
We do not request or store sensitive health identifiers unless strictly mandated to confirm pharmacy dispensing legitimacy.
When we share data (and when we don’t)
We operate on a zero-commercialization rule. Data is transferred strictly to contracted, NDA-bound partners solely to execute healthcare logistics.
Absolute Non-Monetization Pledge
Pharmogram does not sell, rent, lease, or monetize your personal health data to advertising exchanges, insurers, or data brokers.
| Recipient Category | Purpose & Legal Basis | Shared Data Parameters |
|---|---|---|
Licensed Payment Gateways | To process secure cashless payments, settle UPI transactions, and handle instant customer refunds. | Transaction reference, billing amount, and payment success status (no complete card numbers retained). |
Verified Logistics & Couriers | To dispatch temperature-controlled orders and physically deliver packages to your verified address. | Recipient name, delivery address, pincode, contact number, and package tracking ID. |
Customer Support Services | To resolve fulfillment tickets, provide pharmacist consultations, and coordinate replacements. | Ticket logs, prescription re-upload context, and optional user-provided screenshots. |
Cybersecurity & Anti-Fraud | To safeguard user accounts against credential stuffing, unauthorized takeovers, and fraudulent orders. | Anonymized device identifiers, suspicious IP flags, and security telemetry logs. |
Statutory Authorities & Law | To satisfy strict regulatory audits under the Drugs and Cosmetics Act and lawful court warrants. | Specific legally demanded records under authorized, documented statutory process only. |
All third-party data processing agreements enforce confidentiality covenants, strict retention limits, and data deletion upon service termination.
Enterprise security & patient protection
We implement defense-in-depth technical and operational safeguards to protect your personal and clinical records against unauthorized access.
TLS 1.3 & AES-256 Encryption
All data in transit is encrypted using modern TLS 1.3 ciphers, and sensitive databases utilize 256-bit AES encryption at rest.
Zero-Trust Access Architecture
Least-privilege permission models, mandatory multi-factor authentication (MFA), and strict role segregation for support personnel.
Continuous Security Audit Logs
Immutable audit trails monitor access to prescription databases with automated anomaly detection for suspicious queries.
Isolated Tiered Infrastructure
Cloud servers hosted in certified Indian data centers with air-gapped backups, disaster recovery, and DDoS mitigation.
Vulnerability Management
Regular static code analyses, third-party penetration tests, and prompt security patching cycles protect platform endpoints.
DPDP Act 2023 Compliance
Architected in direct alignment with India’s Digital Personal Data Protection Act rules and national healthcare security benchmarks.
Vulnerability Disclosure Policy
Responsible security researchers who identify potential vulnerabilities may report findings directly to security@pharmogram.in. We investigate all disclosures promptly.
Empowered choices & user authority
You hold statutory rights under India’s DPDP Act 2023. Exercise your rights anytime through in-app profile preferences or by reaching out to our compliance desk.
Right to Access & Review
You can inspect all historical profile data, verified addresses, and order invoices directly within your authenticated app dashboard.
Right to Rectification
Promptly correct inaccurate clinical delivery details, phone numbers, or business tax registrations via self-service profile settings.
Right to Data Portability
Request a machine-readable archive (JSON / PDF) of your personal account activity and tax-compliant pharmacy transaction receipts.
Right to Erasure & Forgotten
Initiate account deactivation and data purging, subject strictly to mandatory 5-year pharmaceutical dispensing audit record rules.
Submit a Data Subject Request
Email privacy@pharmogram.in with your registered account mobile number. We process requests within 7 business days following identity authentication.
How cookies and tokens are utilized
Cookies enable reliable sessions and protect account data. We never employ third-party cross-site trackers or sell browser fingerprints.
Essential Platform Cookies
Mandatory session tokens, CSRF security verifications, and cart persistence indispensable for web portal checkout.
Performance & Telemetry
Aggregated, cookieless metrics measuring load times and diagnostic benchmarks to detect broken links or server errors.
Security & Anti-Abuse
Detects automated scraping bots, identifies brute-force login attempts, and prevents unauthorized API manipulation.
Service Notifications
Retains dismissible banner preferences and essential regulatory compliance announcements for returning visitors.
Browser Cookie Preferences
You may configure cookie blocking via your browser settings. Note that disabling essential session cookies may prevent order checkout and account authentication.
Quick answers to privacy inquiries
Need dedicated compliance clarifications? Write to our Data Protection Officer at privacy@pharmogram.in.
Questions regarding your data? We’re here to help.
For compliance inquiries, data subject access requests, or to speak directly with our Data Protection Officer, reach out anytime. We typically respond within 24–48 business hours.