Legal
Privacy Policy
Last updated: September 24, 2026
1. Who we are
PharmFlow (“PharmFlow”, “we”, “us”) operates the pharmacy management platform at pharmflow.io. You can reach us about this policy at hello@pharmflow.io.
In short: pharmacies use PharmFlow to manage prescriptions, pickup queues, and patient notifications. For patient personal information entered into the Service, the pharmacy is the custodian (under British Columbia’s PHIPA) or the organization with control (under PIPA), and PharmFlow acts as its service provider. For account and billing data about our customers, PharmFlow is the controller.
2. Information we collect
- Account information: staff names, email addresses, credentials, roles, and pharmacy details.
- Pharmacy Data entered by customers: patient names, dates of birth, phone numbers, provincial health numbers, prescription and queue records, and notes — stored encrypted where indicated.
- SMS consent records: whether a patient consented to SMS notifications, and when.
- Usage and log data: pages viewed, actions taken, IP address, browser and device information, and audit events required for compliance.
- Payment data: billing contact and plan details. Payment card details are handled by our payment processor, not stored by us.
3. How we use information
- Operate the Service: prescriptions, queues, inventory, notifications, and reporting for your tenant.
- Send SMS notifications a pharmacy has requested to consented recipients, through our messaging provider.
- Secure the Service: authentication, audit logging, abuse prevention, and debugging.
- Communicate with customers about their account, product changes, and support requests.
- Meet legal and regulatory obligations that apply to us.
We do not use patient records to market to patients, and we do not use Pharmacy Data to train AI models.
4. Service providers (processors)
We share information with vendors who help us run the Service, only as needed and under contract:
- Cloud hosting and storage: Cloudflare (compute, database, object storage).
- Messaging: Twilio, to deliver SMS notifications and to receive inbound SMS replies.
- Transactional email delivery for account and notification email.
- Payment processing for subscriptions.
Each provider processes data under its own terms. We choose providers that commit to protecting personal information.
5. SMS consent and mobile information
When a patient consents to SMS notifications, we record that consent and use it only to send the pharmacy’s messages and to honour opt-outs. Recipients can reply STOP to opt out at any time and HELP for help. Message and data rates may apply.
Mobile information and SMS consent records are never shared with or sold to third parties or affiliates for marketing purposes.
6. No sale of personal information
We do not sell personal information, and we do not share it with third parties for their own marketing.
7. International transfers
Our providers may process data outside Canada, including in the United States. When they do, your information is subject to the laws of those jurisdictions. We use contractual and technical measures to protect it.
8. Retention
We keep account and Pharmacy Data for as long as the account is active and as required for legal, audit, and compliance purposes. Verification codes and short-lived tokens expire automatically. When a pharmacy closes its account, we delete or de-identify its data within a reasonable period unless law requires retention.
9. Security
We use encryption in transit and at rest for sensitive fields, tenant isolation, access controls, and audit logs. No system is perfectly secure; we work to prevent incidents and will notify affected parties and regulators when the law requires it.
10. Your rights
Depending on your jurisdiction, you may have rights over your personal information, including to access it, correct it, delete it, restrict or object to processing, withdraw consent, and receive a portable copy.
- British Columbia (PIPA/PHIPA): patients should direct requests about their pharmacy records to the pharmacy, which is the custodian. We assist pharmacies in fulfilling those requests.
- European Economic Area and UK (GDPR): the rights listed above apply, plus the right to complain to your supervisory authority.
- California (CCPA/CPRA): the right to know, delete, correct, and to not be discriminated against for exercising rights. We do not sell or share personal information for cross-context behavioural advertising.
To exercise a right, email hello@pharmflow.io. For patient records, contact the pharmacy first — we will help them respond.
11. Children
Staff accounts are for adults. Patient records of minors are entered and managed by pharmacies under their own obligations; PharmFlow does not knowingly collect data directly from children.
12. Cookies
We use cookies and similar storage for sessions, security, and preferences. See your browser settings to control them; disabling them may break sign-in.
13. Changes to this policy
We may update this policy from time to time. For a material change we will post the new policy here and update the “Last updated” date. Continued use after the change takes effect is acceptance of the updated policy.
14. Contact
Privacy questions and requests: hello@pharmflow.io. See also our Terms of Service.