PharmFlow

Legal

Privacy Policy

Last updated: September 24, 2026

1. Who we are

PharmFlow (“PharmFlow”, “we”, “us”) operates the pharmacy management platform at pharmflow.io. You can reach us about this policy at hello@pharmflow.io.

In short: pharmacies use PharmFlow to manage prescriptions, pickup queues, and patient notifications. For patient personal information entered into the Service, the pharmacy is the custodian (under British Columbia’s PHIPA) or the organization with control (under PIPA), and PharmFlow acts as its service provider. For account and billing data about our customers, PharmFlow is the controller.

2. Information we collect

  • Account information: staff names, email addresses, credentials, roles, and pharmacy details.
  • Pharmacy Data entered by customers: patient names, dates of birth, phone numbers, provincial health numbers, prescription and queue records, and notes — stored encrypted where indicated.
  • SMS consent records: whether a patient consented to SMS notifications, and when.
  • Usage and log data: pages viewed, actions taken, IP address, browser and device information, and audit events required for compliance.
  • Payment data: billing contact and plan details. Payment card details are handled by our payment processor, not stored by us.

3. How we use information

  • Operate the Service: prescriptions, queues, inventory, notifications, and reporting for your tenant.
  • Send SMS notifications a pharmacy has requested to consented recipients, through our messaging provider.
  • Secure the Service: authentication, audit logging, abuse prevention, and debugging.
  • Communicate with customers about their account, product changes, and support requests.
  • Meet legal and regulatory obligations that apply to us.

We do not use patient records to market to patients, and we do not use Pharmacy Data to train AI models.

4. Service providers (processors)

We share information with vendors who help us run the Service, only as needed and under contract:

  • Cloud hosting and storage: Cloudflare (compute, database, object storage).
  • Messaging: Twilio, to deliver SMS notifications and to receive inbound SMS replies.
  • Transactional email delivery for account and notification email.
  • Payment processing for subscriptions.

Each provider processes data under its own terms. We choose providers that commit to protecting personal information.

5. SMS consent and mobile information

When a patient consents to SMS notifications, we record that consent and use it only to send the pharmacy’s messages and to honour opt-outs. Recipients can reply STOP to opt out at any time and HELP for help. Message and data rates may apply.

Mobile information and SMS consent records are never shared with or sold to third parties or affiliates for marketing purposes.

6. No sale of personal information

We do not sell personal information, and we do not share it with third parties for their own marketing.

7. International transfers

Our providers may process data outside Canada, including in the United States. When they do, your information is subject to the laws of those jurisdictions. We use contractual and technical measures to protect it.

8. Retention

We keep account and Pharmacy Data for as long as the account is active and as required for legal, audit, and compliance purposes. Verification codes and short-lived tokens expire automatically. When a pharmacy closes its account, we delete or de-identify its data within a reasonable period unless law requires retention.

9. Security

We use encryption in transit and at rest for sensitive fields, tenant isolation, access controls, and audit logs. No system is perfectly secure; we work to prevent incidents and will notify affected parties and regulators when the law requires it.

10. Your rights

Depending on your jurisdiction, you may have rights over your personal information, including to access it, correct it, delete it, restrict or object to processing, withdraw consent, and receive a portable copy.

  • British Columbia (PIPA/PHIPA): patients should direct requests about their pharmacy records to the pharmacy, which is the custodian. We assist pharmacies in fulfilling those requests.
  • European Economic Area and UK (GDPR): the rights listed above apply, plus the right to complain to your supervisory authority.
  • California (CCPA/CPRA): the right to know, delete, correct, and to not be discriminated against for exercising rights. We do not sell or share personal information for cross-context behavioural advertising.

To exercise a right, email hello@pharmflow.io. For patient records, contact the pharmacy first — we will help them respond.

11. Children

Staff accounts are for adults. Patient records of minors are entered and managed by pharmacies under their own obligations; PharmFlow does not knowingly collect data directly from children.

12. Cookies

We use cookies and similar storage for sessions, security, and preferences. See your browser settings to control them; disabling them may break sign-in.

13. Changes to this policy

We may update this policy from time to time. For a material change we will post the new policy here and update the “Last updated” date. Continued use after the change takes effect is acceptance of the updated policy.

14. Contact

Privacy questions and requests: hello@pharmflow.io. See also our Terms of Service.