PharmacyIQHome

Legal

Privacy Policy

Last updated:

This policy explains what information PharmacyIQ collects, why, who receives it, how long we keep it and how to exercise your rights. It covers the PharmacyIQ platform at app.pharmacyiq.co and our website at pharmacyiq.co.

Questions or requests: privacy@pharmacyiq.co.

1. Who we are

PharmacyIQ is a software platform that licensed clinics use to order compounded (503A) and outsourcing facility (503B) medications for their patients through our pharmacy network, and to manage their patients, prescriptions, orders and billing. PharmacyIQ is not a pharmacy and does not compound, dispense or take title to any medication.

PharmacyIQ is operated by [LEGAL ENTITY NAME]. Contact: privacy@pharmacyiq.co. Mailing address: [PharmacyIQ mailing address].

2. What we collect

Clinic users (owners, prescribers and staff).

  • Name, work email, phone number, role and the clinic you belong to.
  • Clinic details: practice and legal name, address, phone, email, website, practice type and expected order volume, and the documents you upload during onboarding.
  • For prescribers: NPI (checked against the public CMS NPI Registry), credential, state licence numbers and expiry dates, and DEA registration where applicable. DEA numbers are encrypted.
  • Sign-in data: your password (handled by our authentication provider; we never see it in plain text), two-step sign-in enrolment, and sign-in history.
  • Security and audit data: IP address, browser and device (user agent), and a timestamped record of what was viewed or changed. On screens that show patient information we also record attempts to copy, print or screenshot that information.
  • Documents you upload, such as licence and DEA certificate copies during onboarding, and a prescriber’s saved “signature on file” image if they choose to keep one.
  • Agreements and consents: each acceptance of the terms (version, time, IP address and user agent), your signed platform agreement and drawn signature, fee authorisations and ACH debit mandates.

Patient information entered by clinics. This is protected health information (PHI) that the clinic controls:

  • Name, date of birth (encrypted), sex, state, phone, email and home shipping address.
  • Prescriptions and orders: medications, dosing and directions, the prescriber, indications, clinical documentation a prescriber records for an order, and order and shipment history.
  • Where the clinic uses these features: allergies (encrypted), patient notes, chart notes, intake form answers and appointments.
  • Patient notification preferences, including whether the patient agreed to receive text messages.

Payment information. Cards and bank accounts are entered into Stripe’s secure form and stored by Stripe. We keep only Stripe’s reference, the card brand or bank name, the last four digits, and when an ACH mandate was accepted. We never store full card or bank account numbers. Patients never pay PharmacyIQ directly; charges go to the clinic.

Website visitors. Our marketing website at pharmacyiq.co has no forms, accounts or trackers. Like any website, its host receives your IP address and browser details, and the site loads its typefaces from Google Fonts (see section 5).

Messages. A log of the emails and text messages the platform sends (recipient, type, status and time), and replies such as STOP, START or HELP to our text messages.

3. Why we use it

  • To provide the platform: accounts, patient records, ordering, prescribing and order tracking.
  • To fulfil orders through our pharmacy network, including routing each prescription to a pharmacy licensed for the patient’s state.
  • To bill the clinic and process payments.
  • To keep the platform secure and prevent fraud: sign-in checks, two-step sign-in, rate limits and lockouts, audit logs, and Cloudflare Turnstile bot checks on sign-in and public forms.
  • To meet legal duties, such as verifying prescriber credentials and keeping medical and prescription records for the required period.
  • To send service messages: account, security, order and billing emails, and the order updates a clinic turns on for its patients.

We do not sell personal information, and we never use patient information for advertising or marketing.

4. Patient information and HIPAA

For patient information, the clinic is the HIPAA covered entity and PharmacyIQ acts as a business associate of the clinic under a Business Associate Agreement (BAA). We use and disclose patient information only to provide the service to the clinic, as the BAA and the law allow. Each clinic can see the status of its BAA with PharmacyIQ, and the service providers that handle its patients’ information, in the platform under Compliance.

The licensed pharmacy that fills a prescription is its own HIPAA covered entity for that fill and handles the patient’s information under its own legal duties.

The clinic’s own Notice of Privacy Practices governs patients’ rights. Patients should send requests to see, correct or receive a copy of their records to their clinic; we help the clinic respond.

5. Who we share it with

We share information only with the service providers below, only what each needs, and only to run the platform. A provider that handles patient information may use it only to provide its service to us. Our policy is to require a business associate agreement from each provider that stores or processes patient information on our behalf.

Supabase

Database, authentication and file storage

Receives: Account and clinic records, patient and prescription records, uploaded documents and signatures, sign-in and two-step sign-in data

Vercel

Hosting and delivery of the application

Receives: Everything that passes between your browser and the platform, including IP address, browser details and request logs

Stripe

Payment processing (cards and ACH bank debits)

Receives: Card or bank details you enter into Stripe's secure form, the clinic's billing name and email, and each charge's amount with its order or statement number. No patient information

Resend

Transactional and notification email

Receives: Recipient email address and the message. Patient notification emails never include a medication, dose, diagnosis or the patient's name

Twilio

Patient text-message (SMS) notifications, only for patients who opted in

Receives: The patient's mobile number and the message: clinic name, order reference, status and tracking link

Cloudflare Turnstile

Bot protection on sign-in, signup, password reset and other public forms

Receives: IP address and browser and device signals used to tell people from bots

Our pharmacy network

Licensed pharmacy network (prescription fulfilment and shipping)

Receives: The patient, prescription, prescriber and shipping details needed to dispense and ship each order, and the clinic details needed to fill and bill it

Google Fonts

Typefaces for our marketing website (pharmacyiq.co) only

Receives: The IP address and browser details of website visitors. The platform at app.pharmacyiq.co serves its own fonts and sends nothing to Google

We may also disclose information when the law requires it (for example a valid subpoena or a regulator’s request), to protect people’s safety, or as part of a merger or sale of the business, in which case this policy and the BAA continue to apply.

6. Cookies and trackers

The platform uses only cookies it needs to work: your sign-in session, the two-step sign-in step, your in-progress order, and, when you arrive through a representative’s signup link, which representative referred your clinic (kept for 60 days). When PharmacyIQ support is viewing or assisting an account, a short-lived support cookie marks that session. Your browser also stores a few display preferences (side navigation, catalog view, whether you have seen the welcome message), never patient information. Stripe’s payment form, on billing pages, and the Cloudflare Turnstile check, on sign-in and public forms, may set their own cookies to prevent fraud and abuse.

We use no advertising or analytics trackers: no ad pixels, no third-party analytics and no session recording. Because there are no non-essential cookies, there is no cookie banner to accept. The full list, with how long each lasts, is in our Cookie Policy.

7. How long we keep it

  • Account and clinic data: while the account is active.
  • When a clinic is closed: non-clinical data (team logins and profiles, settings and preferences, onboarding drafts and most onboarding uploads) is scheduled for deletion 30 days after closure.
  • Signed agreements, fee authorisations, records of when each person accepted our terms, invoices and payment records: kept for as long as contract, tax and accounting law requires, including after an account is closed.
  • Medical and prescription records: at least 7 years from the last entry, or longer where state law requires (some states require 10 years, and records of minors are kept until adulthood plus the state’s period).
  • Audit and security logs: append-only (they cannot be edited or deleted) and kept for at least 6 years.
  • Backups: roll off on our hosting and database providers’ backup schedules.

8. How we protect it

  • Encryption in transit (HTTPS only, with HSTS) and at rest.
  • Field-level encryption (AES-256-GCM) of the most sensitive fields, such as patient date of birth and allergies and prescriber DEA numbers.
  • Two-step sign-in required for platform administrators and prescribers.
  • Role-based access: a clinic sees only its own patients and orders.
  • Audit logging of access to patient records, including views.
  • Cloudflare Turnstile bot checks on sign-in and public forms, rate limits, and lockout by account and by IP address after repeated failed sign-ins, with lock times that increase on each repeat.
  • New passwords are checked against a list of common passwords and, anonymously, against the Have I Been Pwned breached-password service: only the first 5 characters of a one-way hash leave our servers, never the password itself.
  • Automatic sign-out after a period of inactivity.
  • Patient information is shared with a patient only through the platform’s “Share with patient” feature, which produces a marked, attributed document and is logged.

If a breach affects patient information, we notify the clinic as the BAA and the law require, so the clinic can notify affected patients.

9. Your rights and requests

Depending on where you live, you can ask to access, correct, delete or export your personal information.

  • Clinic users can delete their own account in Settings → Security (“Delete my account”), and a clinic owner can close the clinic’s account there (“Close clinic account”).
  • Anything else: email privacy@pharmacyiq.co. We may need to verify your identity, and we respond within 30 days.
  • Patients: contact your clinic, which controls your records. We help the clinic answer your request.

Where the law requires us to keep a record (for example medical and prescription records, or invoices), we keep it for the required period, restrict it and tell you what was kept and why. We will not treat you differently for exercising a privacy right.

10. Deleting your account or closing a clinic

Both are in Settings → Security and take effect online, straight away, after you confirm with your password (and your authenticator code, if you use one). You do not need to email or call us.

Delete my account immediately removes your login so it can never sign in again, signs you out on every device, removes your two-step sign-in and recovery codes, replaces the name and email on your profile, clears your personal preferences and any team invitations that named you, and deletes a saved “signature on file” image. Elsewhere in the platform you are shown as “Former team member”. We do not keep marketing lists, so there is no marketing data to remove.

What we keep, and why: the medical and prescription records your clinic must retain by law (patient charts, orders, prescriptions and the signatures on them) for at least 7 years, or longer where a state requires it. A prescriber’s name and NPI stay on the prescriptions they signed, because the law requires them there. We also keep the audit trail, which cannot be edited (entries made before the deletion still show the name as it was at the time), and the record of when you accepted our terms. If you are a clinic’s only owner, make another team member an owner first, or close the clinic instead.

Close clinic account immediately turns off auto-pay, ends every autoship schedule, cancels draft orders (orders already submitted continue and remain billable), revokes open team invitations, suspends access for all of the clinic’s users and signs them out, and emails the owner a confirmation with the dates below. Non-clinical data is scheduled for deletion 30 days later. Medical and prescription records, signed agreements, fee authorisations, invoices and the audit trail are kept for the periods in section 7. Outstanding invoices remain due.

11. Email and text messages

The platform does not send marketing or newsletter email, and patient information is never used for marketing. The platform sends two kinds of email:

  • Service email to clinic users: invitations, password resets, two-step sign-in codes, onboarding reminders, and failed-charge notices to the clinic’s billing inbox.
  • Patient notification emails, sent on the clinic’s behalf: order confirmed, shipped and delivered, refill reminders and refill created. They come from a shared PharmacyIQ address with the clinic’s name as the sender name, and replies go to the clinic’s inbox.

Every email carries our mailing address in the footer.

If PharmacyIQ emails a clinic about our own services, that email identifies PharmacyIQ as the sender, carries our mailing address and a one-click unsubscribe link, and we honour an unsubscribe within 10 business days. Unsubscribing from marketing never stops the service emails your account needs.

Patient notification emails carry a visible Unsubscribe link and one-click List-Unsubscribe headers. The link needs no login and contains no personal information, only an opaque signed identifier. Unsubscribing takes effect immediately and stops that clinic’s notification emails to that patient. Opt-outs are stored centrally so every server honours them, and the clinic can see when a notification was skipped because the patient unsubscribed.

Text messages are separate. They are sent through Twilio, only to patients who agreed to receive them, and every text says how to opt out: reply STOP to stop texts, START to resume them, or HELP for help.

12. Children

The platform is for clinics and their staff, who must be 18 or older. We do not knowingly collect information directly from children under 13. Records of patients who are minors are entered by their clinic and handled under HIPAA like any other patient record.

13. Changes and contact

We will update this policy when our practices change and show the new date at the top. If a change is material, we will tell clinic users in the platform or by email before it takes effect.

Contact: privacy@pharmacyiq.co, or write to PharmacyIQ at [PharmacyIQ mailing address]. See also our Terms of Service, Cookie Policy, Refund and Cancellation Policy and the full Platform Agreement.