Privacy Policy
Last updated: 3 August 2026
Pharmacy360 Services ("Pharmacy360", "we", "us") provides pharmacist-led digital pharmacy services. This policy explains what personal information we collect, why, who we share it with, and the choices you have.
A note on HIPAA
Many health services are "covered entities" under HIPAA. Pharmacy360 currently is not. HIPAA applies to health care providers who transmit health information electronically in connection with specific standard insurance transactions — claims, eligibility checks, coordination of benefits. Pharmacy360 does not bill insurance; our services are paid directly by you, by card.
We say this plainly because it changes which laws protect you. Instead of HIPAA, your information is protected by the Federal Trade Commission Act, the FTC Health Breach Notification Rule, and state consumer-health-privacy laws — including Washington's My Health My Data Act, Nevada SB 370, and Connecticut's consumer health data provisions.
We apply HIPAA-grade security controls regardless — see How we protect your information below. If we ever begin billing insurance, HIPAA will apply to us, and we will update this policy before that change takes effect.
Information we collect
Health information you give us
When you use the symptom checker, an OTC Consult, a Medication Check-Up, or a pharmacist consultation, we collect what you enter: symptoms and their severity and duration; medicines you take and allergies; pregnancy or breastfeeding status where relevant; age or age range, and sex at birth where clinically relevant; conditions you disclose, such as kidney or liver disease. Where an adult asks on a child's behalf, we collect the child's age and weight.
Account and contact information
Your name, email address, and a secure hash of your password — we never see the password itself. A phone number if you give one. For pharmacists applying to join: professional licence state, number and type, and optionally NPI and DEA numbers, which are encrypted.
Payment information
Payments are processed by Stripe. Card numbers are entered directly with Stripe and never reach Pharmacy360's systems. We keep a record that a payment happened, its amount, and Stripe's reference for it.
Technical information
Your IP address, in the ordinary course of serving and securing the site; where we retain it against a submitted form we store a one-way hash, not the address itself. Browser and device information your browser sends with each request. First-party cookies, listed below.
What we do not collect
We use no third-party analytics or advertising trackers. There is no Google Analytics, no advertising pixel, no session-replay tool, and no cross-site tracking on this site — every cookie we set is our own. We do not buy personal information about you from data brokers, and we do not collect precise geolocation.
How we use your information
To run symptom triage and emergency red-flag screening, to prepare a personalised over-the-counter recommendation, and to put that recommendation in front of a licensed pharmacist for review. A pharmacist sees your intake alongside the draft and decides whether to approve, amend, or withhold it — that human review is the service you are paying for. We also use your information to take payment and issue refunds, to keep the records a pharmacist is professionally expected to keep, and to keep the service safe and working.
We do not use your health information for marketing, and we do not sell it.
We do not sell your information
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We do not use your health information to target advertising, and we do not disclose it to advertisers or data brokers.
Some over-the-counter suggestions include affiliate links to retailers. If you follow one, the retailer knows you arrived from us — but we do not send your symptoms, medicines, or any other health information to them. We may earn a small commission at no extra cost to you; see how we earn money.
How we protect your information
- Encryption at rest. Health information is encrypted in our database using AES-256-GCM with a dedicated key.
- Encryption in transit. All traffic uses TLS.
- Redaction before AI processing. We use a large language model to help draft clinical narrative. Before any free text you write leaves our systems for that model, an automated step removes direct identifiers — names, phone numbers, addresses, email addresses, medical record numbers, NPI, DEA and prescription numbers. A pharmacist, not the model, owns the clinical decision.
- Health information is kept out of our logs, enforced by an automated test that fails our build if it regresses.
- Access control. Data is segregated by organisation at the database level, staff access is role-based, and sensitive administrative actions require a second factor.
- Multi-factor authentication is available on accounts.
No system is perfectly secure, and we do not claim otherwise.
Who we share information with
We share personal information only with service providers who help us run the service, and only as needed:
- Amazon Web Services — hosting, database, encrypted backups (United States)
- Stripe — card payments and refunds (United States)
- Anthropic — AI drafting of clinical narrative, using redacted text only (United States)
- Resend and Amazon SES — transactional email (United States)
- Cloudflare — content delivery and protection against attack (global)
We may also disclose information where the law requires it, to protect someone's safety in an emergency, or in connection with a sale or reorganisation of the business — in which case we would notify you.
Our pharmacists see your intake and the draft recommendation. That is the service. They are licensed professionals bound by professional confidentiality obligations.
Cookies
We use only first-party cookies, and no advertising or tracking cookies. They keep you signed in, remember your role and active organisation, track two-factor status within a session, link you to your own symptom-checker result, and anonymously measure how the service is used. Blocking cookies will prevent sign-in and prevent you from seeing your own symptom-checker result.
Your choices and rights
You can ask us to show you the personal information we hold about you, correct it, delete it, give you a copy, or stop processing your health information. Depending on where you live — including Washington, Nevada, Connecticut and California — you may have these rights by law, and the right not to be treated differently for exercising them.
How to ask: contact us through our contact form. We will confirm your request and respond within 45 days. We may need to verify your identity first, so that nobody else can obtain or delete your information.
Requests are handled by our team. We will tell you if we cannot delete something and why — for example records we are professionally or legally required to retain, or transaction records we must keep for tax and accounting.
How long we keep information
Clinical records — your intake, the recommendation, and the pharmacist review — are retained as professional record-keeping obligations require. Account information is kept for as long as you have an account. Payment records are kept as tax and accounting rules require, typically seven years. Security and request logs are kept for a short operational period.
Children
Pharmacy360 is intended for adults aged 18 and over, and we do not knowingly collect personal information directly from children. An adult may seek guidance on a child's behalf; when they do, we collect only what is clinically necessary about the child — age and weight — and the adult confirms they are the child's parent, legal guardian, or otherwise authorised. Some services are adult-only and will stop if a minor is indicated. If you believe a child has given us information directly, contact us and we will delete it.
Where your information is held
Pharmacy360 operates in the United States, and information is stored and processed there. We do not currently offer the service outside the United States.
If there is a data breach
If unencrypted personal health information is exposed, we will notify affected individuals and the Federal Trade Commission as the FTC Health Breach Notification Rule requires, and any state authority that must also be told.
Changes, and contacting us
We will post any change here and update the date at the top. If a change is significant we will say so prominently rather than change it quietly. Questions or requests: contact us.