Privacy policy
This policy explains what information PharmaOS collects, why, and the choices you have. It is written to describe how the product actually works.
Effective 16 September 2026. Applies to PharmaOS, a ChefoTech product.
Who we are
PharmaOS is operated by ChefoTech (“we”, “us”). We are the data controller for information about website visitors and account holders. Pharmacies that use PharmaOS are the controllers of the data they enter about their own customers, suppliers and staff; we process that data on their instructions to provide the service.
Information we collect
Account information. When you create an organization we collect the organization name, your name, email address, an optional phone number and the GST state you choose. Passwords are stored only as salted hashes.
Data you enter. Products, stock, batches, sales, purchases, customers, suppliers, prescriptions, documents and settings that your organization records in the application. This may include personal data about your customers and staff, which you are responsible for collecting lawfully.
Usage and security information. Server logs with IP address, browser type, request identifiers and timestamps; login activity; and an audit log of actions taken inside your organization (who changed what and when). We use these to run the service securely and to show you your own audit trail.
Website enquiries. If you request a demo or contact us, we keep the name, email, phone, pharmacy name and message you send so we can respond.
Payments. Subscription payments are processed by Razorpay. We receive the payment status, order and payment identifiers and the amount; we do not receive or store card numbers.
Optional AI features. If your organization connects a Google Gemini API key, the questions you ask the assistant, the page context you share with it and any documents you upload for reading are sent to Google's Gemini API under your key and Google's terms. The key is encrypted at rest and never shown after saving. AI usage counts (tokens, feature, duration) are stored for your usage limits; the content of conversations is not stored by us beyond the request.
How we use information
- To provide, operate and support PharmaOS, including sending transactional emails such as invitations, invoices, statements and alerts that your organization configures.
- To secure the service: authentication, rate limiting, fraud and abuse prevention, and the audit trail.
- To respond to enquiries and provide demos.
- To bill subscriptions and comply with tax and accounting obligations.
- To improve the product using aggregate, non-identifying usage information.
We do not sell personal data and we do not use your organization's data for advertising.
Cookies and local storage
The application uses a secure, HTTP-only cookie to keep you signed in and browser storage for conveniences such as the bill you are typing at the counter. The public website sets no advertising cookies. If we enable a web analytics tool it is configured without personal identifiers where the tool allows it. See the cookie policy.
Service providers
We use infrastructure and service providers to run PharmaOS, which may include cloud hosting and a managed database, file storage for uploaded documents and images, transactional email, SMS and WhatsApp delivery when your organization enables them, push notification delivery, Razorpay for payments and Google for optional AI features. Each provider processes data only to provide its service to us.
Retention and deletion
Your organization's data is kept for as long as the account is active. Financial documents may need to be retained to meet legal obligations. You can export your whole organization as a JSON archive from Settings at any time. To delete an organization or an account, contact us and we will confirm the request with the organization owner before acting on it. Website enquiries are kept for as long as needed to respond and follow up.
Security
Data is transmitted over HTTPS. Every request is scoped to your organization on the server, permissions are enforced by the API, passwords are hashed, sessions can be reviewed and revoked, and sensitive secrets such as AI keys are encrypted at rest. No system is perfectly secure; if you believe your account has been compromised, change your password and contact us.
Your rights
Depending on where you live you may have rights to access, correct, export or delete personal data, or to object to certain processing. Account holders can update their own details in the application. For other requests, contact us; if your request concerns data a pharmacy entered about you, we may refer you to that pharmacy as the controller.
Children
PharmaOS is a business tool for pharmacies and is not directed at children. Pharmacies are responsible for the customer records they keep.
Changes
We will post any changes to this policy on this page and update the effective date. Material changes will be announced inside the application to organization owners.
Questions about this policy: use the contact form or email support@chefo.in.