Cookie Policy
Last updated: 8 August 2026
This policy explains how MedStore ERP stores information in your browser. The short version: we do not use cookies at all, and we do not track you.
1. We do not use cookies
Instead, the application uses two browser storage mechanisms that stay on your own device and are never attached to outgoing requests the way cookies are.
2. Local storage
Local storage holds small settings and your session, so the app remembers you and your preferences between visits. These are the keys we write:
| Key | Purpose |
|---|---|
access_token | Keeps you signed in between page loads. |
device_id | Identifies this device to your store account. |
gdrive_token | Google Drive access token for optional backups. Expires automatically. |
gdrive_token_expiry | When the Google Drive token stops being valid. |
backup_auto_daily | Whether you switched on the automatic daily backup. |
medstore_whatsapp_config | Your WhatsApp Business API settings. |
paused_bills_* | Bills you put on hold at the counter, kept per store. |
owner_phone | Owner number used for alert messages. |
last_customer_phone | Speeds up repeat billing for the same customer. |
All of these are strictly necessary to operate the software. None are used for advertising, profiling, or measuring your behaviour.
3. Where pharmacy records are kept
Your medicines, invoices, customers, ledgers, and prescriptions are not stored in your browser. They are held on our servers and fetched as you use the application, as described in the Privacy Policy.
The exception is bills you deliberately put on hold at the counter, which are kept on the device under the paused_bills_* keys above until you resume or clear them.
4. Service workers
MedStore ERP does not use a caching service worker. Earlier versions registered one, and the current application actively removes any it finds left over from those versions so that it cannot serve you outdated pages.
The one exception is a messaging service worker used by Firebase Cloud Messaging, which is registered only if you turn on push notifications. It delivers notifications and does not cache your data.
5. Third-party storage
A small number of features load code from other providers, which may use their own browser storage when you use them:
- Google Identity Services — loaded only when you click to connect Google Drive backups, in order to sign you in to Google.
- Firebase Cloud Messaging — stores a device token if you enable push notifications.
- Sentry — may store a short-lived session identifier to group error reports.
None of these are used for advertising.
6. Clearing stored data
Signing out clears your session. To remove everything, clear site data for this domain in your browser’s settings, which deletes the local storage entries listed above.
7. Changes to this policy
If we ever introduce cookies, we will update this page and, where the law requires it, ask for your consent first.
Contact us
Questions about this document, or a request concerning your data? Email contact@codemites.com. We aim to respond within 7 business days.
MedStore ERP is operated by Codemites, Jammu & Kashmir, India.