Cookie Policy

Last updated: 8 August 2026

This policy explains how MedStore ERP stores information in your browser. The short version: we do not use cookies at all, and we do not track you.

1. We do not use cookies

MedStore ERP sets no cookies. There are no advertising cookies, no analytics cookies, and no third-party tracking pixels anywhere in the application. This is why you will not see a cookie consent banner — there is nothing to consent to.

Instead, the application uses two browser storage mechanisms that stay on your own device and are never attached to outgoing requests the way cookies are.

2. Local storage

Local storage holds small settings and your session, so the app remembers you and your preferences between visits. These are the keys we write:

KeyPurpose
access_tokenKeeps you signed in between page loads.
device_idIdentifies this device to your store account.
gdrive_tokenGoogle Drive access token for optional backups. Expires automatically.
gdrive_token_expiryWhen the Google Drive token stops being valid.
backup_auto_dailyWhether you switched on the automatic daily backup.
medstore_whatsapp_configYour WhatsApp Business API settings.
paused_bills_*Bills you put on hold at the counter, kept per store.
owner_phoneOwner number used for alert messages.
last_customer_phoneSpeeds up repeat billing for the same customer.

All of these are strictly necessary to operate the software. None are used for advertising, profiling, or measuring your behaviour.

3. Where pharmacy records are kept

Your medicines, invoices, customers, ledgers, and prescriptions are not stored in your browser. They are held on our servers and fetched as you use the application, as described in the Privacy Policy.

The exception is bills you deliberately put on hold at the counter, which are kept on the device under the paused_bills_* keys above until you resume or clear them.

Your sign-in session lives in this browser, so treat the device as sensitive. Use a screen lock, avoid shared or public computers, and sign out when you finish on a device that is not yours.

4. Service workers

MedStore ERP does not use a caching service worker. Earlier versions registered one, and the current application actively removes any it finds left over from those versions so that it cannot serve you outdated pages.

The one exception is a messaging service worker used by Firebase Cloud Messaging, which is registered only if you turn on push notifications. It delivers notifications and does not cache your data.

5. Third-party storage

A small number of features load code from other providers, which may use their own browser storage when you use them:

  • Google Identity Services — loaded only when you click to connect Google Drive backups, in order to sign you in to Google.
  • Firebase Cloud Messaging — stores a device token if you enable push notifications.
  • Sentry — may store a short-lived session identifier to group error reports.

None of these are used for advertising.

6. Clearing stored data

Signing out clears your session. To remove everything, clear site data for this domain in your browser’s settings, which deletes the local storage entries listed above.

Clearing site data does not touch your pharmacy records, which are held on our servers — you will simply be signed out. It does discard any bills left on hold on that device, so resume or complete them first.

7. Changes to this policy

If we ever introduce cookies, we will update this page and, where the law requires it, ask for your consent first.

Contact us

Questions about this document, or a request concerning your data? Email contact@codemites.com. We aim to respond within 7 business days.

MedStore ERP is operated by Codemites, Jammu & Kashmir, India.