Privacy Policy
Last updated: 8 August 2026
MedStore ERP is pharmacy management software operated by Codemites. This policy explains what data the software handles, where it is stored, who it is shared with, and the choices you have. It applies to the MedStore ERP web application and any pharmacy that subscribes to it.
1. Who we are
MedStore ERP (“the Service”, “we”, “us”) is operated by Codemites, Jammu & Kashmir, India. We provide the software; each subscribing pharmacy operates its own store account.
For data protection purposes, the subscribing pharmacy is the data fiduciary (controller) for the customer, prescription, and business records it enters. We act as a data processor, handling that data only to run the Service on the pharmacy’s behalf. We do not sell any data, and we do not use pharmacy or patient records to train machine-learning models.
2. Data we process
Depending on how a pharmacy uses the Service, the following categories are processed:
- Account data — staff names, email addresses, hashed passwords, assigned roles (Owner, Manager, Pharmacist, Cashier, Accountant), and a device identifier used to recognise the devices signed in to your account.
- Pharmacy business records — medicines, batches, expiry dates, stock movements, purchase orders, suppliers, invoices, expenses, and accounting entries.
- Pharmacy customer data — names, mobile numbers, addresses, dates of birth, credit limits, and ledger history entered by pharmacy staff about their own customers.
- Health-related data — prescription images and medical notes, where the pharmacy chooses to record them. We treat this as sensitive personal data and it receives the protections described in section 5.
- Technical data — IP address, browser type, and error diagnostics captured when something goes wrong.
3. Google Drive backups and Google user data
MedStore ERP offers an optional backup feature that saves a copy of your store data to your own Google Drive. It is off until you explicitly connect a Google account, and it can be disconnected at any time. This section describes exactly what that feature does.
- Scope requested. We request only
https://www.googleapis.com/auth/drive.file. This is a per-file scope: it grants access solely to files the application itself creates. MedStore ERP cannot see, read, list, or modify any other file in your Drive. - What we write. A single JSON export of your store data per day, named
YYYY-MM-DD.json, placed in a folder namedMedStorein your Drive. - What we read. Only the existence and metadata of the backup files we created, so the app can tell you whether today’s backup already exists.
- Where the token lives. The Google access token is held in your browser’s local storage on your own device and expires automatically (typically within one hour). It is never transmitted to, or stored on, our servers.
- No server involvement. Backups upload directly from your browser to Google’s API. The backup contents do not pass through MedStore ERP servers.
Revoking access. Use the Disconnect button on the Backup page in the app, or visit myaccount.google.com/permissions and remove MedStore ERP. Revoking access does not delete backup files already in your Drive — those are yours, and you can delete them from Drive directly.
4. Where your data is stored
Your pharmacy records are held on our servers and retrieved by the application as you work.
- On our servers — a PostgreSQL database hosted with Supabase, with each store’s data isolated by a store identifier enforced at the database level.
- Prescription images — Cloudflare R2 object storage.
- On your device — only your sign-in session and a small set of settings and conveniences, held in your browser’s local storage. These are itemised in our Cookie Policy.
- In your Google Drive — only if you enable the optional backup feature described above.
Our servers and storage are operated by providers that may process data outside India. Where that happens, we rely on the providers’ contractual safeguards.
5. Security
- Passwords are stored hashed, never in plain text.
- Access is controlled by role, enforced on the server for every request rather than only hidden in the interface.
- Every store’s data is isolated by store identifier, checked on every database query.
- Medical notes are encrypted at rest.
- Changes to records are written to an immutable audit log recording who changed what and when.
- Traffic between your browser and our servers is encrypted with HTTPS.
No system is perfectly secure. Your sign-in session is held in your browser and is protected by your device’s own security — keep your device locked and sign out on shared computers.
6. Third-party services we use
We share data with these processors only to the extent needed to run the Service:
- Supabase — hosts the primary database.
- Vercel — hosts and serves the web application.
- Cloudflare R2 — stores prescription and receipt images.
- Google Drive API — optional backups, as described in section 3.
- Meta (WhatsApp Business API) — sends invoices, receipts, and payment reminders where a pharmacy enables it. Recipient mobile numbers and message contents pass through Meta.
- Firebase Cloud Messaging — delivers push notifications.
- Sentry — collects error diagnostics to help us fix faults.
We do not sell personal data, and we do not share it with advertisers or data brokers.
7. How long we keep data
Records are retained for as long as the pharmacy’s subscription is active, because pharmacy billing and stock records must remain available for statutory and tax purposes. Deletions inside the app are soft deletes: the record is marked deleted and hidden from view, but retained so that linked records and the audit trail stay intact.
After a subscription ends, store data is retained for 90 days so it can be exported or the account reinstated, then scheduled for permanent deletion. Audit logs and records we are legally required to keep may be retained longer.
8. Your rights
Under India’s Digital Personal Data Protection Act, 2023, and comparable laws, you may request access to your personal data, correction of inaccurate data, erasure, and a summary of processing. You may also withdraw consent for optional features such as Google Drive backups or WhatsApp messaging at any time.
Pharmacy staff should contact their store Owner in the first instance, since the Owner administers the account. To reach us directly, email contact@codemites.com.
9. Children
The Service is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. A pharmacy may record a customer’s details, including a minor’s, as part of its own dispensing records; responsibility for the lawful basis of those records rests with the pharmacy.
10. Changes to this policy
We may update this policy as the Service changes. The “last updated” date at the top will change, and material changes will be announced in the application. Continuing to use the Service after an update means you accept the revised policy.
Contact us
Questions about this document, or a request concerning your data? Email contact@codemites.com. We aim to respond within 7 business days.
MedStore ERP is operated by Codemites, Jammu & Kashmir, India.
See also our Cookie Policy, Terms & Conditions, and Disclaimer.