Privacy Policy
1. Who we are
MedSpora ("we", "us") operates a business-to-business platform that connects retail pharmacies ("retailers") with medicine distributors and wholesalers ("distributors"). The platform is for licensed businesses and their staff only. It is not a consumer pharmacy, and we don't process patient health records.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, email address, phone number, password (stored only as a one-way hash), role | You or your employer |
| Business | Legal and trade name, address, PAN/VAT details, drug licence number and expiry, contact person, bank or settlement details (distributors) | You, during registration |
| Verification documents | Licence and registration certificates you upload (PDF, JPG, PNG) | You |
| Commercial | Catalogue listings, prices, schemes, carts, orders, invoices, payments, credit and ledger entries, returns, disputes and messages | Your use of the platform |
| Inventory | Stock levels, batches and expiry dates (distributors); shop stock and minimum/maximum levels (retailers) | You |
| Field sales | Visit plans, check-ins and requirement notes entered by sales representatives | Sales reps |
| Security and audit | Signed-in devices (device name, IP address, browser/app user agent), sign-in times, and a log of sensitive actions with before/after values | Automatically |
| One-time codes | Email verification and password-reset codes, stored only as a keyed hash, short-lived and attempt-limited | Automatically |
Camera. The app asks for camera access only to scan product barcodes. It reads the code on your device, and no images are uploaded. Document photos are uploaded only when you choose to attach them.
We do not collect your precise location, contacts, patient or prescription data, or advertising identifiers.
3. How we use it
- To create and secure accounts, verify businesses, and keep users signed in.
- To run the marketplace: search, price and scheme calculation, order splitting, fulfilment, invoicing, settlement and platform commission.
- To keep accurate financial and regulatory records, including an unchangeable record of what was agreed for each order.
- To prevent fraud and abuse (for example, rate-limiting sign-in attempts) and to investigate disputes.
- To send service messages such as one-time codes, order updates and licence-expiry reminders. We do not send marketing without your consent.
- To produce analytics for you (your own purchases or sales) and aggregate platform metrics. Analytics never expose one business's confidential data to another.
Where the law requires a legal basis, we rely on performing our contract with your business, meeting legal obligations (such as tax and invoice records), and our legitimate interest in running a secure marketplace.
4. Who can see your data
- Your trading partners. When a retailer orders from a distributor, each side sees what it needs to fulfil and pay for that order (business name, address, contact, order lines, invoices and balances with each other).
- Not other businesses. A distributor never sees another distributor's retailer prices, inventory, orders, finances or private schemes. A retailer never sees another retailer's data. We enforce this on our servers, not only in the app.
- MedSpora staff, limited by role (platform, operations or finance admin). Access to sensitive documents is logged. Licence numbers are masked in general views.
- Authorities, where the law or a valid legal request requires it.
We don't sell personal data, and we don't share it for advertising.
5. Service providers
We use a small number of providers who process data on our instructions:
- Email delivery (Resend) for one-time codes and service emails. They receive the recipient's address and the message content.
- Hosting for our servers, database and encrypted document storage.
- Payment providers, if you pay online once that option is enabled. They process card or wallet details directly, and MedSpora never stores full payment credentials.
6. Security
- All traffic is encrypted with HTTPS.
- Passwords are stored as one-way hashes, and one-time codes as keyed hashes. Neither is ever stored in plain text.
- Uploaded business documents are encrypted at rest (AES-GCM).
- Sign-in attempts are rate-limited. You can see your signed-in devices and sign out of all of them, and a password reset signs out every other device.
- Access is role-based and checked per record. Sensitive actions are written to an audit log that ordinary users can't change.
No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authorities as the law requires.
7. Retention
- Financial and order records (orders, invoices, payments, settlements, ledger entries) are never physically deleted. They are kept for as long as tax, commercial and pharmaceutical record-keeping laws require.
- Audit logs are kept to support investigations and compliance.
- Accounts can be deactivated. The personal details on them are kept only as long as needed for the records above or for legal claims.
- One-time codes expire within minutes and are useless after that.
8. Your rights
Subject to applicable law (in Nepal, including the Individual Privacy Act, 2075 (2018)), you can ask us to:
- give you access to, or a copy of, your personal data;
- correct inaccurate data (most profile and business details can also be edited in the app);
- delete or restrict data we no longer need, except records we must keep by law;
- deactivate your account.
To delete your account, follow the steps on Delete your account.
Email privacy@medspora.com from your registered address. We may need to verify your identity, and we will reply within the time the law requires.
9. Cookies and tracking
This website sets no cookies and uses no analytics or third-party trackers. The staff portal keeps your sign-in token in browser session storage, which is cleared when you close the tab. The mobile app keeps tokens in your device's secure storage.
10. Children
MedSpora is for businesses and their adult staff. We don't knowingly collect data from children.
11. Changes
We will post any update here with a new version and date. If a change is material, we will notify account holders in the app or by email before it takes effect.
12. Contact
Privacy questions or requests: privacy@medspora.com. General support: support@medspora.com.