Legal & policies
Privacy Policy
What we collect, why we collect it, who can see it, how long we keep it, and how you get it back or get it deleted. Health data is held to a higher standard than the rest, and we do not sell any of it.
- We collect what dispensing and shipping require — not what might be useful later.
- Prescriptions are encrypted and visible only to pharmacy and support staff who need them.
- We never sell, rent or trade personal or health data, and run no ad trackers on prescription pages.
- You can ask for a copy of your data, or deletion of anything our licence does not oblige us to keep.
A summary for convenience. The numbered sections below are the operative terms.
Identity and contact details you give us: name, delivery address, billing address, email and phone number. Account credentials are stored as a salted hash — we cannot read your password and will never ask for it.
Health information you upload: prescriptions, the prescriber's details, allergies or excipient sensitivities you tell us about, and the order history that follows from them. This is the most sensitive category we hold and it is treated accordingly.
Transaction data: order contents, invoice, coupon applied, delivery destination, tracking reference and a masked card reference such as the last four digits. We never receive or store a full card number.
Technical data: IP address, device and browser type, and pages visited, used to keep the site secure and working. We do not build advertising profiles from it.
To dispense lawfully: a pharmacist must verify a prescription against an order before prescription-only medicine is supplied, and our drug licence requires records that let any parcel be traced back to a batch, a supplier and a dispensing decision.
To ship and support: to print a label, prepare an accurate customs declaration, tell you where the parcel is, and answer you when something goes wrong.
To meet legal obligations: tax invoicing, records required by the Drugs and Cosmetics Rules, and responses to a lawful order from an authority with jurisdiction.
For service messages you can switch off: refill reminders and order updates. Marketing email is opt-in and every message carries a one-click unsubscribe.
Inside Indogenmed, access is by role. Pharmacists and support staff see the prescriptions and orders they are working on. Warehouse staff see picking data and addresses, not clinical detail. Nobody has blanket access to the health records of all customers.
Outside, we share the minimum with processors who make delivery possible: the payment gateway (which handles card data directly and independently), carriers and customs brokers (name, address, phone, declaration), and the manufacturer or its regulator where a batch complaint has to be investigated.
We do not sell, rent, trade or barter personal or health data to advertisers, data brokers, affiliates or anyone else. There is no version of our business in which your prescription history is a product.
Dispensing and purchase records are retained for the period our drug licence and Indian tax law require, because a regulator must be able to reconstruct who supplied what to whom. We cannot delete those early, and we will tell you so plainly rather than pretend otherwise.
Everything else — marketing preferences, saved addresses, dormant account data, uploaded files no longer tied to a required record — is deleted on request or on a schedule, whichever comes first.
Write to care@indogenmed.org from the address on your account and ask for access, correction, an export, or deletion. We confirm identity first, because handing a stranger your prescription history would be the worse failure.
We respond within 30 days, usually much sooner. If we refuse part of a deletion request we name the specific legal obligation that requires us to keep it. If you are unhappy with the outcome, our grievance officer is reachable at the same address and replies within 3 working days.
Data in transit is encrypted with TLS; prescriptions and identity documents are encrypted at rest; administrative access requires individual accounts with multi-factor authentication and is logged.
No system is perfect. If a breach affects your data we will tell you what happened, what was exposed and what to do about it — without waiting for a news cycle to force it.
Changes to this document. When we change a policy we raise the version number, update the date at the top, and keep the previous version available on request. Material changes affecting an order already placed do not apply retroactively to that order — the version in force on the day you paid is the version that governs it.
