PharmaOS
Legal

Privacy notice

How PharmaOS uses personal information: what we collect, why, who sees it, how long we keep it, and your rights.

Draft. This page is being reviewed by our legal and data-protection advisers and may change before PharmaOS launches. Details in [square brackets] are still to be confirmed. Last updated 29 September 2026.

The short version

  • When you book, the pharmacy is responsible for your information; we process it for them.
  • We collect what's needed to book and remind you: name, date of birth, contact details and appointments.
  • Your data is stored in London. Card details stay with Stripe.
  • We don't sell data, show adverts or use analytics cookies.
  • You can ask for a copy of your data or for it to be deleted.

1.Who we are

PharmaOS is run by SiteGrowth [SiteGrowth Ltd, company number and registered address to be confirmed]. PharmaOS gives UK community pharmacies online booking: a booking page, a diary and payments.

When you book with a pharmacy, that pharmacy is responsible for your information (the data controller). We process it on the pharmacy's behalf, under a data processing agreement, and only to run the service for them.

We are the data controller for your PharmaOS sign-in account, for pharmacy staff accounts, for pharmacies' claims and subscriptions, and for messages sent through our website.

2.What we collect

Patients booking with a pharmacy:

  • your name, date of birth, email address and phone number;
  • your appointments: the pharmacy and branch, the service, the date and time, the price and whether you have paid, attended or cancelled;
  • requests you make about your data, such as a request to delete it.

The service you book can reveal something about your health, which is special category data under UK GDPR, so it gets extra protection. PharmaOS is not a clinical record: your consultation notes and prescriptions stay in your pharmacy's own clinical systems.

Pharmacy staff: name, work email, role, the branches you work at, working hours, and for prescribers your GPhC registration number. For pharmacies that claim a listing: the GPhC premises number, the superintendent pharmacist's name and the claimant's contact details.

Everyone who signs in: your email address, the one-time codes we send you (kept for 10 minutes), and for staff an authenticator app secret. For security we record sign-ins and sensitive actions with the IP address and browser used.

Payments: card payments are made on Stripe. We never see or store card details; we keep the amount, status and Stripe's reference.

Our website's contact form: your name, email, optional pharmacy name and your message.

3.How we use it, and our legal reasons

  • To book and manage appointments for the pharmacy you choose, send confirmations and a reminder the day before, and take payment. The pharmacy relies on providing you with health care (UK GDPR Articles 6(1)(b) and 9(2)(h)) [to be confirmed with each pharmacy's own notice].
  • To run your account and keep it secure: sign-in codes, two-step sign-in for staff, rate limits and security logs (our legitimate interests in protecting the service, and our duty to keep data secure).
  • To provide PharmaOS to pharmacies: accounts, checking pharmacies against the GPhC register, subscriptions and invoices (contract; legal obligations such as keeping tax records).
  • To answer messages sent through our contact form (legitimate interests).

We don't sell personal data, show adverts, or use your information for marketing without asking. Booking emails leave out the name of the service, so a shared inbox doesn't reveal why you're visiting.

4.Who we share it with

The pharmacy you book with sees your details and appointments there. Other pharmacies can't: each pharmacy's data is kept apart by the database itself.

We use these service providers to run PharmaOS, each under a contract that only lets them use the data to provide their service:

  • Vercel: hosting, with our servers running in London;
  • Neon: our database, in London;
  • Resend: sending emails, from Ireland (EU);
  • Stripe: card payments, into the pharmacy's own Stripe account;
  • Google Workspace: our own email inbox, for contact form messages.

Some of these companies are based outside the UK. Where data leaves the UK, we rely on UK adequacy regulations or the UK International Data Transfer Agreement or Addendum [to be confirmed per provider]. We may also share information when the law requires it.

5.How long we keep it

  • Booking records are kept for as long as the pharmacy needs them for its records, then deleted or anonymised [retention period to be agreed with pharmacies].
  • Deletion requests: when a pharmacy approves one, your details are anonymised straight away.
  • Sign-in codes expire after 10 minutes; staff are signed out after 30 minutes of inactivity and after 12 hours at most.
  • Staff notifications are deleted after 90 days.
  • Security logs and the audit log are kept to protect the service and show who changed what [retention period to be confirmed].
  • Contact form messages are kept in our inbox while we help you [retention period to be confirmed].

6.Your rights

Under UK GDPR you can ask to:

  • get a copy of your information;
  • correct information that's wrong;
  • have your information deleted;
  • restrict or object to how it's used;
  • receive it in a format you can take elsewhere.

For your bookings, ask the pharmacy: it is responsible for them, and you can ask for your data to be deleted from your bookings page on its site. The pharmacy must answer within one month. For your PharmaOS account, or if you're not sure who to ask, email info@pharmaos.co.uk.

7.Cookies

We only use cookies that are needed to sign you in and keep your session secure. We don't use advertising or analytics cookies, so there's nothing to opt out of. When you pay by card, Stripe's payment page uses its own cookies under Stripe's privacy policy.

8.How we protect it

Data is stored in London and encrypted in transit and at rest. There are no passwords to leak, staff use two-step sign-in, and every change to patient and appointment data is written to a tamper-evident audit log. Read more about security.

9.Complaints

If you're unhappy with how your information has been used, please tell us first at info@pharmaos.co.uk. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

10.Changes to this notice

We'll update this notice when how we use information changes, and change the date at the top. If a change affects you significantly, we'll tell you by email.

Questions about this page?

Email info@pharmaos.co.uk and we'll reply within one working day.