Privacy Policy – Medirush Technology Pvt Ltd

Effective Date: 19 June 2025 | Last Updated: 25 August 2025

Medirush Technology Private Limited (“RXpress”, “we”, “our”, “us”) operates the RXpress website, mobile app, WhatsApp Business account, and customer support channels (collectively, the “Platform”). This Privacy Policy explains how we collect, use, disclose, and protect information.

1) Scope

This Policy applies to all users of the Platform located in India. By using the Platform, you consent to the practices described here.

2) Information We Collect

  • Identity & Contact: name, mobile number, email, address, DOB, gender.
  • Health & Prescription: uploaded prescriptions, medication details, and medical history shared for fulfilling orders (sensitive personal data).
  • Transaction & Payment: order history, invoices, payment references (UPI/cards via PCI-DSS compliant providers).
  • Technical/Usage: device identifiers, IP, app & web analytics, cookies, crash logs, support interactions.
  • Communications: messages/calls with support; opt-ins for WhatsApp/SMS/e-mail notifications.

3) Lawful Grounds for Processing

We process data to perform contracts (order fulfilment), comply with legal obligations, based on your consent (marketing, storing prescriptions), and our legitimate interests (secure operations, fraud prevention, service improvement).

4) How We Use Data

  • Process, validate, dispense, and deliver orders (including pharmacist review).
  • Customer support, troubleshooting, and safety.
  • Transaction confirmations, delivery updates, prescription requests.
  • Personalize features, improve performance, and prevent fraud.
  • Legal, regulatory, and tax compliance.

5) WhatsApp/SMS & DLT Compliance

Transactional/service messages are sent via DLT-registered headers/templates. Promotional messages are only sent with opt-in. You may opt out anytime.

6) Sharing of Information

  • Pharmacists/healthcare partners for prescription validation & dispensing.
  • Delivery partners to complete deliveries.
  • Payment gateways/banks for payments.
  • IT/Cloud, analytics, and support vendors under contracts.
  • Regulators/law enforcement where required.

7) Cross-Border Transfers

Primary storage is in India. Limited cross-border transfers (e.g., backups/CDN) follow Indian laws with safeguards.

8) Retention

  • Prescriptions/health records: 3 years or as legally required.
  • Tax/transaction records: 7 years.
  • Support/chat logs & marketing preferences: as necessary or until consent withdrawn.

9) Security

We use encryption, role-based access, logging, and least-privilege principles. No method is 100% secure, but we continuously improve safeguards.

10) Your Rights

Subject to law, you may access, update, correct, or delete information; request portability; withdraw consent; or lodge a complaint. Data may be retained if legally required.

11) Children & Minors

The Platform is intended for users 18+. No data knowingly collected from children under 13. Ages 13–17 should use with parental involvement. Contact us if a child’s data needs deletion.

12) Cookies & Analytics

We use essential, functional, and limited analytics cookies. You can control cookies in browser settings (some features may not work without them).

13) Grievance Redressal (IT Rules, 2021)

Grievance Officer: Aditya Pathak
Email: privacy@rxpress.shop
Phone: +91-7838513747
Timelines: Acknowledge within 24 hours and resolve within 15 days.

14) Changes to this Policy

We may update this Policy periodically. Continued use after changes constitutes acceptance. Latest version will show the “Last Updated” date.

15) Contact

For privacy questions or rights requests, contact: privacy@rxpress.shop