Pre-launch legal information: registered-office, CIN and grievance-officer details are not yet configured. They must be completed and these policies reviewed by qualified Indian legal and tax advisers before live commercial payments are enabled.
Privacy Policy
How PharmaDeal collects, uses, protects, and retains account and marketplace information.
1. Scope and data fiduciary
This Privacy Policy applies to pharmadeal.net, the PharmaDeal Manufacturer Android app, the PharmaDeal Wholesaler Android app, the administration portal, support channels and related services (together, the Platform). The Platform is operated by IBA Healthcare Private Limited (“PharmaDeal”, “we”, “us”). It is intended for business users in the pharmaceutical supply chain, not for patients or consumers seeking medical advice.
2. Information we collect
- Account and identity: name, email, phone number, login credentials, email-verification status, Google/Firebase user identifier, account role and status.
- Business and compliance: company or firm name, contact or owner name, drug-licence number, GST number where supplied, annual-sales range, business address, city, state and pincode. PharmaDeal currently records the licence number; it does not collect a licence-document upload in this release.
- Marketplace activity: product listings, category, pricing, stock, expiry, offers, favourites, cart activity, orders, delivery addresses, order status, invoices, Premium status and manufacturer/wholesaler communications necessary to fulfil an order.
- Payments and refunds: Razorpay order, payment and refund identifiers, amount, currency, status, timestamps and signature-verification results. Razorpay processes payment credentials; PharmaDeal does not store full card, UPI PIN, CVV or online-banking credentials.
- Support and requests: support-ticket content, linked order, priority and resolution notes; website access requests including name, business name, role, email, phone, city and message.
- Device, security and diagnostics: app version, device and operating-system details supplied by platform services, push-subscription/external user identifiers, notification preference, IP-derived security records, session and audit data, failed-login data, and crash/ANR diagnostics. We configure Crashlytics not to deliberately attach drug-licence, order, payment or similar sensitive business fields.
3. How information is collected
We receive information directly from you; from the other party to an order; automatically from the Platform; and from service providers such as Google/Firebase, Razorpay and OneSignal when you use the relevant feature. Google sign-in supplies a verified email, display name and Firebase identity token. Optional push notifications require device permission and may be disabled in the app or Android settings.
4. Why we use information
- create, authenticate, approve, secure and support accounts;
- verify role and business eligibility, prevent cross-role account conflicts, and enforce Platform rules;
- publish eligible products, reserve stock, split mixed carts into manufacturer-specific orders, process commission payments and refunds, and maintain transaction records;
- send service messages about approvals, orders, payments, refunds, support, stock, expiry and offers where permitted;
- detect abuse, diagnose failures, maintain audit trails, meet legal obligations and establish or defend claims; and
- improve reliability and understand aggregate service performance.
Depending on the activity and applicable law, processing is based on providing the service you request, complying with law, protecting legitimate business and security interests, or your consent (for example, optional device notifications). You may withdraw an optional consent without affecting earlier lawful processing.
5. When information is shared
We do not sell personal information. We may share the minimum necessary information with:
- the manufacturer or wholesaler involved in an order, including business identity, licence details, contact information, delivery address and transaction information needed for fulfilment and records;
- administrators and authorised support personnel who need access for approval, support, reconciliation, security or compliance;
- service providers acting for the Platform, including Hostinger (hosting and mail), Google/Firebase (authentication and crash diagnostics), OneSignal (push delivery) and Razorpay (payments and refunds), subject to their own terms and privacy notices;
- professional advisers, auditors, insurers, regulators, law-enforcement bodies or courts when reasonably required; and
- a successor in a merger, financing, reorganisation or transfer, subject to appropriate confidentiality and legal requirements.
6. Cookies and local storage
The website and admin portal use necessary session, security and CSRF-protection technologies. The Android apps use encrypted or platform-protected storage for the login token and ordinary local preferences for items such as cart, selected tab and notification choice. PharmaDeal does not currently use third-party advertising cookies or sell behaviour for targeted advertising.
7. Security
We use measures such as HTTPS, access controls, password hashing, limited-duration API tokens, encrypted session cookies, login throttling, signed payment verification, audit logs, backups and account-token revocation. No internet service is completely secure. Protect your device and credentials, and notify us promptly about suspected unauthorised access.
8. Retention and deletion
We keep information only for as long as reasonably required for the purposes above. Deactivation immediately blocks normal account access and revokes active API sessions. Order, invoice, payment, refund, subscription, audit, fraud-prevention and compliance records may remain for the period required by tax, pharmaceutical, corporate or other applicable law, and for dispute resolution. Support, access-request and diagnostic records are retained for a reasonable operational period. Backup copies are removed through the applicable backup rotation unless a legal hold applies.
9. Your choices and rights
Subject to applicable law, you may request access, correction or erasure of eligible information; withdraw optional consent; deactivate your account; raise a grievance; or nominate another person where the Digital Personal Data Protection Act, 2023 and implementing rules provide that right. We may need to verify your identity and may retain data that the law requires us to keep. Profile details can be corrected in the app; notification permission can be changed in the app or Android settings.
10. Children, transfers and changes
The Platform is for authorised business users aged 18 or older and is not directed to children. Some providers may process information outside your state or India under their service arrangements; we require lawful safeguards where applicable. We may update this Policy for legal, technical or business changes and will post the revised date. Material changes may also be communicated in the Platform.
Contact and grievance support
IBA Healthcare Private Limited
Email: ibahealthcare2026@gmail.com
WhatsApp: 918279987432