Privacy
This page describes what MedShelf stores and who can see it. It is a plain-language summary, not a contract.
What a shop's data is
Everything you record — sales, stock, customers, staff, cash counts — belongs to your pharmacy. Every row carries your pharmacy's id and every request is filtered by it, so one shop cannot read another's data. If you work at more than one pharmacy, each keeps its own ledger and nothing is shared or combined between them.
What we store about you
Your name, email address and optionally a phone number. Your password is stored only as a bcrypt hash, which cannot be reversed. If you sign in with Google we store the verified email address that Google confirms and no password at all.
Customers you record
A name and phone number you type in, so you can find a customer again and track বাকি. That record belongs to your pharmacy. We do not sell it, share it, or use it to contact anybody.
Who at MedShelf can see it
Our operators can see accounts, pharmacies and subscription status in order to run the service and answer support requests. Access is limited to what a request needs, and nobody at MedShelf sells or shares your data.
Deleting things
A pharmacy's ledger is deliberately append-only: a cancelled sale is recorded as a reversal and the original stays readable, because a pharmacy that can make a sale disappear cannot be audited. Removing a salesman removes them from your roster, and the sales they rang up keep their name on them. If you want an account or a pharmacy closed entirely, write to us.
Contact
Write to privacy@medshelf.com.