NHS — Providing NHS services

Privacy Policy

Last updated: 27 August 2026

This policy explains what personal information Hello Pharmacy collects when you use our website and patient account, why we collect it, who we share it with, and the choices and rights you have.

1. Who we are

Hello Pharmacy is a GPhC-registered pharmacy providing NHS and private pharmacy services. We are the "data controller" for the personal information described in this policy, which means we decide how and why it's used.

Our registered company name is Hello Pharmacy (company number 16919644), with our registered office at 49 Richford Gate, Richford Street, London W6 7HY. Our GPhC registration number is 1041447, and our Superintendent Pharmacist is Kiran Karnam.

2. Information we collect

When you create an account, we collect:

  • Your name, date of birth, email address, and password, and a phone number if you give us one.
  • Your consent for us to access your NHS Summary Care Record where appropriate, and to be nominated as your chosen pharmacy on the NHS Electronic Prescription Service (EPS), which you confirm when you sign up.

When you use your account to order or manage prescriptions, we additionally collect:

  • The names of medicines you request, dosage information, and the status of each request.
  • Your GP practice, where you tell us who it is.
  • Delivery addresses you save, and a copy of the address used for each individual order (kept with that order even if you later change or delete your saved address).
  • Whether an order is for you or for a family member (dependant) on your account, and that dependant's name, date of birth, and relationship to you, if you add one.
  • Photos or files you upload of a prescription or medicine query.

If you message our pharmacy team through the in-app chat, we collect the text of your messages, any voice messages you record, and any files or images you attach.

We also collect limited technical information needed to keep your account secure and working correctly, such as your sign-in sessions and, for staff accounts, a temporary marker used to remember that a member of staff has recently re-confirmed their identity before actioning sensitive requests.

3. How we use your information

  • To provide pharmacy services: processing your prescription requests, dispensing medicines, and arranging delivery or collection.
  • To communicate with your GP practice where needed to approve a prescription request — see section 4.
  • To support your account: sending order confirmations, prescription status updates, appointment reminders, and other service-related notifications by email, and responding to messages you send us. These are sent to every patient as a normal part of running your account and delivering pharmacy services, not as marketing, so we don't ask for a separate opt-in for them.
  • To meet our legal and regulatory obligations as a pharmacy, including keeping dispensing and prescription records for the periods we're required to.
  • To keep our service secure, including detecting and preventing unauthorised access to accounts.

We don't currently run any marketing emails or promotional communications. If that ever changes, we'll ask for your separate, explicit consent first and this policy will be updated to reflect it.

4. Who we share your information with

We share personal information only where it's necessary to provide our service, and with the following:

  • Your GP practice — when a prescription request needs GP approval, we email your GP practice the relevant medicines, your name, and date of birth, so they can confirm it's appropriate to dispense.
  • NHS systems — where you've given consent at sign-up, we may access your Summary Care Record and act on your Electronic Prescription Service (EPS) nomination to support safe, accurate dispensing.
  • Supabase, our database and account-security provider, which stores your account and pharmacy records and handles secure sign-in.
  • Resend, our transactional email provider, which sends account, order, and request-related emails on our behalf (for example, order confirmations or a response to a data request). Resend processes the content of these emails but does not use it for its own purposes.
  • Ideal Postcodes, an address look-up service. As you type an address into a delivery-address field, the text you've typed so far (which may include partial address details) is sent directly from your browser to Ideal Postcodes to suggest matching addresses.
  • Cloudflare Turnstile, a bot-protection check shown on our sign-in, sign-up, and password-reset forms, used to help stop automated attacks on accounts.
  • Stripe, our payment processor, which handles card payments for prescription charges and private services. Stripe receives your name, email, and payment details directly, we do not store your card details ourselves.
  • Firebase Cloud Messaging (Google), used to deliver push notifications to our app, for example letting you know your order has been dispatched. This involves sharing a device identifier (not linked to your health information) and the text of the notification itself.

We do not sell personal information, and we do not use any advertising or analytics services on our website or app.

5. Cookies and similar technologies

We keep this deliberately minimal. We use:

  • An essential sign-in cookie, so you stay logged in as you move around your account. Without it, our service can't work.
  • A small amount of on-device storage (not sent to us) used for things like remembering which family member's account you're currently viewing, or, for pharmacy staff, a short-lived marker of when they last confirmed their identity before actioning a sensitive request.

We do not use analytics, advertising, or tracking cookies of any kind.

6. How long we keep your information

As a regulated pharmacy, we're required to keep certain records for a minimum period set by law and pharmacy regulation, even after you stop using our service or ask us to close your account:

  • Prescription and dispensing records, including the register of prescription-only medicines, are kept for a minimum of 2 years from the date of the last entry, under the Human Medicines Regulations 2012.
  • Your wider clinical and medication history is kept for longer, in line with the NHS Records Management Code of Practice, which sets a retention period of 10 years after a patient's death for this type of record.

Information that isn't subject to a legal retention requirement — such as your account login details — is kept for as long as your account is active, or until you ask us to delete it (see section 7).

7. Your rights

Under UK data protection law, you have the right to:

  • Access a copy of your data. From your account, go to Settings → "Download your data" to receive a full export of your account, orders, prescriptions, messages, and delivery addresses as a file, immediately.
  • Ask us to delete your data. From Settings → "Request account deletion," you can submit a request, which our pharmacy team will review. Because we're required to retain certain pharmacy records for a set period, some information may not be deletable immediately — we'll explain why if that applies to your request.
  • Ask us to correct information that's inaccurate or incomplete.
  • Complain to the Information Commissioner's Office (ICO) if you think we've handled your information incorrectly — details at ico.org.uk. We'd appreciate the chance to resolve any concern directly first.

8. How we keep your information secure

  • Your account can only be accessed with your password, and pharmacy staff accounts additionally require a one-time code from an authenticator app every time they sign in.
  • Our database enforces that patients can only ever see their own records, and staff access to patient records is logged.
  • We limit repeated failed sign-in attempts and use bot-protection on our sign-in and sign-up forms to guard against automated attacks.
  • Staff accounts require re-confirming identity before actioning sensitive requests (such as approving a prescription or a data deletion request), and are automatically signed out after a period of inactivity.

9. Family members and children's information

If you add a family member (dependant) to your account to order on their behalf, you're confirming you're authorised to do so — for example, as their parent or legal guardian for a child. We treat a dependant's information with the same care as our own patients'.

10. Changes to this policy

We'll update this page if the way we handle personal information changes, and update the date at the top. If a change is significant, we'll take reasonable steps to let account holders know directly.

11. Contact us

If you have any questions about this policy or how we handle your information, you can reach us via our Contact page.

You can also contact our privacy team directly at staff@hello-pharmacy.co.uk.