Privacy notice

Last updated: 29 September 2026

This notice is provisional. It is published in draft while our legal review is completed. It describes what we actually do today; if anything here is unclear, ask us.

1. What this notice covers

This notice covers the personal data you give us through this website, by email, or when you start a free trial — the situations where ZOA DIGITAL LTD decides why and how your data is used (in data-protection terms, where we are the controller).

It does not cover the records a pharmacy keeps inside PharmacyHUB — controlled-drug entries, patient-safety incidents, private prescriptions, staff records and the like. For those, the pharmacy is the controller and we process the data on its behalf under a written data processing agreement. If you are a patient or a member of staff at a pharmacy that uses PharmacyHUB, that pharmacy’s own privacy notice applies to those records.

2. Who we are

PharmacyHUB is a trading name of ZOA DIGITAL LTD, a company registered in England and Wales, company number 17485002. Registered office: 217 Kingsway, Manchester, England, M19 2WB.

For anything about your personal data, email hello@pharmhub.co.

3. What we collect, and why

Browsing this site. The public pages set one technical cookie, keep one small note in your browser (see Cookies and browser storage, below) and load no advertising scripts. We count visits with Vercel Web Analytics: it uses no cookies and no third-party trackers, and it does not identify you — visitors are counted from a hash of the request that is discarded within 24 hours. Our hosting provider keeps standard server access logs (your IP address, browser type, and the pages requested) to run and protect the service, and we measure page performance (how quickly pages load) to keep the site fast.

Enquiries. If you email us, we keep your message and your contact details for as long as we need them to answer you and deal with any follow-up.

Leaving your details. The form on our Pharmacy Show page asks for your name, your work email address, your pharmacy’s name and, if you want to tell us, how many branches it has. We save them with the campaign tag on the link you followed (which QR code brought you), and we use them to get back to you about PharmacyHUB. We send you marketing email, such as product news, only if you tick “Email me about PharmacyHUB”, and you can ask us to stop at any time. So that the same form can’t be sent over and over from one connection, we also keep a one-way fingerprint of the network address it came from, never the address itself. The form uses bot detection, like the signup form.

Starting a trial. The signup form asks for your pharmacy’s name, a branch name, your name, your work email address, a password, and the plan you chose. We use these to create your account and your pharmacy’s workspace, to send you the emails the service needs (invitations, password resets, and compliance alerts), and to contact you about your trial. Your password is stored only as a one-way hash. The signup form uses bot detection to tell people from automated scripts.

Using the service. Once you sign in, we record your sessions, the network address a shared branch terminal is used from (branch access is restricted by location), and a tamper-evident audit trail of the actions you take. The audit trail is a compliance requirement of the service, not a marketing tool.

When a page breaks. On this site and in the app, our error monitoring (Sentry) records the error and the technical details around it, such as the page and the browser. It is set up not to send personal details. It also keeps a replay of the page, so we can see what went wrong: its layout, the pages visited and what was clicked. Your browser holds only about the last minute of this, and sends it only if an error happens — if nothing breaks, nothing is sent. After an error, it goes on recording that visit in the same way until you close the tab, you are idle for 15 minutes, or an hour has passed.

A replay keeps the shape of a page, never what it says. Before anything leaves your browser, every piece of text — including what you type — is replaced with placeholder characters, and every image is left out, so the names, numbers and records on a page are not sent. Error reports and replays are stored by Sentry in its EU data centre in Frankfurt, Germany, and deleted after 30 days.

Paying. When you add a payment method or pay for a booking, you do so on pages hosted by Stripe, our payment provider. Stripe collects the billing name, billing address and card details directly; card details never pass through our servers. We keep Stripe’s reference numbers for your customer record and subscription so we can show you your billing status and invoices.

We do not sell your data, and we do not use it for advertising.

4. Our lawful basis

  • Contract — to set up and provide your trial and your account, and to take payment.
  • Legal obligation — to keep the statutory pharmacy records and audit trails the service exists to keep.
  • Consent — to send you marketing email, if you tick the box on our Pharmacy Show form. You can withdraw it at any time by telling us.
  • Legitimate interests — to keep the site and the service secure and working (access logs, error monitoring, bot detection, the branch-location restriction), and to answer your enquiries. We balance these against your rights.

5. Cookies and browser storage

PharmacyHUB keeps a few small items in your browser. Before you sign in, this site sets one cookie, __vdpl; the rest of the cookies arrive when you sign in. This is the complete list.

Name and what it is for
CookiesSent back to our servers with each page you open.
__vdplKeeps you on the same version of the site while we release a new one. It holds a deployment number, nothing about you. Set on every page.How long it lasts: 30 minutes
__Secure-better-auth.session_tokenKeeps you signed in. It is a random token that points to your session on our server. Set when you sign in.How long it lasts: 7 days, renewed while you use the service; removed when you sign out
__Secure-better-auth.session_dataA signed copy of your session, so each page can check you are signed in without asking the database every time. Set when you sign in.How long it lasts: 5 minutes
Local storageStays on your device and only our own pages read it. Kept until you clear it.
ph-sidebarRemembers whether you left the app's side menu open or closed. Saved when you open or close it.How long it lasts: Until you clear your browser's data for this site
pharmacyhub:dashboard:v6:<your user ID>Remembers how you arranged your dashboard, separately for each person on a shared computer. Saved when you change it.How long it lasts: Until you clear your browser's data for this site
pharmhub:announcements-collapsed:<your user ID>Remembers whether you folded away your branch's announcements, separately for each person. Saved when you fold or unfold them.How long it lasts: Until you clear your browser's data for this site
Session storageStays on your device and only our own pages read it. Gone when you close the tab.
sentryReplaySessionLets our error monitoring attach a replay to the right visit if a page breaks (see When a page breaks, above). It holds a random ID and timestamps, nothing you typed or saw. Set on every page.How long it lasts: Until you close the tab
phh.skewReloadAtIf a page breaks because we have just released a new version, it reloads once to fetch it. This records when, so it can never reload over and over.How long it lasts: Until you close the tab
phub_handover_shown_<branch>_<date>_<60 or 15>Remembers that today's closing-time handover reminder has been shown, so each reminder appears once rather than on every page.How long it lasts: Until you close the tab
phub_handover_draft_<branch>_<date>Keeps the handover note you are typing if the page reloads before you save it.How long it lasts: Until you save the note or close the tab
phub_rp_signin_draft_<branch>_<your user ID>If we release a new version while you are signing in as Responsible Pharmacist, the sign-in can only be saved after the page reloads. When you choose to reload, this keeps your answers so the sign-in form reopens filled in. Only you, on that branch, get them back.How long it lasts: Until the sign-in form reopens (at most 10 minutes), or you close the tab

If you arrive from a link that carries a campaign tag (a utm_source on a QR code or an advert), we read it from the link and, if you start a trial from that page, save it with your signup so we know which banner or advert brought you. It is not stored in your browser. On our Pharmacy Show page we also add one to a daily count for that tag, so we know how many people each QR code brought; the count holds the tag and the day, nothing about you, and nothing else is recorded about how you got here.

Why there is no cookie banner. The law lets a site keep things on your device without asking first when they are strictly necessary for the service you came for: keeping you signed in, keeping the site working, finding and fixing faults, and remembering choices you make on screen. Everything in the list is one of those. None of it is used for analytics or advertising, none of it follows you to other sites, and none of it is shared with anyone else, so there is nothing to ask your consent for. Our visit counting and page-speed measurement keep nothing on your device.

6. Who we share it with

We use a small number of service providers to run PharmacyHUB. They process data only on our instructions and only for the purpose listed. The full register is maintained in our documentation and referenced by our data processing agreement.

  • Supabase — database hosting. London (AWS eu-west-2).
  • Vercel — application hosting, cookieless visit counting (Web Analytics), page-performance measurement (Speed Insights) and bot detection on the signup and Pharmacy Show forms (BotID). London compute (lhr1).
  • Vercel Blob — file storage for uploaded documents. UK/EU.
  • Resend — transactional email (invitations, password resets, alerts). EU.
  • Sentry — error monitoring, including replays of pages that break. EU (Frankfurt, Germany).
  • Stripe — payments — subscription billing and, where a pharmacy takes them, booking payments. Global; may process payment data outside the UK/EU under its own safeguards.

We may also disclose personal data where the law requires it — for example to a regulator or the police with proper authority.

7. Where your data is kept

Application data is hosted in the United Kingdom and the European Union: the database is in London and the application runs in London. The one exception is payment data. Stripe is a global payment provider and may process the billing details it collects outside the UK/EU; it does so under its own transfer safeguards, described in Stripe’s privacy notice. No application data — nothing you or your pharmacy records in PharmacyHUB — is transferred outside the UK/EU.

8. How long we keep it

While a pharmacy subscribes, we keep its account, its staff’s accounts and the records it keeps in PharmacyHUB, with the audit trail that goes with them.

When a pharmacy cancels, its account works as normal until its subscription ends, then is read-only for one month: its registers can still be viewed and exported, but nothing new can be added. After that month the account is closed and no one can sign in. Three months after the subscription ends, we delete the pharmacy’s data, except its invoices, which we keep for as long as tax law requires.

The statutory registers — the controlled drugs register, the responsible pharmacist log, private prescription records and the rest — are the pharmacy’s to keep, for as long as the law says. That duty is the pharmacy’s, not ours, and its export is its copy, so it should export them before the account closes.

Enquiry emails: for as long as needed to deal with the enquiry. Details left on our Pharmacy Show form: 12 months from when you send them, then deleted, unless you ask us to delete them sooner. Error reports and replays: 30 days (see When a page breaks, above).

9. Your rights

You have the right to ask for a copy of your personal data, to have it corrected, to have it erased, to restrict or object to how we use it, and to receive it in a portable form. Erasure has one limit: a pharmacy’s records of the work you did there keep what they recorded about you — your name and professional registration number on its registers and staff records, and whatever its audit trail noted at the time — because those are the pharmacy’s legal records, not ours to delete.

To make a request about your account, your signup or anything you have emailed us, email hello@pharmhub.co, from the address on your account if you can. We check the request comes from you before we act on it, and we reply within one month. If a request is complex we may need up to two more months, and we will tell you why within the first month. There is no fee.

You can also delete your own account from My account, under Security. If it tells you your account can’t be deleted yet — because you are your pharmacy’s only head-office user, for example — email us and we will arrange it.

For records a pharmacy keeps in the service, contact the pharmacy. It is the controller, it answers these requests, and it can export your data from PharmacyHUB itself. If you write to us about those records, we will tell you who to ask and help the pharmacy respond.

10. Security

Each pharmacy’s data is isolated from every other’s at the database level, sensitive fields are encrypted at rest with keys specific to each pharmacy, everything is encrypted in transit, access control fails closed, and every change to a record is written to a tamper-evident audit log. To report a security problem, email hello@pharmhub.co.

11. Complaints and changes

If you are unhappy with how we have handled your data, please tell us first at hello@pharmhub.co. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

We will update this notice when what we do changes, and the date at the top will change with it. Our terms of use cover the use of this website itself.