Privacy Policy

Effective Date: 2025-12-14

This Privacy Policy explains how TCM Pharmacy Express (“we”, “us”, or “our”) collects, uses, discloses, and safeguards information when you use our platform (the “Platform”).

We design our workflows to support regulated healthcare environments in Ontario, Canada, including privacy obligations under the Personal Health Information Protection Act, 2004 (PHIPA) where applicable. This policy is provided for transparency and does not constitute legal advice.

1. Who this policy applies to

  • Practitioners / Clinics using the Platform for prescription and dispensing workflows.
  • Patients receiving payment links, order communications, or dispensing-related notifications.
  • Visitors to our marketing pages (e.g., landing pages).

2. Information we collect

We collect only what is reasonably necessary to operate the Platform.

  • Account information: name, email, clinic information, and authentication metadata.
  • Order and dispensing information: prescription details, herb line items, directions, order status, shipping details, and related operational notes.
  • Payment-related metadata: payment status and transaction references. We do not store full card numbers.
  • Communications: emails we send (e.g., payment links, notifications) and delivery status logs.
  • Technical data: IP address, device/browser info, and security logs used for fraud prevention and system integrity.

3. How we use information

  • Provide and operate the Platform (prescriptions, payment links, labels, and order tracking).
  • Communicate with practitioners and patients about orders, payments, and delivery status.
  • Maintain security, prevent fraud, troubleshoot, and monitor platform performance.
  • Comply with legal and regulatory requirements.

4. PHIPA and personal health information

In Ontario, certain information processed through the Platform may constitute personal health information (“PHI”) under PHIPA. In typical workflows:

  • The practitioner or clinic is generally the health information custodian (HIC) responsible for the PHI they collect and use.
  • TCM Pharmacy Express typically acts as a service provider supporting the practitioner/clinic’s authorized purposes.

We will use and disclose PHI only as necessary to provide the Platform and as permitted by applicable law and practitioner instructions.

5. Consent and practitioner instructions

Practitioners are responsible for ensuring they have an appropriate legal basis and any required consent to submit patient information into the Platform.

6. Disclosure and third-party service providers

We may share information with vetted service providers who help us run the Platform (for example, email delivery, payment processing, hosting, and logging). These providers are permitted to process information only for the purposes of delivering their services to us.

  • Email delivery: to send payment links and order notifications.
  • Payment processors: to process patient payments and confirm payment status.
  • Cloud hosting and database: to store and deliver platform data securely.

7. Data location and cross-border transfers

Depending on configuration and service providers, information may be processed or stored in Canada or other jurisdictions. Where cross-border processing occurs, we take reasonable steps to ensure appropriate contractual and technical safeguards.

8. Safeguards

We use administrative, technical, and physical safeguards designed to protect information against loss, theft, unauthorized access, disclosure, copying, use, or modification.

  • Role-based access controls and least-privilege permissions where supported.
  • Encryption in transit (TLS) and, where available, encryption at rest.
  • Audit logs and monitoring to detect suspicious activity.
  • Secure authentication and session controls.

9. Retention

We retain information only as long as reasonably necessary to provide the Platform, meet contractual obligations, comply with legal requirements, and resolve disputes. Practitioners remain responsible for their own clinical record retention obligations.

10. Access and correction

Patients seeking access to or correction of PHI should generally contact the prescribing practitioner or clinic (the health information custodian). Practitioners can contact us for platform-support requests where appropriate.

11. Cookies and analytics

We may use cookies or similar technologies necessary for authentication, security, and basic site functionality. If analytics tools are used, they are configured to minimize data collection and avoid collecting unnecessary sensitive information.

12. Changes to this policy

We may update this Privacy Policy from time to time. The “Effective Date” will be updated when changes are posted.

13. Contact

If you have questions about this Privacy Policy or privacy practices, contact:

  • TCM Pharmacy Express
  • Email: dispenser@tcmfertility.ca

Practitioner note: If you are integrating the Platform into your clinic workflow, consider adding this Privacy Policy link to your patient-facing communications and ensuring your clinic’s own privacy notice covers your use of third-party service providers.