Legal

Privacy Policy

Last updated: 28 July 2026

1. About this policy

PharmStack Pty Ltd (ACN 697 662 427) ("PharmStack", "we", "us", "our") provides software that helps pharmacies serve their customers. Contact us at support@pharmstack.ai.

This policy covers our public website at pharmstack.ai, sales and enquiry activities, accounts, the PharmStack application, document tools, SMS notifications, support, and related services. It explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

A customer contract or service schedule may impose tighter terms. Those terms apply to the extent of any inconsistency with this policy.

2. Roles

We handle personal information used for our website, enquiries, accounts, billing where applicable, security, sales, marketing, and direct customer relationships.

A pharmacy customer usually decides what operational content, documents and customer communications are submitted. For that pharmacy content, we provide the contracted service and follow the pharmacy's documented instructions, contract and applicable law. That information belongs to the pharmacy's relationship with its customers. The pharmacy remains responsible for obtaining any consent or other authority required before submitting it. This does not remove PharmStack's own obligations under applicable privacy law.

Requests about a pharmacy's customer or health-related information may need to go to that pharmacy first. We will reasonably assist as required.

3. Information we handle

Depending on how you use PharmStack, we may handle:

  • Enquiry and sales data, such as names, pharmacy or business names, contact details, roles, store details, operational questions, and messages submitted through forms or email.
  • Account and pharmacy-staff data, such as names, email addresses, user identifiers, authentication and session records, roles, preferences and support messages.
  • Pharmacy operational data, such as documents, workflows, announcements, tasks and related operational records uploaded or generated in the service.
  • Customer and health-related information, limited information pharmacies submit so they can serve their customers. This may include customer contact details and limited health-related information in documents or SMS notifications (for example prescription, medication, appointment or order-related details, and in some documents prescriber details, patient initials or date of birth).
  • Technical and analytics data, such as IP address, device or browser details, pages viewed, approximate location derived from IP, and security or diagnostics events.

Pharmacies must have consent or another lawful basis before submitting sensitive information, including health information, and should submit only information reasonably necessary for the relevant feature. PharmStack may reject, remove or restrict content that appears unnecessary or inappropriate for the service.

4. Collection

We collect information from you, pharmacy customers and their authorised users, pharmacy customers' end recipients where messages are sent through the service, devices that access our website or service, and service providers that help us operate.

If you do not provide required enquiry, account, security or service information, we may be unable to respond, open an account, provide a feature, or meet legal and security requirements. Optional fields can be left blank unless we say otherwise.

5. Purposes

We use personal information to:

  • respond to enquiries, demo requests and workflow reviews;
  • help pharmacies serve their customers through operational workflows, documents and service messages;
  • provide accounts, authentication, support and related service administration;
  • operate, secure and improve the website and service;
  • provide AI-assisted document and workflow features described below; and
  • comply with legal obligations and protect our systems, users and legal rights, including detecting fraud, misuse and security incidents.

Where we send direct marketing, each marketing communication will include a simple, free way to opt out, and we will honour opt-out requests. Operational, transactional and health-service communications (including SMS notifications sent by a pharmacy) are separate from marketing and may continue where permitted by law or required to provide the service.

6. AI

PharmStack may use AI-based services, including Microsoft Azure OpenAI, to help pharmacists extract and organise information from documents and support operational workflows.

  • Documents or selected portions of documents may be securely transmitted to Azure OpenAI for processing.
  • Document processing uses Standard Azure OpenAI deployments in Microsoft's Australia East region. PharmStack does not use Global or Data Zone deployments for document processing where doing so would permit processing outside Australia.
  • Structured customer or patient data stored within the platform is managed separately and is only provided to AI services where needed for the relevant function.
  • Submitted information is not used to train public or shared foundation models, and is not shared between customers. Microsoft may undertake limited processing necessary to operate, secure and monitor the service under its contractual terms and abuse-monitoring arrangements.

PharmStack does not provide clinical decision-making, diagnosis, treatment recommendations, or patient-specific clinical advice. AI-generated outputs are intended to assist pharmacists and are subject to human review before being relied upon.

7. Disclosures and overseas processing

We do not sell your personal information. We disclose information to trusted service providers that help us host, authenticate, process, message, email, analyse, support and secure the service. Primary pharmacy data is hosted in Sydney-region cloud infrastructure and application processing is configured to run in Sydney, but we do not claim that all processing occurs in Australia.

Likely overseas recipient countries include the United States, EU member states, Singapore and the Philippines, depending on the provider and subprocessors involved. Where personal information is disclosed overseas, we take reasonable steps to ensure appropriate safeguards in line with applicable privacy law.

Current service categories include:

  • Authentication and session management. A third-party identity provider processes limited account and technical information about authorised pharmacy users, such as email addresses, user identifiers, authentication records, IP addresses and device information. Patient health information, pharmacy documents and operational customer data are not provided to that provider. Multi-factor authentication may be available but is not currently mandatory for all accounts. Authentication information may be processed in the United States.
  • Application hosting and database. Primary pharmacy application data and processing are configured in Sydney-region cloud infrastructure. Limited operational, support, security, analytics, edge-delivery, log or account information may be processed overseas, including in the United States and Singapore, by our hosting and database providers and their subprocessors.
  • Document AI processing. Document content used by AI features is processed using Standard Azure OpenAI deployments in Australia East, as described in section 6. Microsoft may undertake limited processing necessary to operate, secure and monitor the service under its contractual terms.
  • Website email delivery (Resend). We use Resend to send transactional emails relating to this website, such as when you submit a contact or workflow-review form. Resend is not used to deliver emails from within the PharmStack application. Resend's primary processing operations are in the United States. We only share the contact details and message content necessary to deliver the email.
  • SMS and text notifications (ClickSend). Pharmacy customers may use PharmStack to send SMS notifications to Australian mobile numbers, including messages concerning prescriptions, medications, appointments, orders and other health-related matters. The pharmacy determines the recipients and message content and is responsible for ensuring it has the authority or consent required to send each message. To deliver the notification, PharmStack provides ClickSend with the recipient's mobile number and message content, which may include personal information or sensitive health information. ClickSend's handling of that information, including hosting and any overseas processing by ClickSend and its subprocessors, is described in ClickSend's privacy policy. Recipients may opt out by replying STOP or contacting their pharmacy.

Your pharmacy's data remains isolated to your account and is not shared with other customers or used to train public or shared AI models.

8. Security

We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. This includes secure storage, encrypted transmission of documents, access controls, and limiting exposure of personal information during processing by third-party services.

Access to personal information is restricted through role-based access controls. Authorised users receive permissions based on their role and responsibilities within the customer pharmacy. Database-level access controls are also used to maintain separation between customer pharmacy accounts.

We maintain a data-breach response process. Where required under the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC).

9. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, or as required by law.

  • Website enquiries, demo requests and related correspondence are retained for as long as needed to respond, follow up and maintain ordinary business records.
  • Customer pharmacy data and documents are retained while the relevant account remains active and for a reasonable period afterwards to allow orderly account closure, dispute resolution or legal compliance.
  • After account termination, we take steps to delete or de-identify personal information that is no longer required, subject to backup retention periods, legal obligations and legitimate security or audit needs.
  • Backups may persist for a defined recovery period after deletion from live systems. We do not promise immediate deletion from all backup copies.

10. Access, correction and complaints

You may request access to or correction of personal information we hold about you by contacting support@pharmstack.ai. We may need to verify your identity before responding. Where information is handled on a pharmacy's instructions, we may ask you to direct your request to that pharmacy in the first instance, and we will reasonably assist as required.

We ordinarily respond to access and correction requests within 30 days. Correction requests are free of charge. If we refuse a request in whole or in part, we will ordinarily explain the reasons in writing and tell you about available complaint options.

If you believe we have mishandled your information, please contact us first using the details above. We will acknowledge a privacy complaint within a reasonable period, investigate it and ordinarily provide a written response within 30 days. You may also complain to the OAIC at oaic.gov.au.

11. Changes and contact

We may update this policy from time to time. The "Last updated" date at the top will change when we do. Material changes will be notified through the service or by another appropriate method where required.

PharmStack Pty Ltd (ACN 697 662 427)
Privacy contact: support@pharmstack.ai

See also our Terms of Use.