Who this policy applies to
This policy applies to DMS customers, prospective customers, vendors, business partners and visitors who use the DMS website, DMS mobile app, enquiry forms, vendor registration or related support services.
Information we collect
Depending on how you use DMS, we may collect:
- Account and contact details: name, mobile number, email address, date of birth and login or OTP records.
- Customer and order details: delivery addresses, selected products, quantities, order history, prescription files, payment method, payment status and transaction references.
- Vendor information: business name, owner or contact details, address, GSTIN, PAN, FSSAI or Drug Licence details when supplied, and Aadhaar number and document used for vendor verification.
- App and device information: device identifier, Firebase notification token, app version, device type and diagnostic information. Location is accessed only when you permit it and use a location-based feature.
- Website and support information: enquiries, messages, IP address, browser details and records of your communication with DMS.
How we use information
We use information to create and secure accounts, verify OTP login, process B2C and B2B orders, review prescriptions, calculate availability and delivery charges, provide customer support, verify vendor applications, send order updates, prevent fraud and comply with applicable legal or record-keeping requirements.
Promotional notifications are sent only when enabled. Essential service messages, such as order or account updates, may still be sent where necessary to provide the service.
Prescriptions and vendor documents
Prescription and identity or licence documents are treated as sensitive records. They are used only for medicine review, business verification, fraud prevention, compliance and support. Access is restricted to authorised administrators and verification personnel.
Storage and retention
We retain information only for as long as needed to provide DMS services, resolve disputes, maintain transaction and medicine records, meet legal obligations and protect against misuse. When information is no longer required, we delete it or remove identifying details where reasonably possible.
How we protect information
We use access controls, encrypted connections, protected credentials, audit records and other reasonable technical and organisational safeguards. No online system is completely risk-free, so please keep your OTP and account access private and contact us if you notice suspicious activity.
Your choices and rights
You may ask us to provide information about your data, correct inaccurate details, delete information that is no longer required, withdraw optional consent, stop promotional notifications or raise a privacy grievance. Some order, prescription, tax or verification records may need to be retained where applicable law requires it.
App permissions can be controlled through your device settings. Signing out removes the active notification token for that device from your account.
Children’s privacy
DMS accounts and purchases are intended for adults. A person under 18 should use DMS only with the involvement and consent of a parent or lawful guardian.
Policy updates
We may update this policy when our services, technology or legal obligations change. The latest version will remain available on this page with its updated date.
Contact and privacy requests
For questions, correction or deletion requests, or a privacy grievance, contact DMS using the details below. We may verify your identity before acting on an account-related request.