Privacy Notice
RxRecon Pro is designed around data minimization. This Notice describes the current website, access-request, account, billing, legal-acceptance, usage, and analytical privacy boundaries.
Access-request information
Netlify Forms processes the pharmacy's business identity, license-related identifiers, location, business contact information, requested use, and acknowledgments submitted through the access form. Do not submit patient, prescription, prescriber, report, or other protected health information through that form or by support email.
Account information
Supabase Auth processes the invited user's email address, authentication credentials, and session information. RxRecon Pro stores organization membership, entitlement status, document versions and server timestamps for legal acceptance, and privacy-safe usage metadata needed to control access and monthly run limits. Passwords are handled by Supabase Auth and are not available to the RxRecon Pro administrator.
Billing information
Stripe hosts subscription checkout and processes the subscriber's business contact, billing, transaction, and payment-method information. RxRecon Pro does not receive or store complete card numbers. Stripe may provide RxRecon Pro with subscription status, customer and transaction identifiers, card brand and last four digits, billing contact information, and payment results needed for account activation, support, accounting, fraud prevention, and legal obligations. Do not enter patient, prescription, prescriber, or pharmacy-report information in Stripe fields.
Pharmacy files
Dispensing reports and wholesaler files are parsed in the browser. Direct patient and prescriber identifiers and the browser's local re-association map are designed to remain on the user's device. They are not included in the approved analytical request schema.
Protected analytical requests
The authenticated application sends a strictly allowlisted analytical projection containing run-scoped opaque tokens and reconciliation fields to protected compute. The schema is designed to exclude direct patient and prescriber identifiers; unexpected fields and raw-file payloads are rejected. Because submitted values are controlled by the client and free text cannot be identified with certainty, this safeguard does not guarantee that every identifier will be detected or excluded.
Retention and browser-local state
Browser-local report data is temporary and is not a hosted backup. Closing or refreshing the page may discard local state. RxRecon Pro retains account, entitlement, legal-acceptance, billing, security, and aggregate usage records for as long as reasonably necessary to operate the service, document transactions and consent, enforce agreements, prevent abuse, resolve disputes, and satisfy accounting or legal obligations. Executed BAAs, amendments, signature evidence, and required HIPAA documentation are retained for at least six (6) years from creation or the date last in effect, whichever is later, and longer when required by law, contract, legal hold, or an unresolved claim. RxRecon Pro may retain records that cannot lawfully or reasonably be deleted and may de-identify or aggregate records where permitted.
Service providers and disclosure
RxRecon Pro uses service providers such as Netlify, Supabase, Stripe, and approved hosting or compute providers for the functions described above. Information may also be disclosed when required by law, to protect users or the service, in a business transfer subject to appropriate safeguards, or with the subscriber's direction. RxRecon Pro does not sell personal information.
Security and choices
RxRecon Pro uses technical and organizational safeguards proportionate to the service, but no system is completely secure. The named administrator may request correction of business contact information, account assistance, cancellation, or another privacy request by emailing ADMIN@RXRECONPRO.COM. RxRecon Pro may verify identity and authority before acting and will respond as required by applicable law. A request does not require deletion of records that RxRecon Pro must or is permitted to retain.
Regulated-data limitation
Use synthetic or appropriately de-identified data unless the pharmacy-specific BAA has been fully executed, RxRecon Pro has activated the approved location for PHI use, and both parties have implemented their required safeguards. Keeping identifiable records browser-local reduces exposure but does not make the subscriber's devices, workforce, network, source systems, or overall operations compliant and does not transfer the subscriber's HIPAA duties to RxRecon Pro.
Contact
Privacy questions and requests should be sent to ADMIN@RXRECONPRO.COM. Do not include PHI in email.