01 Overview
Respicare ("we", "our", or "us") operates the MyPOB — Personal Order Booking mobile and web application (the "Service"). This Privacy Policy explains how we collect, use, store, and protect information when you use the Service, and what choices you have.
MyPOB is an enterprise field-sales management platform used by pharmaceutical companies to submit, track, and approve Purchase Orders and Bills. Access is granted exclusively to employees and authorised representatives of client organisations ("Users"). This is not a consumer application open to the general public.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use and contact your organisation's administrator.
02 Information We Collect
Account & Identity Data
Provided by your employer or entered during onboarding:
- Full name and employee code
- Work email address
- Role and hierarchy level (MR, DSM, ZSM, etc.)
- Assigned territory, city, and state
- Manager / reporting structure
Transaction & Activity Data
Generated as you use the Service:
- POB submissions — product names, quantities, unit costs
- Approval actions (approve, reject, comments) and timestamps
- File attachments uploaded in support of POBs (receipts, invoices)
- Status history and full audit trail of each order
Device & Technical Data
Automatically collected when you use the app or web interface:
- Device model, operating system version, and app version
- Unique device identifiers (for session management only)
- IP address and approximate location (country/region) for security logging
- App crash reports and error logs
- Session tokens (stored via Flutter Secure Storage on mobile)
We do not collect: precise GPS location, contacts, camera or microphone access, call logs, SMS content, or any data unrelated to the Service.
03 How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Authenticate and manage your account | Email, password hash, session token | Contract performance |
| Process and route POB submissions | Transaction data, role & hierarchy | Contract performance |
| Enable approval workflows | User hierarchy, approval actions | Contract performance |
| Generate management reports & exports | Aggregated transaction data | Legitimate interest |
| Maintain security and prevent fraud | IP address, device identifiers, logs | Legitimate interest |
| Diagnose bugs and improve performance | Crash reports, error logs | Legitimate interest |
| Comply with legal obligations | As required by applicable law | Legal obligation |
We do not use your data for advertising, profiling, or sale to third parties.
05 Data Retention
We retain personal data for as long as your account is active and as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
- Active accounts: For the duration of the employment / licence relationship.
- Deactivated accounts: Up to 3 years for audit and legal compliance, then securely deleted or anonymised.
- POB records: Minimum 7 years to comply with financial and regulatory requirements.
- Logs & crash reports: Up to 90 days, then purged automatically.
You may request deletion of your personal data at any time (see Your Rights), subject to legal retention requirements.
06 Data Security
We implement appropriate technical and organisational measures to protect your data:
- Encryption in transit: All data uses TLS/HTTPS between the app and our servers.
- Encryption at rest: Sensitive credentials and tokens use Flutter Secure Storage on mobile.
- Authentication: Passwords are stored as one-way bcrypt hashes. Session tokens are revoked on logout.
- Role-based access control: Users can only access data within their authorised hierarchy.
- Audit trails: All approval and modification actions are logged with timestamps and user identity.
No method of Internet transmission is 100% secure. Please use strong passwords and notify us immediately of any suspected unauthorised access.
07 Your Rights
Depending on your location, you may have the following rights regarding your personal data:
All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Restriction: Request that we restrict processing in certain circumstances.
- Objection: Object to processing based on legitimate interests.
European / UK Users (GDPR)
You have the right to lodge a complaint with your local data protection authority. You may also withdraw consent at any time where processing is consent-based.
California Residents (CCPA / CPRA)
You have the right to know what personal information is collected, the right to delete it, the right to opt out of its "sale" (we do not sell personal information), and the right to non-discrimination for exercising these rights.
To exercise any right, contact pharmacrafters@gmail.com. We will respond within 30 days. Because MyPOB is an enterprise app, some requests may need to be coordinated with your employer.
08 Children's Privacy
MyPOB is an enterprise application intended exclusively for adults who are employees or authorised representatives of client organisations. The Service is not directed to, and we do not knowingly collect personal information from, anyone under the age of 18.
If we become aware that we have inadvertently collected personal information from a minor, we will promptly delete it. If you believe we hold information about a minor, contact pharmacrafters@gmail.com immediately.
09 Third-Party Services
The application may use the following third-party services, each governed by their own privacy policies:
- Cloud Infrastructure: Servers and database are hosted in India. Data does not leave India under normal operating conditions.
- Google Play Services / Apple App Store: Downloading the app is subject to their respective privacy policies.
- Push Notifications: If enabled, delivery may use Firebase Cloud Messaging (Google) or Apple Push Notification Service, which may process device tokens.
We do not integrate advertising SDKs, analytics platforms, social media SDKs, or any third-party tracking tools.
10 International Data Transfers
MyPOB is operated from India and primarily intended for use within India. Your data is stored and processed in India. If you access the Service from outside India, you understand that your information may be processed in India, where data protection laws may differ from those in your country.
For users in the EEA or UK, we ensure appropriate safeguards are in place for any such transfers in accordance with applicable data protection law.
11 Policy Changes
We may update this Privacy Policy from time to time. When we make material changes we will:
- Update the "Last updated" date at the top of this page.
- Notify administrators of client organisations by email where required.
- Display an in-app notice when you next open the application.
Continued use of the Service after changes become effective constitutes acceptance of the revised policy.
12 Contact Us
For questions, concerns, or data requests regarding this Privacy Policy:
Respicare — MyPOB Team
🌐 mypob.csplclient.com/privacy-policy
We respond to all legitimate requests within 30 days. For complex requests, we will notify you if more time is needed.