Privacy Policy
GDPR CCPA / CPRA COPPA Google Play App Store
Plain-English summary: MyPOB collects only the data needed to run a field-sales order management system. We do not sell your data, share it with advertisers, or use it for any purpose beyond operating and improving this application.

01 Overview

Respicare ("we", "our", or "us") operates the MyPOB — Personal Order Booking mobile and web application (the "Service"). This Privacy Policy explains how we collect, use, store, and protect information when you use the Service, and what choices you have.

MyPOB is an enterprise field-sales management platform used by pharmaceutical companies to submit, track, and approve Purchase Orders and Bills. Access is granted exclusively to employees and authorised representatives of client organisations ("Users"). This is not a consumer application open to the general public.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use and contact your organisation's administrator.

02 Information We Collect

Account & Identity Data

Provided by your employer or entered during onboarding:

  • Full name and employee code
  • Work email address
  • Role and hierarchy level (MR, DSM, ZSM, etc.)
  • Assigned territory, city, and state
  • Manager / reporting structure

Transaction & Activity Data

Generated as you use the Service:

  • POB submissions — product names, quantities, unit costs
  • Approval actions (approve, reject, comments) and timestamps
  • File attachments uploaded in support of POBs (receipts, invoices)
  • Status history and full audit trail of each order

Device & Technical Data

Automatically collected when you use the app or web interface:

  • Device model, operating system version, and app version
  • Unique device identifiers (for session management only)
  • IP address and approximate location (country/region) for security logging
  • App crash reports and error logs
  • Session tokens (stored via Flutter Secure Storage on mobile)

We do not collect: precise GPS location, contacts, camera or microphone access, call logs, SMS content, or any data unrelated to the Service.

03 How We Use Your Data

PurposeData UsedLegal Basis
Authenticate and manage your accountEmail, password hash, session tokenContract performance
Process and route POB submissionsTransaction data, role & hierarchyContract performance
Enable approval workflowsUser hierarchy, approval actionsContract performance
Generate management reports & exportsAggregated transaction dataLegitimate interest
Maintain security and prevent fraudIP address, device identifiers, logsLegitimate interest
Diagnose bugs and improve performanceCrash reports, error logsLegitimate interest
Comply with legal obligationsAs required by applicable lawLegal obligation

We do not use your data for advertising, profiling, or sale to third parties.

04 Data Sharing & Disclosure

We do not sell, rent, or trade personal information. Data is shared only in these limited circumstances:

  • Your Organisation: Your employer (the client that licensed the Service) can access data you generate within the application as part of the business relationship.
  • Service Providers: Trusted sub-processors (e.g., cloud hosting) who process data solely on our instructions under data processing agreements.
  • Legal Requirements: Where required by law, court order, or government authority, or to protect the rights, property, or safety of Respicare, our users, or the public.
  • Business Transfers: In the event of a merger or acquisition, user data may transfer subject to the same privacy protections.

05 Data Retention

We retain personal data for as long as your account is active and as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.

  • Active accounts: For the duration of the employment / licence relationship.
  • Deactivated accounts: Up to 3 years for audit and legal compliance, then securely deleted or anonymised.
  • POB records: Minimum 7 years to comply with financial and regulatory requirements.
  • Logs & crash reports: Up to 90 days, then purged automatically.

You may request deletion of your personal data at any time (see Your Rights), subject to legal retention requirements.

06 Data Security

We implement appropriate technical and organisational measures to protect your data:

  • Encryption in transit: All data uses TLS/HTTPS between the app and our servers.
  • Encryption at rest: Sensitive credentials and tokens use Flutter Secure Storage on mobile.
  • Authentication: Passwords are stored as one-way bcrypt hashes. Session tokens are revoked on logout.
  • Role-based access control: Users can only access data within their authorised hierarchy.
  • Audit trails: All approval and modification actions are logged with timestamps and user identity.

No method of Internet transmission is 100% secure. Please use strong passwords and notify us immediately of any suspected unauthorised access.

07 Your Rights

Depending on your location, you may have the following rights regarding your personal data:

All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your data, subject to legal retention requirements.
  • Portability: Request your data in a structured, machine-readable format.
  • Restriction: Request that we restrict processing in certain circumstances.
  • Objection: Object to processing based on legitimate interests.

European / UK Users (GDPR)

You have the right to lodge a complaint with your local data protection authority. You may also withdraw consent at any time where processing is consent-based.

California Residents (CCPA / CPRA)

You have the right to know what personal information is collected, the right to delete it, the right to opt out of its "sale" (we do not sell personal information), and the right to non-discrimination for exercising these rights.

To exercise any right, contact pharmacrafters@gmail.com. We will respond within 30 days. Because MyPOB is an enterprise app, some requests may need to be coordinated with your employer.

08 Children's Privacy

MyPOB is an enterprise application intended exclusively for adults who are employees or authorised representatives of client organisations. The Service is not directed to, and we do not knowingly collect personal information from, anyone under the age of 18.

If we become aware that we have inadvertently collected personal information from a minor, we will promptly delete it. If you believe we hold information about a minor, contact pharmacrafters@gmail.com immediately.

09 Third-Party Services

The application may use the following third-party services, each governed by their own privacy policies:

  • Cloud Infrastructure: Servers and database are hosted in India. Data does not leave India under normal operating conditions.
  • Google Play Services / Apple App Store: Downloading the app is subject to their respective privacy policies.
  • Push Notifications: If enabled, delivery may use Firebase Cloud Messaging (Google) or Apple Push Notification Service, which may process device tokens.

We do not integrate advertising SDKs, analytics platforms, social media SDKs, or any third-party tracking tools.

10 International Data Transfers

MyPOB is operated from India and primarily intended for use within India. Your data is stored and processed in India. If you access the Service from outside India, you understand that your information may be processed in India, where data protection laws may differ from those in your country.

For users in the EEA or UK, we ensure appropriate safeguards are in place for any such transfers in accordance with applicable data protection law.

11 Policy Changes

We may update this Privacy Policy from time to time. When we make material changes we will:

  • Update the "Last updated" date at the top of this page.
  • Notify administrators of client organisations by email where required.
  • Display an in-app notice when you next open the application.

Continued use of the Service after changes become effective constitutes acceptance of the revised policy.

12 Contact Us

For questions, concerns, or data requests regarding this Privacy Policy:

Respicare — MyPOB Team

📧 pharmacrafters@gmail.com

🌐 mypob.csplclient.com/privacy-policy

We respond to all legitimate requests within 30 days. For complex requests, we will notify you if more time is needed.