
Privacy Policy
How DynomedRx collects, uses, stores, and protects your information.
Privacy Policy
How DynomedRx collects, uses, stores, and protects your information
Effective Date: Pending Attorney Review
Last Updated: August 21, 2026
Version: 1.1 Draft
Jurisdiction: United States
Website: https://dynomedrx.com
Email: support@dynomedrx.com
Plain-Language Summary
DynomedRx is a pharmacy data analytics, inventory audit, claims-history, reconciliation, and reporting platform built for independent pharmacies. Depending on the features enabled for a pharmacy location, the Service may compare claims with purchases, parse wholesaler files and PDFs, maintain a dashboard and manual purchase ledger, estimate prescription profitability, ingest files through a connector, preserve validated claims snapshots, and support PBM audit preparation.
We do not sell personal information or Uploaded Pharmacy Data, and we do not use Uploaded Pharmacy Data for advertising or unrelated marketing. We use identifiable Uploaded Pharmacy Data to provide, secure, maintain, troubleshoot, and support the Service and only use it for improvement as permitted by law, an applicable Business Associate Agreement, and a written customer agreement.
Retention depends on the workflow. Active Dashboard Mode source files remain until replaced or deleted; temporary report jobs and their server-only diagnostics are scheduled to expire after seven (7) days; Dashboard Mode source files and snapshots are scheduled for deletion thirty (30) days after subscription access ends; controlled connector-pilot and Persistent Claims History records follow the separate schedules in Section 5.
If your use of DynomedRx involves PHI and makes DynomedRx a HIPAA business associate, an appropriate written Business Associate Agreement is required before the PHI is provided to or processed by the Service.
1. Introduction and Scope
DynomedRx ("DynomedRx," "we," "us," or "our") is committed to protecting the privacy, confidentiality, and security of information submitted through our website, application, platform, connectors, integrations, and related services.
This Privacy Policy explains how we collect, use, store, protect, disclose, and retain information when you access or use DynomedRx, including any related websites, software, local connectors, APIs, dashboards, reports, administrative review workflows, support services, or subscription services, collectively referred to as the "Service."
This Privacy Policy applies to pharmacies, pharmacy owners, pharmacy operators, employees, contractors, authorized users, and any other individual or entity that accesses or uses the Service.
By using DynomedRx, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, you should not use the Service.
2. Information We Collect
DynomedRx collects only the information reasonably necessary to provide and support the Service.
2.1 Information You Provide to Us
We may collect the following categories of information:
Account, Authentication, and Security Information
This may include your name, display name, email address, account identifier, authentication provider, password credential maintained by our authentication provider, multi-factor enrollment information and phone number, subscription and access status, login history, and account security events. If you choose Google or Microsoft sign-in, the identity provider supplies basic account information such as your name, email address, provider identifier, and profile information you authorize it to share.
Pharmacy and Business Information
This may include pharmacy name, store or pharmacy-location identifier, contact information, NPI number, DEA number, state license information, wholesaler relationships, pharmacy-system configuration, and other business identifiers needed to operate or configure the Service.
Uploaded Pharmacy Data
This may include prescription claims and claim-history files; prescription, patient, and prescriber identifiers; prescription numbers; dates of service; drug names, NDCs, quantities, claim status, BIN and PCN values, payor and billing fields, reimbursement and copay amounts; wholesaler spreadsheets, CSVs, EDI records, and PDFs; invoice numbers, dates, product codes, costs, credits, and purchase records; supplier data; filenames and file metadata; and other pharmacy operational records provided for inventory audit, claim reconciliation, profitability analysis, discrepancy detection, or reporting. Uploaded files may contain PHI even when DynomedRx does not require a patient name.
Workspace Entries and Review Data
This may include report date ranges and settings, dashboard filters, flagged drug groups, manually entered purchase details, edit and void history, void reasons, source-detection results, parser warnings, file format and package-size exceptions, normalization decisions, report diagnostics, and records showing who performed an action or review.
Connector and Integration Data
If a connector or integration is enabled, we may collect device and pharmacy-location identifiers, connector version, machine name, configured wholesaler identifiers, selected file names and metadata, file size and cryptographic hash, local creation and modification timestamps, upload and duplicate-detection status, last successful upload time, service and folder-health status, scan timestamps, pending-file counts, bounded error codes, credential status, and related operational audit events. The connector is designed not to include patient data in its operational health logs, but the pharmacy files it transmits may contain PHI or other sensitive pharmacy data.
Billing and Payment Information
This may include subscription plan and status, Stripe customer and subscription identifiers, transaction and invoice records, and billing contact details. Payment card information is processed by Stripe; DynomedRx does not intentionally store full payment card numbers on its own servers.
Support and Communication Information
This may include emails, support requests, messages, feedback, troubleshooting details, and other communications you send to us.
2.2 Information Collected Automatically
When you use the Service, we may automatically collect limited technical and usage information, including:
IP address
Browser type and version
Device type
Operating system
Login timestamps
Pages or features accessed
Error logs
System activity logs
Security and authentication events
Request, upload, report-generation, and connector event metadata
This information is used to operate, secure, troubleshoot, and improve the Service.
2.3 Sources of Information
We collect information directly from you and your Authorized Users; from files, folders, systems, and devices you choose to connect; from pharmacy management systems and wholesaler exports acting at your direction; from authentication providers such as Google and Microsoft when you use provider sign-in; from payment and email service providers; and automatically from your browser, device, and use of the Service.
2.4 Information We Do Not Intentionally Collect
DynomedRx is designed to operate with the minimum information necessary. Unless specifically required for the Service and covered by appropriate contractual safeguards, we do not intentionally collect:
Social Security numbers
Personal banking credentials
Biometric identifiers
Government-issued identification numbers unrelated to pharmacy operations
Sensitive personal information unrelated to pharmacy inventory audit or claim reconciliation.
Users are responsible for ensuring that files uploaded or connected to DynomedRx are appropriate for use with the Service and comply with applicable laws, contracts, and pharmacy obligations.
3. How We Use Your Information
DynomedRx uses information only for legitimate business purposes related to operating, securing, supporting, and improving the Service.
3.1 To Provide the Service
We may use information to:
Receive, validate, normalize, parse, and process uploaded or connector-supplied pharmacy and wholesaler files, including supported PDFs and EDI records;
Compare billed claims against purchased inventory
Generate inventory audit, claims-history, profitability, MFP, aberrant-usage, and related reports and dashboards;
Detect potential claim-to-purchase discrepancies
Identify NDC, RxNorm, quantity, package-size, purchase, cost, reimbursement, or billing mismatches;
Maintain active dashboard workspaces, flags, manual purchase ledgers, void history, validated claims snapshots, source-authority metadata, and requested exports;
Detect duplicate or repeated files and select data according to configured date coverage and source-precedence rules;
Operate authorized connectors and integrations, issue short-lived upload authorizations, verify transmitted file size and cryptographic hashes, and show connector and coverage health;
Support PBM audit preparation and internal pharmacy review
Maintain user accounts and subscriptions
Provide access to platform features
Deliver reports and related outputs
3.2 To Communicate With You
We may use your information to:
Send account confirmations
Send subscription and invoice-related communications
Respond to support requests
Provide technical assistance
Notify you of security issues
Send administrative notices
Provide important updates about the Service
Notify you of material changes to this Privacy Policy or our Terms of Service
3.3 To Improve and Secure the Service
We may use information to:
Monitor platform performance
Troubleshoot errors
Improve functionality
Develop new features
Detect unauthorized access
Prevent fraud, abuse, or misuse
Maintain audit logs and security controls
Conduct internal analytics using aggregated, anonymized, or de-identified data where appropriate and permitted by an applicable BAA;
Validate parsers, investigate support issues, and review restricted report diagnostics and normalization exceptions.
3.4 To Comply With Legal Obligations
We may use information to:
Comply with applicable laws and regulations
Respond to valid legal process
Enforce our Terms of Service
Protect the rights, property, and safety of DynomedRx, users, pharmacies, and others
Establish, exercise, or defend legal claims
3.5 Restricted Human Review
Authorized DynomedRx personnel and contractors may access Uploaded Pharmacy Data, server-only report diagnostics, source metadata, or normalization exceptions only when reasonably necessary to provide support, validate or correct a parser or package-size rule, investigate a security or integrity issue, prevent fraud or abuse, comply with law, or perform another purpose permitted by an applicable BAA or written agreement. Access is intended to be role-limited and logged where supported. Human review does not make DynomedRx a pharmacy auditor, legal advisor, or clinical decision-maker.
4. Uploaded Pharmacy Data
Uploaded Pharmacy Data may include sensitive pharmacy operational information and PHI, including prescription and patient identifiers, prescriber information, claim and payment records, NDC data, wholesaler purchase records, invoice files, EDI records, and related pharmacy business data.
DynomedRx uses identifiable Uploaded Pharmacy Data to provide, secure, maintain, troubleshoot, and support the Service, including claim-to-purchase reconciliation, claims-history resolution, inventory audit and profitability analysis, discrepancy reporting, parser and normalization review, duplicate detection, and requested support. DynomedRx uses identifiable Uploaded Pharmacy Data for product improvement only where permitted by applicable law, an applicable BAA, and a written customer agreement.
DynomedRx does not sell Uploaded Pharmacy Data. DynomedRx does not use Uploaded Pharmacy Data for advertising, unrelated marketing, or resale to third parties.
User-facing files and server-only diagnostics may contain different subsets or transformations of the same source data. Customers should treat all downloads and exports as potentially sensitive and store them appropriately.
5. Data Retention
DynomedRx retains different categories of information for different periods depending on the purpose of collection, operational needs, legal obligations, and contractual requirements.
5.1 Temporary Report Jobs
Generated reports, exports, report-specific source copies, and server-only report diagnostic files are scheduled to expire seven (7) calendar days after report generation. Deletion and cloud-provider expiration processes may be asynchronous. Limited job metadata and activity records may remain after file content expires for security, support, dispute resolution, and business recordkeeping.
5.2 Dashboard Mode
Claims and invoice source files and dashboard snapshots remain available as the active Dashboard Mode workspace until the user replaces or deletes them. A replacement is activated only after successful processing, after which the replaced source objects are scheduled for deletion.
Manual purchase entries, edit and void history, flags, dataset metadata, source detections, and related activity records may remain after source objects are replaced or subscription access ends to preserve an audit trail, support the Service, and protect data integrity. They are removed as part of active account deletion where implemented, subject to the exceptions below.
When subscription access is canceled, unpaid, or otherwise ends, Dashboard Mode access is blocked and its source files and dashboard snapshot objects are scheduled for deletion after thirty (30) days unless the subscription is restored or a different period is required by a written agreement, applicable BAA, law, security need, or legal hold. This thirty-day schedule does not automatically apply to the separate categories described below.
5.3 Controlled Connector Pilots
Confirmed raw EDI files and related receipt and duplicate-detection records in a controlled connector pilot currently have no automatic deletion date and may be retained for parser reprocessing and audit until an approved production retention policy or written customer agreement replaces that pilot rule. Failed connector upload records generally become eligible for deletion ninety (90) days after failure once any mismatched object has been deleted. Connector-created customer audit records generally become eligible for deletion after three hundred sixty-five (365) days, revoked-device records after three hundred sixty-five (365) days, connector rate-limit records after twenty-four (24) hours, and structured connector operational logs after thirty (30) days. Cloud-provider TTL deletion may occur after the stated eligibility time.
5.4 Persistent Claims History
If Persistent Claims History is expressly enabled, each fully validated normalized snapshot and its date-authority metadata may be maintained as immutable claims history for at least two (2) years from generation. Older snapshots may remain available for audit even when a newer authoritative snapshot supersedes their rows for calculations. Raw claims source files may follow a separate connector, workspace, or written retention schedule; deleting a raw source object does not necessarily delete or alter an already validated snapshot or its audit metadata.
5.5 Account, Billing, Support, Review, and Security Records
Account and profile information may be retained for the life of the account and for a reasonable period afterward for administration, dispute resolution, legal compliance, and business recordkeeping. Billing, invoice, subscription, payment, and Stripe records may be retained as required for tax, accounting, legal, fraud-prevention, and compliance purposes. Support communications, normalization decisions, package-size rules, review metadata, security logs, login records, and audit trails may be retained for their support, integrity, security, dispute-resolution, and compliance purposes unless a specific period above or a written agreement applies.
5.6 Account Deletion
An authenticated account-deletion request cancels active DynomedRx subscriptions and removes the Firebase authentication account, active user profile, user-scoped application subcollections, and files under the user's primary Service storage prefix. Related support-request content is deleted or redacted where implemented. DynomedRx and its service providers may retain a minimal deletion record, billing and tax records, redacted support metadata, security or fraud-prevention records, backups pending normal rotation, de-identified data, and information subject to a legal hold or other legal or contractual duty. Account deletion does not automatically override a BAA, a written retention agreement, an enabled Persistent Claims History schedule, or controlled connector-pilot records stored under separate server-private paths.
5.7 De-Identified or Aggregated Data
DynomedRx may retain aggregated, anonymized, or de-identified data that does not reasonably identify a specific user, pharmacy, patient, or individual, subject to applicable law and any applicable BAA.
Unless otherwise stated in a written agreement, users are responsible for downloading and preserving any reports, exports, or records they need for their own business, legal, audit, or compliance purposes. DynomedRx is not a system of record unless expressly agreed in writing.
6. How We Share Information
DynomedRx does not sell, rent, lease, or trade your personal information or Uploaded Pharmacy Data.
We may share information only in the limited circumstances described below
6.1 Service Providers
DynomedRx may use carefully selected third-party service providers to help operate the Service. These may include providers for:
Cloud hosting
Authentication;
Database and file storage
Payment processing
Email delivery
SMS delivery and abuse prevention for multi-factor authentication
Error monitoring
Security tools
Customer support
Analytics and infrastructure
When a provider processes information on DynomedRx's behalf, it is authorized to process that information only for the contracted service and related legal obligations. A payment processor, identity provider, or other service you choose may also process information under its own terms and privacy notice.
Current core providers may include Google Firebase and Google Cloud for authentication, database, storage, and infrastructure; Vercel for application hosting and execution; Stripe for subscriptions, billing, and payment processing; Resend for transactional and support email; and Google or Microsoft when you choose their identity-provider sign-in. Provider availability and roles may change as the Service evolves. When HIPAA applies, DynomedRx will address service-provider handling of PHI as required by the applicable BAA and law.
6.2 Personnel and Contractors
Authorized DynomedRx personnel and contractors may access information on a need-to-know basis for the purposes described in this Policy, including support, restricted diagnostic or normalization review, security, fraud prevention, billing, and legal compliance. They are expected to be subject to confidentiality and security obligations appropriate to their role.
6.3 Legal Requirements
We may disclose information if required to do so by law, subpoena, court order, regulatory request, or other valid legal process.
Where legally permitted, DynomedRx will make reasonable efforts to notify affected users before disclosing information in response to legal process.
6.4 Business Transfers
If DynomedRx is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction, information may be transferred as part of that transaction. Any successor entity will be expected to handle information in a manner consistent with this Privacy Policy unless users are notified otherwise.
6.5 Protection of Rights and Security
We may disclose information when reasonably necessary to protect the rights, property, or safety of DynomedRx, our users, pharmacies, patients, the public, or others.
7. Data Security
DynomedRx uses technical, administrative, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction.
These safeguards may include:
Encryption of data in transit
Encryption of stored data through configured cloud infrastructure
Tenant-scoped and role-based access controls
Authentication safeguards
Optional SMS multi-factor authentication
Short-lived signed connector upload authorizations and file-integrity verification
Monitoring and logging
Secure cloud infrastructure
Restricted administrative access
Vendor review and oversight
Security incident response procedures
No internet-based system can be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of account and connector credentials, securing connected devices and local export folders, reviewing Authorized Users, and ensuring that only authorized personnel access their DynomedRx account and connected pharmacy systems.
You should notify DynomedRx immediately if you believe your account has been compromised or accessed without authorization.
8. HIPAA and Healthcare Data
DynomedRx may receive or process pharmacy data that could include Protected Health Information as defined by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, collectively referred to as "HIPAA."
8.1 Business Associate Agreement
If DynomedRx creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity or business associate in a manner that makes DynomedRx a business associate, an appropriate written Business Associate Agreement is required before the PHI is uploaded, connected, or processed through the Service.
Users must not upload, connect, or otherwise provide PHI to DynomedRx unless an appropriate Business Associate Agreement is in effect or the data has been properly de-identified in accordance with applicable law. If this Policy conflicts with an executed BAA regarding PHI, the BAA controls.
8.2 Minimum Necessary Standard
Where HIPAA applies and a Business Associate Agreement is in effect, DynomedRx will use and disclose PHI only as permitted by the BAA or required by law and will apply the HIPAA minimum-necessary standard where it applies.
8.3 User Responsibility
Users are responsible for determining whether their uploaded files contain Protected Health Information and whether their use of the Service complies with HIPAA, state privacy laws, payer contracts, pharmacy obligations, and other applicable requirements.
9. Cookies and Tracking Technologies
DynomedRx and its authentication and hosting providers may use cookies, browser storage, SDK state, and similar technologies to operate and secure the Service.
9.1 Types of Cookies We May Use
Necessary and Security Technologies
These support login, authentication state, Google or Microsoft sign-in, session management, multi-factor authentication, reCAPTCHA abuse prevention, security, and core platform functionality.
Functional Technologies
These may remember user preferences, settings, and interface choices or preserve temporary application state.
9.2 What We Do Not Use
DynomedRx does not use Uploaded Pharmacy Data for advertising. DynomedRx does not sell personal information to advertisers or data brokers and does not currently use advertising cookies or cross-context behavioral advertising pixels.
9.3 Managing Cookies
You may control cookies and browser storage through your browser settings. Disabling necessary authentication, security, or storage technologies may prevent the Service from functioning properly.
10. Your Privacy Rights
Depending on your location and applicable law, you may have certain rights regarding your personal information.
These rights may include:
The right to access personal information we maintain about you
The right to correct inaccurate information
The right to request deletion of certain information
The right to receive a copy of certain information
The right to object to or restrict certain processing
The right to opt out of marketing communications
The right not to be discriminated against for exercising privacy rights
To exercise privacy rights, contact DynomedRx using the contact information listed below. We may need to verify your identity before processing your request.
Certain information may be retained where required for legal, tax, accounting, security, contractual, or legitimate business purposes.
11. California Privacy Notice
If you are a California resident and DynomedRx is a business subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, you may have additional rights. Some information handled under HIPAA or other laws may be exempt from some CCPA requirements.
DynomedRx does not sell personal information. DynomedRx does not share personal information for cross-context behavioral advertising.
In the preceding twelve (12) months, DynomedRx may have collected the following CCPA categories: identifiers; customer-record and commercial information; internet or other electronic network activity; professional or employment-related information; sensitive personal information contained in authentication, account, claims, or pharmacy files; and inferences or analytics derived from those records. The specific data, sources, purposes, and retention criteria are described in Sections 2, 3, and 5.
DynomedRx may disclose identifiers, account and commercial information, internet or device activity, communications, and Uploaded Pharmacy Data to the service-provider categories described in Section 6 for a business purpose. DynomedRx may also make the disclosures described in Sections 6.2 through 6.5. DynomedRx does not knowingly sell or share the personal information of individuals under age sixteen (16).
California residents may have the right to:
Know what categories of personal information are collected
Know the purposes for which personal information is used
Request access to personal information
Request correction of inaccurate personal information
Request deletion of personal information
Opt out of sale or sharing, where applicable
Limit use of sensitive personal information, where applicable
Be free from discrimination for exercising privacy rights
To submit a California privacy request, contact us using the information below and include "California Privacy Request" in the subject line. We may verify your identity and authority and will respond as required by applicable law. An authorized agent may submit a request where permitted by law, subject to verification.
12. Children's Privacy
DynomedRx is intended for use by businesses, pharmacies, and authorized pharmacy personnel. The Service is not intended for children or individuals under the age of 18.
We do not knowingly collect personal information from children. If you believe a child has provided personal information to DynomedRx, contact us and we will take appropriate steps to delete the information.
13. Third-Party Links and Integrations
The Service may contain links to third-party websites, tools, systems, or integrations. DynomedRx is not responsible for the privacy practices, security practices, or content of third-party services.
If you enable an integration or identity provider, information may pass between DynomedRx and that third party at your direction. Users should review the privacy policies, terms, export settings, and access controls of any third-party service before connecting it or submitting information to it. References to PrimeRx, wholesalers, PBMs, Google, Microsoft, Stripe, or other third parties do not imply sponsorship or endorsement unless expressly stated.
14. International Users
DynomedRx is operated from the United States and is intended primarily for use by United States-based pharmacy businesses.
If you access the Service from outside the United States, you understand that your information may be processed and stored in the United States, where privacy laws may differ from those in your jurisdiction.
15. Updates to This Privacy Policy
DynomedRx may update this Privacy Policy from time to time. When we make material changes, we may notify users by email, through the Service, or by posting an updated version on our website.
The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.
If a change would permit a materially different use of previously collected identifiable information, DynomedRx will provide additional notice or obtain consent where required by applicable law, an applicable BAA, or a written agreement. Your continued use of the Service after an updated Privacy Policy becomes effective means you acknowledge the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or DynomedRx's data practices, contact us at:
DynomedRx
Email: support@dynomedrx.com
Website: https://dynomedrx.com
For privacy-related requests, please include "Privacy Request" in the subject line
17. Legal Disclaimer
This Privacy Policy is a draft prepared for business planning and attorney review and should not be published or relied upon until approved by qualified counsel. It does not constitute legal advice and may need to be revised based on DynomedRx's legal entity and address, final production retention and deletion procedures, controlled connector-pilot status, Persistent Claims History rollout, service-provider and subprocessor agreements, state-specific obligations, HIPAA and BAA status, incident-response program, and executed customer agreements.