01Who we are
anvip.in is operated under the name Anvip. You can reach us at [email protected].
02The two roles we play
The same company handles data in two very different capacities, and the difference matters to you as a pharmacy.
| Data | Who decides what happens to it | Our role |
|---|---|---|
| Your store's business records: invoices, buyers and patients, stock, suppliers, purchases, reports | You do. We act only on your instructions, inside your workspace. | Data processor |
| Your Anvip account, team-member logins, payment records, partner ledger, demo requests | We do, to run the service you paid for | Data controller / principal fiduciary |
03What we collect
Everything below is stored in our own database. We do not buy lists of businesses or people, and we do not merge your records with outside data.
| When you | What we store |
|---|---|
| Create an account | Name, email address, account type, and your password as a one-way hash (`PBKDF2-SHA256, 100,000 iterations, unique random salt`). We cannot read your password. |
| Submit store setup | Store name, address, city, state, PIN code, phone, email, drug licence number (required), GSTIN and GST state code (optional), invoice settings and logo |
| Add a team member | Their name, email, role, and the password you choose for them. There is no invite-by-email flow, so the owner sets staff passwords. |
| Record purchases and stock | Supplier name, contact person, phone, email, address and GSTIN; purchase invoices, line items, batch numbers, quantities, expiry dates |
| Make a sale | Buyer name, buyer phone if given, medicines, quantities, prices, batch numbers, and an optional prescription reference number and per-medicine dosage text |
| Save a customer | Name, phone, email, address, GSTIN, outstanding balance and customer classification, scoped to your store |
| Pay for Anvip | Razorpay order and payment identifiers, plan, amount, currency, dates and a receipt reference. Not card numbers, expiry dates or CVV. |
| Join as a partner | Display name, role, phone, UPI ID for payout administration, referral code, and a commission ledger including any payout reference |
| Request a demo | Name, store name, phone, and optionally email, city, state and your message |
| Use security settings | Two-factor enrolment, hashed one-time recovery codes, a session counter, password change timestamps, and the history of any email-change request |
04What we never collect
This list is as important as the one above. If a category is not here, it does not exist in our database.
- No Aadhaar, PAN, passport or driving-licence numbers. One caveat, stated precisely: an Indian GSTIN embeds the holder's PAN by construction, so storing a GSTIN does store those characters.
- No bank account numbers, IFSC codes or cheque details. Partners give us a UPI ID for payouts; that is a payment handle, not an account.
- No card data. Checkout runs in Razorpay's hosted frame; card numbers never reach an Anvip server.
- No prescription images, scans or photographs. The workspace has no upload path for them at all. Only a free-text prescription reference number is stored, and since it is optional a walk-in sale is never blocked by it.
- No medical history, diagnosis, doctor name or lab result. The clinical text we hold is limited to what appears on an invoice: which medicine, how much, and the dosage instruction you typed.
- No location tracking, no contact-book import, no address-book sync.
- No advertising or analytics trackers. The site loads no Google Analytics, Meta pixel, Hotjar, Clarity, PostHog or similar script, and no third-party font loader. Fonts are served from our own host.
- No visitor IP addresses in the application. Referral link visits are counted, never identified: a tally plus a channel tag, with no IP, user-agent, cookie or fingerprint. Cloudflare and Razorpay keep their own platform logs under their own settings.
- No email or SMS is sent to your customers by Anvip. There is no outbound messaging system in the product. Invoices reach customers as a printed bill or a PDF you save from the browser.
- No AI training. Anvip has no AI feature and does not send your data to a language model. Barcode and QR scanning happen on your own device; the camera frame is decoded locally and nothing is uploaded.
05Patient and buyer information, in detail
Because a medical store's customer is usually a patient, we think you are entitled to a precise answer rather than a general one.
- Every invoice carries a buyer name field. For a counter sale the app fills it with the literal word Walk-in, so no personal name is captured unless someone types one. A typed name is stored on that invoice as a copy, which is why printed bills stay readable even if the customer entry changes later.
- Per-medicine dosage instructions are stored as text (for example 1-0-1 after food). Name plus medicine plus dose on one record is health information about an identifiable person, so we treat it as sensitive personal data and hold it to that standard.
- Nothing is shared between stores. Every query in the API is filtered by your store identifier. A person who buys at two Anvip pharmacies has two unrelated records, and we do not build a cross-store patient index, a national buyer list, or any aggregate dataset from your business records.
- We do not read your patient records in ordinary operation. Our platform administration view exposes store identity, licence and GST details, contact fields, subscription dates, invoice counts and total billed value, plus Razorpay identifiers. It has no route to invoice line items or your customer register.
- The customer register is optional. Stores that run in stock-only mode never create customer records at all; billing, customers and team features then stay off. You choose how much personal data enters your workspace.
07How we use what we hold
- To run the workspace you signed up for: authenticate you, apply your subscription, and serve your data back to you
- To keep the medicine, GST and stock calculations working across stores
- To answer support email and investigate anything that looks like abuse or a fault
- To generate the in-app reminders you see for expiring stock and overdue credit
- To bill you and to record the payment against your store
- To credit, track and settle partner commission
- To contact a demo requester about the request they made
We do not use your data for advertising, resale, profiling, market reporting or model training. We have no other revenue besides your subscription, and there is no mechanism in the product to send messages to your customers.
10How long we keep it
| Data | How long |
|---|---|
| Account, credentials, security settings | Until you ask us to close the account |
| Business records (stock, invoices, buyers, suppliers) | While the account exists. A lapsed subscription does not delete anything; we hold your data so paying again restores the workspace exactly as you left it. Removed only when you delete it, or ask us to close the account. |
| Nightly backups | We snapshot the business tables once a day. On an erasure request we remove the record from the live database at once and also clear it from backup snapshots, which we target within 14 days. |
| Bulk-import staging | Import previews expire after 24 hours, but the staged rows remain so nothing is lost mid-import. Tell us and we purge them. |
| Demo requests and support email | Until handled, then kept for context. There is no automatic expiry. |
| Commission ledger | Kept after a referred store stops paying, deliberately, so both dashboards can explain what was earned |
| Server logs | Request lines for troubleshooting, under our hosting account settings. We do not use them for analytics. |
11Your rights, and how to exercise them
Under the Digital Personal Data Protection Act, 2023 and the rules notified under it, a data principal may seek access, correction, completion, erasure, withdrawal of consent, and grievance redressal. As an account holder you have those rights over your own Anvip data; as a pharmacy you also act as fiduciary for your patients' data.
- In the app: correct or delete most business records yourself, and export your accounting data (a Tally XML file including buyer names, or a daily aggregate CSV with no personal data) from Reports.
- By email, because there is no self-serve button yet: closing an account, removing a saved customer permanently, a full copy of everything we hold, or a purge of backups and import staging. Write to [email protected].
- Patient requests come through you, not us. If a patient asks Anvip to delete their bill, we cannot verify them against your pharmacy, so we refer it to the account holder. Give your patients a way to reach you, then act on it in-app or ask us.
We reply to a verified request within 2 working days and complete simple requests within 14 days. There is no charge. If we must refuse, we give you the reason and the legal basis for it.
12Where your data is processed
Anvip runs on Cloudflare's global network. Application code executes close to the visitor; your database rows and backup files sit in Cloudflare storage, whose region is selected by Cloudflare and which we do not currently pin to one named country. Razorpay processes payments under its own infrastructure terms.
13How we protect it
Transport is HTTPS end to end. Passwords are hashed, sessions are signed and revocable, every store query is filtered by store identifier, uploads are type-sniffed rather than trusted, and payment activation is re-verified server-side so no browser can grant itself access. Two-factor authentication is available and we recommend it, though it is not yet enforced for any role.
The full technical inventory, including what we have not implemented, is on the Data & Security page. No security measure is a guarantee, and we do not claim certifications we do not hold.
14Children
Anvip is business software for licensed pharmacies and is not directed at children. We do not knowingly collect data about anyone under 18. If you believe a child's data reached us, email us and we will remove it.
15Changes to this policy
If this policy changes, we update the date at the top of this page and, for a material change, also say so in the workspace. Your continued use after the effective date accepts the revised policy. This version is effective 27 September 2026.
16Contact and grievance officer
Dipak Parmar is our grievance officer and data protection contact. Write to [email protected] and we respond within 14 days. Include enough to locate the record: your store name, the account email, and what you want done. Email is the only channel we publish, and it reaches the same person either way.
Still unhappy? You may complain to the Office of the Data Protection Authority under the DPDP Act, or, for a payment dispute, raise it with Razorpay. We would rather fix it by email first. The Contact page lists who to write to for what.
Questions about this document
We would rather explain a clause than have you guess at it. If you are about to pay, or already pay, and something on this page is ambiguous, email us and we will answer plainly - and correct the page if it is badly written.