HopMeds Pharmacy
Privacy Policy
Last updated: 23 September 2026
This policy is published in English and Nepali. If the two versions differ, the English version is the one that applies.
This policy explains what information HopMeds handles, why, and who can see it. HopMeds is pharmacy and clinic management software made in Nepal. It can run on a pharmacy’s own computer (a local installation) or through our hosted service at pharmhops.com, and where the two differ this policy says which one it means. The PharmHops app on Google Play always uses the hosted service.
1. Who we are and who is responsible
HopMeds and the PharmHops Android app are developed and run by Hopmeds Health Tech Pvt. Ltd., Jawalakhel-5, Lalitpur, Nepal. In this policy, “HopMeds”, “we” and “us” mean that company. Our contact details are in section 12.
The pharmacy or clinic using HopMeds decides which patient and business records its staff enter. It is responsible for getting any consent those records need and for telling its patients how their records are handled. On the hosted service, Hopmeds Health Tech Pvt. Ltd. stores and processes those records in order to provide the service. For Google Play’s Data safety section, we treat everything sent to the hosted service as collected by us.
For privacy questions, or to find out who runs a particular local installation, contact the pharmacy or clinic that collected the information, or email us at: info@hopmeds.com
2. The PharmHops Android app
This policy covers the PharmHops app for Android (package name com.pharmhops.app), which Hopmeds Health Tech Pvt. Ltd. publishes on Google Play. The app opens the HopMeds staff web app at https://pharmhops.com/app/ and nothing else. It connects only to pharmhops.com, always over an encrypted HTTPS connection, and cannot be pointed at any other server. Links to other websites open in your phone’s browser, outside the app. Everything this policy says about the hosted service applies to the app.
The only permission the app asks you to approve is the camera. It asks only when you choose to take a photo in the app, so that you can photograph a medicine label, a prescription, a customer’s bill, a supplier’s bill or your pharmacy’s payment QR sticker instead of typing the details. The app does not use the camera in the background, and it reads a file from your phone only when you pick one. It does not ask for your location, microphone, contacts or calendar.
A photo you take is saved in the app’s private storage on your phone so that it can be uploaded; it is not added to your photo gallery. The app deletes older photos by itself the next time you open it or take another photo, and Android may clear them sooner; they are also removed when you clear the app’s storage or uninstall the app. To keep you signed in, the app also stores your sign-in tokens and your basic profile, such as your name, email address and role, on your phone. Signing out removes them, so sign out when you finish on a shared counter phone.
Bills, reports and exports you download are saved as files on your phone, either in its shared Downloads folder or in the app’s own files folder, and you open them in a viewer app of your choice. They can contain patient names and medicines. Signing out does not delete them. Files in the Downloads folder stay even after you uninstall the app, and other apps that can read your files, and anyone using your phone, can open them. Delete them yourself when you no longer need them, especially on a shared phone.
The app contains no advertising, analytics or tracking software of any kind.
3. Information we handle
- Account and signup data: an applicant’s name, email, phone number, organization and branch details, registration or licence number, optional PAN and VAT status, address, and review outcome. An applicant may also attach a copy of the pharmacy or clinic’s registration or licence (a PDF or photo) so we can verify it, and an organization may upload documents such as its PAN certificate, company registration or Department of Drug Administration registration in Settings. Staff accounts contain a name, email, phone number, role and a hashed sign-in password or PIN. If you pay for a HopMeds plan, we record the payer’s name, the bank and the transaction reference so the payment can be matched to your account.
- Patient and clinical data: HopMeds is used by pharmacy and clinic staff, so almost all of the health information in it is about patients who do not use the app themselves; staff record it while caring for them. It can include a patient’s name, phone number, email, date of birth, gender, blood group, address, national identity or citizenship number and emergency contact; their allergies, long-term conditions and current medicines; visit records, including the complaint and the diagnosis; prescriptions, with the prescribing doctor’s name and registration number and each medicine’s dose, frequency and quantity; dispensing records; blood-pressure and blood-sugar readings taken at a refill review; whether the patient has agreed to receive refill reminders; and the controlled-medicine register required by the Department of Drug Administration, which records the name and address of the person supplied.
- Doctor data: for doctors who use HopMeds, their name, Nepal Medical Council registration number, specialty, phone number, email, clinic, district and municipality; the times they say they are available and the place they give; and when their device last connected. The pharmacy that added a doctor holds these details. Pharmacies that receive the doctor’s referrals, and pharmacies whose requests the doctor accepts, see the doctor’s name, registration number and phone number, and HopMeds platform administrators can see them too (section 6).
- Pharmacy business data: medicine catalogues, stock batches, expiry dates, suppliers, purchase orders, bills, payments, accounting entries and reports entered by authorized users.
- Payment and credit records: how a customer paid a bill, including the amount, the method and any bank or wallet reference a member of staff types in. HopMeds does not process payments: it records payments made elsewhere, in cash or through the customer’s own bank or wallet app, and never asks for or stores card numbers, bank passwords or wallet PINs. If your pharmacy adds its own bank payment QR code, we keep only the text of that code so that bills can show it. Where a pharmacy gives a customer credit (khata), HopMeds records what the customer owes, any credit limit staff set, and any payment reminders staff log.
- Photos you take in the app: scanning is optional. You can photograph a medicine label, so the app can suggest the medicine, batch, expiry and price; a prescription or a customer’s bill, so it can suggest the patient, the prescriber and the medicines; a supplier’s bill, so it can suggest the lines of a purchase; or your pharmacy’s payment QR sticker. A prescription or bill photo can show a patient’s name and age, a diagnosis and the medicines prescribed, and the scanner is designed to read exactly those details.
- Service and security data: for each request, our server log records the time, the part of the service requested, the result, the account making it, your browser or app version, and a one-way cryptographic hash of your network address instead of the address itself. We also keep an activity record of each change made in the app, showing who made it, when, and what was submitted, leaving out passwords, PINs, sign-in tokens and photos. If the app hits an error, it sends us an error report with the error details, the screen it happened on and your app or browser version.
How scanned photos are read
On the hosted service, a photo of a medicine label, a prescription or a customer’s bill is read in one of two ways, depending on how the service is set up at the time. Either it is sent to Google’s Gemini API, which we use only on Google’s paid tier, where Google processes the photo for us as a service provider and does not use it to train its models; or it is read on the HopMeds server by Tesseract, an open-source text-recognition engine, and is not sent to any other company. A local installation reads photos on its own computer unless whoever runs it connects it to an outside service.
Either way, HopMeds does not keep the photo after reading it. What is saved is the record a member of staff checks and saves, which for a prescription can include the text the scanner read from it.
Two kinds of photo are handled differently. A supplier’s bill that you scan under Suppliers is kept with your accounts as the record of that purchase; where automatic reading of supplier bills is switched on, the bill is also sent to Google’s Gemini API, again only on Google’s paid tier, to read its lines. A payment QR photo is read once, in memory, on the HopMeds server and then discarded: only the text of the QR code is kept, and you can remove it at any time.
HopMeds does not sell pharmacy, clinic or patient records, does not use them for advertising, and does not train AI models on them. Photos are sent to Google only on its paid tier, where Google does not use them to train its models.
4. How information is used
- To provide billing, inventory, patient-record, reporting and staff-access features.
- To review access requests, verify pharmacy or clinic details, contact applicants, and create approved organization and administrator accounts.
- To synchronize records between authorized devices when synchronization is enabled.
- To create exports, including HMIS or DoHS reports, when an authorized user requests them.
- To read the details out of a photo when a user starts a scan of a medicine label, a prescription, a bill or a payment QR code.
- To send a prescription or a referral to another pharmacy, to find a doctor for a walk-in patient, or to show a doctor the patients booked into their session or on refill plans they authorized, when a user chooses to (see section 5).
- To show doctors and HopMeds platform administrators which pharmacies have a medicine in stock (see section 5).
- To send service emails, such as email verification, password recovery, account approval and account-deletion confirmation.
- To provide support, investigate errors, prevent abuse and protect the service.
The hosted service does not currently send SMS text messages. Staff can record whether a patient agrees to receive refill reminders by SMS; we will update this policy before any SMS is sent.
5. When information is shared
Service providers
For the hosted service at pharmhops.com we use the service providers below. They process information on our behalf, to provide their service to us.
- Render Services, Inc. hosting and the database. Receives all stored records and our server logs. Location: United States (Oregon).
- Cloudflare, Inc. the network edge in front of pharmhops.com. All traffic to and from the service passes through it in transit. Location: Cloudflare’s global network.
- Twilio Inc. sends our emails, such as verification, password-recovery, approval and account-deletion emails, and notifications to HopMeds staff. Receives each recipient’s email address and the message; a notification to our staff about a doctor request includes the patient’s name, phone number, age band and complaint. Location: outside Nepal.
- Google LLC reads photos you choose to scan, through the Gemini API, and only when we use it on Google’s paid tier (see section 3). Receives the photo, which may show a patient’s name, age, diagnosis and medicines. Location: outside Nepal.
This means information on the hosted service is stored and processed outside Nepal. We will update this list if a provider changes.
Sharing with other pharmacies and doctors
These features send patient information to a doctor or to another pharmacy. Each one runs only when a user chooses to use it:
- Electronic prescriptions: when a doctor using HopMeds sends a prescription to a pharmacy the patient chooses, that pharmacy receives the patient’s name and phone number, the doctor’s details and the prescription, including the medicines and any diagnosis or note on it. If that pharmacy runs HopMeds on its own computer, the prescription is delivered there. The prescription is also kept in the records of the pharmacy that added the doctor to HopMeds, with the patient’s name, phone number and any diagnosis, even when the patient collects it somewhere else.
- Doctor referrals: when a doctor using HopMeds refers a patient to a named pharmacy, that pharmacy receives the patient’s name and phone number if the doctor entered them, the medicine asked about and the doctor’s note.
- Doctor sessions: when a pharmacy books a patient into a visiting doctor’s session, that doctor sees the booking list, including each patient’s name, phone number, age and reason for the visit.
- Refill plans: the doctor who authorized a patient’s refill plan can see the patient’s name, the condition, the plan dates, when the patient last collected their medicine, when their supply runs out and whether it has lapsed.
- Request-a-Doctor: when a pharmacy asks for a doctor for a walk-in patient, the doctors offered the request see the patient’s age band, the complaint in the patient’s own words, how long it has lasted, any danger signs, any note from the pharmacy, the kind of doctor needed, and the pharmacy’s municipality and district. Only the doctor who accepts also sees the patient’s name and phone number. Once the request closes, doctors who did not accept no longer see its details. If no doctor is available, the request goes to HopMeds staff, who see the patient’s name, phone number and complaint and the pharmacy’s note, and arrange a doctor. That doctor may not use HopMeds; our staff may give them the details they need to contact the patient.
These doctors and pharmacies are not HopMeds staff. The pharmacy, clinic or doctor using these features is responsible for getting the patient’s agreement first.
Some business features also show details such as your pharmacy’s name, phone number, district and branch to other pharmacies or to distributors, together with the stock you offer or ask for, when you use them: for example, offering near-expiry stock to other pharmacies, posting a request for a medicine, or connecting to a distributor. They contain no patient information.
Medicine availability
HopMeds keeps an index of the medicines each pharmacy on the hosted service has in stock, and of the stock of local installations that choose to send theirs. It is built automatically: a pharmacy on the hosted service is included without having to switch it on. Doctors using HopMeds and HopMeds platform administrators can search it, and for each pharmacy branch they see the medicine’s name, generic name, strength and form, the quantity in stock, the branch name and district, and the pharmacy’s name and phone number. It contains no patient information.
Other disclosures
Information may also be disclosed when an authorized user exports or shares it, or when Nepali law or a valid legal process requires it.
6. Access by HopMeds platform administrators
Apart from the features described in section 5, a pharmacy or clinic’s records can be seen only by its own staff and by a small number of HopMeds platform administrators, who are our own staff. Platform administrators can see information across all pharmacies and clinics on the hosted service, and use this access to give support, investigate problems and security incidents, review signup applications, arrange doctors for pharmacies and run the platform. They can:
- Open a read-only view of any pharmacy or clinic’s records, including its patient records. They cannot change records through this view.
- Look up patients across all pharmacies by all or part of a phone number, or list the most recently registered patients, including patients a pharmacy has deleted. For each patient, this shows the phone number, the patient number the pharmacy gave them, when the record was created, how many bills they have, the total they have spent, and their first and last visit dates; the name of each pharmacy where they have bought, with the number of bills, the amount spent and the last visit there; and the five medicines they have bought most, with quantities. It does not show the patient’s name, age, conditions or allergies.
- See summaries across organizations, such as each pharmacy’s branches, sales and stock value, which medicines sell most and where, and the names and email addresses of the most active staff accounts.
- See and handle doctor requests that no doctor has accepted, with the patient’s name, phone number and complaint and the pharmacy’s note; and see the name, contact details, registration number, specialty, clinic and availability of every doctor on HopMeds.
- Search the medicine availability index described in section 5, and read the error reports sent from the app by every pharmacy and clinic.
7. Storage, retention and security
Hosted service, including the PharmHops app. Hopmeds Health Tech Pvt. Ltd. runs the service. Records are stored in a managed PostgreSQL database that Render Services, Inc. runs for us in the United States (Oregon). Render keeps short-term point-in-time backups of it, and we also download full copies of the database from time to time and keep them in restricted storage so that we can recover from a disaster. Details deleted from the service can remain in these backups until those copies are replaced or deleted; we use them only to restore the service.
Bills, payments, accounting records and the controlled-medicine register are kept for as long as Nepali tax and drug-control law requires. Deleting a patient hides the record from everyday screens but does not erase it: the patient’s details, and the bills, prescriptions and register entries linked to that patient, stay stored. Signup applications are kept while they are reviewed and may then remain as a record of the approval or rejection. Other records are kept while the pharmacy or clinic’s account is open.
When a pharmacy or clinic closes its HopMeds account, we switch the account off and keep its records until it asks us to delete them. It can write to us at any time, and we will then delete its records, except those that Nepali tax and drug-control law requires us to keep, which we keep only for as long as that law requires. When a staff account is deleted, its personal details are removed or replaced with a code, except the copies described in section 8.
Local installation. A pharmacy that runs HopMeds on its own computer keeps its records there and is responsible for their storage, backup and retention.
The public request form does not collect a password. When an application is approved, we email the applicant a one-time link to set their own password. If that email cannot be sent, a temporary password is shown once to the authorized reviewer instead; HopMeds stores only its hash, and it must be replaced at first sign-in.
Passwords and PINs are stored only as one-way cryptographic hashes. All traffic between your device and the hosted service is encrypted with HTTPS, and the Android app refuses unencrypted connections. Apart from the sharing described in section 5 and the platform administrator access described in section 6, each user sees only their own organization’s records, and what they can see and do depends on their role. No system can guarantee absolute security, so protect your device and your sign-in details, and tell us promptly if you suspect unauthorized access.
8. Access, correction, export and deletion
Authorized users can review and correct records in the app, and can create supported reports and exports. For access, correction or an export you cannot do yourself, email: info@hopmeds.com
Staff account holders can delete their own account: in the app under Settings → Compliance → Delete my account, or without signing in on our account-deletion page: pharmhops.com/delete-account.html
The deletion takes effect 14 days after it is confirmed, and can be cancelled until then by signing in.
Deletion removes the account’s sign-in credentials, sessions, error reports and the submitted details in its activity log, and replaces the name, email and phone number on the account with a random code. The signup application the account was approved from is also replaced with a code, and the licence document uploaded with it is deleted, unless the application must be held for a legal reason.
Bills, payments, the controlled-medicine register, accounting records and patient records belong to the pharmacy or clinic and are kept for as long as Nepali tax and drug-control law requires. Most of them stay linked to the code rather than to a name. Some legal and audit records, however, keep their own copy of the email address of the staff member who made them, and deleting the account does not change it. These include the controlled-medicine register, medicine disposal records, accounting entries, records of printed bill copies, changes to stock batches, and records of connections with distributors. Changes to stock batches also keep the person’s name, and distributor records keep their phone number. The pharmacy's own contact details in its profile, which may be the person's if they set up the account, belong to the pharmacy and are not changed by a deletion. Details removed by a deletion can also remain in the backups described in section 7 until those copies are replaced or deleted.
The last administrator of a pharmacy cannot delete their account alone. To close a whole pharmacy account, email: info@hopmeds.com
Doctors who use HopMeds do not have a staff account. A doctor who wants their details removed can email us; prescriptions and other records the law requires us to keep will still show the doctor’s name and registration number: info@hopmeds.com
If you are a patient, the pharmacy or clinic that treated you holds your record and decides what happens to it, so please ask them first. If you cannot reach them, email us and we will pass your request on: info@hopmeds.com
9. Children
HopMeds is a business tool for pharmacy and clinic staff. It is not a consumer service, it is not directed to children, and its accounts are meant for adults who work in a pharmacy or clinic. A pharmacist or clinician may record a child’s health information as part of that child’s care.
10. Governing law and complaints
This policy and the hosted HopMeds service are governed by the laws of Nepal. You may raise a complaint with the competent authorities in Nepal, but if you think we have mishandled your information, please write to us first: info@hopmeds.com
11. Changes to this policy
We may update this policy as the product or its data practices change. The current version and its “Last updated” date will remain available at this URL.
12. Contact
Hopmeds Health Tech Pvt. Ltd.
Jawalakhel-5, Lalitpur, Nepal
Email: info@hopmeds.com
Phone: +977-9768542410
Delete your account: pharmhops.com/delete-account.html