HopMeds Pharmacy

Privacy Policy

Last updated: 23 September 2026

This policy is published in English and Nepali. If the two versions differ, the English version is the one that applies.

This policy explains what information HopMeds handles, why, and who can see it. HopMeds is pharmacy and clinic management software made in Nepal. It can run on a pharmacy’s own computer (a local installation) or through our hosted service at pharmhops.com, and where the two differ this policy says which one it means. The PharmHops app on Google Play always uses the hosted service.

1. Who we are and who is responsible

HopMeds and the PharmHops Android app are developed and run by Hopmeds Health Tech Pvt. Ltd., Jawalakhel-5, Lalitpur, Nepal. In this policy, “HopMeds”, “we” and “us” mean that company. Our contact details are in section 12.

The pharmacy or clinic using HopMeds decides which patient and business records its staff enter. It is responsible for getting any consent those records need and for telling its patients how their records are handled. On the hosted service, Hopmeds Health Tech Pvt. Ltd. stores and processes those records in order to provide the service. For Google Play’s Data safety section, we treat everything sent to the hosted service as collected by us.

For privacy questions, or to find out who runs a particular local installation, contact the pharmacy or clinic that collected the information, or email us at: info@hopmeds.com

2. The PharmHops Android app

This policy covers the PharmHops app for Android (package name com.pharmhops.app), which Hopmeds Health Tech Pvt. Ltd. publishes on Google Play. The app opens the HopMeds staff web app at https://pharmhops.com/app/ and nothing else. It connects only to pharmhops.com, always over an encrypted HTTPS connection, and cannot be pointed at any other server. Links to other websites open in your phone’s browser, outside the app. Everything this policy says about the hosted service applies to the app.

The only permission the app asks you to approve is the camera. It asks only when you choose to take a photo in the app, so that you can photograph a medicine label, a prescription, a customer’s bill, a supplier’s bill or your pharmacy’s payment QR sticker instead of typing the details. The app does not use the camera in the background, and it reads a file from your phone only when you pick one. It does not ask for your location, microphone, contacts or calendar.

A photo you take is saved in the app’s private storage on your phone so that it can be uploaded; it is not added to your photo gallery. The app deletes older photos by itself the next time you open it or take another photo, and Android may clear them sooner; they are also removed when you clear the app’s storage or uninstall the app. To keep you signed in, the app also stores your sign-in tokens and your basic profile, such as your name, email address and role, on your phone. Signing out removes them, so sign out when you finish on a shared counter phone.

Bills, reports and exports you download are saved as files on your phone, either in its shared Downloads folder or in the app’s own files folder, and you open them in a viewer app of your choice. They can contain patient names and medicines. Signing out does not delete them. Files in the Downloads folder stay even after you uninstall the app, and other apps that can read your files, and anyone using your phone, can open them. Delete them yourself when you no longer need them, especially on a shared phone.

The app contains no advertising, analytics or tracking software of any kind.

3. Information we handle

How scanned photos are read

On the hosted service, a photo of a medicine label, a prescription or a customer’s bill is read in one of two ways, depending on how the service is set up at the time. Either it is sent to Google’s Gemini API, which we use only on Google’s paid tier, where Google processes the photo for us as a service provider and does not use it to train its models; or it is read on the HopMeds server by Tesseract, an open-source text-recognition engine, and is not sent to any other company. A local installation reads photos on its own computer unless whoever runs it connects it to an outside service.

Either way, HopMeds does not keep the photo after reading it. What is saved is the record a member of staff checks and saves, which for a prescription can include the text the scanner read from it.

Two kinds of photo are handled differently. A supplier’s bill that you scan under Suppliers is kept with your accounts as the record of that purchase; where automatic reading of supplier bills is switched on, the bill is also sent to Google’s Gemini API, again only on Google’s paid tier, to read its lines. A payment QR photo is read once, in memory, on the HopMeds server and then discarded: only the text of the QR code is kept, and you can remove it at any time.

HopMeds does not sell pharmacy, clinic or patient records, does not use them for advertising, and does not train AI models on them. Photos are sent to Google only on its paid tier, where Google does not use them to train its models.

4. How information is used

The hosted service does not currently send SMS text messages. Staff can record whether a patient agrees to receive refill reminders by SMS; we will update this policy before any SMS is sent.

5. When information is shared

Service providers

For the hosted service at pharmhops.com we use the service providers below. They process information on our behalf, to provide their service to us.

This means information on the hosted service is stored and processed outside Nepal. We will update this list if a provider changes.

Sharing with other pharmacies and doctors

These features send patient information to a doctor or to another pharmacy. Each one runs only when a user chooses to use it:

These doctors and pharmacies are not HopMeds staff. The pharmacy, clinic or doctor using these features is responsible for getting the patient’s agreement first.

Some business features also show details such as your pharmacy’s name, phone number, district and branch to other pharmacies or to distributors, together with the stock you offer or ask for, when you use them: for example, offering near-expiry stock to other pharmacies, posting a request for a medicine, or connecting to a distributor. They contain no patient information.

Medicine availability

HopMeds keeps an index of the medicines each pharmacy on the hosted service has in stock, and of the stock of local installations that choose to send theirs. It is built automatically: a pharmacy on the hosted service is included without having to switch it on. Doctors using HopMeds and HopMeds platform administrators can search it, and for each pharmacy branch they see the medicine’s name, generic name, strength and form, the quantity in stock, the branch name and district, and the pharmacy’s name and phone number. It contains no patient information.

Other disclosures

Information may also be disclosed when an authorized user exports or shares it, or when Nepali law or a valid legal process requires it.

6. Access by HopMeds platform administrators

Apart from the features described in section 5, a pharmacy or clinic’s records can be seen only by its own staff and by a small number of HopMeds platform administrators, who are our own staff. Platform administrators can see information across all pharmacies and clinics on the hosted service, and use this access to give support, investigate problems and security incidents, review signup applications, arrange doctors for pharmacies and run the platform. They can:

7. Storage, retention and security

Hosted service, including the PharmHops app. Hopmeds Health Tech Pvt. Ltd. runs the service. Records are stored in a managed PostgreSQL database that Render Services, Inc. runs for us in the United States (Oregon). Render keeps short-term point-in-time backups of it, and we also download full copies of the database from time to time and keep them in restricted storage so that we can recover from a disaster. Details deleted from the service can remain in these backups until those copies are replaced or deleted; we use them only to restore the service.

Bills, payments, accounting records and the controlled-medicine register are kept for as long as Nepali tax and drug-control law requires. Deleting a patient hides the record from everyday screens but does not erase it: the patient’s details, and the bills, prescriptions and register entries linked to that patient, stay stored. Signup applications are kept while they are reviewed and may then remain as a record of the approval or rejection. Other records are kept while the pharmacy or clinic’s account is open.

When a pharmacy or clinic closes its HopMeds account, we switch the account off and keep its records until it asks us to delete them. It can write to us at any time, and we will then delete its records, except those that Nepali tax and drug-control law requires us to keep, which we keep only for as long as that law requires. When a staff account is deleted, its personal details are removed or replaced with a code, except the copies described in section 8.

Local installation. A pharmacy that runs HopMeds on its own computer keeps its records there and is responsible for their storage, backup and retention.

The public request form does not collect a password. When an application is approved, we email the applicant a one-time link to set their own password. If that email cannot be sent, a temporary password is shown once to the authorized reviewer instead; HopMeds stores only its hash, and it must be replaced at first sign-in.

Passwords and PINs are stored only as one-way cryptographic hashes. All traffic between your device and the hosted service is encrypted with HTTPS, and the Android app refuses unencrypted connections. Apart from the sharing described in section 5 and the platform administrator access described in section 6, each user sees only their own organization’s records, and what they can see and do depends on their role. No system can guarantee absolute security, so protect your device and your sign-in details, and tell us promptly if you suspect unauthorized access.

8. Access, correction, export and deletion

Authorized users can review and correct records in the app, and can create supported reports and exports. For access, correction or an export you cannot do yourself, email: info@hopmeds.com

Staff account holders can delete their own account: in the app under Settings → Compliance → Delete my account, or without signing in on our account-deletion page: pharmhops.com/delete-account.html

The deletion takes effect 14 days after it is confirmed, and can be cancelled until then by signing in.

Deletion removes the account’s sign-in credentials, sessions, error reports and the submitted details in its activity log, and replaces the name, email and phone number on the account with a random code. The signup application the account was approved from is also replaced with a code, and the licence document uploaded with it is deleted, unless the application must be held for a legal reason.

Bills, payments, the controlled-medicine register, accounting records and patient records belong to the pharmacy or clinic and are kept for as long as Nepali tax and drug-control law requires. Most of them stay linked to the code rather than to a name. Some legal and audit records, however, keep their own copy of the email address of the staff member who made them, and deleting the account does not change it. These include the controlled-medicine register, medicine disposal records, accounting entries, records of printed bill copies, changes to stock batches, and records of connections with distributors. Changes to stock batches also keep the person’s name, and distributor records keep their phone number. The pharmacy's own contact details in its profile, which may be the person's if they set up the account, belong to the pharmacy and are not changed by a deletion. Details removed by a deletion can also remain in the backups described in section 7 until those copies are replaced or deleted.

The last administrator of a pharmacy cannot delete their account alone. To close a whole pharmacy account, email: info@hopmeds.com

Doctors who use HopMeds do not have a staff account. A doctor who wants their details removed can email us; prescriptions and other records the law requires us to keep will still show the doctor’s name and registration number: info@hopmeds.com

If you are a patient, the pharmacy or clinic that treated you holds your record and decides what happens to it, so please ask them first. If you cannot reach them, email us and we will pass your request on: info@hopmeds.com

9. Children

HopMeds is a business tool for pharmacy and clinic staff. It is not a consumer service, it is not directed to children, and its accounts are meant for adults who work in a pharmacy or clinic. A pharmacist or clinician may record a child’s health information as part of that child’s care.

10. Governing law and complaints

This policy and the hosted HopMeds service are governed by the laws of Nepal. You may raise a complaint with the competent authorities in Nepal, but if you think we have mishandled your information, please write to us first: info@hopmeds.com

11. Changes to this policy

We may update this policy as the product or its data practices change. The current version and its “Last updated” date will remain available at this URL.

12. Contact

Hopmeds Health Tech Pvt. Ltd.

Jawalakhel-5, Lalitpur, Nepal

Email: info@hopmeds.com

Phone: +977-9768542410

Delete your account: pharmhops.com/delete-account.html