Skip to content
NotchRx

Privacy

How we handle information.

Short, specific, and written to be read. If anything here is unclear, ask us and we will answer directly rather than pointing at a clause.

Last updated August 23, 2026

What this page covers

This notice describes how NotchRx handles information collected through notchrx.com. Use of the NotchRx product at app.notchrx.com is governed by the agreement between NotchRx and the organization that provisioned your account.

What this website collects

This site uses privacy-preserving analytics to count page views and understand which sections are read. It does not identify individual visitors, and it does not use advertising cookies or cross-site tracking.

If you write to us through the contact page, the message is composed in your own email client and sent directly to us. We hold what you chose to put in it, and use it only to reply to you.

What the product holds

NotchRx holds compliance records on behalf of the pharmacies, chains, and enterprises that use it: policies and their versions, acknowledgments, credentials and their scans, task completion and proof, screening determinations, and an audit trail of administrative actions.

Some information is deliberately not held. The identifier used to confirm an exclusion match is entered on the government's own site and never into NotchRx. Dates of birth published in the OIG exclusion file are discarded when the file is imported.

A scan of a license carries a name, a number, and often a signature. Only a pharmacy administrator, or the person who uploaded it, can open the file.

Retention

Compliance history is retained deliberately. Removing somebody from a roster marks them terminated rather than deleting them, and their acknowledgments and activity stay in the audit trail, because a record that can be erased is not evidence. Turning off a module stops new records being written; it does not delete what is already on file.

Your choices

Anyone with an active NotchRx account can update their own name and employee ID from Settings, and can deactivate their own account there. Deactivation is not deletion: the account is disabled and sessions are ended, and compliance history remains.

For any other request about information we hold, write to privacy@notchrx.com and we will respond.

Changes

If this notice changes materially, the date below changes with it. This is a working document for a product still in active development, and we would rather revise it plainly than leave it vague.

Questions about this notice: privacy@notchrx.com