Privacy Policy

Last updated: April 1, 2026

1. Introduction

Our Mall Pharmacy ("OMP", "we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

2. Information We Collect

2.1 Personal Information

We may collect the following personal information when you use our services:

  • Identity Data: Full name, date of birth, gender
  • Contact Data: Email address, phone number, delivery address
  • Health Data: Prescription details, medication history
  • Financial Data: M-Pesa phone number, payment transaction records
  • Technical Data: IP address, browser type, device information

2.2 Automatically Collected Information

When you access our website, we automatically collect certain information including your IP address, browser type, operating system, referring URLs, and browsing behavior through cookies and similar technologies.

3. How We Use Your Information

We use your personal information to:

  • Process and fulfill your orders and prescriptions
  • Verify prescriptions with healthcare providers
  • Process payments through M-Pesa and other payment gateways
  • Provide pharmacist consultation services
  • Send order updates and delivery notifications
  • Send refill reminders for recurring medications
  • Improve our services, website, and user experience
  • Comply with legal and regulatory obligations under Kenyan law

4. Data Protection

We implement industry-standard security measures to protect your personal information, including:

  • SSL/TLS encryption for all data transmission
  • Encrypted storage of prescription images and health data
  • Secure M-Pesa integration through Safaricom Daraja API
  • Role-based access control for staff handling sensitive data
  • Regular security audits and vulnerability assessments

5. Prescription Data

Your prescription data is treated with the highest level of confidentiality in accordance with the Pharmacy and Poisons Act (Cap 244) of Kenya. Prescription images are stored in encrypted, access-controlled storage and are only accessible to licensed pharmacists involved in fulfilling your order.

6. Third-Party Sharing

We may share your information with:

  • Delivery Partners: Name and address for order fulfillment
  • Payment Processors: Safaricom (M-Pesa), Visa/Mastercard processors
  • Healthcare Partners: Only with your explicit consent for prescription processing
  • Regulatory Bodies: When required by law (PPB, Ministry of Health)

We will never sell your personal information to third parties.

7. Your Rights

Under the Kenya Data Protection Act (2019), you have the right to:

  • Access your personal data held by us
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal retention requirements)
  • Object to processing of your data for marketing purposes
  • Data portability — receive your data in a structured format

8. Cookies

We use essential cookies to ensure our website functions properly, and analytics cookies to understand how visitors interact with our site. You can control cookie preferences through your browser settings.

9. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy. Prescription records are retained for a minimum of 5 years as required by Kenyan pharmaceutical regulations.

10. Contact Us

For any privacy-related inquiries, please contact our Data Protection Officer:

  • Email: ourmallpharmacy@gmail.com
  • Phone: +254 722 390 003
  • Address: Our Mall, Off Magadi Rd, Avocado Lane, Ground Floor (Shop No. 22)