Privacy Policy
Last updated: May 2026
Ailaaj Pharmacy (Pvt) Ltd ("Ailaaj", "we", "us") is a DRAP-licensed online pharmacy. This policy explains how we collect, use, share and protect your personal and health information when you use our website, mobile app or services.
1. Information we collect
- Account data — name, email, phone, date of birth, gender, password.
- Health data — prescriptions you upload, doctor details, conditions you tell us about, and order history of medicines.
- Payment data — payment method, last 4 digits of cards, billing address. Full card numbers are tokenised by our PCI-DSS Level 1 payment processor and never stored by Ailaaj.
- Delivery data — addresses, location at the time of delivery, delivery instructions.
- Device & usage data — IP address, device type, browser, pages viewed, cookies, and analytics events.
2. How we use your information
- Process and deliver your orders, including pharmacist verification of Rx items.
- Operate subscriptions, refill reminders and recurring charges with your authorisation.
- Provide customer service, respond to queries and resolve complaints.
- Detect fraud, abuse and protect the security of our platform.
- Comply with legal obligations under DRAP, taxation and consumer protection law.
- Send service messages (always) and marketing messages (only with your consent).
3. How we share your information
- Couriers and riders — name, phone, address and order summary, only as needed to deliver.
- Pharmacists & doctors — clinical detail required for safe dispensing or tele-consult.
- Payment processors — to charge your selected method and process refunds.
- Regulators — DRAP, tax authorities or law enforcement where legally required.
- We do not sell your personal or health data to advertisers.
4. Data retention
We retain order and prescription records for at least 5 years to comply with DRAP record- keeping requirements. Account data is retained while your account is active and for up to 18 months after closure for fraud and legal purposes, after which it is deleted or anonymised.
5. Your rights
- Access — request a copy of the data we hold about you.
- Correction — fix inaccurate or outdated information.
- Deletion — request erasure where retention is not legally required.
- Withdraw consent — opt out of marketing or recurring charges at any time.
- Lodge a complaint with our Data Protection Officer.
6. Cookies and analytics
We use first- and third-party cookies for session management, preferences, analytics and measuring marketing performance. You can manage cookies in your browser; disabling them may break parts of the site.
7. Security
All traffic is encrypted in transit (TLS 1.2+). Health data is access-restricted and audit-logged. We follow PCI-DSS for payment data and ISO 27001-aligned controls for information security.
8. Children
Ailaaj is intended for users 18 and older. Parents may order on behalf of minors with valid prescriptions. We do not knowingly market to children.
9. Changes to this policy
We will notify you of material changes by email or in-app at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
10. Contact
Data Protection Officer · Ailaaj Pharmacy (Pvt) Ltd
Plot 12, Tech Park, Karachi 75500 · dpo@ailaaj.com · 021-111-AILAAJ
