Privacy Policy

Last updated: March 14, 2026

1. Overview

RxText ("we", "our", "us") provides HIPAA-compliant texting and payment services for independent pharmacies. This Privacy Policy describes how we collect, use, and protect information when you use our platform at rx-text.com.

2. Information We Collect

We collect information necessary to provide our services:

  • Pharmacy staff: name, email, role, and authentication credentials via Clerk.
  • Patient data: name, phone number, consent status, and communication history as entered by pharmacy staff.
  • Payment data: transaction amounts, descriptions, and payment status. Card details are handled directly by Stripe and never stored on our servers.
  • Usage data: IP addresses, browser information, and audit logs for security and compliance.

3. HIPAA Compliance

RxText is designed to handle Protected Health Information (PHI) in compliance with HIPAA regulations. We execute Business Associate Agreements (BAAs) with all customers and maintain BAAs with our subprocessors. All PHI is encrypted in transit (TLS 1.2+) and at rest. Access to PHI is logged in an immutable audit trail.

4. How We Use Information

  • To send and receive SMS messages on behalf of pharmacies.
  • To process payment collections via Stripe Connect.
  • To maintain compliance audit logs.
  • To enforce patient consent preferences (opt-in/opt-out).
  • To improve and secure our platform.

5. Subprocessors

We use the following third-party services to operate RxText:

  • Clerk - Authentication and user management (BAA in place)
  • Supabase - Database hosting (BAA in place)
  • Stripe - Payment processing (BAA in place)
  • Twilio / Telnyx - SMS messaging (BAA in place)
  • Vercel - Application hosting (BAA in place)

6. Data Retention

Patient data is retained for the duration of the pharmacy's account plus 6 years for HIPAA compliance. Deleted patient records are soft-deleted (marked inactive) and retained in the database for audit purposes. Audit logs are immutable and retained indefinitely.

7. Patient Rights

Patients can opt out of SMS communications at any time by replying STOP to any message. Pharmacies can export all patient data through the compliance dashboard for Right of Access requests. Patients do not create accounts on RxText - all data is managed by their pharmacy.

8. Contact

For privacy inquiries or data requests, contact us at privacy@rx-text.com or visit our contact page.