At Rx Foundry, Inc. (“Rx Foundry,” “we,” “us,” or “our”), we understand that in the pharmacy technology space, data security and patient privacy are paramount. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our website, our Swifty Rx platform, and our related sales, marketing, and support activities (collectively, the “Services”). This Policy applies to personal information relating to our business customers, prospective customers, website visitors, and other individuals who interact with us in a business or professional capacity. It does not apply to Protected Health Information, as described in Section 1 below.Please read this Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood this Policy.
1. Our Role: Business Data vs. Protected Health Information (PHI)Because Swifty Rx operates in the healthcare software industry, it is critical to distinguish between two categories of data we handle, each governed by a different legal framework:
• Protected Health Information (PHI). When our B2B customers (pharmacies, health systems, and other healthcare providers) use Swifty Rx to process patient data, prescriptions, or medical records, that information constitutes PHI under the Health Insurance Portability and Accountability Act (“HIPAA”). In these instances, our customers act as Covered Entities (or, under applicable state law, Data Controllers), and Rx Foundry acts solely as their Business Associate (or Data Processor). Our creation, receipt, maintenance, and transmission of PHI is governed exclusively by HIPAA and the Business Associate Agreement (“BAA”) executed with each customer — not by this Privacy Policy. We do not use PHI for our own marketing purposes, and we do not sell PHI to any third party.
• Corporate and Business Data. This Privacy Policy governs the personal information we collect and process as a Data Controller (or “Business” under applicable state law) when you interact with Rx Foundry directly as a business professional — for example, by visiting our website, requesting a demo, communicating with our sales or support teams, or administering your organization's Swifty Rx account.If you are unsure which category applies to your information, please see Section 9, particularly if you are a patient of a pharmacy that uses Swifty Rx.
2. Information We Collect:
A. Information You Provide to Us
• Business Contact Information: name, business email address, phone number, employer/pharmacy name, job title, and mailing address.
• Account Credentials: usernames, passwords, and other authentication credentials used to access the Swifty Rx platform.
• Billing and Payment Information: billing contact details and payment information necessary to process corporate software subscriptions (payment card data is processed by our PCI-compliant payment processor and is not stored on our systems).
• Support and Communications: information you provide when contacting our sales, support, or account management teams, including the content of your inquiries.
• Event and Marketing Information: information provided when registering for webinars, conferences, or requesting marketing materials.
B. Information Collected Automatically
• Device and Log Data: IP address, browser type and version, device identifiers, operating system, referring/exit pages, and access timestamps.
• Usage Data: information about how authorized users navigate and interact with the Swifty Rx interface, used to optimize workflows and platform stability.
• Cookies and Similar Technologies: as described in Section 4 below.
C. Information from Other SourcesWe may also receive business contact information from third parties, such as marketing partners, data enrichment providers, resellers, or publicly available professional sources (e.g., LinkedIn), to help us identify and reach prospective customers.
D. California CCPA Data Categories (Preceding 12 Months) For residents of California, the CCPA requires us to disclose the specific statutory categories of personal information we have collected and disclosed for a business purpose in the preceding 12 months. We do not sell or share personal information for cross-context behavioral advertising, and have not done so in the preceding 12 months.
● Identifiers (e.g., name, email address, IP address, account username). Collected and disclosed to service providers.
● Personal Information under Cal. Civ. Code § 1798.80 (e.g., phone number, mailing address, employment information). Collected and disclosed to service providers.
● Commercial Information (e.g., products or services purchased, billing records). Collected and disclosed to billing processors.
● Internet or Other Electronic Network Activity (e.g., browsing history, interaction with the Swifty Rx platform). Collected and disclosed to analytics providers and cloud hosts.
● Sensitive Personal Information (e.g., Swifty Rx account login and password). Collected and disclosed to cloud hosting and security providers solely to provide the Services.
3. How We Use Your InformationWe use business and corporate personal information for the following purposes:
• Service Delivery: provisioning Swifty Rx accounts, authenticating authorized users, and processing billing.
• Customer Support and Training: resolving technical issues, providing onboarding, and responding to inquiries.
• Platform Improvement: analyzing usage trends to improve the performance, security, and functionality of Swifty Rx.
• Marketing and Communications: sending product updates, security notices, newsletters, and (where permitted by law) promotional communications about new Rx Foundry offerings. You may opt out of marketing communications at any time (see Section 9).
• Legal Compliance and Enforcement: enforcing our Terms of Service, detecting fraud or security incidents, and complying with applicable law, regulation, or legal process.
• Business Operations: internal recordkeeping, auditing, and corporate governance.We do not use business or corporate personal information for automated decision-making that produces legal or similarly significant effects without human involvement.
4. Cookies, Analytics, and Online Tracking TechnologiesOur website and platform use cookies, pixels, and similar tracking technologies to operate securely, remember preferences, and analyze traffic. We use:
• Strictly Necessary Cookies to enable core site and platform functionality;
• Analytics Cookies to understand aggregate usage patterns; and
• Preference Cookies to remember your settings. You can control cookies through your browser settings. Where required by law, we will honor opt-out preference signals, including the Global Privacy Control (“GPC”), as a valid request to opt out of the “sale” or “sharing” of personal information for targeted advertising. We do not currently respond to browser Do Not Track signals other than GPC, as no uniform industry standard for DNT has been adopted.
5. How We Disclose Your InformationRx Foundry does not sell personal information for money, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under applicable state law. We disclose corporate and business personal information only in the following circumstances:
• Service Providers: We engage third-party service providers and sub-processors — including cloud hosting providers (e.g., AWS, Azure), customer relationship management (CRM) platforms, billing processors, and analytics vendors — to help operate our business. These providers are contractually bound to use personal information only as directed by us and to maintain appropriate security safeguards.
• Legal and Safety Reasons: We may disclose information where required by law, subpoena, or court order, or where we believe disclosure is necessary to protect the rights, property, or safety of Rx Foundry, our customers, or the public.
• Business Transfers: If Rx Foundry is involved in a merger, acquisition, financing, or sale of assets, business contact information may be transferred as part of that transaction, subject to continued privacy protections consistent with this Policy.
• With Your Consent: We may disclose information for any other purpose with your consent.
6. Data RetentionWe retain business and corporate personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy. Because retention needs vary by data type, we apply the following criteria:
● Account Credentials & Business Contact Information: Retained for the lifespan of your active Swifty Rx subscription, plus a reasonable transition period to allow for account reactivation, unless earlier deletion is requested.
● Billing and Payment Information: Retained for the duration of the customer relationship and up to seven (7) years thereafter to satisfy tax, accounting, and legal auditing obligations.
● Device, Log, and Usage Data: Retained in identifiable format for up to 12 months for security and troubleshooting purposes, after which it is aggregated or securely deleted.
● Event and Marketing Information: Retained until you opt out of marketing communications or request deletion.When personal information is no longer needed based on these criteria, we securely delete or de-identify it in accordance with our internal data retention procedures. We retain business and corporate personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy, including maintaining your active subscription, providing support, satisfying tax and accounting obligations, and enforcing our agreements. When personal information is no longer needed, we securely delete or de-identify it in accordance with our internal data retention procedures.Retention and deletion of PHI processed through Swifty Rx on behalf of our pharmacy customers is governed exclusively by the terms of the applicable Business Associate Agreement, not this Policy.
7. Data SecurityGiven our footprint in the pharmacy sector, security is a top priority for Rx Foundry. We maintain administrative, technical, and physical safeguards designed to protect both PHI (as required by HIPAA) and business personal information, including encryption of data in transit and at rest, role-based access controls, multi-factor authentication (MFA), network monitoring, and periodic security assessments. No system can be guaranteed 100% secure; if we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law.
8. Children's PrivacyThe Services are directed to business professionals and are not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us using the information in Section 11 so that we may delete it.
9. Your Privacy RightsDepending on your state of residence, you may have certain rights under applicable U.S. state privacy laws — which may include, among others, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and comparable laws in states such as Colorado, Connecticut, Virginia, and Utah — with respect to the business personal information we hold about you. These rights may include the right to:
• Know/Access the categories and specific pieces of personal information we have collected about you;
• Correct inaccurate personal information;
• Delete personal information we maintain about you, subject to certain exceptions;
• Opt Out of the sale or sharing of personal information (we do not currently engage in either activity) or of targeted advertising;
• Non-Discrimination for exercising any of these rights; and
• Appeal a decision we make in response to your request, in applicable states.
• Limit the Use of Sensitive Personal Information: The right to direct us to limit our use or disclosure of your sensitive personal information (such as your account log-in credentials) to only what is strictly necessary to perform the services or provide the goods reasonably expected by an average consumer. To submit a request, please contact us using the contact form at the bottom of this page or submit a request to privacy@rxfoundry.com. We will verify your identity before processing your request and will respond within the time period required by applicable law. You may designate an authorized agent to submit a request on your behalf, subject to verification. Important Note for Pharmacy Patients: If you are a patient of a pharmacy or healthcare provider that uses Swifty Rx, Rx Foundry is not able to respond directly to requests regarding your health records or prescriptions, because we act only as a Business Associate/Processor to that pharmacy. Please contact your pharmacy or healthcare provider directly to exercise
rights regarding your PHI.
10. Changes to This PolicyWe may update this Privacy Policy periodically to reflect changes in our practices or applicable law. We will indicate the date of the most recent revision by updating the “Effective Date” above and, where changes are material, will provide additional notice as required by law (e.g., via email or a notice on the Swifty Rx platform).
11. Contact UsIf you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:
● Email: privacy@rxfoundry.com
● Web Form: at the bottom of the page
We will verify your identity before processing your request and will respond within the 45-day time period required by applicable law (extendable by an additional 45 days if reasonably necessary).
If you have questions about our Privacy Policy, would like to contact our Data Protection Office, or have another inquiry, we’d like to hear from you. Please use the form below.