Who we are
Roborx ("we") builds pharmacy operations and financial software. This policy explains what information we collect, why, who we share it with, and the choices you have.
Contact us through the contact form on roborx.ai. We do not publish direct addresses, because published addresses attract automated mail and bury real requests; the form reaches a monitored queue and privacy requests are routed out of our sales pipeline on arrival.
Who this policy covers
Roborx software is used by pharmacy businesses and their authorized staff. Depending on the product, we handle:
- Business data belonging to our pharmacy customers, including their bank and card account activity.
- Staff data for the individuals who use our applications on behalf of those businesses.
- Patient data, where a product processes it under our customer's direction.
For most data, our pharmacy customer is the controller and Roborx acts as their service provider, processing data on their documented instruction.
Information we collect
Account and identity information — name, work email address, role, and the business you act for. Used to authenticate you and apply the right permissions.
Financial account information, via Plaid — when an authorized person connects a bank or card account, our provider Plaid Inc. establishes the connection and returns account and transaction information to us. We receive account metadata (institution, account type, masked account number) and transaction activity (date, amount, description, category).
We never receive or store your online banking username or password. Those credentials are entered directly into Plaid's interface and are never visible to Roborx.
Usage and technical information — application logs, error reports, and security events such as sign-in attempts. Used to operate, secure, and debug the service.
How we use information
- To provide the service: bank feed ingestion, reconciliation, cash-flow reporting, and accounting workflows.
- To secure the service: authentication, fraud and abuse prevention, audit logging, and incident investigation.
- To support you: responding to requests and diagnosing issues.
- To meet legal obligations, including financial record-keeping requirements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use your financial data to train machine-learning models.
Legal basis and consent
We collect financial account information only after an authorized person affirmatively connects an account. Before the connection is created we present the purpose, the data categories involved, and Plaid's role, and we record the consent — who granted it, what scope, and when. Consent can be withdrawn at any time by disconnecting the account.
Who we share information with
| Category of recipient | Purpose | Data received |
|---|---|---|
| Plaid Inc. | Financial account connectivity | Account connection and transaction data, when you choose to connect an account. Governed by Plaid's end user privacy policy |
| Cloud infrastructure and hosting providers | Running and delivering the service, and storing its data | Application data in transit and at rest |
| Managed database providers | Storing application records | Application records |
| Communications providers | Sending transactional email you have asked for or that the service requires | Recipient address and message content |
Plaid is named because you interact with it directly: when you connect an account, you enter your bank credentials into Plaid's own interface, and their policy governs what they do with them.
The remaining recipients are identified by category. Privacy law requires us to tell you the categories of third party that receive personal information, and that is what this table does. We do not publish the identity, architecture, or configuration of our infrastructure providers, because that information is of more use to someone attacking the service than to someone reading a privacy notice.
You can ask. Request our current subprocessor list through the contact form and we will provide it. Customers and partners can also request it under NDA, together with the security detail that goes with it.
We also disclose information when required by law, and to a successor in a merger or acquisition, in which case we will give notice.
We require every subprocessor handling sensitive data to protect it under terms no less protective than this policy.
How we protect information
All data is encrypted in transit using TLS 1.2 or better, and at rest on our managed storage platforms. Financial access credentials are held in a segregated secret store rather than in our application database. Access is restricted to authorized personnel behind a centralized identity provider with multi-factor authentication, and tenant data is isolated at the database layer. Full detail is in our Information Security Policy and Encryption Standard.
How long we keep information
We keep information only as long as needed for the purpose it was collected or as law requires. Financial transaction records are retained for seven years to meet accounting and tax record obligations; financial access credentials are deleted within seven days of an account being disconnected; security logs are kept for twelve months. Full detail is in our Data Retention and Disposal Policy.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of your personal information, and to withdraw consent. You may also ask us to tell you what categories of information we hold and who we have shared them with.
To exercise any right, use the contact form and select "Privacy request" as the topic. We will acknowledge within 10 business days and respond within 45 days. We will verify your identity first, and we will not discriminate against you for exercising a right.
To report a security vulnerability, use the same form and select "Security".
If a request concerns data we process for a pharmacy customer, we will route it to that customer as the controller and assist them in responding.
Disconnecting an account
You can disconnect a linked financial account at any time from the application. When you do, we remove the connection at Plaid so our access to the institution ends, and we delete the stored credential. Transaction records already ingested are retained only where a financial record-keeping obligation requires it.
Children
Roborx software is business software and is not directed to children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We will post any change here and update the effective date. Material changes will be communicated to affected customers before they take effect.
Contact
Roborx Contact form · roborx.ai