Privacy Policy
Last updated: 04/05/2026
Privacy Policy
Wolverhampton Road Pharmacy (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, store, and share personal data when you use our website and pharmacy services, including NHS services where applicable, private pharmacy services, online consultations, prescription processing, payment, and delivery.
We operate as a regulated UK community pharmacy and process personal and health information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, professional pharmacy standards, and applicable healthcare confidentiality obligations.
Medical urgency: If you require urgent medical help, contact NHS 111. In an emergency, call 999.
1. Who we are
Wolverhampton Road Pharmacy is the data controller for personal data collected through this website and for personal data processed when we provide pharmacy services, dispensing, payment handling, and delivery.
Pharmacy name: Wolverhampton Road Pharmacy
Address: 112 Wolverhampton Rd, Stafford, ST17 4AH
Email: info@wolverhamptonroadpharmacy.com
GPhC premises registration: 1036989
As a regulated pharmacy, we are required to process and retain certain information for clinical safety, dispensing records, governance, audit, legal compliance, and professional obligations.
2. What this Privacy Policy covers
This Privacy Policy applies when you:
- visit or use our website;
- contact us by email, phone, online form, or other communication method;
- request NHS or private pharmacy services;
- complete an online consultation, assessment, or medical questionnaire;
- submit or arrange a private prescription for dispensing;
- make a payment after clinical or service approval, where applicable;
- receive medicines by post, courier, or local delivery;
- raise an enquiry, refund request, complaint, dispute, or chargeback.
3. Online consultations and third-party providers
For some private services, online consultations may be provided by a third-party consultation, clinical, or prescribing provider. These providers may act as independent data controllers for the consultation, medical assessment, prescribing decision, and related clinical records.
Where a prescription is issued and sent to Wolverhampton Road Pharmacy for dispensing, we act as data controller for the pharmacy services we provide, including dispensing, pharmacy checks, payment processing, supply, delivery, record keeping, and any related patient support.
Third-party consultation provider currently referenced:
Sinclair Method UK
Where a third-party provider is involved, you should also read their own privacy notice and terms, as they may explain separately how they collect and use your consultation and medical information.
4. Personal data we collect
Depending on the service you use, we may collect the following types of information.
Identity and contact information
Name, address, email address, phone number, date of birth, and other information needed to identify you and provide pharmacy services safely.
Health and consultation information
Medical history, symptoms, allergies, current medicines, previous medicines, lifestyle information, consultation answers, prescribing information, and other details relevant to clinical safety.
Health information is special category data under UK data protection law and is handled with additional care and safeguards.
Prescription and dispensing records
Prescription details, dispensing records, pharmacist checks, clinical notes, intervention records, audit records, and records stored in our Pharmacy Management Record (PMR) system.
Payment and transaction information
Order references, payment status, transaction identifiers, payment method type, payment confirmation, refund information, dispute information, and chargeback-related information where applicable.
We do not store full card numbers or full card security details on our website. Card payments are securely processed through our approved payment gateway provider.
Delivery information
Delivery name, delivery address, delivery instructions, tracking number, delivery status, proof of delivery, and related communication records.
Technical and security information
IP address, device and browser information, website logs, timestamps, security logs, fraud prevention signals, and records of how the website is accessed and used.
5. How we use your personal data
We use personal data to:
- provide safe and appropriate pharmacy services;
- review prescription, consultation, and patient information where required;
- dispense medicines where clinically and legally appropriate;
- carry out pharmacist checks and clinical safety checks;
- maintain pharmacy records for patient safety, legal compliance, audit, and governance;
- process payments after approval where applicable;
- confirm orders, payment status, refunds, and transaction outcomes;
- arrange delivery and provide delivery or tracking updates;
- respond to enquiries, complaints, refund requests, disputes, and chargebacks;
- prevent fraud, misuse, unauthorised transactions, and abuse of pharmacy services;
- protect patients, the public, our staff, and the pharmacy business;
- comply with legal, regulatory, tax, accounting, and professional obligations.
6. Legal basis for processing
We process personal data under one or more of the following lawful bases:
- Contract: where processing is necessary to provide services you request or to take steps before providing those services.
- Legal obligation: where processing is necessary to comply with pharmacy, healthcare, tax, accounting, regulatory, or legal requirements.
- Legitimate interests: where processing is necessary to operate the pharmacy, manage the website, prevent fraud, protect against misuse, handle disputes, and protect patients and the business.
- Consent: where consent is required for optional activities, such as certain types of marketing or non-essential cookies.
Where we process health data, we also rely on an additional special category condition, such as processing necessary for the provision of healthcare or treatment, the management of healthcare services, or compliance with legal and professional obligations.
7. Payments, Pixxles, fraud prevention, and chargebacks
Payments made through our website are processed securely through the Pixxles payment gateway integrated with WooCommerce. Pixxles is our approved payment gateway provider for online website payments.
Customers can pay at checkout using accepted Visa, credit card, or debit card payments. Apple Pay, Google Pay, and account-to-account payment methods are not currently offered through our website checkout.
Pixxles uses secure card payment processing, including 3D Secure authentication where required or supported. Payment information may be processed by Pixxles for payment authorisation, transaction processing, settlement, fraud prevention, security monitoring, refunds, dispute handling, and chargeback management.
Payment gateway provider: Pixxles
Website payment system: WooCommerce checkout integrated with Pixxles
Accepted payment methods: Visa, credit card, and debit card payments
Security: Secure card processing with 3D Secure authentication where applicable
To protect patients, cardholders, and the pharmacy business:
- payment may only be requested or accepted after appropriate clinical, prescription, or service approval where applicable;
- we may refuse, cancel, or refund an order where supply is not clinically appropriate, legally permitted, safely deliverable, or operationally possible;
- we may maintain transaction records, order records, audit trails, payment confirmations, refund records, and delivery evidence;
- we may use fraud prevention and security checks to detect suspicious, abusive, unauthorised, or high-risk activity;
- we may verify identity, address, payment, delivery, prescription, or consultation information where necessary;
- we may share relevant order, payment, delivery, consultation status, communication, and audit evidence with Pixxles, card schemes, banks, fraud prevention partners, legal advisers, or dispute-handling bodies where necessary to investigate or respond to refunds, disputes, suspected fraud, unauthorised transactions, or chargebacks;
- we may retain relevant records for pharmacy governance, accounting, regulatory, legal, complaint, dispute, fraud prevention, and chargeback purposes.
We do not store full card numbers or card security codes on our website. These details are handled securely by the payment gateway and relevant payment processing partners.
We do not use payment information for health advertising, and we do not sell patient or customer data.
8. Who we share data with
We share personal data only where necessary and appropriate. This may include sharing information with:
- payment providers, including Pixxles, for payment processing, fraud prevention, refunds, disputes, and chargebacks;
- delivery partners such as Royal Mail, courier providers, or local delivery services for delivery and tracking;
- pharmacy systems, PMR providers, and dispensing software providers for lawful pharmacy record keeping;
- website hosting, email, IT, analytics, and security providers;
- third-party consultation, clinical, or prescribing providers where applicable;
- NHS services or healthcare professionals where required or appropriate for patient care;
- regulators, law enforcement, professional bodies, courts, insurers, or legal advisers where required by law or necessary to protect rights, safety, or the pharmacy business.
We do not sell personal data. We do not use health data for advertising.
9. Data retention
We keep personal data only for as long as necessary for patient safety, pharmacy governance, legal compliance, accounting, dispute handling, and operational needs.
- Clinical, prescription, and dispensing records are kept in line with pharmacy governance, professional, and legal requirements.
- Order, payment, refund, accounting, and transaction records are usually kept for up to 6 years where required for tax, accounting, audit, legal, or dispute purposes.
- Consultation records that do not result in supply may be kept for a limited period for patient safety, audit, complaint handling, and clinical governance purposes.
- Security logs are usually kept for a shorter period unless needed to investigate fraud, misuse, security incidents, complaints, or legal claims.
Data is securely deleted, anonymised, or archived when it is no longer required.
10. International processing
Our services are primarily intended for users in the United Kingdom. Some service providers may process personal data outside the UK. Where this happens, we take steps to ensure appropriate safeguards are in place in line with UK data protection law.
11. Security
We use appropriate technical and organisational measures to protect personal data, including secure hosting, encryption in transit, access controls, staff confidentiality obligations, audit records, and appropriate supplier controls.
No website, email system, or online service can be guaranteed to be completely secure. If you believe your data, account, payment, prescription, or order information may be at risk, please contact us immediately.
12. Your rights
You have rights under UK data protection law, including the right to request access to your personal data and, in certain circumstances, to request correction, restriction, objection, portability, or deletion.
Some rights may be limited where we are required to keep records for patient safety, pharmacy regulation, legal compliance, dispute handling, or professional obligations.
To exercise your rights, contact us at info@wolverhamptonroadpharmacy.com. We may request identity verification before responding to protect patient confidentiality and safety.
13. Marketing and cookies
We will not use your health information for marketing. We will only send marketing communications where permitted by law and, where required, with your consent.
Our website may use essential cookies to operate securely and, where enabled, optional cookies for analytics or user experience. Optional cookies should only be used where the correct cookie notice and consent controls are in place.
14. Complaints
If you have concerns about how your data is handled, please contact us first so we can investigate and respond.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office (ICO)
https://ico.org.uk/make-a-complaint/
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, payment providers, legal requirements, pharmacy operations, or website functionality.