Privacy Policy
How we collect, secure, and process your account and billing data
Last updated: June 13, 20261. Account Data & Information Collection
When you register or log in to PharmNode, we collect basic account details using third-party OAuth providers (Google and GitHub). This includes your public profile information such as name, email address, profile picture, and provider identifier.
We collect this information strictly to manage your user account, authorize access to your personal formulation workspace, and persist your custom ingredient definitions across sessions. We do not solicit or purchase list broker databases.
3. Payment & Billing Information (Paddle)
All financial transactions, subscriptions, invoices, and payments on PharmNode are handled exclusively by Paddle, our Merchant of Record. Paddle processes your billing details in full compliance with PCI-DSS standards.
PharmNode does not receive, process, or store your credit card numbers, billing addresses, or bank details. We only process secure server-to-server webhook events sent by Paddle. These notifications contain the subscription ID, active tier state, renewal dates, and billing portal links which are stored in our PostgreSQL database to grant Professional access rights.
4. Cryptographic Security & Form Isolation
We employ strict security measures to protect your digital pharmaceutical designs and account details. All data transmitted between your browser and our platform is encrypted in transit using Transport Layer Security (TLS) and HTTPS protocol.
User recipe formulations, canvas node coordinates, and custom ingredient rules are isolated inside our relational PostgreSQL database. We implement strict multi-tenant constraints at the database query layer to prevent accidental exposure of raw formula data to other users.