Privacy notice

For the Oswaldtwistle Pharmacy website and app. Last updated 5 October 2026.

This notice explains what personal information we collect through our website and app, why, who we share it with, how long we keep it, and your rights. It covers the website and app only. When you visit the pharmacy in person, or we provide NHS services such as dispensing your prescriptions, our in-store privacy notice also applies; ask us for a copy.

Who we are

, trading as Oswaldtwistle Pharmacy, 300 Union Road, Oswaldtwistle, Accrington, BB5 3JD, is the data controller for the information described here. We are a registered pharmacy (GPhC registration 9010870) and are registered with the Information Commissioner's Office (registration ).

Our data protection lead is . You can contact them about anything in this notice: call 01254 399898, email , or write to us at the address above.

What we collect, and why

WhatWhyOur lawful basis
Your name, mobile number, email and delivery address when you orderTo prepare, deliver or hand over your order, take payment and contact you about itContract; legal obligation (keeping sales records)
What you tell us when you ask to return something (the reason and what's happened), and any refundTo sort out the return, refund or replacement, kept with your orderContract; legal obligation (consumer rights, sales records)
Your mobile number, if you press Notify me on something out of stockTo text you once when it's back in stock (the text doesn't say what it is). Deleted once we've texted you, or after 90 daysConsent (you asked us to)
Answers to health questions when you buy a pharmacy medicineSo a pharmacist can check the medicine is safe and suitable for you, as the law requiresContract and legal obligation; health data: providing health care (UK GDPR Article 9(2)(h))
Appointment and vaccination bookings: your name, date of birth, contact details, GP practice, NHS number if you give it, your answers to eligibility and health questions, and what was done. If we book you by phone or at the counter with just your mobile, we text you a private link to a form for the rest: it shows only your first name, works only for that booking until the end of its day, and what you send goes on your bookingTo provide the service safely, keep a record of the care we gave, and tell your GP or the NHS where the service requires itNHS services: performing a task in the public interest; private services: contract. Health data: providing health care (Article 9(2)(h))
Repeat prescriptions, when you tell us you've ordered one (and where, and whether we're your nominated pharmacy) or ask us to order it: the patient's name, date of birth, mobile number, GP surgery, NHS number if you give it, the medicines and quantities, and a delivery address if you choose deliveryTo look out for the prescription or ask the GP surgery for it (we email the surgery the patient's name, date of birth, NHS number and the medicines, from our secure NHSmail account), get it ready, and tell you when it's readyProviding health care (UK GDPR Article 6(1)(e) and, for health data, Article 9(2)(h))
Prescription reminders, only if you ask for them: the patient's first name, the mobile number, how often the prescription is due, when the next one is due, and when you askedTo remind you about a week before your next repeat prescription is due. The message never names a medicineYour consent, which you can withdraw at any time (the link in every reminder, or ask us)
Checking in when you arrive, on the screen in the pharmacy or on your phone: the patient's name, address and postcode, date of birth if you give it, why you're here (collecting a prescription or a missed delivery), your answers to that visit's questions (such as who you're collecting for, and their name), and any note you add. If you save your details, they go in your profile (below)To let the team know you're here, find your prescription or delivery, and call your number. Waiting-time reports use totals only, never names. The waiting-room screen shows ticket numbers onlyProviding health care (UK GDPR Article 6(1)(e) and, for health data, Article 9(2)(h))
Your saved details and 6-digit code, only if you choose to save them (after checking in, booking, filling in the form we text you, asking for a prescription or registering for a jab) or have an account: your name, date of birth, mobile, email, address, postcode and NHS number if you give them, and when the code was last used. Appointments, check-ins, orders and prescription requests you make for yourself while signed in or with your code are linked to them, and you can see those in Your account. Details you give for someone else (booking for a child, say) are never saved to yoursSo the code, with your postcode, fills your details in at the check-in screen, on our website and in our app, and you don't have to type them again. The list helps the pharmacy team look after youYour choice to save them (contract); the list: providing health care (Article 9(2)(h))
Each year, the pharmacy team looks back at who we've seen, and works out from age and past jabs who looks eligible for an NHS flu or COVID-19 vaccination that season. Before contacting anyone, we check our dispensing records or the NHS Spine. If we know someone has passed away, we keep their name and date of birth so they're never contactedTo invite people who may be eligible for a free NHS jab, so nobody who should be offered one is missed, and never to upset a family by contacting someone who has diedNHS vaccinations: performing a task in the public interest; health data: providing health care (Article 9(2)(h)). Tell us if you'd rather not be invited, and we won't
In our app only, and only if you say yes: your phone works out whether you're at the pharmacy, to offer you the check-in. Your location is checked on your phone and is never sent to us or anyone elseTo offer the check-in as you walk inYour choice; you can turn it off in your phone's settings at any time
The offers list, only if you join it: your mobile number, your first name if you give it, and what you agreed to, when and whereTo text you offers and seasonal health news, no more than twice a monthYour consent, which you can withdraw at any time (the link in every text, or ask us)
Our email newsletter, only if you sign up and confirm: your email address, your first name if you give it, the topics you chose, and what you agreed to, when and where. If you've ordered from us with the same email address, we use that to choose which newsletters go to you (for example, one for recent customers)To email you health news, seasonal advice and offers, no more than twice a monthYour consent, which you can withdraw at any time (the unsubscribe link in every newsletter, or ask us)
A basket reminder, only if you tick “remind me” at checkout: your mobile number, your email and first name if you give them, and what's in your basket (never pharmacy medicines)To send you one text (or email) two hours later if you haven't finished your order, with a link that puts your basket back. It never says what's in itYour consent: untick the box, or place your order, and we delete it
Messages you send us in live chat, and requests for a business accountTo answer youLegitimate interests (helping customers); contract
An account, if you create one: email, name, mobile, your saved details and code (above), and your password stored only as a one-way hash, which nobody can read, our staff includedSo you don't have to type your details each time. If you forget your password, a pharmacist can set a new one for youContract
Loyalty points, gift cards and discount codesTo give you the rewards you've earned or boughtContract
Security records: sign-in attempts and a scrambled (hashed) form of your internet addressTo stop people guessing passwords or flooding the siteLegitimate interests (keeping your information safe)
Only if you agree: which of our public pages you visit, roughly where you came from (such as a Google search), your device type and town or region, through Google Analytics cookiesTo see how people use the site so we can improve itYour consent, which you can withdraw at any time

We only send marketing (our offers texts and email newsletter) to people who've signed up themselves, and anyone can leave at any time. To see which products people look at, the shop counts views, baskets, checkouts and searches by the day without knowing who: no cookies, and nothing is kept on your device. To count each visitor only once a day, the website briefly keeps a scrambled (one-way) version of your internet address and browser, mixed with a random value that changes every day, and deletes it after two days; we can't work out your address from it, and only the day's count is kept (our legitimate interest in understanding how the shop is used). We don't sell your information, we don't use it to make automated decisions about you, and the website and app don't show adverts or follow you around other websites.

Texts and WhatsApp messages

If you give us a mobile number, we may send you messages about your order or appointment, such as a reminder the day before. We send them by WhatsApp where you use it (it's cheaper for us), and otherwise by text. They never say which service or medicine they're about. Reply or call us if you'd rather not get them.

Prescription reminders and offers only go to people who've asked for them. Every one has a link to stop them, and stopping takes effect straight away. Offers always come by text, never WhatsApp, between 9am and 8pm.

Who we share it with

Only the companies that run parts of the service for us, under contracts that only let them use it to do that, and only what each one needs:

  • Netlify, Inc. hosts the website and app and stores the records described above.
  • Twilio sends our texts and WhatsApp messages, and WhatsApp (Meta) delivers the WhatsApp ones. They see your number and the message.
  • Our email provider sends the emails about your order or appointment, and password reset links, if you gave us an email address. It sees your email address and the email: for an order, what you ordered and the total; for an appointment, the time but never what it's for.
  • Stripe takes card payments. You type your card details into Stripe's own secure form; we never see or keep your card number. Stripe is told the amount and your email address (it sends your receipt there), never what you ordered. If you pay with Apple Pay or Google Pay, Apple or Google passes your payment to Stripe in the same way. Stripe also uses payment details to prevent fraud, as its own privacy policy explains. If your business has an account with us, Stripe also sends your invoices, and sees the business name, the email address they go to, and what's on them.
  • Cloudflare checks that forms like booking, sign-up and prescription requests are sent by a person, not a program (Cloudflare Turnstile). It looks at how your browser behaves, not what you type, and sets no cookies.
  • Google runs Google Analytics for us, only if you agree to analytics cookies (see below).
  • Ideal Postcodes finds the addresses for a postcode when you check in, if we've switched the address finder on. It's sent the postcode only, never your name.

Google reviews on our home page. The reviews at the bottom of the home page are public reviews of the pharmacy on Google Maps. When you scroll to them, our server asks Google for the latest ones and passes the reviewers' profile pictures on to you, so your browser doesn't contact Google to show them and nothing about you is sent to Google. We don't keep a copy of the reviews.

Some of these companies are based in, or use systems in, the USA. Where your information is handled outside the UK, it's protected by the safeguards UK law requires, such as the UK International Data Transfer Addendum or the UK-US data bridge.

We also share information when the care we give needs it (for example, asking your GP surgery for a repeat prescription, telling your GP about a vaccination, or recording it on the NHS's own vaccination system), or when the law requires it.

How long we keep it

  • Orders, payments and gift cards: 6 years, for our accounts and tax records.
  • Invoices for card payments (your name, email and, for a delivery, address; what you bought and the VAT): 6 years, as the law requires for VAT records. If you ask us to erase your details, we keep the invoice but remove your name, email and address from it. You can see and print yours on the Track your order page, with your order reference and mobile number.
  • Pharmacy medicine sales and the health answers given: kept with the order, 6 years.
  • Appointments, consultations and vaccinations: as health records, following the NHS Records Management Code of Practice (generally 8 years after your last care for adults, and longer for children).
  • Your account: until you delete it.
  • Live chat: 2 years after the last message. Business account requests: 2 years after we last dealt with them.
  • The vaccine waiting list: 1 year after you joined.
  • Checking in at the pharmacy: 1 year.
  • Your saved details and 6-digit code: until 2 years after you last used them, unless you have an account (then until you delete it). You can ask us to delete them at any time.
  • Repeat prescription requests: 1 year after it was collected, delivered or cancelled. The record of what we dispensed is kept in our dispensing system, as the law requires.
  • Prescription reminders: until you stop them, then 90 days. If you haven't told us about a prescription for a year, they stop and are deleted.
  • The offers list: until you leave it, when you're taken off straight away. If we haven't sent you an offer for a year, you're taken off.
  • The email newsletter: if you don't confirm, 7 days. Then until you unsubscribe, when you're taken off straight away. If we haven't sent you a newsletter for a year, you're taken off.
  • A basket kept for a reminder: 7 days at most, and deleted as soon as you order or untick the box.
  • Which texts and emails we sent you: 90 days (we only keep the last three digits of your number, and the first letter and domain of your email address, in these logs).
  • Password reset links: they work for an hour, and we delete them the next day.
  • Backups: we copy everything once a day so nothing is lost if something goes wrong, and delete each copy after 14 days. If we erase your details, they're gone from the backups 14 days later.
  • Security records: a day for sign-in attempts; a year for our security log, which never holds your contact details.

The shorter periods are cleared automatically each day.

How we keep it safe

Everything travels encrypted (HTTPS). Staff each have their own named account, and only pharmacists can look up, export or erase a customer's records. Passwords are stored only as one-way hashes. Every staff sign-in and every look-up, export or erasure of customer data is recorded in a security log that can't be edited.

Cookies and what's saved on your device

The site keeps your basket, wishlist and preferences in your browser (or the app) so they're there next time; these aren't sent to us until you order. A cookie keeps you signed in if you have an account, and if you tick Remember me on this device when you use your 6-digit code, a cookie called owp_patient fills your details in for a year (Not you? on any form forgets it). Your choice of day or night colours, whether you've seen the "get the app" message, and your answer about the check-in offer in the app are kept in your browser too. These are needed for the site to work, so they don't need your agreement. The check-in screen in the pharmacy remembers its language and accessibility settings, and nothing about you (it never remembers a code): it clears your details from the screen 30 seconds after you've checked in.

Analytics cookies, only if you say yes. We ask before using Google Analytics, and nothing from it runs until you agree. If you do, its cookies (named _ga and _ga_ followed by letters and numbers) last up to 13 months and tell us which of our public pages are used, how people find us, and their device type and rough area. We've set it up so that:

  • it never runs on staff pages, your appointment or order look-ups, or the private links we text you;
  • it isn't told what you search for, your name, phone number, booking references or what you order (only an order's total value);
  • Google can't use it for adverts or link it to your Google account (Google signals and ad personalisation are switched off);
  • Google acts for us under its data processing terms, and may handle the data in the USA, with the safeguards UK law requires.

You can change your mind at any time: . Saying no removes the analytics cookies from this browser.

The fonts on our pages come from our own site, not from other companies. You can clear everything the site saved at any time on the Delete your account or data page.

Your rights

You have the right to:

  • get a copy of the information we hold about you;
  • have anything wrong corrected;
  • have it erased, or its use restricted, where we don't have to keep it (we can't erase a health record we're required to keep, but we can stop using it for anything else);
  • object to how we use it, where we rely on legitimate interests;
  • delete your account yourself at any time, on the Delete your account or data page.

Contact us as shown above. It's free, and we'll reply within one month. We may ask you to prove who you are first.

If you're unhappy with how we've handled your information, please tell us. You can also complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, or call 0303 123 1113.

Your NHS data and the national data opt-out

Information from NHS services we provide may be used, in a form that doesn't identify you where possible, for planning and research. You can choose to stop your confidential information being used this way: see nhs.uk/your-nhs-data-matters. This doesn't affect the care you receive.

Changes to this notice

We'll update this page if anything changes, and change the date at the top.