Privacy Policy
The Trost · Privacy Notice
Privacy Policy
Prescription review, personal data, and your rights
1. Introduction
Herbidus Formulations Private Limited ("we", "us", or "Company"), trading as The Trost, operates the website https://thetrost.com/ ("Website"). This Privacy Policy explains how we collect, use, store, disclose, and safeguard your personal data when you use our Website, purchase our Products, or take part in our prescription review process.
Some of the products we sell require a prescription review by a registered medical practitioner before we are able to dispatch them. If you order such a product, we will collect and process health-adjacent information about you. Sections 2.3, 3 and 4 explain exactly what we collect, why, and on what basis.
This Policy is governed by the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable laws of India. By using our Website, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of our Website.
Data Fiduciary: Herbidus Formulations Private Limited, CIN: U24232DL2020PTC369976; GSTIN: 07AAFCH4440M1ZF, 2nd Floor, 12/22, East Patel Nagar, New Delhi, Delhi 110008, India. Contact: info@thetrost.com.
2. Information We Collect
2.1 Information You Provide
- Name, email address, postal address, and date of birth when you register or place an order
- Phone number for order updates, delivery coordination, and — where a prescription review is required — the consultation call
- Language and communication preferences
- Any other information voluntarily submitted via forms, surveys, or customer support interactions
2.2 Information Collected Automatically
- IP address, browser type, operating system, and device information
- Pages visited, referring URLs, and navigation behaviour on our Website
- Cookie and tracking data (see Section 10)
2.3 Health-Adjacent Information Collected for Prescription Review
If your order contains a product that is classified as requiring a prescription, a doctor assigned by us will contact you by telephone. In connection with that review we collect and record:
- your age, and your sex where the doctor considers it clinically necessary;
- the symptoms or complaints you describe, relevant history you choose to share, and the advice, clinical notes, and decision the doctor records;
- your consent or refusal to proceed, the date, time, language and outcome of each call attempt, and the identity of the doctor assigned to you;
- the prescription itself — the products prescribed, dosage, duration, date of issue and validity, the issued PDF document, and the issuing doctor’s professional details and signature;
- evidence that the prescription was delivered to you, and the resulting decision to release or hold your order for dispatch;
- audit, access, security and grievance records needed to operate, protect and account for this process.
We treat this as the most sensitive category of data we hold and restrict it accordingly, as described in Section 6.
2.4 What We Do Not Collect
- We do not record consultation calls. No audio recording of your call with the doctor is made or stored.
- The prescription system does not accept file uploads from customers. Please do not send us prescriptions, diagnostic reports, scans, or medical files.
- We do not collect Aadhaar or other government identification images, or biometric information.
- We do not store credit card, debit card, or banking information. Payment transactions are processed directly by our payment gateway partners.
- We do not collect your delivery address into the prescription system, and we do not ask for medical history unrelated to the product you have ordered. Please do not provide identity or medical information beyond what the doctor asks for.
3. How the Prescription Review Works
- Classification. When you place an order, we check whether any item in it is classified as requiring a prescription. If none is, none of the processing described in this Section applies to your order.
- Doctor assignment and call. If a review is required, your order is assigned to a registered doctor, who calls you on the phone number captured with your order. At the start of the call the doctor identifies themselves and The Trost, explains that the consultation is taking place remotely, and asks for your consent before any clinical discussion.
- Adults only. This process is intended for an adult patient acting for themselves. If the patient is under 18, is represented by another person, or cannot be verified as required, we stop and escalate the order internally rather than issue a prescription.
- Issue or reuse. Where clinically appropriate, the doctor issues a prescription. A prescription issued through this process is valid for six months from its date of issue. If you already hold a valid prescription that covers every relevant item in a new order, we may reuse it rather than call you again.
- Who issues it. Prescriptions are issued by a medical practitioner registered with the applicable professional council or authority. The practitioner’s name, qualification, and registration number appear on the prescription document itself.
- Delivery. The prescription PDF is emailed to you automatically from the issuing doctor’s The Trost Workspace mailbox, to the email address verified on your order. If your order has no usable email address, it remains on hold until a doctor or the founder records an approved alternative delivery method and confirmation.
- Dispatch. An order that requires a prescription is not dispatched until the prescription has been issued and its delivery evidenced. If you refuse consent, if the doctor is unable to reach you after three call attempts, or if the doctor declines to prescribe, the order will not be released and our team will contact you about cancellation or next steps.
- Clinical judgement. The doctor may decide that a telephone consultation is not clinically sufficient, and may ask you to attend a video or in-person review, refer you elsewhere, or decline to prescribe.
4. Lawful Basis and Consent
We process your order, contact and payment-status data in order to perform your purchase and to meet our legal, tax and accounting obligations.
By placing an order for a product that requires a prescription review, you consent to our processing of the consultation and prescription data described in Section 2.3 for that review. This notice is referenced at checkout for orders that require a review. At the start of the consultation call, the doctor confirms your consent before any clinical discussion takes place, and the system records the consent outcome. Consent to the prescription review is not bundled with consent to marketing, and you can decline marketing independently.
You may refuse consent, or withdraw it at any time before a prescription is issued, by telling the doctor during the call or writing to info@thetrost.com. Withdrawal is as straightforward as giving consent. Withdrawing consent does not affect processing already lawfully carried out.
Consequence of refusal or withdrawal: we will not be able to complete the prescription review, and we will not be able to dispatch the affected order. Our team will contact you about cancellation. If you do not provide the identity, contact or clinical information the doctor reasonably needs, the same consequence applies.
Once a prescription has been issued, it is a professional medical record. We may be required to retain it even after you withdraw consent — see Section 9.
5. How We Use Your Information
We process your personal data only for lawful purposes, including:
- Processing and fulfilling your orders, including payment and delivery coordination
- Determining whether an ordered product requires a prescription review
- Assigning the review to a doctor, enabling the doctor to contact you, assess the request, record consent, advise, refer, refuse, issue, amend, revoke, or reuse a valid prescription
- Delivering the prescription to you and recording evidence of that delivery
- Holding an order that remains clinically or operationally unresolved, and releasing it for dispatch only once the required evidence exists
- Creating and managing your account on the Website
- Sending transactional communications (order confirmations, shipping updates, invoices)
- Sending promotional communications, newsletters, and offers, where you have consented
- Personalising your Website experience based on your preferences
- Conducting internal research, analytics, and service improvement
- Detecting, preventing, and investigating fraud, errors, or criminal activity
- Securing, auditing, troubleshooting and recovering the service; responding to access, correction, grievance and clinical-record requests
- Complying with legal obligations, court orders, or government directives
We do not use consultation or prescription information for advertising or marketing, and we do not sell it. Consultation and prescription data is not used to train any artificial intelligence model and is not submitted to any general-purpose AI service.
6. Who Can Access Your Prescription Information
Access to consultation and prescription records is restricted by role and by assignment. These restrictions are enforced in the system itself, not merely hidden in the interface.
- The assigned doctor can access the records for the orders assigned to them, for as long as needed for treatment and follow-up. A doctor cannot access another doctor’s patients.
- The founder / administrator can access records for authorised operational, security and governance duties — managing queues, resolving problems, responding to your requests, and investigating incidents. An administrator cannot alter issued clinical content and cannot act under a doctor’s identity.
- A designated view-only operational account is limited to a minimised, non-clinical view. It cannot access consultation notes, prescriptions, prescription documents, or your contact details.
Every access to sensitive data and every change to it is written to an append-only, tamper-evident audit record showing who accessed what, when, and for what stated purpose. Prescription documents and doctor signatures are held in private storage; access links are issued only to authorised staff and expire within minutes.
Data is encrypted in transit, and encrypted at rest using our providers’ managed encryption. Administrative access requires multi-factor authentication. Access rights are reviewed periodically and when a staff role changes.
7. Sharing of Your Information
We do not sell your personal data. We share it only with the following categories of recipients, bound by appropriate contractual data protection obligations:
7.1 Service providers used to operate the prescription review
- Shopify — the store platform, and the source of your customer and order record. A coarse status such as "on hold" or "ready to dispatch" is written back to your order. No consultation notes or clinical detail are written to Shopify.
- Supabase — the managed database, staff authentication, and private file storage for the prescription system.
- Google Cloud — application hosting, background job processing, secrets management, security logging, and encrypted recovery copies.
- Google Workspace / Gmail — staff identity, and delivery of your prescription PDF by email.
7.2 Other recipients
- Service providers: payment gateway operators, logistics and delivery partners, SMS/email communication platforms
- Group companies and affiliates of Herbidus Formulations Private Limited, for operational and analytics purposes. Consultation and prescription data is not shared with affiliates for analytics or marketing.
- Regulatory, law enforcement, or government authorities when required by law, court order, or to prevent fraud
- Professional advisors such as lawyers or auditors under strict confidentiality obligations
All third parties who receive your data are required to handle it securely and in accordance with applicable law. They may not use your personal data for their own marketing purposes.
8. Where Your Data Is Stored, and Cross-Border Transfer
- The prescription system’s primary database, staff authentication records, and private prescription files are currently stored and processed in Mumbai, India, on Supabase. The previous Singapore project has been deleted, and no future region migration is planned.
- Our Google Cloud workloads and encrypted recovery storage are configured in the Mumbai (asia-south1) region where the selected service supports it.
- Your prescription PDF is delivered using Gmail, operated by Google on its own global infrastructure.
- Shopify operates its own infrastructure, which is located outside India.
Shopify, Google and Supabase, their sub-processors, and their authorised support personnel may access or process limited data outside India under their applicable contracts and safeguards. We do not represent that a provider’s regional label means that every control-plane, support, email, commerce or sub-processor operation occurs only in that region.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law.
9.1 Commerce records
- Account and order data: retained for 7 years from the date of last transaction, as required under Indian accounting laws
- Marketing data: retained until you withdraw consent or opt out
9.2 Prescription review records
We do not run automatic deletion of clinical records. The system calculates a proposed review date for each record and produces a controlled manifest for human review, but no automatic clinical deletion takes place. Herbidus Formulations Private Limited and the prescribing practitioner will formally review this schedule within 90 days of the prescription system going live, and we will update this Policy with the outcome.
Our current proposed schedule, subject to that review and to legal advice, is:
- issued prescriptions, consultation and consent records, call-attempt records, delivery evidence, and the associated audit records: three years from issue or treatment
- abandoned draft consultations: 90 days after last activity
- delivery-attempt details: 180 days, unless part of a clinical record, dispute, incident, or legal hold
- security and application logs: at least 180 days, with controlled access
- database and encrypted file backups: a finite rolling window, currently targeted at 35 days, unless an incident or legal hold requires a protected snapshot
Applicable law, professional record-keeping duties, a legal hold, an ongoing dispute, or the defence of a claim may require us to keep a record for longer, or to keep a minimum record after an erasure request. Where that applies to your request, we will tell you. Backup copies age out through their own rolling lifecycle after a change or deletion has been applied to the live record.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. We use the following types of cookies:
- Essential cookies: Shopify cookies needed for core Website functions, including sessions, cart and checkout. Some may be necessary and cannot be disabled.
- Analytics and session-measurement technologies: Google Analytics and Microsoft Clarity help us understand how users navigate and use our Website. Enabled only with your consent.
- Marketing technologies: Meta Pixel and Google Ads Pixel help us measure advertising performance and, where enabled, deliver relevant advertisements. Enabled only with your explicit consent.
You may manage cookie preferences via the cookie banner displayed on your first visit, or through your browser settings. Disabling non-essential cookies will not affect your ability to make purchases on our Website. Cookies are not used in the prescription review process.
11. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:
- Right to Access Information: ask us to confirm what personal data we hold about you, how it is being processed, and the categories of recipients it has been shared with, and to be given an accessible copy.
- Right to Correction and Completion: request correction of inaccurate or incomplete personal data. Contact and order data is corrected at source. An issued prescription is never silently overwritten — a correction is recorded by the doctor as a linked amendment or revocation, so that the clinical and audit history remains reliable.
- Right to Erasure: request deletion of your personal data, subject to the legal, professional, accounting and dispute-related retention obligations described in Section 9.
- Right to Withdraw Consent: withdraw your consent to the prescription review at any time before a prescription is issued, as described in Section 4.
- Right to Grievance Redressal: raise a complaint with our Grievance Officer (see Section 17).
- Right to Nominate: nominate another individual to exercise your rights in the event of your death or incapacity.
How to exercise these rights: write to info@thetrost.com with your order reference and a description of your request. Please do not email medical documents or government identification. We will use a proportionate method, based on the order and contact details we already hold, to confirm that the request concerns you.
We aim to acknowledge your request within seven days and to respond within 30 days. Where your request is for a copy of a clinical record covered by applicable medical record-keeping regulations, we aim to respond within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India or another statutory authority with jurisdiction. Contacting us first does not affect that right.
12. Data Security
We implement technical, administrative, and physical safeguards to protect your personal data from unauthorized access, loss, misuse, disclosure, or alteration. These include encryption in transit and managed encryption at rest, role- and assignment-based access control enforced at the database layer, private object storage, least-privilege service identities, multi-factor protection of administrative accounts, append-only audit records, backups, and recovery testing. Access to personal data is restricted to authorised personnel who are bound by confidentiality obligations.
While we take these precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security and are not liable for breaches resulting from circumstances beyond our reasonable control, including hacking, acts of third parties, or failures in third-party infrastructure. We investigate and respond to suspected incidents under our internal incident response process, and will notify affected individuals and the relevant authorities where the law requires it.
You are responsible for keeping your login credentials confidential. If you suspect unauthorized access to your account, please notify us immediately at info@thetrost.com.
13. Third-Party Websites
Our Website may contain links to third-party websites. This Privacy Policy does not apply to those websites. We are not responsible for the privacy practices or content of external sites. We encourage you to review the privacy policies of any third-party sites you visit.
14. Children’s Privacy
Our Website and Services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. The prescription review process described in Section 3 is available only to an adult patient acting for themselves; where there is any indication that the patient is a minor or is represented by another person, the process is stopped and escalated rather than completed.
If you believe a minor has provided us with personal information, please contact us at info@thetrost.com and we will take steps to delete such data promptly.
15. Updates to This Policy
We reserve the right to update this Privacy Policy at any time. This page shows the effective date and version of the current Policy. Material changes will be communicated to you via email or a prominent notice on our Website at least 7 days before they take effect. Continued use of the Website after the effective date of changes constitutes acceptance of the revised Policy.
16. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and any rules and regulations framed thereunder.
Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the courts located in New Delhi, India.
17. Contact Us and Grievance Redressal
For any questions, requests, or concerns regarding this Privacy Policy or our data practices, and to raise a privacy grievance, please contact:
- Grievance Officer: Harshal Goel, Founder
- Public contact: info@thetrost.com. Direct Grievance Officer contact: harshal@thetrost.com.
- Website: https://thetrost.com/pages/contact-us
- Post: Herbidus Formulations Private Limited, 2nd Floor, 12/22, East Patel Nagar, New Delhi, Delhi 110008, India
Requests about a prescription or consultation record are routed to the issuing practitioner; privacy requests are handled by the Company. Both can be raised at the address above.
