MediHealth Direct — UK online pharmacy, registered with the General Pharmaceutical Council (GPhC Reg No. 9012663)

Privacy Policy

Privacy Policy

How we collect, use and protect your personal information at MediHealth Direct.

Last updated: 14 September 2026

1. Introduction

This privacy policy explains how MediHealth Direct collects, uses and protects your personal information when you use our website and services. We are committed to handling your data responsibly and in line with UK GDPR and the Data Protection Act 2018.

The data controller is MEDIHEALTH DIRECT LTD, a company registered in England & Wales (Company No. 15745634), registered office: Unit 21 Armitage Business Park, Private Road No. 3, Colwick, Nottingham NG4 2TB, a GPhC-registered pharmacy (Reg No. 9012663). For any privacy question or to exercise your rights, contact hello@medihealthdirect.com.

2. Information we collect

  • Contact details such as your name, email address, phone number and delivery address.
  • Health information you provide during consultations, including medical history and the treatments you request.
  • Account and order information, including your consultation outcomes, prescriptions and order history.
  • Technical data such as your device and usage information when you browse the site.

3. How we use your information

  • To provide your care, including reviewing consultations and dispensing treatments.
  • To process orders, payments and deliveries.
  • To contact you about your orders, account and clinical care.
  • To meet our legal and regulatory obligations as a registered pharmacy.

4. Legal basis for processing

UK GDPR requires a lawful basis for each purpose we use your data for:

  • Clinical care (reviewing consultations, prescribing, dispensing and aftercare): performance of our contract with you (Article 6(1)(b)) and compliance with our legal obligations as a registered pharmacy (Article 6(1)(c)). Because this involves health data, we additionally rely on Article 9(2)(h) (provision of health care by professionals bound by confidentiality), read with Schedule 1, Part 1, paragraph 2 of the Data Protection Act 2018.
  • Orders, payments and deliveries: performance of our contract with you (Article 6(1)(b)).
  • Record keeping, medicines-safety reporting and regulatory duties: compliance with our legal obligations (Article 6(1)(c)), with Article 9(2)(h) for any health data involved.
  • Running, securing and improving our website and preventing fraud: our legitimate interests (Article 6(1)(f)).
  • Marketing messages and non-essential cookies: your consent (Article 6(1)(a)), which you can withdraw at any time.
  • We do not rely on your consent to hold your clinical records: pharmacy law requires us to keep them, so they are processed under the healthcare and legal-obligation bases above. Consent is reserved for marketing and optional cookies only.

5. Sharing your information

We only share your data where necessary to provide our service, or where required by law. We never sell your personal data. The trusted service providers we work with are:

  • Stripe: to process card payments securely. We never see or store your full card details.
  • Royal Mail and DPD (with TrackingMore for tracking updates): to deliver your orders and let you follow your parcel.
  • Resend: to send service emails such as order confirmations and sign-in links.
  • Omnisend: to send marketing emails, only if you have opted in. We share your contact details and marketing preferences, never your health information.
  • Twilio: to send text message reminders and updates to your phone.
  • Whereby: to host secure video consultations with our clinical team.
  • Yoti: to verify your identity where treatment requires it.
  • Trustpilot: to invite you to review your experience after an order. You can opt out at any time.
  • Google Ads: to measure our advertising. Under Advanced Consent Mode, Google Ads can send limited cookieless measurement signals before you choose and when marketing is rejected; advertising cookies are only used with marketing consent. Existing approved conversion events contain only the minimal order ID, value and currency fields; no health or customer data is intentionally added.
  • Google Tag Manager and Google Analytics: to understand how the site is used. Google Analytics and custom Google Tag Manager purchase/signup events remain consent-gated.
  • Meta: to measure our advertising, only with marketing consent.
  • Reddit: with marketing consent, its base pixel measures a PageVisit on eligible homepage and medication pages. Reddit may receive the medication page address and title, revealing your treatment interest, along with browser/network details. Pages with query strings or fragments and visits with unapproved referring pages are excluded. We do not configure Reddit conversions, advanced matching or tracking on consultation, login, checkout, patient or staff pages.
  • Replit: the secure cloud platform that hosts our website and systems. Replit also provides cookieless page statistics (pages visited, referring site, approximate country, browser and device type), which run only if you consent to analytics cookies and only ever receive page addresses with personal references removed.
  • OpenAI (accessed through Replit's AI service): powers our AI assistants. The public support assistant only ever sees the medicine and service information already published on this website, never your account or patient record. If you choose to use the Health Coach in your account, your messages (with personal identifiers removed) and your weight-loss treatment name and weight history are shared so it can personalise its guidance. When you submit a consultation, a de-identified copy of your questionnaire answers, with your name, contact details, address and exact date of birth removed, is used to prepare a safety pre-check for our prescriber. The pre-check is advisory only: every prescribing decision is made by our pharmacist prescriber.
  • Cloudflare: to store and serve the images and videos shown on our website, such as product photos. No customer records are stored there.

6. International transfers

Some of our providers process personal data outside the UK. Stripe, Twilio, Resend, Google, Meta, OpenAI, Cloudflare and our hosting provider Replit are headquartered in the United States; Omnisend processes data in the European Economic Area, which UK adequacy regulations cover.

Whenever data leaves the UK we rely on safeguards recognised by UK law: the UK Extension to the EU-US Data Privacy Framework for certified US providers, or the UK International Data Transfer Agreement / Addendum (standard contractual clauses) built into our contracts with them. You can contact us for more detail on the safeguard used for any specific provider.

7. Cookies and tracking

We use cookies and similar browser storage in three groups: strictly necessary (always on, for example the cookie that keeps you signed in), analytics (only with your consent, to understand how the site is used), and marketing (to measure our campaigns). Under Advanced Consent Mode, Google Ads can send limited cookieless measurement signals before you choose and when marketing is rejected; these signals do not set advertising cookies, which are only used with marketing consent. Meta, Reddit, Omnisend and custom Google Tag Manager purchase/signup events remain consent-gated. Reddit measures page visits on eligible homepage and medication pages with marketing consent, as described above. You can change your choice at any time via the Cookie Preferences link in the footer.

A full list of every cookie and storage item, including who sets it, what it does and how long it lasts, is published on our Cookie Policy page at www.medihealthdirect.com/cookies.

With Marketing consent, our site can retain a Google advertising click ID and timestamp in a first-party cookie for 90 days to attribute a later conversion. This landing-page capture does not store the page URL or treatment details, does not load Google on the landing page, and makes no network request itself. We remove this cookie when Marketing consent is withdrawn.

8. How long we keep your data

We keep different records for different periods, in line with our legal and professional obligations as a pharmacy:

  • Clinical and dispensing records (consultations, prescriptions, medicine orders): 8 years from your last treatment, in line with NHS and Royal Pharmaceutical Society records-management guidance. Prescription registers are kept for at least the 2 years the Human Medicines Regulations 2012 require.
  • Financial and payment records: 6 years plus the current year, as required by HMRC.
  • Marketing preferences and contact details used for marketing: until you opt out or your account is deleted.
  • Support enquiries: up to 2 years after resolution; complaint records: 6 years.
  • After the applicable period, your data is securely deleted or anonymised.

9. Your rights

  • Access a copy of the personal data we hold about you.
  • Receive your data in a structured, machine-readable format (data portability): signed-in patients can download this from their account at any time.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of your data where there is no legal reason for us to keep it.
  • Object to or restrict certain processing, and withdraw consent at any time.

10. Managing your data

Signed-in patients can export their data and submit access requests from the Profile & privacy section of their account. You can also email us to exercise any of your rights.

You can ask us to delete your account from the same section. Deleting the account removes your sign-in, profile, saved cards and marketing contact. The clinical and payment records we must keep by law are moved to a restricted archive for the periods above; it is not used for any other purpose and can only be opened by our superintendent pharmacist for a recorded reason. We confirm the request with a code sent to your email and complete it within one month.

11. Contact us

If you have any questions about this policy or how we handle your data, contact us at hello@medihealthdirect.com. You also have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, or telephone 0303 123 1113.

This privacy policy is provided for general information only and does not constitute legal advice. Please contact us if you have any questions.