Privacy Notice

Q10 Pharmacy website, vouchers, member cards, Birthday Club, Telegram services and staff tools

Baca Notis Privasi dalam Bahasa Melayu

Last updated: 23 July 2026

Operator: Q10 Pharmacy, Miri, Sarawak

Short version. We use customer details to run pharmacy membership, vouchers, requested reminders, wallet cards and customer service. We do not sell customer data. Some online features use Cloudflare, Telegram, Google or Samsung, so those providers process the data needed for the selected feature. You can contact us to ask what we hold, correct it, withdraw optional consent or request deletion, subject to records we must retain.

1. Scope and responsibility

This notice explains how Q10 Pharmacy handles personal data in the services named above. It supplements any in-store notice that applies to dispensing, regulated-sales or patient-care records. Some pharmacy, transaction or dispute records may need to be retained even after an optional service is cancelled.

This notice describes the deployed system. We will review it whenever a provider, database field, retention period or customer channel changes. It is not a guarantee of legal compliance or a substitute for professional legal review.

2. Data we handle

FeatureData usedWhy
In-store membership / IRS POSName, member account, contact details and other information entered in the local pharmacy system. Dispensing or regulated-sale records may contain additional health or identity information.Membership, customer service, transactions and pharmacy operations.
Member directory and digital-card linksName, member ID, a SHA-256 normalized-phone lookup hash, an HMAC-SHA-256 IC/passport verifier, its version, and record update time. Raw IC/passport is not saved in the cloud member record. Public phone-and-IC web self-verification is disabled.Let authorised staff locate and verify the correct member, or let the linked Telegram bot revalidate an existing member link, before issuing a 15-minute, provider-specific, one-use Wallet link.
New-member staff queueName, member ID and one normalized phone for up to eight days. No Wallet bearer token is stored in the sync entry.Let authorized staff prepare and send a requested member-card link, then remove the temporary queue item.
Vouchers and spinName, purpose-limited contact phone, phone/identity hashes where used, voucher code and offer, outlet, dates, redemption/void status, eligibility information and minimized anti-abuse signals.Issue, find, validate and redeem a voucher; prevent repeated or fraudulent claims.
Birthday ClubName, normalized phone, birthday month, privacy-notice version, registration time/source and separate WhatsApp choice.Create one annual reward and deliver it through WhatsApp if chosen, through a separately opted-in linked Telegram account, or through staff retrieval.
Browser notificationsA browser push endpoint and cryptographic subscription keys tied to the voucher that authorized them.Send the optional reminder for that voucher. An old voucher subscription is not reused as general marketing permission.
Google or Samsung WalletName, member ID/barcode, pass identifier and the voucher/member information shown on the selected pass.Create and update the digital pass you requested.
Telegram botTelegram user/chat ID, linked member details, preferences, reminder text/times, commands, limited conversation history and—only after you agree—eligible purchase information retrieved for reminder setup.Link the customer, deliver requested reminders/rewards and answer requested questions.
Customer-order toolCustomer name, phone/member ID, requested item, notes, deposit/status and staff activity.Manage reservations and customer orders.
Security and diagnosticsIP address, user agent, timestamps, rate-limit counters, staff access logs and minimized device/browser signals. High-risk voucher attempts may be flagged for staff review.Protect accounts and vouchers, investigate failures and maintain the service.
Hashing is not encryption or anonymization. The unkeyed phone lookup hash may still be guessed because phone numbers have limited formats. The IC/passport verifier uses a separate secret key, which prevents offline guessing from the cloud record alone, but it remains personal data and depends on that key staying secret. We therefore also use access controls, request limits and staff review.

3. Where data comes from

4. How the services connect

FlowData movement
Member syncLocal IRS SQL → read-only sync on a Q10 PC → minimized schema-v3 records in Cloudflare KV. Raw IC, points, city and state are not part of the cloud member schema.
Member verification and Wallet-link issuePublic phone-and-IC web self-verification is disabled. After an in-person check, authorised staff use an authenticated dashboard to request a separate Google or Samsung Wallet link. A linked Telegram user may request a link only after the bot revalidates the member link. The Q10 Worker creates an opaque token limited to the selected provider, valid for up to 15 minutes and accepted once.
Voucher issue / redemptionCustomer or staff browser → Q10 Worker → a per-customer/per-code Cloudflare Durable Object that serializes the operation → the retained voucher record in Cloudflare KV.
Birthday ClubAuthorised staff create a 15-minute one-use enrollment link after an in-person check. Your browser then sends the link token, birthday month, notice acknowledgement and optional WhatsApp choice to the Q10 Cloudflare Worker/KV. The purpose-limited record contains the normalized phone so Q10 can match the registration to staff retrieval, optional WhatsApp delivery or a separately opted-in linked Telegram account.
WalletAuthorised staff dashboard or linked Telegram bot → Q10 Worker creates a 15-minute, provider-specific token → your browser presents it once to Q10 Worker → Google Wallet or Samsung Wallet receives the pass data when you choose that provider. A Google token cannot be used for Samsung, or vice versa.
Telegram automationTelegram → Q10 Telegram Worker → Q10 storage. For AI-assistant questions, recent conversation context and the question may be sent to Google Gemini.
Browser pushYour browser → Q10 Worker → the push service selected by your browser/device → your device.
Staff operationsAuthorized staff browser → Cloudflare Worker/storage → the relevant outlet or owner Telegram chat for an operational notification where configured.

5. Purposes and choices

We process data to provide the service you request, operate membership and vouchers, keep appropriate records, secure the systems, respond to enquiries and meet applicable obligations. Birthday and promotional channel choices are separate from ordinary pharmacy service.

6. Service providers and disclosures

We do not sell customer data. Depending on the feature you choose, data may be processed by:

These providers may process data outside Malaysia. Their own terms and privacy notices also apply. We are responsible for assessing these transfers, keeping the applicable records and putting suitable contractual safeguards in place. See the Malaysian regulator’s cross-border transfer guidance.

7. Retention

We aim to keep personal data only for the service, security, accounting, dispute and regulatory periods that apply. Current application controls include:

RecordCurrent application retention
New-member staff queueUp to 8 days.
Purpose-specific Google or Samsung Wallet bearer token prepared by staff or the linked Telegram botUp to 15 minutes and accepted once. Replaced, consumed or expired tokens are not valid.
Birthday Club one-use enrollment tokenUp to 15 minutes, and deleted after successful use or replacement.
Unused voucher and duplicate-prevention indexVoucher expiry plus approximately 90 days.
Redeemed voucher recordUp to 2 years for reconciliation, dispute and accounting/audit purposes.
Spin/audit logUp to 180 days.
Minimized device anti-abuse recordUp to 90 days.
Voucher-specific push subscriptionUntil approximately one day after that voucher expires.
Telegram purchase hand-off eventNormally 24–48 hours.
AI conversation context in Q10 KVUp to 1 hour. The provider may apply its own processing/retention terms.
Telegram pairing codeUp to 15 minutes; the linked profile and reminders remain until unlinked/deleted or no longer needed.
Birthday ClubUp to 2 years after the most recent registration or preference update, or sooner when consent is withdrawn, deletion is requested or the program ends. Channel consent is checked before outreach.
Customer-order toolActive records for up to 400 days; completed or archived records for up to 180 days. Staff Telegram links expire after up to 180 days unless renewed or removed sooner.
Cloud member indexWhile membership is active and until the next reconciliation removes an obsolete record.
Local pharmacy and transaction recordsAccording to applicable operational, accounting, professional and legal requirements.

Backups, provider logs and records required for legal claims or regulatory purposes may take longer to remove. We will explain an applicable exception when responding to a request.

8. Security and automated controls

Measures include HTTPS in transit, minimized member-sync fields, a phone lookup hash, a keyed identity verifier, purpose-bound one-use tokens, staff role/outlet checks, request limiting, restricted secrets and audit logging. No internet service can promise absolute security.

Rate limits, duplicate checks and fraud rules can automatically delay or reject a voucher attempt. They do not determine medical treatment. Ask Q10 staff for human review if a legitimate request is blocked. The Telegram AI assistant is not a substitute for a pharmacist, doctor or emergency service.

If Q10 suspects loss, unauthorized access or disclosure, our operational response is to contain the issue, preserve relevant logs, assess the data and people potentially affected, contact the relevant provider, escalate it to Q10 management/privacy contact, and make customer or regulatory notifications where our assessment finds they are required. These steps do not guarantee that an incident will not occur or that every event has the same notification duty.

9. Browser storage and external resources

Some pages use local/session storage for a voucher code, interface preference or short session. Browser push creates a subscription only after permission. Pages may load static assets or libraries from content-delivery providers; those providers can receive ordinary request information such as IP address and user agent. We do not intentionally use advertising pixels for these voucher/member pages.

10. Your requests and choices

Subject to the Personal Data Protection Act 2010 and other applicable requirements, you may ask whether we process your data, request access or correction, withdraw optional consent, object to direct marketing, or ask us to stop a particular use or delete data that is no longer required. Withdrawal may prevent an optional service from continuing but does not undo processing already completed.

The Malaysian Personal Data Protection Commissioner describes data-subject rights on its official rights page. You may also contact or complain to the Commissioner.

When making a request, tell us the phone number/account and feature involved. We may need to verify that the request concerns your data. We will not ask you to send a full IC through an ordinary public chat merely to make a privacy enquiry.

11. Children and family members

A parent or guardian should manage online reward, Wallet, Telegram and reminder choices for a child. Pharmacy records concerning a child may still be processed for care, dispensing, safety and legal requirements. Do not submit another adult’s phone, birthday or identity details without their authority.

12. Changes

We may update this notice when features, providers or legal requirements change. The latest date appears at the top. If a change materially affects an existing optional consent, we will request a new choice rather than treating silence as agreement.

Contact Q10 about personal data

Privacy contact: Q10 Pharmacy Management

You can also visit Q10 Pharmacy Riam. Say “privacy request” and specify whether you want access, correction, channel opt-out, Telegram unlinking or deletion. Reply STOP to a Q10 WhatsApp birthday message to withdraw that channel choice.

To report suspected loss, unauthorized access, disclosure or misuse, say “privacy/security incident” and give the approximate date, affected feature and a safe way to contact you. Do not send a full IC/passport, password, secret or active link token through an ordinary public chat. Q10 management will record and assess the report through the operational response described above.

← Back to Q10 Pharmacy