Home · Trust
Trust & Security
This page is maintained by Lemba Care to answer common security and privacy questions about Pharmacy Hub. It describes the controls we have enabled today; it is editable app-owner content and is not an independent audit, certification, or attestation.
Shared responsibility
Pharmacy Hub runs on the Lovable Cloud platform. Lovable provides the underlying hosting, managed database, authentication service and storage. Lemba Care is responsible for how the app is configured, what data it collects, who can access it, and how customer requests are handled. You are responsible for keeping your sign-in credentials private and for the accuracy of information you submit (delivery address, prescription details, contact number).
Accounts & access
- Email + password sign-in, with password storage handled by the managed auth service.
- Customers can only see their own orders, addresses and prescriptions.
- Pharmacy owners can only see orders and stock for pharmacies they have been linked to.
- Administrative actions (approving pharmacy applications, granting roles) are restricted to super-admin accounts.
- Roles are stored in a dedicated table — never on the user profile — and every privileged action re-checks the caller's role on the server.
Data we collect
- Account: name, email, phone number.
- Delivery: address details you enter at checkout.
- Health: prescription images you upload and the medicines on your orders. This is special personal information under POPIA.
- Order history: items, quantities, prices, status and the fulfilling pharmacy.
See the Privacy & POPIA notice for the full breakdown of purposes, sharing and your rights.
How your data is protected
- Database access is gated by row-level security: each query is filtered by the signed-in user's identity and roles before any rows are returned.
- Prescription images are stored in a private bucket. Only the customer who uploaded the image, the pharmacy fulfilling that order, and admins can read it.
- Privileged backend operations (fulfilling orders, receiving stock, approving pharmacy registrations) run as server-side functions that re-verify the caller's role and pharmacy ownership.
- Traffic between your device and the app is served over HTTPS by the hosting platform.
- Data at rest is encrypted by the managed database and storage services provided by Lovable Cloud.
Subprocessors & integrations
- Lovable Cloud — hosting, managed Postgres database, authentication, file storage, realtime updates.
- Dispensing pharmacy you choose at checkout — receives the order details, contact information and any prescription image needed to dispense and deliver.
We do not sell your personal information and do not share it with advertisers.
Retention & deletion
Account data is kept while your account is active and for 12 months after closure. Prescription images and dispensing records are kept for as long as the dispensing pharmacy is legally required to retain them (typically 5 years under South African pharmacy regulations). To request deletion or correction of your personal information, email privacy@lembacare.com.
Privacy & data requests
Access, correction, deletion and objection requests under POPIA: privacy@lembacare.com. You also have the right to lodge a complaint with the Information Regulator of South Africa.
Security contact & vulnerability reporting
If you believe you have found a security issue affecting Pharmacy Hub, please email security@lembacare.com with steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond.
Compliance
Pharmacy Hub is operated by Lemba Wholesale Pharmacy (Reg 2024/451568/07). Dispensing is performed by SAPC-registered pharmacies on the platform. We work towards compliance with POPIA and applicable SAPC rules. We do not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS or any other third-party certification.
Last updated: 22 June 2026. This page is reviewed and updated by Lemba Care; please email us if anything here is unclear or out of date.