Version 1.8 | Effective: 2 September 2026 | Last updated: 2 September 2026. This policy describes the public site's on-device functions, necessary technical processing, institutional commercial enquiries and the production-gated company-merchant order flow. It will be updated before a function or processing activity changes.
Information we process
Website-hosting and security services may process necessary technical logs under their configuration, such as visit time, request path, browser type and security events. This is used for operation, security and troubleshooting. The current site has no accounts, subscriptions, online consultations, prescription upload or cloud medical-record function. Company checkout appears only when the fixed API explicitly confirms every production gate.
Institutional commercial enquiries
When no “Submit institutional enquiry securely” button is displayed, the commercial-enquiry tool only prepares an email draft on your device. It does not send automatically or submit the form content to an OriginDrug server. Information enters the processing environment of your chosen outbound email provider and the recipient's email provider only after you review the draft and click send.
When “Submit institutional enquiry securely” is displayed, the website sends information to the fixed OriginDrug API only after you actively accept this policy and submit. The fields are organization name and public website, work email, institution type, procurement stage, use case, target markets, medicine or page scope, delivery format, update frequency, timing and acceptance requirements, plus page language, consent status and policy version. To understand which public outreach produces institutional enquiries, the same record also stores constrained campaign source, medium, campaign name, current entry path and referring-site hostname. It does not store the full referring URL, its query string, search terms or referring-page path. Do not enter patient names, person-linked medicine lists, prescriptions, person-linked pack photographs, medical records, test reports, identity documents, payment information or other unnecessary sensitive information.
The server creates an enquiry reference and records received time, processing status, consent-policy version and scheduled deletion date. A connection-origin signal is held transiently in server memory only to limit abusive frequency and is not written into the enquiry record. Online enquiry records use the retention period declared in the deployed service configuration and may be retained longer only where necessary for applicable law, an established contract or dispute resolution. You may use the email below to request access, correction or deletion; where immediate deletion is not possible, we will explain the scope and reason.
The five-fact quick enquiry creates a random enquiry reference on this device and lets you download a TXT or JSON record. Generation and download do not submit the fields to an OriginDrug server; the file stays under your control until you choose to copy, send or upload it elsewhere. A medicine record's Share control invokes the browser or operating system share panel, or copies the public page link. The site does not receive the recipient or message. Secure institutional-enquiry submission does not create an account, order, payment or automatic subscription.
Company-merchant orders and transactional email
When online company checkout is enabled, the order form requires a delivery email and records page language, Privacy Policy consent version, order ID, product code, finance-approved amount, currency, payment status, payment-provider transaction reference, expiring-download time and download count. OriginDrug does not collect card numbers, payment passwords or payment screenshots in the website form. WeChat Pay or Alipay processes payment in its company-merchant cashier; success is established only by a verified server callback and order reconciliation.
After verified payment, OriginDrug uses Alibaba Cloud DirectMail's SingleSendMail interface to send the order's expiring delivery link to the delivery email, with click tracking disabled. The email event ID returned by Alibaba Cloud and sent time are retained for troubleshooting and duplicate-send control. The credential is placed in the URL fragment, so it is not sent to the static website with the page request; the landing page removes it from the address bar immediately and submits it to the fixed API only when you choose to retrieve the file. The default is 24 hours and three downloads; the order email controls where it differs. Order, payment, refund, invoice, dispute and security records are retained only as necessary for contract performance and applicable law. You may use the contact below to request access, correction or deletion of the delivery email where legally permitted.
Data kept in this browser
The data below is kept only in local storage for this site in the current browser on this device. OriginDrug does not upload it as account data or automatically synchronise it to another device.
- origindrug-theme: dark or light theme preference.
- origindrug-text-scale: site-wide standard, large or extra-large reading preference.
- origindrug-reader-size: legacy medicine-record larger-text preference, retained only to migrate it to the site-wide setting.
- origindrug.family-medicine-list.v1.zh and origindrug.family-medicine-list.v1.en: Family medicine list. It may contain product name, generic name/active ingredient, strength printed on the pack, dosage form/route, directions copied from the label, start/stop/change history and notes for a pharmacist, and can therefore contain health-related information.
The Family medicine list can be removed with its “Clear this device” control. Theme and reading-size preferences, along with the list, can also be removed by clearing this site's browser data. OriginDrug cannot restore data after it is cleared. Do not enter a name, identification number, address, phone number, full medical record, test report, prescription, payment information or other unnecessary sensitive information in notes or other fields.
Photo identification boundary
A package or label image selected by you, and text read from it, are used only in the current browser page for local preview, text recognition and candidate-record matching. This function does not upload the image or OCR text to OriginDrug servers. The OCR component and model are loaded from OriginDrug itself and the image is not sent to a third-party recognition service. Selecting another image clears the former image's candidates; refreshing or closing the page clears the unsaved image and OCR state for that session.
A single image cannot independently confirm a medicine's identity, authenticity, originator status, individual suitability or whether it should be used. Do not use this function for medical records, prescriptions, identity documents, payment information or other unnecessary sensitive information.
Contact
Contact: Steven Li; email: stevenyiqingli@foxmail.com. This mailbox is for website content, source links, privacy matters, correction leads and institutional commercial enquiries. It is not an individual medical-advice or emergency-response channel. For urgent health concerns, contact local medical services or emergency services.