Privacy Policy
How Community Botanic Dispensary collects, uses, and protects your personal information.
Last updated: 8 May 2026
Overview
Community Botanic Dispensary is operated by Bona Sano Pty Ltd ABN 15 679 537 243.
In this Privacy Policy, "Community Botanic Dispensary", "we", "us" or "our" refers to Bona Sano Pty Ltd and the pharmacy services we provide through our website, in-store services, prescription ordering systems, delivery services and related communication channels.
We are committed to protecting your privacy and handling your personal information, including health information, in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, applicable health records laws, pharmacy professional obligations, and other applicable Australian laws.
This Privacy Policy explains how we collect, use, store, disclose and protect your personal information.
1. What information do we collect?
We may collect personal information and health information about you when you use our website, submit a prescription, create an account, contact us, place an order, receive pharmacy services, or interact with us.
The information we collect may include:
- your name
- date of birth
- gender, where relevant to your care
- residential address
- delivery address
- email address
- phone number
- Medicare, concession, safety net, or health fund details, where relevant
- prescription information
- eScript token details
- medicine history
- order history
- payment and transaction details
- delivery and tracking details
- identity verification information
- health information relevant to dispensing, counselling, clinical review or pharmacy care
- communications between you and our pharmacy team
- information provided by your prescriber, carer, authorised representative, courier, payment provider or other service provider
- website usage information, including device, browser, IP address, pages visited and interactions with our website.
Health information is sensitive information. Australian privacy law has stricter rules about how health service providers collect, use and disclose health information.
2. How do we collect your information?
We may collect information directly from you when you:
- create an account on our website
- submit an eScript token or prescription information
- place an order
- request pickup or delivery
- contact us by phone, email, website form, SMS or in person
- ask for pharmacist advice or medicine counselling
- provide payment or delivery details
- respond to pharmacist questions
- sign up to receive updates or communications from us
- interact with our website.
We may also collect information from third parties where it is necessary or appropriate, including:
- your prescriber or medical clinic
- prescription exchange services
- pharmacy dispensing software or eScript systems
- payment providers
- delivery providers
- carers, guardians or authorised representatives
- government or regulatory bodies, where required by law
- health insurers, where relevant and authorised.
Where possible, we collect personal information directly from you. However, in some cases, pharmacy care requires us to verify or receive information from other health providers or authorised systems.
3. Why do we collect your information?
We collect, use and hold your personal information so that we can provide safe, lawful and appropriate pharmacy services.
This may include using your information to:
- verify your identity
- match you to your prescription
- review and validate your prescription
- dispense prescription medicines
- provide pharmacist counselling and medicine-related support
- confirm medicine availability and pricing
- process orders and payments
- arrange pickup, delivery and tracking
- communicate with you about your prescription, order or pharmacy care
- contact your prescriber where clarification is needed
- keep pharmacy records as required by law
- manage recalls, safety notices, product issues or dispensing issues
- respond to enquiries, complaints or refund requests
- improve our website, services, systems and customer experience
- prevent fraud, misuse, unauthorised access or unlawful activity
- comply with legal, professional, regulatory and reporting obligations.
4. Prescription and health information
When you submit an eScript token or prescription details, we use that information for pharmacy-related purposes, including prescription review, dispensing, supply, record keeping, pharmacist counselling, delivery and support.
We may need to contact your prescriber if:
- prescription details are unclear
- there is a stock or substitution issue
- the prescription appears expired, invalid or already dispensed
- repeats are not yet due
- further clinical or legal clarification is needed
- there is a safety concern.
We do not use prescription or health information for unrelated marketing purposes without your consent.
5. Website accounts
You need to create an account to use certain website features, such as submitting prescriptions, managing orders, receiving communications or accessing order history.
You are responsible for keeping your login details secure. Please contact us immediately if you believe your account has been accessed without permission.
We may suspend or restrict account access if we suspect unauthorised use, fraud, misuse, or a risk to patient safety or privacy.
6. Payments
We may collect and use payment-related information to process transactions. Payments may be processed through secure third-party payment providers, such as NAB, or another approved payment service used by Community Botanic Dispensary.
We do not recommend sending card details by email, SMS or unsecured message.
Depending on the payment method used, your payment information may be collected and processed directly by the payment provider. Their own privacy policy and security standards may also apply.
7. Delivery and couriers
If you request delivery, we may disclose limited personal information to delivery providers so they can deliver your order.
This may include:
- your name
- delivery address
- phone number
- delivery instructions
- tracking information
- information needed for signature, ID verification or secure delivery.
For privacy and safety, prescription medicine deliveries may require secure handling, signature on delivery or identity verification depending on the medicine and delivery method.
We may use delivery providers such as Australia Post, courier services, or other delivery partners approved by the pharmacy.
8. Use of third-party service providers
We may disclose personal information to trusted third-party service providers who help us operate our pharmacy and website.
These may include:
- pharmacy dispensing software providers, such as FRED Plus
- point-of-sale providers
- payment gateway and merchant service providers
- eScript and prescription exchange services
- delivery and courier providers
- IT support providers
- website hosting and maintenance providers
- email, SMS and communication platforms
- analytics providers
- professional advisers, including accountants, lawyers and insurers
- regulatory bodies, where required.
We take reasonable steps to ensure third-party providers handle personal information appropriately and only for authorised purposes.
9. Google Analytics, cookies and website tracking
Our website may use cookies, pixels, analytics tools and similar technologies, including Google Analytics, to understand how visitors use our website and to improve our services.
These tools may collect information such as:
- pages visited
- time spent on pages
- browser type
- device type
- approximate location
- referral source
- website interactions
- IP address or similar online identifiers.
Cookies may be used to improve website functionality, analyse use and tailor online experiences.
10. Marketing communications
We may send you service-related communications about your prescriptions, orders, delivery, account or pharmacy care.
We may also send marketing or promotional communications where permitted by law and where you have consented or where it is otherwise lawful to do so.
You can unsubscribe from marketing communications at any time. However, we may still need to send you important non-marketing communications about your prescriptions, orders, safety issues, recalls, account activity or pharmacy services.
We do not use your prescription or sensitive health information to advertise unrelated products.
11. Disclosure to prescribers, healthcare providers and representatives
We may disclose relevant information to your prescriber or another healthcare provider where reasonably necessary for your care, dispensing, medicine safety, prescription clarification or legal compliance.
We may also communicate with a carer, guardian, family member or authorised representative if:
- you have authorised them
- they are collecting or managing your medicine on your behalf
- it is necessary for your care or safety
- the law permits or requires it.
Where possible, we will take reasonable steps to confirm authority before disclosing sensitive information.
12. Legal and regulatory disclosure
We may disclose personal information where required or authorised by law, including to:
- pharmacy regulators
- health departments
- law enforcement agencies
- courts or tribunals
- Medicare, PBS or government agencies, where relevant
- professional indemnity insurers
- product suppliers or sponsors for recalls or safety matters
- the Therapeutic Goods Administration, where required for safety reporting.
We may also disclose information where necessary to manage a serious threat to life, health or safety.
13. Overseas disclosure
We aim to store and handle personal information using systems and service providers that are appropriate for an Australian pharmacy business.
Some of our website, database, payment, analytics, communication, hosting, IT support or pharmacy-related service providers may store, process, access or support systems from locations outside Australia. This may depend on the provider, selected data region, technical configuration and the services used.
Where personal information is disclosed to or accessed by an overseas recipient, we will take reasonable steps to ensure the information is handled in accordance with Australian privacy requirements, unless an exception applies.
Where possible, we configure our systems to limit unnecessary access to personal information and health information.
14. How we protect your information
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
These steps may include:
- secure premises
- restricted staff access
- password-protected systems
- role-based access controls
- secure pharmacy software
- secure payment processing
- staff confidentiality obligations
- physical security for pharmacy records
- secure document disposal
- system monitoring and maintenance
- reasonable IT security measures.
No website or electronic system is completely risk-free. If we become aware of a privacy or data security incident, we will take steps to respond in accordance with applicable legal obligations.
15. How long do we keep your information?
We keep personal information for as long as needed for the purposes for which it was collected, including pharmacy care, dispensing, record keeping, legal compliance, accounting, insurance, dispute resolution and regulatory obligations.
Pharmacy and health records may need to be kept for minimum periods required by law.
When information is no longer required, we will take reasonable steps to securely destroy, delete or de-identify it, unless we are legally required to keep it.
16. Accessing your personal information
You may request access to the personal information we hold about you.
To request access, please contact us using the details at the end of this policy. We may need to verify your identity before providing access.
In some situations, we may be legally permitted or required to refuse access, such as where providing access would affect another person's privacy, create a serious safety risk, or be unlawful.
17. Correcting your personal information
You may ask us to correct personal information we hold about you if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.
We will take reasonable steps to correct your information where appropriate. We may need to verify your identity before making changes.
18. Complaints
If you have a concern about how we have handled your personal information, please contact us first so we can try to resolve the issue.
Please provide:
- your name and contact details
- details of your concern
- any relevant dates, orders or communications
- what outcome you are seeking.
We will review your complaint and respond within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
19. Children and young people
Our pharmacy services may involve collecting information about children or young people where relevant to prescription supply, pharmacy care or legal requirements.
Where appropriate, information may be collected from or disclosed to a parent, guardian or authorised representative.
We may require additional verification or consent depending on the patient's age, the medicine involved, the legal requirements and the circumstances.
20. Links to other websites
Our website may contain links to third-party websites, platforms or services.
We are not responsible for the privacy practices or content of third-party websites. You should read the privacy policy of any third-party website you visit.
21. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, website, systems, services or legal obligations.
The updated version will be published on our website with the updated date.
22. Contact us
For privacy questions, access or correction requests, or privacy complaints, please contact:
Community Botanic Dispensary
Operated by Bona Sano Pty Ltd
ABN: 15 679 537 243
Address: 77 Regent Street, Chippendale NSW 2008
Phone: 0468 288 896 / (02) 6190 9780
Email: info@thecbdispensary.com
Website: www.thecbdispensary.com
Have questions about your privacy or personal information?