MedReach CRM
Last updated: 24 September 2026
MedReach CRM is a field CRM for clinic and hospital visit teams. It is
operated from Parañaque City, Philippines. Contact:
[email protected].
Web app: medreachcrm.com.
iOS and Android apps use bundle ID com.medreachcrm.app.
This notice is for people who sign in (reps, managers, admins) and for clinicians and workplace contacts stored in a company’s directory. It is a product notice under the Data Privacy Act of 2012 (Republic Act 10173), not legal advice.
To run the CRM your company asked us to run: log calls, keep a directory, plan coverage, and let managers review unsigned GPS or other exceptions. Lawful bases: legitimate interest in operating that CRM, and consent (you agree to this notice before using the app).
Field data for a signed-in company is stored on our Cloudflare account (Pages, Workers, and D1). Company records are not shared with other clients on the same app. On a phone or tablet, the app may keep a local copy of visits and presentation files so work continues offline; those copies stay on that device until the app is removed or the files are cleared.
To turn GPS coordinates into a street name, the app may send latitude and longitude to our reverse-geocode API (OpenStreetMap Nominatim) and, if needed, to Photon (Komoot) or BigDataCloud. We do not sell personal data. We do not scrape third-party clinician databases. We do not use advertising SDKs.
We keep company records while the company uses MedReach CRM, and for a reasonable period after if needed for a dispute or a legal duty. You may request access or deletion of personal data at [email protected]. Admins can disable accounts. Uninstalling the app removes the on-device cache; it does not delete the company’s server records.
MedReach CRM is for work use by adults. It is not directed at children.
If this notice changes in a material way, we will update the date above and the in-app copy at /privacy.