Wrelik Brands LLC

Privacy Policy

Effective September 3, 2026 · Last updated September 3, 2026

This policy applies to DRX, also presented as Deelrx CRM, including its websites, web application, and native mobile applications.

1. Scope and roles

DRX is a privacy-first operating system for regulated retail businesses. This policy explains how Wrelik Brands LLC ("Wrelik," "we," "us," or "our") handles personal information when people visit our public website or use DRX.

A subscribing business generally controls the customer, inventory, transaction, and workforce records its authorized users enter into DRX. Wrelik processes those records to provide the service. Wrelik separately determines how information is used for account administration, security, billing, compliance, support, and protection of the service.

2. Information DRX processes

Depending on the features a business and its authorized users use, DRX may process:

  • Account and operator information: names, email addresses, authentication and user identifiers, business membership, roles, permissions, account settings, and security events.
  • Business information: business name, locations, owner and staff records, configuration, subscription, and operational settings.
  • Retail customer information: aliases, names, phone numbers, email addresses, delivery or contact addresses, notes, purchase history, loyalty information, balances, payments, credit limits, and age-verification details when a business chooses to record them.
  • Product and inventory information: product names and descriptions, categories, SKUs, vendors, batch records, quantities, units, costs, prices, adjustments, and regulated-product attributes such as THC or CBD percentages where applicable.
  • Sales and financial records: carts, line items, amounts, discounts, taxes, tender type, limited payment references, credit balances and repayments, refunds, voids, deliveries, reconciliation records, and audit history. DRX is not designed to store full payment-card or bank-account credentials.
  • Device, usage, and diagnostics: app version, device and operating-system information, IP-derived network information, Android or DRX installation identifiers, push-notification tokens, feature interactions, crash reports, error logs, and performance diagnostics. The Android app does not request a device's precise GPS location.
  • Communications: support requests, feedback, and other messages a user chooses to send.

Businesses and users should not enter full payment-card data, Social Security numbers, protected health information, or other information DRX is not expressly designed to process.

3. How information is collected

We receive information:

  • directly from visitors, account holders, and authorized business users;
  • from the business that creates or administers an authorized user's account;
  • automatically from the app, browser, device, and connected services; and
  • from integrations that a business or authorized user chooses to enable.

4. How information is used

We use information to:

  • provide, synchronize, support, and improve DRX;
  • authenticate users and enforce business, tenant, role, and permission boundaries;
  • process inventory, sales, balances, deliveries, reports, and user-directed workflows;
  • support encrypted offline operation and reconcile approved offline transactions;
  • send requested service and delivery notifications;
  • measure feature use, diagnose failures, prevent abuse, and secure the service;
  • respond to support, privacy, and account requests;
  • comply with law, enforce agreements, and protect legal rights; and
  • communicate material service, security, account, or policy changes.

5. Mobile and offline storage

The DRX mobile app stores authentication material and a tenant-scoped operator session in protected device storage. On Android, approved offline workflows can store encrypted cached product and customer records, offline authorization data, pending sales, receipts, and delivery reminders in a SQLCipher database. The Android application disables operating-system backup for its app data.

Offline data is synchronized when connectivity returns. Transaction and audit records may be retained when needed to preserve financial correctness, prevent duplicate processing, resolve a conflict, or meet a business or legal recordkeeping obligation.

6. Service providers and disclosure

DRX uses providers that process information to operate the service, including:

  • Clerk for authentication and account sessions;
  • Convex for the operational application backend and database;
  • Vercel for web hosting and application delivery;
  • Expo and Google for mobile build, distribution, device services, and push notifications;
  • PostHog for product analytics, with mobile session replay disabled;
  • Sentry for crash, error, and performance diagnostics; and
  • Featurebase when a user opens the feedback and roadmap experience.

We may also disclose information:

  • to the subscribing business and its authorized users according to configured access;
  • to an integration or other recipient at a business's or authorized user's direction;
  • when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or enforce agreements;
  • to professional advisers that are required to protect the information; or
  • as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards.

We do not sell personal information for money and do not use personal information for cross-context behavioral advertising. Service providers may process information only to provide contracted services or as otherwise permitted by their agreements and applicable law.

7. Analytics, diagnostics, and AI

PostHog and Sentry may receive technical identifiers, device or app information, feature interactions, crash data, and diagnostic context. We configure mobile session replay off and prohibit intentionally placing retail customer contact details, sale line items, payment references, or free-form business records in analytics events. Diagnostic reports can still contain information associated with an authorized user, so access is restricted.

When an authorized user invokes an AI-assisted feature, the selected input, instructions, and necessary tenant-scoped context may be sent to configured AI infrastructure and model providers to return the requested result. DRX AI output is advisory and must not be the sole basis for a legally significant credit, employment, eligibility, or compliance decision.

8. Retention, export, and deletion

We retain information for as long as reasonably necessary to provide DRX, follow the subscribing business's instructions and configured retention settings, maintain security and auditability, meet contractual and legal obligations, and resolve disputes. Encrypted backups and limited logs can retain copies until their scheduled rotation.

A verified deletion request may remove, de-identify, mask, or archive account and profile information. Some transaction, inventory, balance, tax, audit, fraud-prevention, legal-hold, and dispute records cannot be deleted immediately without compromising required records or other people's rights. We limit and protect retained information and remove it when the applicable need ends.

A subscribing business controls ordinary access, correction, export, and deletion requests for the business records it entered into DRX. Retail customers and organization-managed users should contact that business first. Wrelik will assist as required by contract and law.

9. Security

We use safeguards designed to protect information, including encrypted network transport, authentication, server-side tenant and role authorization, encrypted storage for designated sensitive fields, protected mobile storage, audit trails, provider controls, and environment separation. No system is completely secure. Users must protect their credentials and devices and promptly report suspected unauthorized access.

10. Privacy rights and account requests

Depending on the applicable law and our role, a person may have rights to access, correct, delete, or receive a portable copy of information; restrict or object to certain processing; withdraw consent; or appeal a denied request. We may verify identity, account control, and authority before acting.

For a Wrelik-controlled account or website request, email privacy@deelrxcrm.com with the subject "Privacy Request" and identify the DRX account involved. Organization-controlled business-record requests may be routed to the subscribing business.

11. Regulated retail and children

DRX provides business software; it is not a healthcare or pharmacy service. A subscribing business is responsible for lawful product sales, age verification, licensing, tax, consumer notices, and recordkeeping in every jurisdiction where it operates.

DRX is not directed to children under 13 and is not intended for minors to independently purchase age-restricted products. If you believe a child has provided information improperly, contact us so we can investigate.

12. International processing and policy changes

Wrelik and its providers may process information in the United States and other countries. Where required, we use contractual or other safeguards for international transfers.

We may update this policy to reflect changes in DRX, law, or our practices. We will post the revised policy and update the date above. We will provide additional notice or obtain consent before a materially different use when required by law.

13. Contact

Wrelik Brands LLC · Privacy inquiries: privacy@deelrxcrm.com · Product support: support@deelrxcrm.com