1. Scope
This Policy covers two categories of data:
- Account/Business Data: information about you or your business as our direct customer (the "Subscriber"), collected when you register, subscribe, or contact support.
- Customer Data: the transactional, inventory, pricing, and business records that you and your Authorized Users input into the Service while using it to run your business ("End-User Data").
For End-User Data, you (the Subscriber/Merchant) are the data controller, and Peham acts as a data processor, processing that data only as necessary to provide the Service and per your instructions and configuration. You are responsible for ensuring you have the necessary rights and legal basis to input any personal data of your own customers, employees, or suppliers into the Service.
2. Information We Collect
2.1 Information you provide directly
- Account registration details: name, business name, NTN/CNIC (if provided), email, phone number, and business address.
- Billing and subscription details (processed by Paddle as our Merchant of Record; see Section 6).
- Support communications, feedback, and survey responses.
2.2 Information collected through use of the Service (Customer Data)
- Sales transactions, invoices, receipts, pricing, discounts, and tax data you record.
- Inventory, product, and supplier records.
- Customer and vendor contact details you choose to store (names, phone numbers, and addresses of your own customers).
- Usage logs: login timestamps, device/browser type, IP address, and feature usage.
2.3 Automatically collected technical data
- Cookies and similar technologies (see Section 9).
- Diagnostic and error logs for reliability and security purposes.
2.4 Information we do not intentionally collect
- We do not knowingly collect sensitive personal data (such as health records or biometric data beyond what a Customer may voluntarily configure), unless the Customer independently chooses to store such data as part of its own business records. In that case, the Customer is solely responsible for the lawfulness of doing so.
- We do not knowingly collect data from children under 18. The Service is intended for business use by adults.
3. How We Use Information
We use the information described above to:
- provide, operate, and maintain the Service (billing generation, inventory sync, reporting, and dashboards);
- process payments through Paddle and manage your subscription;
- provide customer support and respond to inquiries;
- send service-related communications (updates, maintenance notices, and security alerts) and, where you have opted in, marketing communications;
- monitor, secure, and improve the Service, including detecting fraud, abuse, or violations of our Terms and Conditions;
- comply with our own legal obligations (for example, accounting records for our own business, and responding to valid legal process); and
- where you enable optional integrations, transmit the specific transaction data you configure to FBR's IRIS/POS system or a provincial revenue authority (PRA/SRB/KPRA/BRA) solely because you directed the Service to do so (see Section 6.3).
We do not use your Customer Data (your business's transactional records) to train third-party AI models, sell it to data brokers, or use it for purposes unrelated to providing the Service, without your separate, explicit consent.
4. Legal Basis for Processing
Where applicable data protection law requires a legal basis, we rely on: performance of a contract (providing the Service you subscribed to); our legitimate business interests (security, fraud prevention, and service improvement); your consent (marketing communications and optional integrations); and compliance with legal obligations.
5. Customer Responsibility for Data You Input
5.1 You control what you enter. Tejarify is a tool. Whether the data you input is accurate, complete, lawfully obtained, and lawfully processed under Applicable Laws (including any obligation to obtain consent from your own customers or employees before storing their personal data) is entirely your responsibility as the Subscriber.
5.2 We do not verify your data. Peham has no ability and no obligation to verify that transaction values, tax rates, customer records, or inventory figures you enter reflect your actual business activity. Any statutory, tax, or regulatory consequence of inaccurate or non-compliant data entry rests with you. See the Terms and Conditions, Sections 6 and 7.
5.3 If your business collects personal data of your own end customers (for example, loyalty program phone numbers or delivery addresses) through Tejarify, you are the data controller for that data and are responsible for your own privacy notices, consent mechanisms, and compliance with any applicable data protection law towards your customers.
7. Data Retention
7.1 We retain Account/Business Data for as long as your account is active and for a reasonable period thereafter to comply with our own legal, accounting, and dispute-resolution needs (typically up to six years, consistent with standard Pakistani record-keeping norms).
7.2 We retain Customer Data (your transactional records) for as long as your subscription is active, plus a grace period after termination (see Terms and Conditions, Section 15.3) to allow data export, after which it may be permanently deleted from our systems unless a longer retention period is required by law or agreed with you.
7.3 Peham's retention of a copy of your data within the Service is not a substitute for your own independent statutory record-keeping obligations under tax and company law.
8. Data Storage, Security, and International Transfer
8.1 Tejarify's infrastructure is primarily self-hosted on cloud servers (including Hetzner-provisioned infrastructure), which may be located outside Pakistan. By using the Service, you acknowledge that your data may be processed and stored on servers located in jurisdictions other than Pakistan, and consent to such transfer for the purpose of providing the Service.
8.2 We implement technical and organizational measures designed to protect data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit (TLS/HTTPS), access controls, firewall and reverse-proxy protections, and regular security monitoring.
8.3 No system is completely secure. We cannot guarantee absolute security of data transmitted to or stored within the Service, and disclaim liability for unauthorized access resulting from causes outside our reasonable control, consistent with the Terms and Conditions' limitation of liability.
8.4 In the event of a data breach materially affecting your data, we will notify you without undue delay and in accordance with any applicable legal obligation.
10. Your Rights
Depending on applicable law, you may have rights to:
- access a copy of the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data (subject to our legitimate retention needs described in Section 7);
- object to or restrict certain processing (for example, marketing communications); and
- request export of your Customer Data in a portable format before account termination.
To exercise these rights, contact us at [email protected]. We may need to verify your identity and your authority over the relevant account before acting on a request.
11. Children's Privacy
The Service is intended for business use by adults and legal entities. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have inadvertently collected such data, we will take steps to delete it.
12. Third-Party Links
Our website or Service may contain links to third-party websites or services (including Paddle's checkout pages, FBR's portal, or payment processors). We are not responsible for the privacy practices of third parties, and this Policy does not apply to their sites. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the revised Policy on tejarify.com with an updated "Last Updated" date, and for material changes will provide notice via email or in-Service notification at least 15 days in advance. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
14. Contact Us
For questions, requests, or concerns about this Privacy Policy or our data practices:
Questions about this document? Contact us using the details above.
Terms & Conditions →