Privacy Policy – KhareedDari.com
KhareedDari.com (“Platform”, “Website”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, and your rights. By using the Platform, you agree to this Privacy Policy.
Scope: This Policy covers customers, visitors, registered users, and sellers (brands, manufacturers, suppliers, retail business owners) using our services and tools.
Effective date: | Last updated:
Table of contents
- Definitions
- Data we collect
- How we collect data
- How we use data and legal bases
- Cookies and similar technologies
- Data sharing and disclosures
- International data transfers
- Data retention
- Data security
- Your rights and choices
- Children’s privacy
- Automated decision-making and profiling
- Marketing and communications
- Third-party services
- Policy changes
- Contact and complaints
- Controller and key contacts
Definitions
- Personal data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on personal data (e.g., collection, storage, use, sharing).
- Controller: The entity determining purposes and means of processing personal data (KhareedDari.com).
- Processor: A third party processing data on our behalf (e.g., payment gateways, logistics).
- Sensitive data: Categories requiring higher protection (e.g., financial, health, biometric, precise location).
Data we collect
- Identity data: Name, username, password, government/business IDs (for sellers), profile photo (optional).
- Contact data: Email, phone, billing/shipping address, social handles (if provided).
- Account data: Account preferences, roles (customer/seller), support tickets, communication records.
- Order data: Cart contents, purchase history, invoices, delivery notes, return/refund records.
- Payment data: Payment method, masked card details, transaction IDs (processed via secure gateways; we do not store full card numbers).
- Seller business data: Store name, logo, license/tax registration, bank details for payouts, policy pages.
- Device and technical data: IP address, device IDs, browser type/version, OS, app version, language, time zone, crash logs.
- Usage data: Page views, clicks, search queries, session duration, referral URLs, feature interactions.
- Location data: Approximate geolocation based on IP; precise location only if explicitly enabled.
- Marketing data: Preferences, opt-in/opt-out status, campaign interactions, promo redemptions.
- Cookies data: Session identifiers, authentication tokens, preference settings, analytics metrics.
- Feedback and reviews: Ratings, comments, survey responses, dispute and complaint details.
- Compliance data: Fraud flags, risk scores, KYC outcomes (for sellers), audit logs.
How we collect data
- Direct collection: Data you provide during registration, checkout, support, or seller onboarding.
- Automated collection: Through cookies, SDKs, and server logs when you use the Platform.
- Third-party sources: Payment processors, logistics partners, identity verification services, marketing partners.
- Public sources: Information publicly available (e.g., business registries) to verify seller credentials.
How we use data and legal bases
- Provide services: Account setup, product listings, order processing, delivery, returns, and payouts.
Legal basis: Contract performance; legitimate interests. - Customer and seller support: Respond to inquiries, troubleshoot, resolve disputes.
Legal basis: Contract performance; legitimate interests. - Security and fraud prevention: Authenticate, detect abuse, manage risk, enforce policies.
Legal basis: Legitimate interests; legal obligations. - Personalization: Recommend products, tailor content, remember preferences.
Legal basis: Legitimate interests; consent (where required). - Marketing and promotions: Send updates, offers, and newsletters; manage opt-ins/opt-outs.
Legal basis: Consent; legitimate interests. - Analytics and improvement: Measure performance, improve UX, develop features.
Legal basis: Legitimate interests; consent (for certain cookies/SDKs). - Legal compliance: Tax, accounting, regulatory requests, disputes handling.
Legal basis: Legal obligations; establishment/exercise/defense of claims.
International data transfers
- Cross-border processing: Data may be stored or processed in countries other than your own.
- Safeguards: We use appropriate protections (e.g., contractual clauses, security controls) to safeguard transferred data.
- Access limitation: Only authorized personnel and processors may access personal data for legitimate purposes.
Data retention
- Retention principle: We keep data only as long as necessary for purposes outlined or as required by law.
- Typical periods: Account data retained while active; order and financial records retained for 6–7 years (subject to local law); support logs for 12–24 months.
- Deletion: We securely delete or anonymize data when retention ends, subject to legal holds or dispute resolution.
Data security
- Technical measures: Encryption in transit, hardened infrastructure, access controls, logging, backups.
- Organizational measures: Role-based access, staff training, vendor due diligence, incident response.
- Limitations: No system is 100% secure; we strive to protect data but cannot guarantee absolute security.
- Incident notifications: Where required by law, we will notify you and/or authorities of data breaches.
Your rights and choices
- Access: Request a copy of your personal data we hold.
- Rectification: Correct incomplete or inaccurate data.
- Deletion: Request deletion of data subject to legal retention requirements.
- Objection: Object to processing for certain purposes (e.g., direct marketing).
- Restriction: Request we limit processing in specific circumstances.
- Portability: Request your data in a machine-readable format where technically feasible.
- Consent withdrawal: Withdraw consent at any time for consent-based processing.
- Cookie controls: Manage cookie preferences via our banner and browser settings.
- How to exercise: Contact us via the details below; we may need to verify your identity.
Children’s privacy
- Minimum age: Our services are not directed to children below the age of legal capacity to contract in your jurisdiction.
- Parental consent: If we learn we processed data of a minor without proper consent, we will delete it.
Automated decision-making and profiling
- Personalization: We use profiling to recommend products and optimize the shopping experience.
- Fraud and risk: Automated checks may flag suspicious activity or high-risk transactions.
- Your options: You may object to certain profiling; however, essential fraud checks are necessary for platform integrity.
Marketing and communications
- Transactional messages: Order confirmations, delivery updates, account alerts.
- Marketing messages: Newsletters, offers, and promotions sent with consent or as permitted by law.
- Opt-out: You can opt out of marketing at any time via settings or the unsubscribe link.
- Seller communications: Sellers may contact customers for order-related reasons only, and must comply with this Policy.
Third-party services
- Payment gateways: Process transactions under their own privacy terms.
- Logistics providers: Handle delivery and returns using customer shipping details.
- Analytics/ads tools: Provide insights and advertising capabilities subject to your consent and settings.
- Social logins: If offered, sign-in via social accounts may share limited profile data with us.
- External links: We are not responsible for privacy practices of third-party websites linked from the Platform.
Policy changes
- Updates: We may update this Policy to reflect changes in law, technology, or our services.
- Notice: Material changes will be posted on this page with a revised effective date.
- Continued use: Your continued use after changes indicates acceptance of the updated Policy.
Contact and complaints
- Contact us: Use Platform support or email privacy@khareeddari.com.
- Complaints: If you believe your privacy rights were violated, contact us. You may also lodge a complaint with a relevant data protection authority where applicable.
Controller and key contacts
- Data controller: KhareedDari.com
- Registered address: Karachi, Sindh, Pakistan
- Data protection contact: privacy@khareeddari.com
Annexes and additional disclosures
Annex A: Categories of processors
- Cloud hosting and storage: Infrastructure, CDN, backups.
- Payments: Card processors, wallets, bank payout services.
- Logistics: Couriers, warehousing, return centers.
- Analytics and performance: Web/app analytics, crash reporting.
- Security: WAF/DDoS protection, threat detection, monitoring.
- Marketing: Email/SMS platforms, ad networks (consent-based).
- Verification: KYC/AML providers for seller onboarding.
Annex B: Regional notices
- Pakistan: We align with applicable local regulations and evolving data protection frameworks. Where specific consent or retention rules apply, we will implement them.
- International users: If accessing from other jurisdictions, local rights and rules may vary; we will apply appropriate safeguards and honor applicable legal requirements.
Annex C: Data subject request process
- Submission: Send requests via account settings or email.
- Verification: We may request additional information to confirm identity.
- Response time: We aim to respond within 30 days or as required by law.
- Limitations: Certain requests may be restricted by legal obligations, security, or legitimate interests.