Legal

Privacy Policy

This policy explains what data TaameerPro collects, why, which service providers process it on our behalf, how long we keep it, and the choices you have. It is written to match what the product actually does — nothing more.

Last updated: 11 July 2026Version 2026-07-11

اردو خلاصہ

ہم صرف وہ ڈیٹا اکٹھا کرتے ہیں جو سروس چلانے کے لیے ضروری ہے: آپ کے اکاؤنٹ کی معلومات، آپ کے پروجیکٹ کا ریکارڈ اور اپ لوڈ کی گئی فائلیں۔ کارڈ کی معلومات ہمارے پاس کبھی محفوظ نہیں ہوتیں — ادائیگی سٹرائپ سنبھالتا ہے۔ ہم اشتہاری کمپنیوں کو ڈیٹا نہیں بیچتے اور نہ کوئی ٹریکنگ کوکیز استعمال کرتے ہیں۔ آپ اپنا ڈیٹا دیکھ سکتے ہیں، درست کر سکتے ہیں، اور اپنا اکاؤنٹ مکمل طور پر حذف کروا سکتے ہیں۔

This is a courtesy Urdu summary. The English document below is the binding version.

1.Who this covers

This policy covers everyone who interacts with TaameerPro: workspace owners and team members, clients and vendors who are given portal access, and visitors to this website. TaameerPro is operated from Lahore, Pakistan.

For most of the data in a workspace — project records, workforce details, client contacts — your organization decides what is entered and who sees it; we process that data on the organization’s instructions to provide the Service.

2.What we collect

  • Account data — name, email address, optional phone number, preferred language, and a hashed password (we never store passwords in plain text). If you enable two-factor authentication, the TOTP secret is stored encrypted.
  • Workspace data — everything your organization enters to run its projects: projects and stages, procurement records, workforce records (including labourer names, attendance, and payroll figures), financial entries, client and vendor contact details, and uploaded documents and photos.
  • Billing data — your plan, subscription status, and invoice history. Card details are collected and stored by Stripe, our payment processor; they never touch our servers.
  • Security and usage logs — IP address, browser user-agent, and an audit trail of significant actions inside the workspace (who changed what, and when). These exist to protect accounts and to give administrators accountability.

3.How we use it

  • to provide, operate, and back up the Service;
  • to secure accounts — login rate limiting, lockout after repeated failures, session management, and audit logging;
  • to send transactional email (verification, password reset, invitations, notifications your workspace has enabled, billing and trial reminders) — we do not send third-party marketing;
  • to process subscription payments through Stripe;
  • to generate AI insights, only when you use an AI feature, by sending the relevant project data to Google Gemini.

We do not sell personal data, and we do not share it with advertising networks or data brokers.

4.Service providers (processors)

These are the only third parties that process your data, and only for the purpose stated:

  • DigitalOcean — cloud infrastructure hosting the application and database.
  • Cloudflare R2 — private storage for uploaded files (documents, photos) and encrypted-at-rest database backups; files are served through short-lived signed links.
  • Stripe — subscription payments. Stripe holds all card data; we store only non-sensitive billing references.
  • Google (Gemini) — AI analysis, invoked only when your workspace uses an AI feature.
  • Email (SMTP) provider — delivery of transactional email.

A more detailed operational view — what data each provider sees and why — is on the Data Processing page. We will update this list before adding a new provider.

5.Cookies and local storage

The honest, short list:

  • Refresh-token cookie — an httpOnly, essential-only cookie that keeps you signed in securely. It is not readable by page scripts and is not used for tracking.
  • Browser local storage — your theme, language preference, workspace identifier, and (for client/vendor portals) the portal session token.

There are no advertising or third-party analytics cookies on this site, which is why you do not see a cookie consent banner.

6.How long we keep data

  • Workspace data is kept for as long as your organization's account is active.
  • Read in-app notifications are deleted automatically after 90 days.
  • Workspace audit logs are retained for 90 days.
  • Automated database backups are kept on a rotating schedule — older snapshots are replaced as new ones are taken.
  • If your organization deletes its account, the workspace is purged permanently after the 30-day grace period; backup copies age out as the backup rotation replaces them.

7.Your rights and choices

  • View and correct your account details and workspace data directly in the app.
  • Request a copy of your organization’s data by contacting us via the contact page; a self-serve export is on our roadmap.
  • Delete your organization and all its data via Settings (30-day grace period, then permanent purge).
  • Portal users (clients and vendors): access is issued and managed by the organization that invited you — direct your requests to them, and we will support the organization in fulfilling them.

8.How we protect data

  • encryption in transit (HTTPS/TLS) for all traffic;
  • passwords hashed with bcrypt; two-factor authentication secrets encrypted at rest;
  • short-lived access tokens with rotated, hashed refresh tokens and reuse detection;
  • role-based access control and per-organization data isolation enforced at the data layer;
  • login rate limiting and automatic account lockout;
  • audit trails of significant actions;
  • scheduled automated backups.

We do not currently hold formal security certifications (such as SOC 2 or ISO 27001) and do not claim them. The Data Processing page describes the architecture factually for procurement reviews.

9.Children

TaameerPro is a workplace tool and is not directed at children. Do not create accounts for anyone under 18.

10.Changes to this policy

Material changes are published here as a new dated version, recorded in the changelog below, and notified to workspace administrators.

11.Contact

For privacy questions or requests, reach us through the contact page.

Changelog

Every material revision of this document is recorded here.

  • 2026-07-1111 July 2026First published version of the Privacy Policy.

Related: Terms of Service · Privacy Policy · Data Processing · Contact us