Legal
Privacy Policy
This policy explains what data TaameerPro collects, why, which service providers process it on our behalf, how long we keep it, and the choices you have. It is written to match what the product actually does, nothing more.
- Last updated
- 11 July 2026
- Version
- 2026-07-11
On this page
اردو خلاصہ
ہم صرف وہ ڈیٹا اکٹھا کرتے ہیں جو سروس چلانے کے لیے ضروری ہے: آپ کے اکاؤنٹ کی معلومات، آپ کے پروجیکٹ کا ریکارڈ اور اپ لوڈ کی گئی فائلیں۔ کارڈ کی معلومات ہمارے پاس کبھی محفوظ نہیں ہوتیں, ادائیگی سٹرائپ سنبھالتا ہے۔ ہم اشتہاری کمپنیوں کو ڈیٹا نہیں بیچتے اور نہ کوئی ٹریکنگ کوکیز استعمال کرتے ہیں۔ آپ اپنا ڈیٹا دیکھ سکتے ہیں، درست کر سکتے ہیں، اور اپنا اکاؤنٹ مکمل طور پر حذف کروا سکتے ہیں۔
This is a courtesy Urdu summary. The English document below is the binding version.
Who this covers
This policy covers everyone who interacts with TaameerPro: workspace owners and team members, clients and vendors who are given portal access, and visitors to this website. TaameerPro is operated from Lahore, Pakistan.
For most of the data in a workspace, including project records, workforce details, and client contacts, your organization decides what is entered and who sees it; we process that data on the organization’s instructions to provide the Service.
What we collect
- Account data: name, email address, optional phone number, preferred language, and a hashed password (we never store passwords in plain text). If you enable two-factor authentication, the TOTP secret is stored encrypted.
- Workspace data: everything your organization enters to run its projects: projects and stages, procurement records, workforce records (including labourer names, attendance, and payroll figures), financial entries, client and vendor contact details, and uploaded documents and photos.
- Billing data: your plan, subscription status, and invoice history. Card details are collected and stored by Stripe, our payment processor; they never touch our servers.
- Security and usage logs: IP address, browser user-agent, and an audit trail of significant actions inside the workspace (who changed what, and when). These exist to protect accounts and to give administrators accountability.
- Contact form submissions: if you use the contact form on this website, we store the name, email address, company, topic, and message you send, together with the IP address and browser user-agent of the submission and the page you sent it from. We keep these so we can reply and so we have a record of requests, including account-deletion requests. We use them only to respond to you, and you can ask us to delete a submission at any time.
- Spam protection: contact form submissions are checked with Google reCAPTCHA, which collects device and usage signals under Google’s own privacy policy in order to score how likely the submission is to be automated. We store only the resulting score.
How we use it
- to provide, operate, and back up the Service;
- to secure accounts: login rate limiting, lockout after repeated failures, session management, and audit logging;
- to send transactional email (verification, password reset, invitations, notifications your workspace has enabled, billing and trial reminders). We do not send third-party marketing;
- to process subscription payments through Stripe;
- to generate AI insights, only when you use an AI feature, by sending the relevant project data to Google Gemini.
We do not sell personal data, and we do not share it with advertising networks or data brokers.
Service providers (processors)
These are the only third parties that process your data, and only for the purpose stated:
- DigitalOcean: cloud infrastructure hosting the application and database.
- Cloudflare R2: private storage for uploaded files (documents, photos) and encrypted-at-rest database backups; files are served through short-lived signed links.
- Stripe: subscription payments. Stripe holds all card data; we store only non-sensitive billing references.
- Google (Gemini): AI analysis, invoked only when your workspace uses an AI feature.
- Email (SMTP) provider: delivery of transactional email.
A more detailed operational view, including what data each provider sees and why, is on the Data Processing page. We will update this list before adding a new provider.
How long we keep data
- Workspace data is kept for as long as your organization's account is active.
- Read in-app notifications are deleted automatically after 90 days.
- Workspace audit logs are retained for 90 days.
- Automated database backups are kept on a rotating schedule. Older snapshots are replaced as new ones are taken.
- If your organization deletes its account, the workspace is purged permanently after the 30-day grace period; backup copies age out as the backup rotation replaces them.
- Contact form submissions are kept while we deal with the enquiry and as a record of the request afterwards. Ask us and we will delete a submission.
Your rights and choices
- View and correct your account details and workspace data directly in the app.
- Get a copy of your data. Paid plans can download a complete export of the workspace from Settings → Data transfer. On the free plan or during a trial, request one through the contact page and we will provide it — your right to a copy of your data does not depend on paying us.
- Delete your organization and all its data. Paid plans can do this from Settings, with a 30-day grace period before the permanent purge. On the free plan or during a trial, send a deletion request through the contact page and we will confirm by email and complete it within 30 days. Erasure is never conditional on payment.
- Portal users (clients and vendors): access is issued and managed by the organization that invited you. Direct your requests to them, and we will support the organization in fulfilling them.
How we protect data
- encryption in transit (HTTPS/TLS) for all traffic;
- passwords hashed with bcrypt; two-factor authentication secrets encrypted at rest;
- short-lived access tokens with rotated, hashed refresh tokens and reuse detection;
- role-based access control and per-organization data isolation enforced at the data layer;
- login rate limiting and automatic account lockout;
- audit trails of significant actions;
- scheduled automated backups.
We do not currently hold formal security certifications (such as SOC 2 or ISO 27001) and do not claim them. The Data Processing page describes the architecture factually for procurement reviews.
Children
TaameerPro is a workplace tool and is not directed at children. Do not create accounts for anyone under 18.
Changes to this policy
Material changes are published here as a new dated version, recorded in the changelog below, and notified to workspace administrators.
Contact
For privacy questions or requests, reach us through the contact page.
Changelog
Every material revision of this document is recorded here.
- 2026-07-1111 July 2026First published version of the Privacy Policy.
Legal centre