Nishan
How it works Features Why Nishan Who it's for
Book a demo
← Back to home Legal

Privacy Policy

Last updated: 30 July 2026. Effective immediately.

On this page

  • 1. Overview
  • 2. Data we collect
  • 3. How we use data
  • 4. Who we share data with
  • 5. Retention and deletion
  • 6. Security
  • 7. Your rights
  • 8. International transfers
  • 9. Children's privacy
  • 10. Changes to this policy
  • 11. Contact

1. Overview

Nishan ("we", "us", "our") provides a verified-location memory service for delivery businesses. This policy explains what data we collect, how we use it, who we share it with, and what choices you have. It applies to the nishanhq.com website, the admin console at admin.nishanhq.com, and the developer API at api.nishanhq.com.

Plain-English summary: we store the data needed to run the service, we never sell customer data, and tenant data is strictly isolated between accounts.

2. Data we collect

We collect data in three buckets.

2.1 Account and tenant data

Provided by the customer when signing up and using the service:

  • Tenant name, billing email, phone, country, preferred currency.
  • Owner and user accounts: name, email, role, hashed password (argon2id).
  • API keys (we store only a hash; the raw key is shown once at creation).
  • Subscription plan and monthly order limit.

2.2 Operational data

Generated as tenants use the service:

  • Verified customer locations (latitude, longitude, accuracy, confidence score, geocoder provider, photo URL when uploaded).
  • Delivery records (status, rider, provider calls, distance, cost).
  • Capture events (who, when, what was verified, what was rejected).
  • Audit log entries (actor, action, target, IP, user agent, timestamp).
  • Usage counters and rate-limit telemetry.

2.3 Service data

Generated automatically by the platform:

  • Server access logs (IP, user agent, route, status code) retained 30 days.
  • Error traces and request IDs for debugging (redacted of PII).
  • Aggregated, de-identified metrics (e.g. total verified locations per region) for capacity planning.

We do not intentionally collect special-category data (race, religion, health, political views, etc.). Customer records should not contain such data; if they do, we treat them with the same protections as all operational data.

3. How we use data

We use the data above to:

  • Provide, operate and secure the API and admin console.
  • Authenticate users, enforce row-level security between tenants, and prevent abuse.
  • Bill customers, enforce plan limits, and produce invoices.
  • Detect, prevent and respond to fraud, abuse, and security incidents.
  • Comply with legal obligations and respond to lawful requests.
  • Improve the service (using de-identified or aggregated data only).

We do not use tenant operational data to train third-party models, and we do not sell or rent any personal data to data brokers.

4. Who we share data with

We share data only with the parties below, and only as needed.

4.1 Sub-processors

Sub-processorPurposeRegion
PostgreSQL / PostGIS host (self-hosted on our infra or our cloud)Primary databasePK / QA
Redis hostCache, rate limit, sessionsPK / QA
TPL MapsPakistan geocoding and reverse geocoding (per request)PK
QNAS (Qatar National Address System)Qatar geocoding (per request)QA
Google Maps Platform (optional)Geocoding for tenants who opt inGlobal
WhatsApp / Meta (deep link only)Customer support chat from our landing formGlobal
Email providerTransactional email (account, invoices, security alerts)Global
Stripe (or local PSP)Subscription billingGlobal / PK

4.2 Legal and safety

We may disclose data when required by a valid Pakistani, Qatari, or other applicable legal process, or when necessary to protect the rights, property or safety of Nishan, our customers, or the public.

4.3 Business transfers

If Nishan is acquired or merges, customer data may be transferred to the acquiring entity under a written commitment to honour this policy.

5. Retention and deletion

Data classRetention
Tenant operational data (locations, deliveries, customers)Life of tenant account + 30 days
Audit log entries13 months (then aggregated / anonymised)
Server access logs30 days
Refresh tokens and sessionsUntil expiry (30 days) or logout
API keys (revoked)Hash retained for 13 months for audit
Backups35 days rolling, then overwritten
Financial records (invoices)7 years (tax compliance)

Tenants can request export or deletion of their data at any time via privacy@nishanhq.com. We complete verified requests within 30 days.

6. Security

We protect data with industry-standard controls: TLS 1.2+ in transit, encryption at rest on managed disks, per-tenant row-level security in the database, argon2id password hashing, separate signing keys for tenant and platform-admin tokens, IP allowlisting for the admin console, and a full audit trail for every privileged action. Read the full Security & Data Handling page for details.

7. Your rights

Depending on your jurisdiction, you have some or all of these rights:

  • Access: request a copy of the personal data we hold about you.
  • Correction: ask us to fix inaccurate data.
  • Deletion: ask us to delete your data, subject to legal retention requirements.
  • Portability: receive your data in a machine-readable format.
  • Object / restrict: object to certain processing or ask us to pause it.
  • Withdraw consent: where processing is based on consent.
  • Complain: lodge a complaint with your local data protection authority.

To exercise any of these, email privacy@nishanhq.com from the address on file. We respond within 30 days.

8. International transfers

Primary data for Pakistani tenants is hosted in Pakistan. Primary data for Qatari tenants is hosted in Qatar. If data is transferred across borders (e.g. for support or backup), it is encrypted in transit and we apply the same controls regardless of region.

9. Children's privacy

Nishan is a B2B service. It is not directed to children under 16, and we do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@nishanhq.com and we will delete it.

10. Changes to this policy

We will post changes here and update the "Last updated" date. For material changes (new data uses, new sub-processors, new retention periods) we will email all tenant owners at least 30 days before the change takes effect.

11. Contact

Data Protection contact: privacy@nishanhq.com
General contact: hello@nishanhq.com
Postal: Nishan HQ, Lahore, Pakistan.

Nishan Mapping API

Verified-location memory for delivery teams. Pakistan-first.

Product

How it works Features Why Nishan Who it's for

Company

Contact Security

Legal

Privacy Terms Cookies

© Nishan. All rights reserved.

Built for delivery teams who are tired of paying to find the same doors.