Privacy Policy
Last updated: 30 July 2026. Effective immediately.
1. Overview
Nishan ("we", "us", "our") provides a verified-location memory service for delivery businesses. This policy explains what data we collect, how we use it, who we share it with, and what choices you have. It applies to the nishanhq.com website, the admin console at admin.nishanhq.com, and the developer API at api.nishanhq.com.
Plain-English summary: we store the data needed to run the service, we never sell customer data, and tenant data is strictly isolated between accounts.
2. Data we collect
We collect data in three buckets.
2.1 Account and tenant data
Provided by the customer when signing up and using the service:
- Tenant name, billing email, phone, country, preferred currency.
- Owner and user accounts: name, email, role, hashed password (argon2id).
- API keys (we store only a hash; the raw key is shown once at creation).
- Subscription plan and monthly order limit.
2.2 Operational data
Generated as tenants use the service:
- Verified customer locations (latitude, longitude, accuracy, confidence score, geocoder provider, photo URL when uploaded).
- Delivery records (status, rider, provider calls, distance, cost).
- Capture events (who, when, what was verified, what was rejected).
- Audit log entries (actor, action, target, IP, user agent, timestamp).
- Usage counters and rate-limit telemetry.
2.3 Service data
Generated automatically by the platform:
- Server access logs (IP, user agent, route, status code) retained 30 days.
- Error traces and request IDs for debugging (redacted of PII).
- Aggregated, de-identified metrics (e.g. total verified locations per region) for capacity planning.
We do not intentionally collect special-category data (race, religion, health, political views, etc.). Customer records should not contain such data; if they do, we treat them with the same protections as all operational data.
3. How we use data
We use the data above to:
- Provide, operate and secure the API and admin console.
- Authenticate users, enforce row-level security between tenants, and prevent abuse.
- Bill customers, enforce plan limits, and produce invoices.
- Detect, prevent and respond to fraud, abuse, and security incidents.
- Comply with legal obligations and respond to lawful requests.
- Improve the service (using de-identified or aggregated data only).
We do not use tenant operational data to train third-party models, and we do not sell or rent any personal data to data brokers.
4. Who we share data with
We share data only with the parties below, and only as needed.
4.1 Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| PostgreSQL / PostGIS host (self-hosted on our infra or our cloud) | Primary database | PK / QA |
| Redis host | Cache, rate limit, sessions | PK / QA |
| TPL Maps | Pakistan geocoding and reverse geocoding (per request) | PK |
| QNAS (Qatar National Address System) | Qatar geocoding (per request) | QA |
| Google Maps Platform (optional) | Geocoding for tenants who opt in | Global |
| WhatsApp / Meta (deep link only) | Customer support chat from our landing form | Global |
| Email provider | Transactional email (account, invoices, security alerts) | Global |
| Stripe (or local PSP) | Subscription billing | Global / PK |
4.2 Legal and safety
We may disclose data when required by a valid Pakistani, Qatari, or other applicable legal process, or when necessary to protect the rights, property or safety of Nishan, our customers, or the public.
4.3 Business transfers
If Nishan is acquired or merges, customer data may be transferred to the acquiring entity under a written commitment to honour this policy.
5. Retention and deletion
| Data class | Retention |
|---|---|
| Tenant operational data (locations, deliveries, customers) | Life of tenant account + 30 days |
| Audit log entries | 13 months (then aggregated / anonymised) |
| Server access logs | 30 days |
| Refresh tokens and sessions | Until expiry (30 days) or logout |
| API keys (revoked) | Hash retained for 13 months for audit |
| Backups | 35 days rolling, then overwritten |
| Financial records (invoices) | 7 years (tax compliance) |
Tenants can request export or deletion of their data at any time via privacy@nishanhq.com. We complete verified requests within 30 days.
6. Security
We protect data with industry-standard controls: TLS 1.2+ in transit, encryption at rest on managed disks, per-tenant row-level security in the database, argon2id password hashing, separate signing keys for tenant and platform-admin tokens, IP allowlisting for the admin console, and a full audit trail for every privileged action. Read the full Security & Data Handling page for details.
7. Your rights
Depending on your jurisdiction, you have some or all of these rights:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to fix inaccurate data.
- Deletion: ask us to delete your data, subject to legal retention requirements.
- Portability: receive your data in a machine-readable format.
- Object / restrict: object to certain processing or ask us to pause it.
- Withdraw consent: where processing is based on consent.
- Complain: lodge a complaint with your local data protection authority.
To exercise any of these, email privacy@nishanhq.com from the address on file. We respond within 30 days.
8. International transfers
Primary data for Pakistani tenants is hosted in Pakistan. Primary data for Qatari tenants is hosted in Qatar. If data is transferred across borders (e.g. for support or backup), it is encrypted in transit and we apply the same controls regardless of region.
9. Children's privacy
Nishan is a B2B service. It is not directed to children under 16, and we do not knowingly collect data from children. If you believe a child has provided us data, contact privacy@nishanhq.com and we will delete it.
10. Changes to this policy
We will post changes here and update the "Last updated" date. For material changes (new data uses, new sub-processors, new retention periods) we will email all tenant owners at least 30 days before the change takes effect.
11. Contact
Data Protection contact:
privacy@nishanhq.com
General contact:
hello@nishanhq.com
Postal: Nishan HQ, Lahore, Pakistan.