1. Overview
This Privacy Policy explains how GimartHub ("GimartHub", "we", the data controller) collects, uses, shares, and protects personal data when you use the GimartHub Platform. It forms part of the Terms of Service.
We collect the minimum needed to run a safe marketplace with escrow, prevent fraud, meet legal obligations, and support you.
Which laws apply. GimartHub serves users in Pakistan and internationally. This Policy is written to meet:
- Pakistan — the Electronic Transactions Ordinance 2002, the Prevention of Electronic Crimes Act 2016 (PECA, as amended by the 2025 Amendment Act), the constitutional right to privacy (Article 14), the consumer-protection provisions of the e-Commerce Policy framework, and the forthcoming Personal Data Protection Act (a draft approved by the Federal Cabinet in 2025 but not yet enacted — we will update this Policy to comply once it is in force).
- EU / EEA — the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
- United Kingdom — the UK GDPR and Data Protection Act 2018.
- California — the California Consumer Privacy Act as amended by the CPRA, including the updated CCPA regulations effective 1 January 2026.
See the Regulatory & Compliance Framework for the fuller picture.
2. Data we collect
2.1 You give us
| Category | Examples | When |
|---|---|---|
| Account | Email, password (hashed), display name, handle, locale, country/region | Registration |
| Profile & store page | Avatar, bio, store name, tagline, accent colour, banner image | Optional |
| Identity / KYC | Government ID, selfie, date of birth, address — via our verification provider | When required to sell above USD 500 or on risk review |
| Seller payout | Bank/wallet details (encrypted) | Adding a payout method |
| Listings & orders | Listing content, order details, delivery info you submit | Selling / buying |
| Communications | Order messages, dispute evidence, support tickets and their attachments, contact-form submissions | As you send them |
| Reviews | Ratings, text, and any photo you attach | After orders |
| Uploaded images | Payment screenshots, delivery/pre-delivery proof, review photos, store banner, ticket attachments | When you upload them; stored with our file-hosting provider |
2.2 Collected automatically
- Device & usage: IP address, browser/device type, OS, pages viewed, referring URLs, actions, timestamps.
- Cookies & similar: see the Cookie Policy.
- Security & audit signals: account and access logs (IP addresses, session and device metadata, login events), approximate location from IP, device fingerprint, risk indicators, and an internal audit log of administrative and money-movement actions. These logs are kept to prevent and investigate fraud (for example a Seller reclaiming a sold account) and to assist law enforcement under PECA 2016. Retention is in Section 6.
- Buyer–seller messages: direct messages between a Buyer and a Seller, delivery details and proof, and dispute evidence — stored and visible to GimartHub staff for fraud prevention and dispute resolution.
2.3 From third parties
- Payments partner / banks: transfer confirmations, sender name and reference, and any reversal or chargeback notices for payments made to us or refunds made by us.
- Identity verification provider: verification result and associated metadata.
- Fraud-prevention partners: risk scores and flags.
- SMS provider: delivery status for any one-time codes we send.
3. How we use data and our legal bases
| Purpose | Examples | Legal basis (GDPR-style) |
|---|---|---|
| Provide the Platform | Accounts, listings, search, orders, escrow, messaging, payouts | Performance of a contract |
| Payments & escrow | Process payments, hold funds, release/refund, reconcile ledger | Contract; legal obligation |
| Trust & safety | Verify identity, detect and prevent fraud, moderate content, enforce policies, handle disputes | Legitimate interests; legal obligation |
| Support | Respond to tickets and contact-form messages | Contract; legitimate interests |
| Legal & compliance | Tax, accounting, AML/KYC, responding to lawful requests, DMCA | Legal obligation; legitimate interests |
| Communications | Transactional emails (required); product updates and marketing (optional) | Contract; consent (marketing) |
| Improve the Platform | Analytics, debugging, aggregated metrics | Legitimate interests; consent where required |
| Personalisation | Currency/region defaults, recommendations | Legitimate interests; consent where required |
Where we rely on consent (e.g. non-essential cookies, marketing), you can withdraw it at any time. Where we rely on legitimate interests, we have balanced them against your rights.
4. Sharing
We share personal data with:
- Other users, as needed for a transaction: a Buyer and Seller in the same order see each other's display name, rating, and the messages/delivery info exchanged. Sellers do not receive Buyers' payment details; Buyers do not receive Sellers' payout details.
- Service providers (processors): our regulated Pakistani payments partner and banks, identity verification, cloud hosting and file storage, email and SMS delivery, analytics and error monitoring, and fraud prevention. They may only process data on our instructions.
- Professional advisers: lawyers, auditors, accountants.
- Authorities and third parties: when required by law, to enforce our Terms, to protect the rights, safety, and property of GimartHub, our users, or the public, or in connection with an investigation.
- Corporate transactions: a merger, acquisition, financing, or asset sale, subject to confidentiality and this Policy.
We do not sell your personal data.
5. International transfers
We and our providers may process data in countries other than yours, including outside Pakistan and outside the EEA/UK. For transfers from the EEA/UK we rely on an adequacy decision where one exists, otherwise on the Standard Contractual Clauses (and the UK Addendum) plus supplementary measures. If Pakistan's Personal Data Protection Act is enacted with data-localisation requirements for sensitive personal data, we will store and process that category as required. Use the contact page for transfer details or a copy of the safeguards.
6. Retention
We keep personal data only as long as needed for the purposes above or as required by law. Summary (authoritative detail per data type is maintained internally):
| Data | Typical retention |
|---|---|
| Account profile | Life of the account |
| Policy-acceptance record (user, version, time, IP) | Life of the account + statutory period (ETO 2002 evidence) |
| Orders, payments, ledger, invoices | Up to 7 years after the transaction (financial / legal) |
| KYC documents | Life of the account plus the statutory minimum, then deleted |
| Access / IP / session logs | At least 12 months for fraud prevention and PECA 2016 law-enforcement assistance; longer under legal hold |
| Buyer–seller message logs | Life of the account; retained during any open dispute or legal hold; then purged on a verified deletion request |
| Dispute evidence | Life of the account + up to 2 years |
| Support tickets | Up to 3 years after closure |
| Audit log (admin & money actions, with actor IP) | At least 3 years |
| Analytics / marketing events | Up to 14 months |
| Reserved identifiers after deletion (your email address and phone number) | Kept indefinitely in a minimal block-list so the same email/phone cannot be used to open a new account. No profile, content, or contact use — matching only. |
| Data after account deletion | Profile PII anonymised or deleted within 30 days, except (a) reserved identifiers above, and (b) records under legal, tax, dispute, or law-enforcement hold |
Account deletion
You can delete your account from Settings → Delete account, or ask us to delete it. When an account is deleted:
- you are signed out of all sessions and can no longer log in;
- your email address and phone number are retained in a block-list so they cannot be used to register again (this is a fraud- and abuse-prevention measure; during the current testing phase an administrator may waive it for a specific test account);
- transaction, payment, invoice, dispute and audit records are kept for the periods in the table above — deleting an account does not delete the financial and legal record of trades that happened;
- other personal data in your profile is anonymised or removed within 30 days.
EU / UK users: you have the right to erasure under the GDPR / UK GDPR. Where we must keep certain records (Article 17(3) — legal obligations, establishment or defence of legal claims), we restrict that data to storage only and erase the rest. To make a formal erasure request, contact us via the contact page with the subject "GDPR erasure"; we respond within one month.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and get a copy.
- Rectify inaccurate or incomplete data.
- Erase data ("right to be forgotten"), subject to exceptions (e.g. transaction records we must keep).
- Restrict or object to certain processing, including direct marketing and profiling.
- Portability — receive certain data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to a solely automated decision with legal or similarly significant effect without a right to human review (see Section 9).
- Complain to your local data-protection authority.
To exercise rights, use the in-Platform privacy request tool or contact us via the contact page. We will verify your identity and respond within the timeframe required by applicable law (generally 30 days; up to 45 days for CCPA requests, extendable once). These rights are free unless a request is manifestly unfounded or excessive.
California residents (CCPA / CPRA). In addition to the above, you have the right to know what personal information we collect and how it is used and shared; to delete and to correct; to opt out of the "sale" or "sharing" of personal information; and to limit the use of sensitive personal information. GimartHub does not sell your personal information and does not "share" it for cross-context behavioural advertising. We honour the Global Privacy Control signal as an opt-out. We will not discriminate against you for exercising a right. Under the updated CCPA regulations effective 1 January 2026, "sensitive personal information" is read broadly, and we apply the required care to any automated decision-making technology, risk assessments, and security audits.
Pakistan. Until the Personal Data Protection Act is in force, we voluntarily extend access, correction and deletion requests to users in Pakistan, subject to the record-keeping obligations described in Section 6 and in the Terms of Service.
8. Security and breach notification
We use technical and organisational measures including encryption in transit (TLS) and at rest for sensitive fields, hashed passwords (bcrypt), single-use hashed password-reset tokens that expire in one hour, automatic temporary account lock after repeated failed sign-ins, optional SMS and app-based two-factor authentication, new-device / new-location sign-in alerts by email, access controls and least-privilege staff access, audit logging, network protection, malware scanning of uploads, and regular reviews. No system is perfectly secure.
We maintain an incident-response process. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, and will notify affected users where required. Report security concerns to the contact page.
9. Automated decision-making
We use automated risk scoring to detect fraud and abuse (e.g. flagging orders, limiting accounts, requiring extra verification). Significant actions (suspensions, payout freezes, dispute outcomes) involve human review. You can ask for a human review of, an explanation of, and to contest a decision that significantly affects you by contacting the contact page. We do not use your data to make solely automated decisions producing legal or similarly significant effects without that human safeguard, consistent with the GDPR and the CCPA's automated-decision-making rules (effective 2026, phased).
10. Children
The Platform is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, use the contact page and we will delete it.
11. Cookies
See the separate Cookie Policy. You can manage non-essential cookies via our consent banner and your browser settings.
12. Third-party links
The Platform may link to third-party sites (e.g. a payment provider). Their privacy practices are their own; review their policies.
13. Changes
We may update this Policy. Material changes will be notified (email or in-Platform) before they take effect. The "Effective date" above shows the current version.
14. Contact
Privacy questions, requests and Data Protection contact: the contact page · GimartHub, Pakistan.