IspDaftar

IspDaftar

Back to Home

Privacy Policy

Last updated: 9 May 2026

1. Introduction

IspDaftar ("the Service", "we", "us") is a multi-tenant SaaS platform that helps Internet Service Provider (ISP) operators in Pakistan manage their networks, customer subscriptions, billing, expenses, complaints, and reporting. This policy describes the personal information we collect, why we collect it, how we use and protect it, and the choices you have. It applies to:

  • Our website and web application at ispdaftar.com
  • Our IspDaftar mobile applications for Android (Google Play) and iOS (Apple App Store)
  • All related backend APIs and infrastructure

IspDaftar serves two types of users: (a) ISP operators — the businesses (tenants) that subscribe to use our platform, including their administrative and staff users; and (b) customers/subscribers — the end-users of those ISPs whose accounts are managed on the platform. Where this policy refers to "you", we mean either group as the context requires.

2. Information We Collect

2.1 Account information you (or your ISP) provide

For ISP operator accounts (tenants and staff):

  • Business name, billing email, contact phone number, business logo
  • Staff full name, email address, password (stored as a one-way bcrypt hash, never in plaintext), CNIC (Pakistani National Identity Card number), mobile number, residential or business address, profile photo
  • Role and permission assignments within your organisation

For ISP customers (subscribers):

  • Customer ID assigned by your ISP, full name, email address, password (bcrypt-hashed), CNIC, mobile number, address, profile photo

Customer accounts are typically created and managed by the ISP operator (not self-registered). If you are an ISP customer, your ISP is the controller of your account information; IspDaftar acts as the processor on their behalf.

2.2 Operational data generated by your use of the Service

  • Subscription/package activations (entries): start date, expiry date, package selected, sale and purchase rates, IP type (static or dynamic), assigned static IP if applicable, transaction reference (optional), and the payment method category you selected (e.g. cash, JazzCash, EasyPaisa, U-Paisa, NayaPay, SadaPay, Meezan Bank, Other, Pending) — we do not store any card numbers, CVVs, bank account numbers, or wallet credentials
  • Invoices issued to you or by you, expense records (with optional uploaded receipt image), and extra-income records
  • Complaints you file, including title, description, and any resolution notes added by ISP staff
  • In-app notifications targeted to your role/permissions
  • An audit log capturing who created, modified, deleted, approved, declined, reversed, or restored records (auto-deleted after 90 days)

2.3 Mobile-app permissions (only when you grant them)

  • Camera (Android, iOS): used only when you choose to capture a new profile photo. The image is uploaded to our servers and not shared with any other party.
  • Photos / media library (Android, iOS): used only when you choose to select an existing photo as your profile picture.
  • Network/Internet (Android, iOS): used to communicate with our backend.

We do not request or use location, contacts, microphone, calendar, health, fitness, Bluetooth, or any background-activity permissions. We do not use Apple's AppTrackingTransparency tracking, advertising identifiers (IDFA, GAID), or device fingerprinting.

2.4 What we do NOT collect

  • Credit card or debit card numbers, CVVs, or other payment instrument details — never collected, stored, or transmitted by IspDaftar
  • Your IP address, browser fingerprint, or device advertising ID
  • Your geographic location
  • Health, biometric, racial, religious, or other special-category sensitive data
  • Information from children — see Section 9

3. How We Use Your Data

  • To authenticate you and authorise access to features based on your role and permissions
  • To operate the Service: store and display customer records, generate billing entries, calculate ISP balances, prepare monthly profit-and-loss reports, and surface notifications to relevant staff
  • To send transactional emails (password reset, expense pending review, invoice copies) via our email provider
  • To send transactional WhatsApp messages to ISP customers when their ISP enables this feature: confirmation of package activation, reminders before subscription expiry, and server-up/server-down status updates. Messages use pre-approved templates and are sent only to the customer's own number.
  • To respond to complaints and support requests
  • To maintain audit trails for security, accountability, and legitimate business record-keeping

We do not use your data to deliver advertising, build advertising profiles, retarget you on third-party platforms, train AI or machine-learning models, or sell or rent your data to anyone for any purpose.

4. Service Providers (Sub-processors)

IspDaftar relies on the following carefully selected service providers to operate. Each receives only the minimum data needed to perform its function and is contractually bound to process data on our instructions only.

  • MongoDB Atlas (United States) — primary application database. Encrypts data at rest.
  • Amazon Web Services / Amazon S3 (United States) — storage of profile photos and uploaded expense receipts. Bucket: connect-lodhran-media.
  • Resend (United States) — transactional email delivery (password resets, expense approval notices, etc.).
  • WapiSys (Pakistan) — WhatsApp template-message delivery to ISP customers, when enabled by their ISP.
  • Apple Inc. and Google LLC — solely as the platforms through which our mobile apps are distributed (App Store, Google Play). Standard platform diagnostics may be collected by Apple/Google on their own terms; IspDaftar does not integrate any analytics, crash-reporting, or advertising SDKs of its own.

We do not integrate any third-party analytics, advertising, A/B testing, social media, or attribution SDKs in our mobile or web applications.

5. International Data Transfers

Some of our service providers (notably MongoDB Atlas, AWS, and Resend) are located in the United States. By using IspDaftar, you acknowledge that your information may be transferred to, stored in, and processed in countries other than your country of residence, including the United States. We require all sub-processors to apply industry-standard safeguards including encryption in transit and at rest, access controls, and contractual data-processing terms.

6. Data Retention

  • Active accounts: account and operational data are retained for as long as the account is active and as needed to provide the Service.
  • Audit log entries: automatically deleted 90 days after creation (enforced by a database TTL index).
  • In-app notifications: automatically deleted 90 days after creation.
  • Account deletion: when you (or your ISP, on your behalf) request deletion, we remove personal data from our active systems within 7 working days. Backup copies are purged on our backup-rotation schedule (typically within 30 days).
  • Some records (for example, financial entries and invoices) may be retained for longer where required to satisfy legitimate business, accounting, or legal obligations.

7. Security

  • All data in transit between your device and our servers is encrypted using HTTPS/TLS.
  • Database storage is encrypted at rest by MongoDB Atlas.
  • Passwords are hashed with bcrypt and never stored or transmitted in plaintext.
  • Multi-tenant data isolation: every database query is scoped to your tenant, so one ISP cannot read another ISP's data.
  • Authentication is performed using signed, expiring JSON Web Tokens (JWTs).
  • Role-based access control: staff can only access modules and actions matching the permissions assigned to them.
  • Inputs are validated and sanitised against common attacks (XSS, NoSQL injection).

No system can be guaranteed 100% secure. If we ever become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.

8. Cookies and Local Storage

Web app: we use only browser localStorage to keep your session token while you are signed in. We do not set tracking cookies, advertising cookies, or third-party analytics cookies.

Mobile apps: we use the device's AsyncStorage to persist your session locally (the role you signed in as, your access token, your refresh token if any, and a copy of your basic profile) so that you do not have to log in again every time the app launches. Logging out clears this storage. The mobile apps do not include any tracking, analytics, or advertising libraries.

9. Children's Privacy

IspDaftar is a business platform for ISP operators and their adult customers. The Service is not directed at children under the age of 13 (or under 16 in jurisdictions where 16 is the relevant age), and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact support@ispdaftar.com and we will promptly delete the information.

10. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete information
  • Delete your account and associated personal data ("right to erasure")
  • Object to or restrict certain processing
  • Receive a copy of your data in a portable, machine-readable format
  • Withdraw consent where processing relies on consent

To exercise any of these rights, email support@ispdaftar.com from the address registered on your account. We will respond within 30 days. If you are an ISP customer, please note that your account is controlled by your ISP; we may direct certain requests (such as correction of the customer-record fields they manage) to your ISP first.

11. Account and Data Deletion

ISP operators (tenants and staff): to delete your account and all associated business data (customer records, entries, invoices, expenses, complaints, audit log, uploaded files, and notifications), email support@ispdaftar.com from the email address registered on your account. We will verify the request and complete deletion within 7 working days; backup copies roll off our backup-rotation schedule within 30 days.

ISP customers (mobile-app users): your account is created and managed by your ISP. To have your account and personal data removed, contact your ISP directly, or email support@ispdaftar.com and we will coordinate with your ISP on your behalf.

12. Mobile App Store Disclosures

Apple App Store (iOS): in our app's App Privacy disclosure, we report camera and photo-library access (used solely for profile photos), and account information (name, email, phone, address) linked to your identity for app functionality. We do not engage in tracking as defined by Apple's AppTrackingTransparency framework.

Google Play (Android): in our Data Safety disclosure, we declare collection of name, email, phone number, address, photos (profile picture), and app activity strictly limited to your in-app interactions. Data is encrypted in transit, and we provide a way to request data deletion. IspDaftar does not share user data with third parties beyond the service providers listed in Section 4.

13. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect the most recent revision. For material changes that affect how we use your information, we will provide reasonable advance notice in-app or by email before the change takes effect.

14. Contact Us

If you have any questions, concerns, or requests regarding this policy or your personal data, please contact us at support@ispdaftar.com.

© 2026 IspDaftar. All rights reserved.