Menu
Invoice Get In Touch

Privacy Policy

What we collect, why we collect it, and the control you keep over it. Written to be read, not to be skimmed past.

01 - Our position

Four principles we hold to

Ecomsy (SMC-PRIVATE) LIMITED is the controller of the personal data described here. We built our data practices around four commitments rather than the legal minimum.

We collect the minimum

If we do not need a piece of information to do the job, we do not ask for it. Our forms are deliberately short and every optional field is marked as optional.

We never sell your data

Your information is not sold, rented, traded or handed to data brokers. It is not a product line for us and never will be.

We explain in plain words

No dense legal walls designed to be abandoned halfway. If a practice cannot be explained simply, we treat that as a sign the practice needs rethinking.

You stay in control

You can ask what we hold, request a copy, correct it or have it deleted. One email is enough, and we do not make you justify the request.

02 - Collection

What we actually collect

Everything below comes from one of three places: you give it to us, our systems record it automatically, or a service we use passes it on.

  • Contact details. Name, email address, WhatsApp or phone number and company name, when you submit a form, request a quote or start a chat.
  • Project information. The brief, budget range, timeline and any files or materials you share so we can scope and deliver the work.
  • Support conversations. Messages exchanged with Eva or our team, plus any attachments, so we can resolve and reference your request.
  • Applications. If you apply for a role, the details and documents you submit for that application.
  • Learning records. For course and mentorship students, enrolment details, progress and certification records held in our learning portal.
  • Billing details. Invoice and payment records. Card details are handled entirely by Stripe and never reach or rest on our servers.
  • Technical data. IP address, browser type, device, pages viewed and referring source, recorded automatically for security and analytics.
Contact formName, email, message
WhatsApp numberOptional
Card detailsNever stored by us
Chat transcriptKept for support
Tracking cookiesOnly with consent
Data soldNever

Children

Our services are intended for adults and for businesses. We do not knowingly collect personal data from children under 16. If you believe a child has provided us information, contact us and we will delete it promptly.

03 - Purpose

Why we hold each piece of data

Every purpose below has a lawful basis behind it. We do not repurpose data for something you would not reasonably expect.

PurposeWhat it involvesLawful basis
Responding to enquiriesReplying to your message, preparing a quote and discussing your project.Steps before a contract
Delivering projectsBuilding, testing and supporting the work you engaged us for.Performance of a contract
Billing and recordsIssuing invoices, processing payments and meeting accounting obligations.Contract and legal obligation
Support and ticketsHandling live chat, tickets and follow-up so issues are traceable.Legitimate interests
Improving the siteUnderstanding which pages help visitors and where the site falls short.Legitimate interests or consent
SecurityDetecting abuse, preventing fraud and protecting accounts and infrastructure.Legitimate interests
Marketing updatesOccasional emails about services or offers, only if you opted in.Consent

How long we keep it

Enquiries that do not become projects are kept for up to 24 months in case you return. Project and billing records are retained for the period required by tax and company law, typically several years. Support conversations are kept while they remain useful for context, and applications are kept for up to 12 months unless you ask us to remove them sooner.

04 - Sharing

Who else touches your data

We use a small number of established providers to run the business. Each one processes data on our instructions, and none of them receive your data to use for their own marketing.

Payment processing

Stripe handles card payments end to end. Your card number is entered on Stripe's own secure page and never passes through our servers, so we only ever see that a payment succeeded.

Hosting & email

Our website, application data and email run on established hosting infrastructure with access restricted to the people who need it to operate the service.

AI assistant

Eva, our website assistant, is powered by Anthropic's Claude. Messages you send are processed to generate a reply. Avoid sharing passwords or sensitive personal details in chat.

Analytics & translation

We use analytics to understand site usage in aggregate, and Google Translate to offer the site in multiple languages. Translation sends page text to Google when you switch language.

Professional advisers

Accountants, auditors or legal advisers may see limited records where required to run the company properly or to meet a legal obligation.

Legal requirements

We may disclose information where the law requires it, or to protect our rights, safety or property. We do not hand over data voluntarily beyond that.

International transfers

Some providers operate outside Pakistan, so your data may be processed in other countries. Where that happens we rely on providers who commit to recognised safeguards and contractual protections for the data they handle on our behalf.

05 - Protection

How we protect what we hold

Security is layered rather than a single measure. These are the practical protections behind our site and systems.

Encrypted in transit

The entire site runs over HTTPS, so information you submit is encrypted between your browser and our servers rather than travelling in the clear.

Restricted access

Internal systems sit behind authenticated accounts with role-based permissions, so team members only reach the data their job requires.

Card data never touches us

Payments are handled entirely by Stripe. Because card details are captured on their infrastructure, a breach of our systems could not expose them.

Hardened by policy

Security headers, a content security policy, rate limiting and spam protection reduce the attack surface of the public site and its forms.

Protected uploads

Documents uploaded through our systems are stored outside public reach and served only to authenticated users, never through a guessable public link.

An honest caveat

No system on the internet is perfectly secure, and any company claiming otherwise is overselling. What we can commit to is using appropriate safeguards, keeping them current, and telling you promptly if a breach ever affects your data rather than quietly hoping it goes unnoticed.

06 - Control

Your rights over your data

These rights apply regardless of where you are. You do not need to give a reason, and exercising them costs nothing.

Access

Ask what personal data we hold about you and receive a copy of it.

Correction

Have inaccurate or incomplete information about you corrected.

Deletion

Ask us to erase your data where we have no ongoing legal or contractual need to keep it.

Objection

Object to processing based on legitimate interests, including any direct marketing.

Restriction

Ask us to pause processing while a concern or dispute is being resolved.

Portability

Receive the data you gave us in a common, machine-readable format.

How to exercise them

Email info@ecomsy.com.pk with what you would like. We aim to respond within 30 days and will confirm your identity first, so that nobody else can request your data by pretending to be you. Marketing emails also carry an unsubscribe link in every message, which takes effect immediately.

07 - Cookies

Cookies and local storage

Cookies are small files a site stores in your browser. We use few of them, and only tracking cookies require your consent.

TypeWhat it doesConsent needed
EssentialKeeps you signed in, maintains your session and protects forms from abuse. The site cannot work without these.No
PreferencesRemembers your choices, such as dark mode, language and an ongoing chat with Eva.No
AnalyticsTells us in aggregate which pages are useful and where visitors drop off.Yes
MarketingUsed to measure campaigns where we run them. Not used to build profiles for sale.Yes

Managing cookies

Every major browser lets you view, block or delete cookies in its settings. Blocking essential cookies will break parts of the site such as staying logged in, but blocking analytics or marketing cookies will not affect how the site works for you.

08 - Questions

Privacy questions, answered

The things people most often want to know before sharing their details with us.

No. We do not sell, rent or trade personal data, and we do not pass it to data brokers or advertising networks for their own use. The only organisations that touch your data are the service providers we use to run the business, such as our host and Stripe, and they act on our instructions.

No, and this is deliberate. When you pay an invoice you are redirected to Stripe's own secure checkout, where the card details are entered. Those details never pass through or rest on our servers, so we only ever see confirmation that a payment succeeded and the amount.

Your chat is visible to our support team so they can help you, and it is processed by Anthropic's Claude to generate replies. It is not published or shared beyond that. As with any chat, please do not send passwords, card numbers or sensitive personal information.

Email info@ecomsy.com.pk and ask. We will verify who you are, then delete what we are not legally required to keep. Some records, particularly invoices and accounting entries, must be retained for a period set by tax law, and we will tell you clearly if that applies to anything in your request.

Only if you opted in. Requesting a quote gets you replies about that enquiry, not a newsletter subscription. If you do opt in, every message carries an unsubscribe link that works immediately.

We keep enquiries for up to 24 months, because people often return months later and it helps to have the earlier context. After that it is removed, and you can ask us to delete it sooner at any point.

Primarily on our hosting infrastructure, with some data processed by providers who operate internationally, such as our payment processor and AI provider. Where data crosses borders, we rely on providers who commit to recognised safeguards for the information they handle for us.

Changes to this policy

We update this page when our practices change and revise the date shown here. Material changes will be highlighted on the site rather than slipped in quietly. Questions or concerns can go to info@ecomsy.com.pk, and we would genuinely rather hear from you than have you assume the worst.