What we collect, why we collect it, and what you can make us delete.
Last updated 21 July 2026
Aghaz is an e-commerce platform operated from Pakistan by Arsalan & Brothers ("we", "us"). This policy covers aghaz.pk, the store dashboard, and every store hosted on the platform. Using any of them means this policy applies to you.
Two different kinds of people appear below, and they are not treated the same:
When you open a store: your name, email address, password (stored only as a one-way hash — we cannot read it), your store name and address, and your two-factor secret if you turn 2FA on.
When your store takes an order: the shopper's name, phone number, delivery address, what they ordered, and the order's status history. Cash on delivery means we never see card numbers, because no card is ever entered.
Automatically: IP addresses, browser and device type, the pages visited, and where the visit came from. We use this for the traffic reports in your dashboard, and to block fraud — rate-limiting, phone blacklists and repeat-order checks all need it.
When you contact us: whatever you write in a support message or ticket, and any screenshot you attach.
We do not sell your data, and we do not sell your shoppers' data. We do not use one merchant's customer list to advertise to another merchant.
Only the services that make the platform work, and only the part each one needs:
We also hand over data if the law requires it. If that ever happens we will tell you, unless we are legally barred from doing so.
If you connect a Google account — for Analytics, Search Console or Google Ads — we ask only for the permissions that feature needs, and we tell you what they are before you approve. Data received from Google APIs is used only to provide the feature you connected it for. It is never sold, never used for advertising, and never used to train any AI model. You can disconnect at any time from your dashboard or from your Google account permissions, and we delete the stored tokens when you do.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Traffic is encrypted with HTTPS. Passwords are hashed, never stored in readable form. Two-factor authentication is available and we recommend it. Each store's data lives in its own separate database, so one merchant cannot reach another's. Staff access is limited to what a role needs.
No system is perfectly safe. If a breach ever affects your data, we will tell you what happened and what to do about it.
You can ask us for a copy of your data, to correct it, or to delete it. Most of it you can already export or delete yourself from Settings → Backups & Data. For anything else, email info@arsalanbrothers.com and we will reply within 30 days.
The platform is for businesses. It is not intended for anyone under 18 and we do not knowingly collect their data.
If we change this policy we will update the date at the top, and email you if the change is significant. Continuing to use the platform after a change means you accept it.
Questions about privacy: info@arsalanbrothers.com, or through the contact page.