Privacy Policy
ChaiLink (Pvt) Ltd ("ChaiLink", "we") respects your privacy and is committed to protecting personal data processed through www.chailink.co. This Privacy Policy explains what data we collect, why we collect it, how we use and share it, and your rights under Pakistani law including PECA, applicable SBP regulations on customer data protection, and principles aligned with international best practices.
Table of contents
1. Data Controller and Contact
Data Controller: ChaiLink (Pvt) Ltd Registered Address: Mohala Ahmedabad, Kala Gujran, Near Government School #2 Boys, Jhelum, Punjab, 49490, Pakistan
Data Protection Contact: privacy@chailink.co Legal Contact: legal@chailink.co Support Phone: +92-300-2612-932
We respond to privacy inquiries within fifteen (15) business days unless extended for complex requests.
2. Categories of Personal Data Collected
2.1 Creator Account Data: full name, CNIC/NICOP number (where required), date of birth, email, mobile number, profile photo, bio, social links, bank/wallet payout coordinates, tax identifiers if applicable.
2.2 Supporter Transaction Data: name (optional), message content, payment method selected, transaction amount in PKR, timestamp, device/browser metadata, IP address, and fraud scores.
2.3 Payment Partner Data: when you pay via PayFast, wallets, or banks, those partners process payment credentials on their PCI-compliant pages; ChaiLink receives transaction status, tokens, and limited metadata — not full card numbers or CVV.
2.4 Technical Data: cookies, session identifiers, crash logs, analytics events, referral URLs, and approximate geolocation derived from IP.
2.5 Communications: support tickets, dispute correspondence, and survey responses.
2.6 We do not intentionally collect special categories of data beyond identity verification. Do not submit sensitive data in supporter messages.
3. Purposes and Legal Bases of Processing
3.1 Service Delivery: processing Contributions, maintaining Vault balances, executing Payouts, displaying supporter messages.
3.2 Legal Compliance: AML/CFT screening, SBP reporting, tax record retention, response to lawful orders under PECA and Code of Criminal Procedure.
3.3 Security: fraud detection, abuse prevention, DDoS mitigation, account recovery, cooperation with PayFast Guardian and partner fraud systems.
3.4 Product Improvement: aggregated analytics without direct identification where feasible.
3.5 Marketing: only with explicit opt-in; Creators may receive product updates essential to account operation without separate consent.
5. Data Retention
5.1 Transaction records: minimum seven (7) years per AML/CFT requirements.
5.2 Creator profile data: while account is active and three (3) years thereafter unless longer retention is required.
5.3 Supporter messages: until deleted by Creator or account closure.
5.4 Logs and security data: twelve (12) to twenty-four (24) months unless needed for investigations.
6. Security Measures
6.1 TLS 1.2+ encryption in transit; AES-256 encryption at rest for sensitive fields.
6.2 Role-based access controls, MFA for administrative systems, annual penetration testing.
6.3 PCI-DSS scope minimization — card data tokenized by PayFast and certified gateways; ChaiLink does not store full card numbers or CVV.
6.4 Incident response with notification to affected users, Payment Partners, and regulators within seventy-two (72) hours of confirmed breach affecting personal data.
7. Your Rights
7.1 Access: request a copy of personal data we hold about you.
7.2 Correction: update inaccurate Creator profile information via dashboard or support.
7.3 Deletion: request account deletion subject to legal retention obligations.
7.4 Objection: object to non-essential marketing communications.
7.5 Complaints: contact privacy@chailink.co first; unresolved payment-data concerns may be escalated to PayFast at complaints@gopayfast.com.
9. Children
The Service is not directed to children under eighteen (18). We do not knowingly collect data from minors. Contact privacy@chailink.co for prompt deletion if a minor has created a Creator account.
10. Policy Changes
Material changes will be notified via email or prominent Platform notice at least fifteen (15) days before effectiveness. The "Last Updated" date reflects the current version.