Two things we never collect: your CNIC and your card number. Card details go to the payment provider’s own page and never touch our site. Everything else we collect has one clear job — and that job is written below.
This is a draft. This page is written from what the system actually does, so it is accurate — but no Pakistani lawyer has read it yet. It will be reviewed before launch.
1. Who this policy covers
This policy covers the eJugaar website and any eSIM bought through it. “We” means eJugaar, and “you” means the person using the site or placing an order.
2. What we collect
- Email and WhatsApp number — to send you the QR. We ask for both for that reason alone: if one has a problem, the other works.
- Phone model — only to check whether the eSIM will work.
- Payment details — the transaction ID, the sender’s name, and a screenshot if you send one.
- eSIM usage — how much data was used and when activation happened. Our supplier reports this.
- IP and browser — with the order, to prevent fraud and in case of a dispute with the bank.
We do not ask for a CNIC, and a card number never reaches us.
3. Why we collect it
Everything has one job: getting the QR to you, keeping the order record, supporting you when something goes wrong, and preventing fraud. Anything that serves none of those we do not collect — because data that does not exist cannot leak.
4. How long we keep it
- Payment screenshots — 180 days. The image is deleted 180 days after the order is complete. Its hash and the reconciliation record stay, so the accounts hold up without us holding your bank screenshot.
- Order and payment records — for as long as legal and accounting requirements demand.
- The eSIM activation code — encrypted. It is a bearer credential: whoever has it can install the eSIM.
5. Who it is shared with
Each one receives only what it needs for its own job:
- The eSIM supplier — to create the profile. Your name and email do not go to them.
- Vercel and Supabase — the website and the database.
- Resend — to send email.
- Meta (WhatsApp) — to send the QR.
- Payment providers — to take payment and issue refunds.
We do not sell your data to anyone, and we do not give it to advertisers.
6. Where the data lives
The database is in the Mumbai region — the closest region to Pakistan our provider offers. Some service providers are outside Pakistan, so your data is also processed outside the country.
7. Security
The activation code is stored encrypted, and the QR is served only from the page behind your own login — no open link, no address anyone could guess. Every admin action is recorded, and that record cannot be erased.
8. Cookies
We keep only the cookies the site needs to run: your chosen language, and partner attribution so the right partner gets their commission. No advertising cookies, and your browsing goes to no ad network.
9. Your rights
Ask, and we will: show you your data, correct what is wrong, or delete it — except the records we are legally required to keep, such as the payment ledger.
Pakistan has not yet enacted a comprehensive data protection law. We are giving you these rights without waiting for it, because retrofitting them later would be more painful for both of us.
10. Marketing
Messages about your order — the QR, a notice that your data is running out, an expiry warning — are part of the service and will keep coming.
Marketing is a separate thing and asks for separate permission. There is no pre-ticked box for it at checkout, and there will not be.
11. Contact
The most direct route is email — hello@ejugaar.com — or on WhatsApp at +923712044479. We answer every day from 10 am to 10 pm. Include your order number — it does half the work.
12. Language
This policy exists in several languages. Where the translations differ, the English text applies. The terms of service are in the terms & conditions, and the rules for getting money back in the refund policy.
