Legal
Privacy Policy
Last updated: 29 September 2026
1. Who we are
Primemgr is operated by Mudasir Ahsan Khowaja, an individual (sole trader) based in Pakistan, trading as Primemgr, of C13, Gulshan-e-Ali Phase 1, Federal B Area B7, Karachi, Sindh 75950, Pakistan. You can contact us at admin@primemgr.com.
This policy covers the Primemgr website and service. We are responsible (the “controller”) for the personal information of the people who visit our website, sign up, and use Primemgr.
Information your business puts into Primemgr, such as your customers’ names, contact details, vehicles, jobs, quotes, invoices and photos, belongs to your business. For that information your business is the controller, and we process it only on its behalf and on its instructions (as a “processor”), under the data processing terms in section 10 of our Terms of Service. If you are a customer of a business that uses Primemgr and have a question about your information, please contact that business first; we will help them respond.
2. What we collect
- Account details: your name, email address, phone number (if you add one), your password (stored only as a secure one-way hash), two-step sign-in settings, profile photo, and your language, timezone and theme preferences.
- Business details: your business name, country, industry, tax details, address and the settings you choose for your workspace.
- Billing details: your plan, subscription status and billing history. Payments are taken by Paddle, our reseller and merchant of record. Paddle collects your card or other payment details; we never receive the full card number. We receive limited information such as the card type, its last four digits and its expiry date.
- Your Data: the records you and your team create in Primemgr (see section 1).
- Usage and device information: sign-in times, the IP address and browser or device used, the actions taken in your workspace (kept as an audit log so you can see who did what), and requests made to our API.
- Messages you send us: support requests and anything else you email us.
3. How we collect it
Directly from you when you sign up, fill in forms or contact us; from your colleagues when they invite you or add information; automatically when you use the service; from Paddle about your payments; and from Google if you choose to sign in with Google.
4. Why we use it, and our legal basis
- To provide the service you signed up for: running your account and workspace, sending sign-in codes and invitations, and processing your subscription (performance of our contract with you).
- To keep the service and your account secure: detecting suspicious sign-ins, preventing fraud and abuse, and keeping audit logs (our legitimate interest in a secure service, and yours).
- To support you when you contact us (our contract with you, and our legitimate interest in helping customers).
- To tell you about your account: trial reminders, payment problems, changes to these policies and important service notices (our contract with you). These are not marketing and you cannot turn them off while your account is open.
- To improve Primemgr using information about how features are used (our legitimate interest).
- To meet legal obligations, such as keeping records the law requires and responding to lawful requests.
We only send marketing emails if you have agreed to receive them, and every one lets you unsubscribe. We do not sell personal information, and we do not use Your Data to train artificial intelligence models.
5. Who we share it with
We share personal information only with service providers who help us run Primemgr:
- Paddle (Paddle.com Market Limited, United Kingdom, and its affiliates): our reseller and merchant of record, which takes payments, handles tax, and issues receipts and refunds. Paddle’s own privacy notice covers what it collects at checkout.
- Resend (United States): delivers the emails we send, such as sign-in codes, invitations and receipts. Our sending is handled in its Asia-Pacific (Tokyo) region.
- Our hosting and storage providers, which run the servers, databases and backups the service depends on. They are named in this list before the service first processes customer data with them.
- PostHog (United States), only if you allow analytics cookies: which pages are viewed and features used, linked to an internal account number when you are signed in. On our public pages and while signing up it may also record how pages are used (clicks and scrolling, with anything typed hidden); it never records inside the product and never receives what a business’s customers see on their portal, quote, invoice or booking pages.
- Google (United States), only if you choose to sign in with Google where we offer it.
- Services you connect yourself, such as a payment provider or a webhook address you set up, which receive what you choose to send them.
Each of these providers is bound by data protection terms. We will give business customers at least 30 days’ notice by email before adding or replacing a provider that processes their customers’ information, so that they can object (see our Terms, section 10).
We may also disclose information if the law requires it, to protect people’s safety or our legal rights, or to a buyer if our business is sold, in which case this policy continues to apply to it.
6. International transfers
We are based in Pakistan, and the providers above are in the United Kingdom, the United States, Japan and other countries. Your information is therefore likely to be processed outside your own country. Where the law of your country (for example the UK or the European Union) requires safeguards for such transfers, we rely on our providers’ standard contractual clauses or equivalent protections. For Australian residents, this is our notice under Australian Privacy Principle 8 that disclosure to these countries is likely.
7. How long we keep it
- Account and workspace information: while your account is open.
- After your subscription ends: until you or your business ask us to delete it, so it can still be exported (see our Terms, section 9). We delete or anonymise it within 30 days of a request.
- Backups: 30 days, after which they are overwritten.
- API request logs and automation run history: 90 days.
- Billing and tax records: as long as tax and accounting laws require, which is usually several years.
8. How we protect it
Every connection to Primemgr is encrypted in transit. Each business’s records are held in a separate database. Passwords are stored as one-way hashes, and sensitive credentials are encrypted at rest. You can turn on two-step sign-in and require it for everyone in your workspace. Access by our staff is limited, recorded, and for support needs your business’s permission. No system is perfectly secure; if a breach is likely to cause you serious harm, we will tell you and the regulators the law requires us to tell.
9. Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you. Where Primemgr offers features that use artificial intelligence, they only make suggestions, and a person decides whether to act on them.
10. Cookies
Without your permission our public website sets no cookies, and when you sign in we use only the cookies needed to keep you signed in and to protect sign-in forms against forgery. We ask once whether you allow analytics cookies (PostHog); none is set unless you say yes, and you can withdraw that at any time on the Cookie Policy page. We do not use advertising cookies. Each cookie, what it does and how long it lasts is listed in our Cookie Policy.
11. Your rights
Depending on where you live, you have the right to:
- ask for a copy of the personal information we hold about you;
- ask us to correct it if it is wrong;
- ask us to delete it, or to restrict how we use it;
- object to our using it on the basis of our legitimate interests;
- receive it in a portable format (you can also export your workspace yourself);
- withdraw consent you have given, such as to marketing emails, at any time.
Email admin@primemgr.com to make a request. We will respond within 30 days, and may need to confirm your identity first. There is no charge. If a request is about information your business put into Primemgr, we will pass it to that business, which decides.
12. Complaints
If you are unhappy with how we have handled your information, please contact us first at admin@primemgr.com and we will respond within 30 days. If you are not satisfied, you can complain to the regulator where you live, for example:
- Australia: the Office of the Australian Information Commissioner (oaic.gov.au)
- New Zealand: the Office of the Privacy Commissioner (privacy.org.nz)
- United Kingdom: the Information Commissioner’s Office (ico.org.uk)
- European Union: your national data protection authority.
- India: the Data Protection Board of India, once you have used our grievance process (see section 13).
13. If you are in India
If you are in India, the Digital Personal Data Protection Act 2023 gives you, as a “Data Principal”, the rights below, and we are the “Data Fiduciary” for the personal information described in section 2. We use it for the purposes in section 4, on the basis of the consent you give when you create an account or contact us, or where the Act otherwise permits.
- Access: a summary of the personal information we process about you and what we do with it, and who we have shared it with.
- Correction and erasure: to correct, complete or update it, or to have it erased when it is no longer needed.
- Withdraw consent at any time, as easily as you gave it, by emailing us. You can also cancel your subscription yourself in Settings, and export your data first. Withdrawing does not affect what we did before, and we may then be unable to provide the service.
- Nominate another person to exercise these rights for you if you die or become unable to.
- Grievance redressal: tell us if you are unhappy with how we handle your information. We aim to respond within 30 days and will always respond within 90 days. If you are not satisfied, you can complain to the Data Protection Board of India.
To make any of these requests, email admin@primemgr.com from the email address on your account (that address is how we identify you), or tell us which account it concerns. The same address reaches the person who can answer your questions about how we process your personal information.
14. Children
Primemgr is for businesses and is not intended for anyone under 18.
15. Changes to this policy
We will update this policy when our practices change, and change the date at the top. If a change materially affects you, we will email the workspace owner before it takes effect.
16. Contact
For anything about privacy, email admin@primemgr.com.