Home / Privacy policy
Legal
Privacy policy
What we collect, why we collect it, how long we keep it, and how to make us delete it.
1. Who we are
Meerub Ecom Hub (“Meerub Ecom Hub”, “we”, “us”, “our”) builds ecommerce stores, business and WhatsApp automations, AI-powered chatbots, custom software and on-demand software for business clients. This policy explains how we handle personal data on our website at meerubecomhub.online and in the course of providing those services.
For data you submit through this website, Meerub Ecom Hub is the data controller. For data we process inside a client's systems during a project, the client is normally the controller and we act as a data processor under their instructions and our service agreement.
Before publishing: confirm your registered business name and jurisdiction in this document, and have a qualified lawyer review it for the markets you sell into.
2. Information we collect
Information you give us
- Enquiry details — name, email address, phone or WhatsApp number, company name, store URL, the service you're interested in, and whatever you write in the message field.
- Communication records — emails, WhatsApp messages, call notes and meeting notes exchanged with us.
- Project and billing information — contract details, purchase orders, invoicing and payment records for clients.
- Access credentials — where a project requires it, credentials or delegated access to your platforms. These are handled under section 11.
Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system, referring page and pages viewed.
- Server logs — request timestamps and error records generated by our hosting provider for security and diagnostics.
We do not intentionally collect special category data (such as health, biometric, religious or political information). Please don't send it to us in an enquiry.
3. How we use information
- Responding to your enquiry and preparing a proposal, audit or quote.
- Delivering, supporting and maintaining the services you've engaged us for.
- Invoicing, accounting and meeting our legal and tax obligations.
- Keeping our website secure, diagnosing faults and preventing abuse or spam.
- Improving our services, and — where you have opted in — sending occasional updates about what we build. Every such message includes a way to unsubscribe.
We do not sell personal data, and we do not share it with third parties for their own marketing.
4. Legal basis for processing
Where the UK/EU GDPR or a comparable law applies to you, we rely on the following bases:
- Contract — to take steps at your request before entering a contract, and to perform a contract with you.
- Legitimate interests — to run and secure our business, respond to enquiries and prevent fraud, balanced against your rights.
- Consent — for optional marketing messages and non-essential cookies. You can withdraw consent at any time.
- Legal obligation — for tax, accounting and regulatory record-keeping.
5. WhatsApp and messaging channels
If you contact us through WhatsApp, or interact with a WhatsApp system we operate on a client's behalf, your message content, phone number and profile name are processed to handle the conversation. Message delivery is carried out over the official WhatsApp Business Platform, and Meta's own terms and privacy policy apply to their part of that transmission.
When we build WhatsApp automations for a client, that client determines what messages are sent and to whom. Opt-out instructions in those messages are honoured by the system, and you can stop messages at any time by replying with the stated opt-out keyword or by blocking the number.
6. AI and chatbot processing
Some of our services use AI models to draft replies, classify messages or answer customer questions. Where a chatbot we build processes a conversation:
- Message content may be sent to a third-party model provider for the sole purpose of generating a response.
- We configure our integrations so that customer data is not used to train third-party foundation models, where the provider offers that setting.
- Conversations may be retained by the client to review answer quality, under the client's own retention rules.
- You can ask to be transferred to a human at any point in a conversation.
7. Cookies and analytics
This website runs on a minimal set of cookies. We use strictly necessary cookies for basic operation and security. If we enable analytics or advertising cookies, they will be listed here and, where required by law, requested through a consent banner before they are set.
Fonts on this site are loaded from Google Fonts, which means your browser makes a request to Google's servers and your IP address is visible to them as part of that request. You can block third-party requests in your browser if you prefer; the site remains usable with system fonts.
Most browsers let you refuse or delete cookies through their settings. Blocking necessary cookies may break parts of the site.
8. Sharing and service providers
We share personal data only with parties who help us run the business, and only as far as they need it:
- Hosting and email providers — for website hosting, email delivery and storage.
- Communication platforms — including the WhatsApp Business Platform and standard email and calendar services.
- Payment and accounting providers — for invoicing and reconciliation.
- AI model providers — where a service you use includes AI-generated responses, as described in section 6.
- Professional advisers — lawyers, accountants and auditors, under confidentiality.
- Authorities — where we are legally required to disclose, or to establish or defend legal claims.
If our business is ever sold or reorganised, personal data may transfer to the acquiring party under the same protections described here.
9. Data we handle inside client systems
Delivering a project often means working inside a client's store, CRM, courier account or messaging platform, where end-customer data lives. In those cases:
- We process that data only to perform the agreed services, under the client's documented instructions.
- Access is limited to the team members who need it, and is revoked when the engagement ends.
- We do not use client or end-customer data for our own purposes, and we do not copy it out of the client's systems except where a migration or backup requires it.
- Sub-processors we introduce for a project are disclosed to the client before use.
- On termination, we return or delete the data as instructed, subject to any legal retention requirement.
10. How long we keep information
- Enquiries that don't become projects — up to 24 months, then deleted.
- Client records and correspondence — for the life of the engagement plus 7 years, or as long as tax and contract law requires.
- Invoices and financial records — as required by applicable accounting and tax law.
- Server and security logs — typically 30 to 90 days.
- Credentials and access tokens — revoked and destroyed at the end of the engagement.
11. Security
We apply measures proportionate to the risk, including encrypted transport (HTTPS) across our site and tooling, access control on a need-to-know basis, multi-factor authentication on business accounts, a password manager for shared credentials, least-privilege API scopes rather than full account passwords wherever a platform supports it, and prompt revocation of access when an engagement ends.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority within the timeframes required by applicable law.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Request deletion of your data, where we have no overriding legal reason to keep it.
- Restrict or object to certain processing, including direct marketing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Complain to your local data protection authority.
California residents may additionally request disclosure of the categories of personal information collected and may opt out of “sale” or “sharing” of personal information — noting that we do not sell or share personal information as those terms are defined by the CCPA/CPRA. We will not discriminate against you for exercising any right.
To exercise a right, email admin@meerubecomhub.online. We respond within 30 days and may ask for proof of identity before acting. If your request concerns data held inside a client's system, we will forward it to that client, who is the controller.
13. International transfers
We operate from Pakistan and use service providers located in other countries, including the European Union and the United States. Where personal data is transferred across borders, we rely on the safeguards offered by those providers — such as Standard Contractual Clauses or an equivalent mechanism — and take reasonable steps to confirm the data receives a comparable level of protection.
14. Children
Our website and services are intended for businesses and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy as our services or the law change. The “last updated” date at the top of the page always reflects the current version. Material changes will be announced on this page, and — for active clients — by email before they take effect.
16. Contact us
Questions, requests or complaints about privacy:
- Email: admin@meerubecomhub.online
- Phone / WhatsApp: +92 314 152 3562
- Location: Pakistan — working with clients worldwide
See also our terms of service.