Privacy Policy
What Tsdiq stores, why it is stored, what becomes public, and how to get it removed.
Your data
1. Data we collect
Account data: name, email, mobile number and role. Business data: legal business name, storefront slug, branch addresses, FBR tax registration status and Raast IBAN. Order data: consignment numbers and courier delivery proof. Review data: ratings, written reviews, photos and unboxing videos submitted as proof.
2. Why we process it
To verify that a review belongs to a real, delivered order; to publish accurate public trust profiles; to settle payouts to the correct account; to detect fraud and review manipulation; and to operate the services you subscribe to.
3. What is public
Your public trust profile shows your business name, verification badges, tier, aggregate ratings, published reviews and completed Physical Store Verification outcomes. Buyer reviews display the reviewer's display name only.
Your Raast IBAN, contact email, private CX survey responses and internal audit notes are never public.
4. Private CX surveys
Post-purchase CX survey responses are shared with the merchant in aggregate and as private diagnostics. They are not published on the public profile and do not affect the public rating.
5. Sharing
We share the minimum necessary data with courier partners to validate consignments, with payment infrastructure to settle over Raast, and with law enforcement where legally required. We do not sell personal data.
6. Retention
Verification evidence and transaction records are retained for as long as the public review remains published and for a further period required for dispute and tax purposes. Closing an account removes your console access; published reviews and audit records remain as part of the public trust history.
7. Your rights
You can access, correct or export your account data from the console, and request deletion of data that we are not legally or contractually required to retain. Write to support@tsdiq.com.
8. Security
Data is stored on managed infrastructure with row-level access controls, encrypted in transit, and access to production data is limited to authorised staff.

