PRIVACY POLICY – COLOR KAHAR

🔒 Your Privacy is Our Priority

We are committed to protecting your personal information and being transparent about how we use it.

Version: 1.0 | Last Updated: 1st January, 2026

INTRODUCTION

This Privacy Notice for Color Kahar ('we', 'us', or 'our'), describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our Services ('Services'), including when you:

  • Download and use our mobile application (Color Kahar) or access our website www.colorkahar.com or any other application of ours that links to this Privacy Notice.
  • Use our personalized photo product Services: Our platform allows you to select and customize a variety of products - including photobooks, prints, calendars, mugs, and more - by uploading photos from your phone storage / cloud storage or social media. These are then printed and delivered (through third party courier Service or team member).
  • Engage with us in other related ways, including but not limited to any sales, marketing, or events.

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. By accessing or using our Services, you consent to the terms of this Privacy Policy. You also confirm that you are either above the age of majority (i.e.18 years old) or a minor with parental/guardian consent and supervision. If not, then please discontinue use of our Services immediately.

1DATA CONTROLLER

The entity responsible for processing your personal data is Color Kahar, operated by Color Kahar pvt ltd, a company incorporated in Pakistan. Color Kahar aims to operate in alignment with applicable Pakistani laws governing digital privacy and data protection, including but not limited to the Prevention of Electronic Crimes Act 2016 (PECA) and any forthcoming legislation such as the Personal Data Protection Bill, to the best of its knowledge and understanding. We make reasonable efforts to stay informed of evolving legal frameworks and update our practices accordingly to remain lawful, transparent, and user focused. For questions, concerns, or requests regarding data rights, please contact the support team at support@colorkahar.com.

2PERSONAL INFORMATION WE COLLECT AND PROCESS

We collect personal information that you provide when registering for our Services, interacting with our products, participating in platform activities, or contacting us. You are in control of the data you share, and we only request information necessary to deliver our Services effectively. This may include:

  • Identification Data - such as your name, gender, age (to verify eligibility if under the age of majority), billing/shipping addresses, and communication preferences.
  • Account and Login Credentials - including usernames, passwords, phone numbers, and email addresses. If you choose to log in using a third-party platform (e.g. Google, Facebook), we may receive limited profile data. See Section 15 for details on Social Media Integrations and Third-Party Photo Access.
  • Payment and Transaction Data - such as credit/debit card numbers, mobile Wallet info (e.g. Jazz Cash) and related instrument data are processed securely via third-party payment gateways. We do not store full payment information on our servers. We may retain order-related contact and billing info solely for fulfilment and support.
  • Photo Content and Uploaded Media - Images you upload to personalize products (e.g. photobooks, prints, calendars) are stored securely and used exclusively for processing and fulfilling your order. These images are retained temporarily and deleted after fulfilment, unless required for a reprint, dispute or the improvement of your experience. We do not use uploaded content for marketing unless you give us clear, explicit consent.

Information Collected Automatically

We also collect certain information automatically when you use our Services, to help us maintain a reliable, secure, and personalized user experience. This data is collected in a privacy-conscious manner, and we avoid unnecessary tracking or profiling. Types of data may include:

  • Device and Technical Information including, without limitation, device ID/token, IP address, browser type, app version, operating system, crash reports, hardware model, and general usage data (e.g., screen flows, feature taps). This information helps us detect bugs, improve features, and ensure the stability and security of our platform.
  • Usage Logs including, without limitation, timestamps of activity, navigation flow, and in-app behaviour patterns. These are used for Service analytics and are only linked to your account when needed for customer support or diagnostics. We do not use this data for user profiling or behavioural targeting.
  • Location Information including, without limitation, (with your permission) we may collect geolocation data to support delivery Services and app features that rely on your location. This can be GPS-based or inferred from your IP address. You may modify or revoke these permissions in your device settings at any time.

All automatically collected data is stored securely, handled in accordance with this policy, and never sold or shared for third-party marketing.

Mobile Device Permissions

To deliver certain features within our mobile app, we may request permission to access specific functions on your device. These permissions are strictly used to support the Services you opt to use and can be reviewed or revoked at any time through your device settings:

  • Camera - Enables you to take photos directly for use in our Services including creating customized products (e.g. photobooks, mugs)
  • Photo Gallery - Allows you to select images from your device for order creation through our Service.
  • Storage - Temporarily stores app data, order-related Service data necessary for fulfilment and provision of Service on your device.
  • Notifications - Sends updates related to your order status, delivery alerts, and account activity and marketing/promotion updates

We do not access these features without your permission, and we do not collect or retain data from them unless it is necessary to provide our Service or fulfill your orders.

Information Received from Third Parties

We may collect personal information from external sources when you engage with third-party Services connected to our app, such as app stores, payment gateways, social media platforms, or marketing sites. These sources may share your data with us based on your interactions and their respective privacy policies. We treat all third-party information in accordance with this Privacy Policy. We use all this information to ensure secure operation of our app, support personalized product creation, provide customer support, and perform internal analytics for Service improvement. Where required by law or in the case of sensitive data (e.g., age verification or location data), we may explicitly request your consent prior to processing.

3WHY DO WE NEED TO PROCESS YOUR PERSONAL DATA?

We process your personal data for various legitimate business purposes to deliver our Services effectively, ensure operational continuity, and maintain a secure and personalized user experience. These purposes include:

Core Service Operations:

  • Creating and managing user accounts, including authentication and login procedures
  • Processing and fulfilling orders, including coordination with printing houses and delivery partners
  • Handling customer Service requests and technical support.
  • Managing secure payment workflows via trusted third-party processors.

Communication and Notifications:

  • Sending administrative updates and Service confirmations
  • Delivering policy updates, order notifications, and other essential Service-related information
  • Requesting customer feedback and satisfaction surveys
  • Sharing promotional offers and marketing messages - with the ability to opt out.

Business and Platform Operations:

  • Monitoring and preventing fraudulent activity, unauthorized access, and security risks
  • Analyzing usage trends and user behavior to improve product performance and Service quality
  • Running analytics and performance diagnostics for platform improvements.
  • Conducting advertising and promotional campaigns, subject to appropriate consent
  • Meeting our legal and regulatory obligations, including tax, audit, and reporting requirements

Emergency Situations:

  • Using data, where strictly necessary, to protect your vital interests - for example, in the case of fraud detection, imminent harm, or technical failure

All data processing is carried out in accordance with applicable laws, with transparency, user control, and respect for your privacy rights.

4TO WHOM YOUR PERSONAL DATA WILL BE DISCLOSED

Only authorized staff members can access personal data, and solely for purposes necessary to perform their duties. Each individual is obligated to uphold strict confidentiality regarding any information they handle.

We do not share your personal data with external parties, except for our subsidiaries, affiliated companies, or data processors (such as delivery and payment service providers) contracted to work with us, such as:

  • Manufacturers, wholesalers and retailers - To manufacture and produce your customized photo products
  • Payment Processors - To process transactions securely. These include providers such as United Bank Limited, Jazz Cash, or other payment gateways, each operating under their own privacy policies.
  • Delivery and Logistics Providers - To deliver your orders through partners such as TCS, M&P, and other courier Services.
  • Cloud storage and software providers - Such as AWS, to store and process data in a secure infrastructure. Analytics Providers - For monitoring platform usage, user behavior, and Service performance.
  • Customer Communication Tools - For operations such as sending order updates, resolving support queries, and delivering transactional notifications
  • Analytics Providers - To help us monitor such as performance and improve user experience.
  • Security Services - To secure our Service such as fraud detection, app security, and maintaining Service integrity
  • Marketing and Advertising companies - including Google, for Google Ads personalization
  • Social Media Platforms - To login or integrate features enabled by the user

When We Share Without Your Consent

Without your consent we will not share your personal data with any other third party, unless:

  • Legal Requirements: To comply with applicable Pakistani laws, regulations, court orders, or legal processes, or to protect our legal rights or those of users. These include but are not limited to fraud, cybersecurity investigations or other inquiries. Any such disclosure will be limited strictly to the scope of the request and carried out in accordance with due process and applicable legal safeguards.
  • Business Transfers: In the event of a merger, acquisition, asset sale, reorganization, or other corporate restructuring, your personal data may be transferred to the acquiring entity. We will always try to ensure that any successor organization continues to handle your data in accordance with this Privacy Policy.
  • Protection of Rights: We wish to enforce or protect our rights, property and safety, or the rights, property and safety of our customers, or others.
  • With Your Consent: For any additional purpose that you explicitly approve or opt into

We do not sell your personal data. We never share your information with third parties for unrelated marketing purposes without your clear, informed consent.

5COOKIES AND TRACKING TECHNOLOGIES

Like most online services, we use cookies and similar tracking technologies to deliver a reliable and personalized experience. These small data files are stored on your device to help us remember your settings, secure your session, and improve our platform. Our use of these technologies includes:

  • Maintain Service security and functionality
  • Remember your preferences and settings
  • Analyse Service usage and performance
  • Provide personalized content and advertising

Third-Party Analytics

We work with trusted analytics providers (such as Google Analytics or Firebase) to measure performance and improve features. These services may use cookies, SDKs, or pixels to collect limited technical data. This data is anonymized or aggregated wherever possible and used only to support our Service operations.

Your Control

You have control over your cookie preferences. Most browsers and mobile devices allow you to review, disable, or delete cookies through your settings. Disabling some cookies may impact functionality, but essential features like placing orders or viewing products will remain available.

All tracking technologies we use are governed by this Privacy Policy and handled in accordance with applicable data protection laws.

6INTERNATIONAL DATA TRANSFERS

We rely on trusted third-party infrastructure providers that follow industry-standard security and compliance protocols, such as AWS. Depending on your location and how you access our services, your data may be processed or stored on servers located outside Pakistan - including in countries that may have different data protection standards. When such transfers occur, we reasonably rely on the servers' built-in security and compliance practices to ensure data is stored in accordance with industry norms.

We do not store personal information beyond the time needed to fulfil your order or operate our Service, unless longer retention is required by law (e.g., tax records or transaction history). See Section 7 for more on our retention practices.

All data transfers are handled in compliance with this policy, and no personal data is shared across borders unless necessary for delivering our Services or maintaining platform functionality.

7DATA RETENTION

We retain your personal information/data for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Account data is retained while your account is active.
  • Inactive accounts may be deleted after a period of one (1) year.
  • Order history, order statuses, customer support communications are retained while account is active for customer Service, dispute resolutions and other enhancements for provision of our Service
  • Product browsing behavior including cart contents and navigation history may be retained for active accounts to support reorder recommendations and Service personalization
  • Order-related photo content may be temporarily retained after order fulfillment for quality assurance and potential re-printing. It is deleted once the product is received and accepted by you, unless we are required to retain it temporarily for better Service provision (e.g. Disputed reprinting or operational upgradation). See Section 9 for specific photo handling practices.
  • Some information may be retained longer to comply with legal obligations such as transaction records etc.

When retention is no longer necessary, data is securely deleted or anonymized.

Please refer to Section 9 for guidelines relating specifically to photo content used in the creation of personalized products.

8HOW YOUR PERSONAL DATA IS SECURED

Since the protection of your personal data is important to us, we implement reasonable technical, physical, and organizational safeguards. These measures are placed to defend against accidental or unlawful destruction, loss, damage, alteration, unauthorized disclosure or access, and any other form of improper processing-including unnecessary data collection-so that your information remains secure at every stage. We implement a combination of technical, physical, and procedural safeguards — such as encryption, access controls, internal protocols — to protect your data.

Important Security Notice

While we implement strong measures to secure your data, no system is completely immune to risk. By using our Services, you acknowledge and accept the inherent risks and liabilities associated with digital platforms like ours. We recommend to always use our Services in a secure environment.

If we become aware of an issue that may affect, or has affected, the security of your personal data, we will inform you in accordance with applicable legal requirements, sharing details about the situation and any steps being taken to address and protect your information.

9PHOTO CONTENT AND CONTRIBUTIONS SPECIFIC PRIVACY PRACTICES

Your photos are used only to fulfil all requirements of creating the customized products you order on our Services. We do not view (if unnecessary), reuse, or market your photos without your clear, informed consent.

Photo Handling & Storage

  • Upload Security – We rely on secure industry standards for data transmission.
  • Use Purpose - Photos are used to fulfill your custom orders and use all features of our Services.
  • Quality Review & Disputes - To safeguard your privacy, we typically retain your uploaded photos only for up to 7 days after your order completion and acceptance. In some cases, they may be retained longer for dispute resolution, reprints, quality assurance, or operational requirements, in line with our Terms & Conditions.
  • No Marketing Use - We never use your personal photos for advertising, content galleries, or promotional campaigns without your permission.
  • Voluntary Campaign Submissions - If you choose to participate in promotions or submit content (e.g., testimonials, contest entries), you understand such materials may be featured on our app, website, or social channels. Participation is always optional, and you will be informed of the terms before submission.
  • Metadata Disclaimer - Uploaded files may contain metadata (e.g., GPS, timestamps). We do not actively use or analyse such data for any personalization or profiling. However, metadata may still be transmitted depending on your device settings. We recommend reviewing your files before upload.

We do not use sensitive personal data - such as uploaded photos or product customization choices - to infer personal attributes, characteristics, or behavioural profiles (e.g., gender, ethnicity, political beliefs). All personalization features are user-directed, and uploaded content is stored securely for the exclusive purpose of fulfilling your order and enhancing Service delivery.

Third-Party & Group Photos

If your uploaded content includes third parties or other people (e.g., friends, children, family members), we trust that you've received their consent (or their legal guardians, where applicable) for usage on our Services and creating personalized products. You are responsible for ensuring you have the legal right to upload and use such images. We do not verify or moderate content unless flagged or disputed.

Please do not upload content you do not own or are not authorized to use. In the event of any complaints or legal claims related to content you've submitted, you are solely responsible for resolving those issues and agree that Color Kahar is not liable for any disputes arising from your uploads and usage of photos on our Services.

Storage & Deletion

  • Uploaded photos are stored securely for short-term order processing.
  • Files are typically deleted within 7 days after successful delivery, given that there is no other necessary requirement such as dispute, reprint request or Service requirement.
  • No photos are stored for backups, analytics, or reuse unless you opt in explicitly.

Order Fulfilment and Exceptional Situations

Color Kahar follows careful processes to handle, print, and deliver user photos securely and in line with the order details provided. Our teams and partners work to ensure that each order is processed accurately and respectfully.

In rare situations, if an unexpected issue occurs during order fulfilment, Color Kahar will review the matter and take appropriate steps in line with our standard procedures, which may include reprinting, refunding, or removing affected files.

Any such situation is handled under the safeguards and limitations described in our Terms & Conditions, and Color Kahar's responsibility is limited to the value of the affected order.

10CHILDREN'S PRIVACY AND PARENTAL SUPERVISION

Our Services are not designed for children and are intended for individuals aged 18 years and older (i.e. age of majority). We do not knowingly allow children under the age of 18 to register or use the Services independently.

However, if Teen Users (i.e. minors aged 13-17) are allowed to participate-such as in school events or family-friendly features-their access to the Services must be operated by, or allowed access under the supervision of, a parent or legal guardian at all times. It is the sole responsibility of the parent or guardian to ensure that any age information entered on behalf of a minor is accurate and truthful.

We do not knowingly collect personal information from children / minors. If we become aware that a child has submitted personal data without parental consent, we will take prompt steps to delete such information from our systems.

We reserve the right to introduce age-based access controls or parental consent mechanisms in future releases, in line with evolving laws such as the Personal Data Protection Bill, 2023 (Draft). To exercise these rights or inquire further, please contact us at support@colorkahar.com.

11YOUR DATA RIGHTS

You have certain rights regarding your personal data, subject to applicable laws. These include:

  • Access - Request to view the personal data we hold about you.
  • Correction - Ask us to correct inaccurate or outdated information.
  • Portability - Request a copy of your personal data in a commonly used, machine-readable format.
  • Withdrawal of Consent - Revoke previously granted consent for optional processing activities, such as marketing emails or analytics tracking.
  • Deletion - Request the deletion of your account and associated data, where permitted by law and not subject to legal retention requirements.
  • Objection/Restriction - Object to or request limitations on certain types of data processing.

How to Exercise Your Rights

To exercise any of these rights, you may either:

  • Use the available tools within your account settings (where supported), or
  • Contact us directly at support@colorkahar.com. For your security, we may request identity verification before processing certain requests.

We aim to respond within 15 business days, although response times may vary depending on the nature and complexity of your request. In some cases, certain rights may be limited - for example, if fulfilling the request conflicts with fraud prevention, legal compliance, or contractual obligations.

12ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING

Currently, Color Kahar does not utilize artificial intelligence (AI) or automated decision-making systems in the processing of personal data, content personalization, or product suggestions. Should we implement AI-powered features in the future—such as smart photo organization, theme recommendations, or design automation—we will update this policy to reflect any changes. Any use of AI will be conducted transparently, in compliance with applicable laws, and with respect for your privacy rights, including the opportunity to provide consent where required and to opt out of automated personalization where applicable.

13THIRD-PARTY LINKS

Our Services may include links to third-party websites, plug-ins, social media platforms, or advertisements. These external sites operate independently and are not controlled, endorsed, or reviewed by Color Kahar.

Any information you choose to provide to these third parties — including through login, form submissions, or purchases — is governed solely by their privacy policies and terms of use. We are not responsible for the content, practices, or data handling of such external services.

We strongly encourage you to review the privacy policies of any third-party sites before sharing your personal data. Your interactions with those sites are at your own discretion and risk.

14DO-NOT-TRACK SIGNALS

Currently, we do not respond to browser-based Do-Not-Track signals due to the lack of a standardized implementation protocol. If and when such standards are adopted, we will update our policy accordingly.

15SOCIAL MEDIA INTEGRATIONS AND THIRD-PARTY PHOTO ACCESS

Social Media Login

If you choose to log in using a third-party account (such as Google or Facebook), we may receive profile information, such as:

  • Your name and email address
  • Your profile picture
  • Public profile details
  • Friend list (if applicable and permitted)

We only use this information to enable account login and provide personalized features, as outlined in this Privacy Policy. We do not access or use any private data unless you explicitly authorize it. You can control what's shared with us through your social media privacy settings at any time.

Photo Imports from Social or Cloud Platforms

With your explicit permission, you may connect photo sources like Facebook, Instagram, or Google Photos to import images for your personalized products. This access allows us to:

  • Help you select and upload images directly into our Services
  • Suggest layouts, themes, or templates based on your most recent uploads
  • Show relevant previews or product ideas
  • Offer seasonal promotions tied to your design activity
  • Enhance your experience based on your preferences
  • Enhance our Services based on your preferences

We only connect to these sources after you grant permission, and we do not store your full gallery. Only the images you actively select are uploaded and stored — temporarily and securely — to provide our Services and fulfil your order

Use of Google APIs and Secure Integrations

If you connect your account using Google or other supported services, that connection is handled through secure APIs (Application Programming Interfaces). We only request access to the minimum data necessary to provide optimal Service experience including, without limitation, login, photo import, product creation and personalized features.

When using Google APIs, we try our best to comply with the Google API Services User Data Policy, including its Limited Use requirements. This means:

  • We only access the data required to provide the features you've chosen
  • We do not use this data for advertising, tracking, or retargeting unless you give us explicit consent
  • You can revoke access at any time through your Google account settings or within the Color Kahar app

We do not retain your full photo library. We store only the photos you explicitly select, and only for as long as necessary, in line with our privacy policy.

16ACCOUNT MANAGEMENT

Your Account Controls

You can manage your account and personal preferences at any time through the available settings in the Color Kahar app or website or by contacting us on support@colorkahar.com These controls may include:

  • Profile Updates - Edit your name, email, or other account details.
  • Privacy Settings - Adjust what information is visible or how it's used.
  • Communication Preferences - Opt in or out of marketing messages and notifications.
  • Account Deletion - Request full account closure and associated data removal.

After Account Deletion

Upon confirmation of account deletion, we will deactivate your profile and remove your personal data from our active user systems. However, certain information may be retained in secure archives or backup systems for the following limited purposes:

  • Preventing fraud or abuse
  • Fulfilling legal, regulatory, or tax obligations
  • Resolving ongoing disputes or customer service issues
  • Maintaining internal records for security, auditing, or analytics (in anonymized form where appropriate)

Retained data is access-restricted and securely stored and will only be used as necessary to fulfill these obligations. Once retention is no longer required, the data will be deleted or anonymized in accordance with our policy.

17COMMUNICATION PREFERENCES

We may contact you from time to time for service-related or promotional purposes. Here's what that includes:

1. Service Communications (Mandatory)

These are essential for operating your account and fulfilling your orders. You may not opt out of:

  • Order confirmations and delivery updates
  • Password resets and security alerts
  • Account-related notices or legal policy changes

2. Marketing Communications (Optional)

These include promotional emails, offers, and updates about new products or features. You may opt out of these at any time through:

  • The unsubscribe link provided in our emails
  • Your account settings in the app

3. Personalized Messages

We may tailor messages based on your past orders, preferences, or browsing behavior to make them more relevant to you. You can manage personalization settings or opt out of marketing personalization through your account controls.

Your Rights & Controls

  • Opt Out Anytime - Unsubscribe from marketing without affecting your ability to use the Service.
  • Customize Preferences - Choose what kind of messages you'd like to receive.
  • No Penalty - You won't miss out on essential services if you disable promotional messages.

Note: Even if you unsubscribe from promotional content, we may still send essential order or account-related messages as required to provide the service.

18CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect changes in legal requirements, operational practices, or Services features. The revised version will be posted on our website or mobile app with an updated "Last Modified" date. Significant changes may be communicated directly via email or app notifications. Your continued use of our Services after updates constitutes acceptance of the changes. We encourage periodic review of this policy.

19HOW TO CONTACT US

Get in Touch

If you have questions, concerns, or would like to request actions regarding your personal data, please reach out to:

Email address: support@colorkahar.com

Company Name: Color Kahar

Location: Pakistan

Response Time

Ideally, we try to respond within 24-48 hours for privacy-related inquiries, but delays may occur due to high demand or other factors.