1. What we collect
Account info (name, email, mobile, country), KYC documents (CNIC/passport, selfie, address proof), transactional data (deposits, token purchases, rental payouts, withdrawals), platform usage data (logins, IP addresses, device identifiers), and communications with our team.
2. Why we collect it
To verify your identity, comply with AML obligations, process your transactions, deliver rental payouts, secure your account, prevent fraud, improve the product, and contact you about important changes.
3. Where we store it
Personal data is stored in secure, encrypted databases primarily located in the European Union (Supabase) with appropriate technical and contractual safeguards. KYC documents are stored in private object storage with signed-URL access only.
5. How long we keep it
For the period required by Pakistani law (currently a minimum of 10 years for AML-relevant records) and longer where necessary to enforce our agreements, defend legal claims, or comply with regulatory requirements.
6. Your rights
You can request access to, correction of, or deletion of your personal data (subject to legal retention obligations). You can withdraw marketing consent at any time. Contact privacy@reptostate.com to exercise these rights.
7. Security
Encryption in transit (TLS) and at rest, role-based access controls, two-factor authentication for staff, immutable audit logs, regular penetration testing. No system is perfectly secure but we treat data protection as a first-order concern.
8. Changes to this policy
Material changes will be notified via email at least 14 days before they take effect. The current version is always available at this URL.
Last reviewed: 2026-05-01
