Legal
Privacy Policy
Effective 27 September 2026 · Doxfen (Private) Limited
This policy explains what personal data Doxfen collects, why, who we share it with, how long we keep it and the rights you have.
1. Who is responsible for your data
Doxfen (Private) Limited (Corporate Unique Identification No. 0316008), House No. 7, Rehman Colony, Canal Road, near Memon Masjid, Jhang 35200, Punjab, Pakistan, is the controller of the personal data described in this policy. Contact us about privacy at info@doxfen.com.
2. What we collect
Information you give us
- Account: name, email address, password (stored only in hashed form by Firebase Authentication), country, date of birth, optional phone number and profile photo, and your consent choices. If you sign in with Google, we receive your name, email address and profile photo from Google.
- Orders: the products you buy, service quotes, orders, milestones, deliverables, and transaction records (amounts, currency, status, invoice numbers).
- Communications: support and project chat messages and files you attach, contact-form messages, and reviews you publish.
Information collected automatically
- IP address: used briefly to protect sign-up, sign-in, email, contact, chat and checkout forms against abuse (rate limiting), and, when you open the sign-up form, sent to GeoJS to suggest your country. We do not store your IP address with your account.
- Sign-in and activity: a session cookie and related browser storage (see our Cookie Policy), your last-active time and online status (used to decide whether to email you about new chat messages), and a timestamp used to sign you out after inactivity.
- Error reports: technical details of errors (browser, page, stack trace) sent to Sentry, with email addresses, tokens, cookies and similar data removed before sending.
Payment information
Card and other payment details are entered on Paddle's checkout and processed by Paddle, not by us. We receive the payment status, amount and a Paddle transaction reference. See Paddle's privacy notice.
We do not use advertising trackers or third-party analytics, and we do not sell your personal data.
3. How and why we use it
- To provide Doxfen and fulfil your orders (performance of our contract with you): creating your account, delivering products, carrying out and delivering services, chat support, receipts and order emails.
- To keep Doxfen secure (our legitimate interest in preventing fraud and abuse): verifying emails, rate limiting, detecting misuse, error monitoring.
- To meet legal obligations: keeping transaction and tax records and responding to lawful requests.
- Marketing emails (only with your consent, which you can withdraw at any time in your account settings or by replying to us).
- Public reviews: when you publish a review, your display name and the review are shown on the product page.
5. How long we keep it
- Account data: while your account is open. When you delete your account, your login is removed and your profile is anonymised straight away.
- Orders, transactions, invoices and the related chats: kept after account deletion for as long as tax, accounting and consumer law require (normally up to 10 years), and to handle refunds, chargebacks and disputes.
- Contact-form messages: up to 2 years.
- Rate-limit counters: expire automatically within 24 hours. Error reports: kept by Sentry for at most 90 days.
6. Your rights
Depending on where you live (for example under the EU/UK GDPR), you may have the right to access, correct, delete, restrict or object to the processing of your data, to receive it in a portable format, and to withdraw consent. You can:
- update your details in Account → Profile;
- delete your account in Account → Settings;
- download a copy of your data here (signed-in users):
For anything else, email info@doxfen.com. We reply within 30 days. You also have the right to complain to the data-protection authority in your country.
7. Security
Data is encrypted in transit (HTTPS) and at rest by our hosting providers. Access to customer data is limited to staff who need it, security rules prevent users from reading each other's data, and sign-in sessions use secure, HTTP-only cookies. No system is completely secure; if a breach affects your data, we will tell you and the relevant authorities as required by law.
8. Children
Doxfen is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
9. Changes to this policy
We will update this policy when our practices change and show the new effective date at the top. Material changes are emailed to account holders before they apply.